The heroic, nonstop work of our nation鈥檚 hospitals and health systems, physicians, caregivers and staff continues across the country, as care teams race to treat patients affected by the novel coronavirus (COVID-19) and make every effort to contain its spread. To learn more on this important topic, I encourage you to read AHA President and CEO Rick Pollack鈥檚 March 20 Perspective.  

But a second critical battle also is underway: blocking attempts by cyber criminals seeking to exploit our current situation for financial gain or worse, the interruption of patient care.

These can take many forms, including 鈥渞ansomware鈥 that locks up computer networks unless extortion is paid, and sophisticated phishing emails containing malware that can divert hospitals鈥 payments to a criminal鈥檚 account. Among the most dangerous are the cyberattacks that can render ventilators and other essential life-support medical devices inoperable.

The AHA is monitoring government bulletins and threat information, and sharing information from the field. Hospitals and health systems must recognize mitigating cyber risk that can affect patient care and safety is among their highest priorities.  

Here are a few things you can do: 

For , ensure effective coordination between clinical engineering and information security teams; maintain accurate inventory of devices; and check update and patch status of all software and firmware contained within the devices. For those devices which remain vulnerable, disconnect or segment them from main networks. 

To protect against , implement staff awareness and education, including routine phishing tests. 
For more information, see the recent article by John Riggi, AHA senior advisor for cyber and risk. AHA will continue to bring you resources and information on ways to protect your information systems and guard patient health. If you have specific questions, please contact Riggi at jriggi@aha.org
 

Related News Articles

Headline
The Senate July 29 voted 51-47 along party lines to confirm Susan Monarez as the new director of the Centers for Disease Control and Prevention. Monarez served鈥
Headline
The FBI, Cybersecurity and Infrastructure Security Agency and international agencies July 29 released a joint advisory on recent tactics by the Scattered鈥
Headline
The American Society for Health Care Engineering July 28 announced the recipients of its annual member awards during the 2025 Health Care Facilities Innovation鈥
Perspective
Public
The 2025 AHA Leadership Summit wrapped up on July 22, and as always, it was energizing and inspiring to connect with so many talented and dedicated people鈥
Headline
Microsoft July 22 released an update on the ongoing cyberattacks to SharePoint servers used within organizations, attributing the incidents to China-based鈥
Headline
The FBI, Cybersecurity and Infrastructure Security Agency, Department of Health and Human Services, and Multi-State Information Sharing and Analysis Center鈥