Skip to content
Healthcare

Strong Warning Issued to Hospitals by HHS About EHR Security 

Learn how to protect your healthcare organization’s cloud operations from increasing ransomware attacks.


Last year, the Department of Health & Human Services has issued a strong warning to U.S. hospitals, highlighting the growing cyber threats to healthcare. The Federal agency’s report on hospital cyber resiliency noted that the widespread adoption of health information technology, driven by the Health Information Technology for Economic and Clinical Health (HITECH) Act, the Affordable Care Act, and the 21st Century Cures Act, has expanded the healthcare industry’s vulnerability to cyberattacks. 

“Directly targeted ransomware attacks aimed to disrupt clinical operations are an outsized and growing cyber threat to hospitals,” HHS emphasized. “Ransomware is currently the largest threat to this sector and deserves immediate attention—especially considering the impact the nonavailability of services can have on patient care and safety.” 

Gli attacchi ransomware sono spesso associati al furto di dati sensibili dei pazienti. Secondo ilprogramma di sicurezza informatica dell’HHS, electronic health records (EHRs) are prime targets for cyberattacks because they contain valuable protected health information (PHI) such as names, social security numbers, geographic data, and biometrics. This data is highly profitable for cybercriminals and difficult to secure once exposed. 

Norme di sicurezza relative alle cartelle cliniche elettroniche (EMR/EHR) secondo l’HIPAA

L’avviso dell’HHS evidenzia gravi vulnerabilità nei sistemi informativi sanitari che espongono le organizzazioni ad attacchi ransomware, violazioni dei dati e altre minacce informatiche. Gli operatori sanitari devonoconsiderare questi avvisi come inviti urgenti ad agire, piuttosto che come semplici raccomandazioni di routine. Le implicazioni vanno oltre le semplici questioni tecniche: una sicurezza inadeguata delle cartelle cliniche elettroniche (EHR) comporta responsabilità legali, compromette l’assistenza ai pazienti e danneggia la reputazione delle istituzioni.

Le minacce più comuni alla sicurezza delle cartelle cliniche elettroniche includono:

  • Insider threats: Staff members who accidentally or intentionally misuse their access to patient records.
  • Third-party risks: Vendors and business associates with access to systems but potentially inadequate security practices.
  • Legacy systems: Outdated software and hardware that no longer receive security updates.
  • Mobile device vulnerabilities: Unsecured smartphones and tablets used to access patient information.
  • Cloud security gaps: Inadequate protection for data stored in cloud environments.
  • Phishing attacks: Targeted campaigns designed to steal credentials from healthcare workers.
  • Inadequate backup protocols: Insufficient or untested backup systems that fail during recovery scenarios.

These threats directly connect to HIPAA non-compliance when organizations fail to implement required safeguards. For example, a ransomware attack exploiting unpatched software represents a violation of the HIPAA Security Rule’s system protection requirements.

The financial consequences of these attacks can be severe. According to IBM’s 2024 Cost of a Data Breach Report, healthcare breaches cost organizations an average of $9.77 million. One example is therecent ransomware settlement involving Heritage Valley Health System, where the Office for Civil Rights imposed a $950,000 fine and required a corrective action plan. Incidents like this underscore the importance of robust cybersecurity measures to prevent breaches and reduce risks. 

Le norme di sicurezza relative alle cartelle cliniche elettroniche (EMR/EHR) secondo l’HIPAA prevedono l’implementazione di misure di sicurezza amministrative, fisiche e tecniche ragionevoli e adeguate per la protezione delle informazioni sanitarie protette (ePHI). Lanorma di sicurezza HIPAAstabilisce requisiti specifici per la protezione delle cartelle cliniche elettroniche (EHR). Essa richiede alle entità regolamentate di disporre di:

  • Administrative safeguards: Risk analysis, security management processes, workforce training, and contingency planning.
  • Physical safeguards: Facility access controls, workstation security, and device/media controls.
  • Technical safeguards: Access controls, audit controls, integrity controls, and transmission security.
  • Organizational requirements: Business associate contracts and documentation requirements.
  • Policies and procedures: Implementation of reasonable and appropriate security measures.

