Cyberattacks are having fatal consequences, so the White House wants hospital funding tied to hospital security

American dollars with medical stethescope
(Image credit: Shutterstock)

The Biden administration is looking to introduce a policy that will require US hospitals to meet a certain level of digital security, including multi-factor authentication, in order to secure federal funding.

A number of attacks in recent months have severely impacted hospitals, forcing ambulances to be diverted and non-urgent procedures to be rescheduled.

Hospitals are already bound by a number of requirements relating to building construction, security and how patients are treated in order to secure funding.

Basic cyber hygiene

Hospitals are lucrative targets for ransomware attacks due to the sensitivity and amount of data stored on their systems, and often lack the robust security structure needed to keep cybercriminals out of their systems. The increasing complexity and number of network enabled devices used in medical procedures and patient care increases the vulnerability of hospitals to cyber attacks.

That’s why establishing this basic level of cyber security as a prerequisite for federal funding is seen as a necessary step in preventing cyber attacks against hospitals. Introducing measures such as multi-factor authentication to hospital devices alongside software update timelines can stem the flow of attacks.

An anonymous senior administration official told The Messenger that the government is “homing in on those key cybersecurity practices that we really do believe bring a meaningful impact.” It is expected that this policy will come into effect at some point this year.

The rules for basic cybersecurity are to be proposed in the near future by the Centers for Medicare & Medicaid Services, and will hopefully work in combination with the International Counter-Ransomware Initiative’s pledge of non-payment to ransomware attacks that target government institutions.

Recent studies have shown that cyber attacks on hospitals can have real-world effects on patient health, with a 2022 study finding that some hospitals reported an increase in patient mortality following cyber attacks on IoT devices.

More from TechRadar Pro

Benedict Collins
Staff Writer (Security)

Benedict Collins is a Staff Writer at TechRadar Pro covering privacy and security. Benedict is mainly focused on security issues such as phishing, malware, and cyber criminal activity, but also likes to draw on his knowledge of geopolitics and international relations to understand the motivations and consequences of state-sponsored cyber attacks. Benedict has a MA in Security, Intelligence and Diplomacy, alongside a BA in Politics with Journalism, both from the University of Buckingham.