Cybersecurity-as-a-Service provider Critical Insighthas released its new “2023 H1 Healthcare Data Breach Report” on data breaches in the healthcare sector, showing a decrease in the number of breaches but an increase in the number of victims.

The analysis is based on reported data breaches from healthcare organizations to the U.S. Department of Health and Human Services (HHS).
The report shows a 15% decrease in total breaches in the first half of 2023 compared to the second half of 2022. This is of course considered positive, given that attacks targeting this sector have been on the rise in the past. Let's hope that the downward trend continues in the coming months of 2023.
See also: New variant of XLoader macOS Malware disguises itself as OfficeNote app
However, despite the decrease in breaches, there was a significant increase (31%) in the number of people affected by these data breaches in the first half of 2023 (compared to the second half of 2022). This increase resulted in 40 million people being affected within six months , which is equivalent to 74% of the people affected in 2022. The increase in victims shows that the breach incidents, although fewer, had a greater impact.
The leading causes of breaches continue to be hacking and other IT incidents , accounting for 73% of breaches in the first half of 2023. This is followed by unauthorized access and information disclosure , while there were also a few breaches that occurred through theft and loss of files .
The report also highlights a shift in hackers towards exploiting network server vulnerabilities, which accounted for 97% of individual file breaches. In contrast, breaches originating from vulnerabilities email accounted for only 2%.
See also: Which hospitals are affected by the Prospect Medical Holdings system hack?

Another notable finding is the increased targeting of third-party business partners. Breaches involving business partners outnumbered those affecting healthcare providers themselves. Approximately 48% of compromised records were associated with business partners (while 43% were related to healthcare providers).
Critical Insight executive John Delanoemphasized the importance of proactive defense and breach response planning.
“Our report found that hackers are increasingly targeting the weakest links and vulnerabilities in the supply chain, especially business partners or third-party companies that provide services to healthcare organizations. This highlights the importance of effective incident response planning and proactive defense strategies.“.
The report recommends establishing incident response plans, conducting risk assessments, emphasizing cybersecurity among key partners, securing third-party vendors and partners, and investing in cybersecurity.
See also: Google Bard AI: Fake ads are circulating aimed at distributing malware
Data breaches are a major problem these days. They involve the theft of personal or sensitive information by unauthorized individuals. These people can be individual hackers or organized crime groups. A data breach can affect an organization, business , or individual and can cause irreparable damage to the reputation of the company or individual. Once the data is compromised, it can be used for various fraudulent activities, such as identity theft, phishing attacks, and more .
Source: www.infosecurity-magazine.com
