• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
  • Contact Us
Search
JTS Health Partners

JTS Health Partners

Revenue Cycle Management, Health Information Management, Information Technology, Analytics, & Advisory Consultation for the Healthcare Industry

  • Client Services
    • Client Services
      • Client Services

        Enhancing performance processes and outcomes through consulting, analytics and operational services within Revenue Cycle Management, Health Information Management, Healthcare Information Technology, Analytics as a Service and Financial Technology

      • Healthcare Management Consulting
    • Revenue Cycle Management | RCM
      • Revenue Cycle Management | RCM

        Best-in-class RCM services, with analytical solutions, that tailor and support strategies to align with our clients’ business goals

      • Revenue Cycle Management
    • Health Information Management | HIM
      • Health Information Management | HIM 

        Auditing, consulting, coding, interim management, staffing support, outsourcing and co-sourcing models for the acute and physician settings

      • Health Information Management HIM
    • Health Information Technology | HIT
      • Health Information Technology | HIT

        Consulting, workflow redesign, project management, analytical and operational support for all phases of enterprise implementation

      • Health Information Technology HIT
    • Healthcare Analytics | nCREAS™
      • Healthcare Analytics | nCREAS™

        Powerful, predictive tools dissect client data to offer insights for coding and revenue capture opportunities, denials improvements, A/R trending and productivity metrics

      • Analytics as a Service AaaS
    • Financial Technology | FinTech
      • FinTech

        Optimizes healthcare systems’, hospitals’ and physician practices’ cash flow and liquidity

      • FinTech
  • Expertise
        • JTS’ highly skilled team offers consulting and operational services that align with performance improvement initiatives of healthcare systems, hospitals and physician practices

        • Advisory & Consulting
        • A/R Valuation
        • Auditing
        • Clinical Documentation Improvement with Physician Advisory
        • Coding
        • Compliance & Regulations
        • CyberSecurity
        • Denials Management
        • E&M Education with Peer-to-Peer Training
        • Extended Business Office
        • Financial Health Ratings
        • Interim Management
        • Legacy Collections
        • Liquidity Planning
        • Operational Assessments with Planning
        • Physician Advisory Services
        • Predictive Modelling
        • Project Management
        • Risk Management
        • Staff Augmentation
        • System Implementation & Support
        • Value-based Care
        • Workflow Management
  • Careers
    • Careers
      • Careers

        Learn more about careers at JTS Healthcare.

    • Job Opportunities
      • Job Opportunities

        Search open job opportunities to find a career that aligns with your interests and skills

  • Insights
    • Insights
      • Insights

        JTS is dedicated to providing educational resources on RCM, HIM, HIT and Analytics related topics

    • News
      • News

        Learn what’s new at JTS

    • Knowledge Center
      • Knowledge Center

        Learn about current topics in the healthcare space

    • Case Studies
      • Case Studies

        Explore outcomes of previous engagements

  • About Us
    • About Us
      • About Us

        JTS endeavors to continue to be recognized as a national healthcare professional services and solutions firm by our clients and employees

      • About Us
    • Mission, Vision & Values
      • Mission, Vision & Values

        Our Mission, Vision & Values are who we are as a company and the culture that we live out each day

      • Our Mission & Values
    • Leadership Team
      • Leadership Team

        JTS’ leadership team has a deep expertise in RCM, HIM, HIT and Analytics

      • Our Team
    • Governance
      • Governance

        JTS adheres to the highest standards of corporate governance practices and procedures in the US

      • Governance
    • Giving Back
      • Giving Back

        We take pride is supporting local events and organizations who make the world a better place

      • Our Mission & Values
    • Events
      • Events

        Search our upcoming events and see past events

      • Events and Webinars
  • Client Services
    • Client Services
    • Revenue Cycle Management | RCM
    • Health Information Management | HIM
    • Health Information Technology | HIT
    • Healthcare Analytics | nCREAS™
    • Financial Technology | FinTech
  • Expertise
    • Advisory & Consulting
    • A/R Valuation
    • Auditing
    • Clinical Documentation Improvement with Physician Advisory
    • Coding
    • Compliance & Regulations
    • CyberSecurity
    • Denials Management
    • E&M Education with Peer-to-Peer Training
    • Extended Business Office
    • Financial Health Ratings
    • Interim Management
    • Legacy Collections
    • Liquidity Planning
    • Operational Assessments with Planning
    • Physician Advisory Services
    • Predictive Modelling
    • Project Management
    • Risk Management
    • Staff Augmentation
    • System Implementation & Support
    • Value-based Care
    • Workflow Management
  • Careers
    • Careers
    • Job Opportunities
  • Insights
    • Insights
    • News
    • Knowledge Center
    • Case Studies
  • About Us
    • About Us
    • Mission, Vision & Values
    • Leadership Team
    • Governance
    • Giving Back
    • Events

Healthcare Cyber Attacks Increase in 2023

August 10, 2023 by Michael Meline, CyberSecurity Officer
Healthcare Cyber and Data Breach

Healthcare Cyber Attacks Affect Roughly 12% of U.S. so far this year

From January 1, 2023, to July 31, 2023, there have been almost 300 reportable “hacking/IT incidents” according to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights’ breach portal.  The number of medical records breached add up to just under 41 million.  With a population of just under 332 million, assuming these medical records have no overlap and are all U.S. citizens, roughly 12% of the U.S. population was breached this year alone.  What is even more concerning is that this represents only 300 hacking/IT breaches that are reportable to HHS.  What about the non-reportable, the undiscovered, the ones that were not reported?

Table of Contents

    "Many medical records breaches are unreported, non-reportable or undiscovered."

    Healthcare Cyber Attacks Compared to Prior Year

    The same timeframe for 2022 showed approximately 190 reportable breaches amounting to approximately 22.5 million medical records having been breached for the same type incidents.  Based on this data, we can clearly see that more records are being reported as breaches this year over last year.  The question is, “Why”?

    Five Factors Influencing Healthcare Cyber Attacks

    In our time working with healthcare organizations, we have discovered that there are several factors influencing these increases:

    1. Poor risk assessments

      The risk assessments we see do not allow quality decisions to be made.  When we review the Enforcement Highlight site, we can reasonably conclude that the risk assessments should have provided information that could have been used to mitigate the possibility of the activities occurring.

    2. Training

      A look at All Case Examples | HHS.gov clearly shows that mistakes have led to many of the issues.  These mistakes should have been mitigated through proper training.  Social Engineering attacks have doubled this year and are very successful.  I am roughly 80% effective in gaining system access using Social Engineering attacks when hired to test employees.  Review the Verizon Annual Breach Report and note the following table.  You must build a strategy around Social Engineering attacks.

    Healthcare cyber attacks

    1. Ransomware

      My company gets at least one call per week from organizations who have had ransomware attacks.  If they have not properly prepared for the attack in advance, they are likely to lose data.  Even when they pay the ransom, they will not get all of the data back.

    2. Poor account management and privilege controls

      Any hacker, cybersecurity professional and anyone with any knowledge of cybersecurity practices will tell you that the gold criminals are after is poorly provisioned accounts because they lead to more money, more notoriety, more data.  We see tons of accounts with too much access, accounts that should have been terminated (but were not), users with administrative access and anything in between.  If I, as a professional hacker, can compromise an account, many times I can evade discovery for long periods of time.  In healthcare, not only do you have the normal HIT accounts, but also medical device accounts.  Most healthcare organizations forget to deal with medical device security.

    3. Medical devices

      The convergence of HIT into the medical device arena has left us withMedical device hack a mess for cybersecurity efforts.  Medical devices MUST be secured!  I could write a thesis paper on this topic and barely scratch the surface.  Medical devices must be risk assessed and managed; split tunneling and multiple unmanaged access to these systems MUST be controlled.  Default credentials must be changed, and credentials SHALL NOT be shared.

    These are not all of the issues found in healthcare cybersecurity attacks, but are some of the primary concerns.  I challenge you to take a look at your risk assessment and see if it clearly and accurately identifies these and other issues.  Review your risk assessment and build a five-year plan.  If your answer is that your risk assessment does not help you to build a five-year plan, your risk assessment is broken and needs to be rewritten.

    Are you ready to mitigate your healthcare cyber risks?

    Get started by sending us a message, and we’ll set up a healthcare risk assessment review.

    Contact JTS
    Category: Articles, CyberSecurity, HIT

    JTS Health Partners

    Serving as trusted advisors and industry leaders, JTS is a healthcare management consulting firm dedicated to meeting the needs of the nation’s many top healthcare organizations in both the private and public sectors.

    About Us

    • About Us
    • Leadership Team

    Client Services

    • Revenue Cycle Management
    • Health Information Management
    • Health Information Technology
    • Healthcare Analytics
    • Extended Business Office

    Contact

    Corporate Office
    45 Technology Parkway South
    Suite 100
    Norcross, GA 30092

    Phone: (404) 816-6107
    Fax: (470) 552-5011
    info@jtshealthpartners.com

    𝕏

    ©2023 JTS Ventures, Inc., d/b/a JTS Health Partners (JTS), a United States entity. All rights reserved. The information contained herein is intended for general guidance only. No one should act upon such information without appropriate professional advice. JTS shall not be responsible for any loss whatsoever sustained by any organization or person who relies on this publication. Site Map