Le organizzazioni sanitarie dovrebbero condurre una valutazione completa dei rischi per la sicurezza al fine di identificare le vulnerabilità. Successivamente, dovrebbero sviluppare un piano di rimedio che dia priorità alle lacune critiche, aggiornando le politiche e le procedure di sicurezza, implementando misure di protezione tecniche e fornendo formazione al personale sui protocolli di sicurezza. Audit di sicurezza regolari aiutano a mantenere la conformità continua e ad adattarsi alle minacce emergenti.

Misure di sicurezza EHR e importanza

Poiché gli EHR sono obiettivi primari, la sicurezza è sempre più importante. La sicurezza degli EHR comprende misure di protezione specializzate progettate per proteggere le ePHI all’interno dei sistemi informativi sanitari.La sicurezza degli EHR deve affrontare sia le vulnerabilità tecnichedei sistemi digitali sia i requisiti di privacy specifici imposti dalle normative sanitarie.

La base di un’efficace sicurezza HIPAA EHR si fonda su tre principi fondamentali:

  1. Confidentiality protects against unauthorized access to sensitive patient data.
  2. Integrity maintains the accuracy and consistency of health records throughout their lifecycle.
  3. Availability makes certain that authorized users can access critical information when needed for patient care.

Misure essenziali per la sicurezza delle cartelle cliniche elettroniche

Queste misure di sicurezza EHR possono aiutare le organizzazioni sanitarie a proteggere i dati dei pazienti soddisfacendo al contempo i requisiti HIPAA:

  • Access controls: Role-based permissions that limit data access to authorized personnel based on job function and need-to-know basis.
  • Authentication systems: Multi-factor authentication requiring multiple verification methods before granting system access.
  • Encryption: Data encryption both at rest and in transit to protect information even if systems are breached.
  • Audit trails: Comprehensive logging of all system activities to track who accessed records and what changes were made.
  • Regular EHR security risk analysis: Systematic evaluation of security vulnerabilities and implementation of mitigation strategies.
  • Backup and recovery: Regular data backups with tested recovery procedures to maintain availability during incidents.
  • Physical safeguards: Restricted physical access to servers and workstations containing ePHI.
  • Security awareness training: Ongoing education for all staff on security protocols and threat recognition.

Preoccupazioni relative alla privacy e alla sicurezza dei fascicoli sanitari elettronici (EHR)

L’integrità dei dati e la privacy rappresentano aspetti distinti ma interconnessi delle questioni relative alla privacy e alla sicurezza delle cartelle cliniche elettroniche. L’integrità dei dati si concentra sul mantenimento dell’accuratezza e della completezza delle cartelle cliniche durante tutto il loro ciclo di vita: prevenire alterazioni non autorizzate, rilevare dati danneggiati e preservare l’affidabilità delle informazioni mediche.

La privacy si concentra sul controllo di chi può accedere alle informazioni dei pazienti e in quali circostanze. Entrambi gli elementi richiedono misure di protezione dedicate per mantenere la conformità HIPAA.

Sebbene la crittografia fornisca un livello fondamentale di protezione per i dati EHR, non può fungere da soluzione di sicurezza completa contro le violazioni della sicurezza EHR. I dati crittografati rimangono vulnerabili se i controlli di accesso sono deboli, i sistemi di autenticazione sono compromessi o gli addetti ai lavori abusano dei propri privilegi di accesso legittimi. Le organizzazioni sanitarie devono implementare unapproccio di sicurezza multilivelloche affronti l’intera gamma di potenziali vulnerabilità per risolvere i problemi di privacy e sicurezza EHR.

I controlli di accesso, i registri di audit e le valutazioni periodiche dei rischi operano in sinergia per garantire sia l’integrità che la riservatezza delle cartelle cliniche elettroniche. I controlli di accesso limitano l’esposizione dei dati in base al ruolo e alla necessità. I registri di audit garantiscono la tracciabilità, documentando tutte le interazioni con le informazioni sanitarie protette. Le valutazioni dei rischi identificano le vulnerabilità emergenti prima che possano essere sfruttate.

“The shift to the cloud has gained momentum because it reduces technical debt and improves security,” says Jaimie Fox, Senior Technology Strategist at Microsoft. “Cloud providers offer far greater security than individual hospitals, allowing healthcare providers and EHR vendors to securely move infrastructure while focusing on innovation and efficiency.” 

