CISA has published a new set of online resources to help healthcare IT security leaders improve their organization’s security posture. The Cybersecurity Toolkit for Healthcare and Public Health includes a range of information, guidance and tools to help reduce cyber threats and successful cyberattacks in the sector.

The toolkit is provided by the Cybersecurity and Infrastructure Security Administration (CISA), the Department of Health and Human Services (HHS), and the Health Sector Coordinating Council (HSCC) Cybersecurity Working Group.
See also: Cyberattack disrupts local hospital services
What does the Cybersecurity Toolkit for Healthcare and Public Health include:
- CISA Cyber Hygiene Services, which use vulnerability to help organizations address vulnerabilities that cybercriminals could use to carry out attacks.
- HHS Cybersecurity Practices for the Healthcare Industry, which outline best practices organizations should implement to stay secure.
- The HHS and the HSCC Sector Cybersecurity Framework Implementation Guide, designed to help organizations assess and improve their level of security and resilience, provides suggestions on how to connect cybersecurity to overall information security and risk management activities.
CISA Deputy Director Nitin Natarajan explained that in 2023, CISA has notified over 65 US healthcare organizations about ransomware infections on their networks.
“Attackers see the healthcare sector and public health organizations as high-value but relatively easy targets,” he added.
Healthcare organizations hold a combination of personal data, financial information, health , and countless medical devices. This means that cybercriminals can obtain valuable information of various kinds with just one attack on such an organization.
See also: Clop ransomware group: Accused of attacks on hospitals
HHS Deputy Secretary Andrea Palm explained that the severity and volume of attacks against hospitals and healthcare providers have increased in recent years.
“These attacks expose vulnerabilities in our healthcare system, undermine patient trust , and ultimately safety patient,” he said.
“HHS is working closely with CISA and our industry partners to provide the tools, resources, and guidance needed to help healthcare organizations, especially under-resourced hospitals and health centers, build strong cyber defenses and protect patient lives,” he added.

Attacks on healthcare organizations
The consequences of cyberattacks on hospitals are multiple and serious. One of the main problems is the disruption of health services, as cyberattacks can disable the systems and electronic infrastructure of hospitals. This can lead to postponements and cancellations of appointments, difficulties in providing medical care and even emergency situations where patients may not receive the necessary help in a timely manner.
See also: NoEscape ransomware: Targets healthcare organizations
Additionally, cyberattacks can lead to the theft or loss of sensitive medical data. This can include information , medical reports, prescriptions, and other personal information. The leakage of this information can have serious consequences for patient privacy and security, as well as trust in the healthcare system.
Cyberattacks can also cause financial losses for hospitals. Service interruptions and appointment postponements can lead to lost revenue.
Finally, there can be serious impacts on the community and society at large. If a hospital is unable to provide effective medical care due to a cyberattack, this can affect the health and well-being of people in the area.
Source: www.infosecurity-magazine.com