Many healthcare providers are increasingly recognizing the necessity to take advantage of the cloud’s advantages over traditional infrastructure. However, this shift raises a critical question: How can healthcare organizations protect mission-critical systems from cyber threats while ensuring they remain operational for patient care? 

Miglioramento della sicurezza delle cartelle cliniche elettroniche Cloud

With growing cyber threats to EHR systems, healthcare organizations must adopt proven strategies for cyber resilience. Key methods include leveraging cloud-based security infrastructure, comprehensive risk mitigation, and integrating AI into security workflows to enhance readiness against attacks. 

Grazie aun personale limitato dedicato alla sicurezza informatica, le organizzazioni sanitarie hanno l’opportunità di utilizzare il cloud rafforzare la propria posizione in materia di sicurezza informatica e affrontare il debito tecnico cheaffligge la maggior parte degli ospedali statunitensi. While complying with federal, state, and local regulations is crucial, mitigating cybersecurity risks goes beyond just meeting compliance standards.  

“In cyber resilience, protecting data availability is as critical as ensuring its confidentiality and integrity,” says David Houlding, Microsoft’s Director of Global Healthcare Security and Compliance Strategy. “Healthcare organizations must also defend against breaches, insider threats, and third-party risks, which can cause severe disruptions, including system shutdowns.” 

The cloud’s flexibility and scalability enable the rapid integration of advanced, data-intensive technologies that help healthcare cybersecurity professionals strengthen security and empower clinicians to apply cutting-edge tools to patient care. 

“AI capabilities, which enhance productivity and reduce costs in EHR systems, are only achievable in a cloud environment,” notes Fox. “Traditional on-premises systems cannot support these advanced AI functions, limiting innovation and cutting-edge solutions in clinical care.” 

AI can also revolutionize healthcare cybersecurity by quickly identifying and responding to potential threats to data, systems, and applications.  

“With AI, security analysts can detect and respond to sophisticated attacks, such as phishing and spear phishing, which are now becoming more widespread and cheaper to execute due to attackers also using AI-driven automation,” says Houlding. “Additionally, AI can provide real-time guidance, helping security teams improve their skills on the job, making them better equipped to handle the rapidly evolving threat landscape.” 

As healthcare organizations transition to the cloud, balancing innovation with security is essential.  

Choosing the Right Cyber Resilience Partner 

Sfruttando la sicurezza cloud e le protezioni basate sull’intelligenza artificiale,gli operatori sanitari possono salvaguardare i sistemi critici while driving clinical innovations in patient care. 

“Commvault is a trusted Microsoft partner and a key partner for healthcare organizations seeking true cloud cyber resilience on Azure. They have an unmatched track record, and as you’ve heard from our colleagues, their value proposition is unique and industry-leading, says Karen Cox, Global Healthcare Partner Strategy Leader at Microsoft. 

“Commvault is a leader and early participant in the Microsoft Copilot for Security Partner Program, using the latest technology to protect enterprises,” she continues. “Their solutions are fully integrated with Microsoft security, co-engineered with Microsoft, and adhere to Azure Protection Services standards. This makes Commvault an ideal partner for safeguarding healthcare applications and data, whether in the cloud or a hybrid environment.” 

Healthcare organizations can strengthen their recovery strategies against EHR attacks by leveraging Commvault Cleanroom Recovery, the only solution validated by the Enterprise Strategy Group for ensuring recovery into a guaranteed clean environment. With ransomware posing a top threat, a secure and auditable recovery plan is essential for resuming operations quickly and safely.  

By using Commvault’s advanced cyber resilience platform, healthcare organizations can recover quickly and safely without the risk of reinfection, protecting patient data and ensuring long-term operational security. Download our comprehensive guideto prepare your healthcare organization with practical steps and best practices for cyber recovery.

More related posts


Thumbnail_Blog-Tabletop-Exercise-2026

SaaS Matters – Enterprise Support Made Possible by Clumio

Read more about SaaS Matters – Enterprise Support Made Possible by Clumio
Thumbnail_Blog-QTFY-Advisory-2026

The QTFY Advisory Is More Than a Threat Warning. It Is a Readiness Test.

Read more about The QTFY Advisory Is More Than a Threat Warning. It Is a Readiness Test.
Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio