{"id":17359,"date":"2026-09-21T19:04:00","date_gmt":"2026-09-21T19:04:00","guid":{"rendered":"https:\/\/cjni.net\/journal\/?p=17359"},"modified":"2026-09-30T09:41:20","modified_gmt":"2026-09-30T09:41:20","slug":"cybersecurity-threats-to-hospital-information-systems-a-narrative-review-of-risks-patient-safety-impacts-and-defensive-strategies-with-implications-for-the-united-states","status":"publish","type":"post","link":"https:\/\/cjni.net\/journal\/?p=17359","title":{"rendered":"Cybersecurity Threats to Hospital Information Systems: A Narrative Review of Risks, Patient-Safety Impacts, and Defensive Strategies with Implications for the United States"},"content":{"rendered":"<div class=\"vs-topic\" topic=\"Cybersecurity Threats to Hospital Information Systems: A Narrative Review of Risks, Patient-Safety Impacts, and Defensive Strategies with Implications for the United States\" link=\"https:\/\/cjni.net\/journal\/?p=17359\">\n<p class=\"has-text-align-center\"><em>by <a href=\"mailto:csuchari@calbaptist.edu\">Crissinee Sucharitrak<\/a>, MBA, MSIT, CNA<\/em><\/p>\n\n\n\n<p class=\"has-text-align-center\"><em>Master of Science in Information Technology Management (Business Analytics)<\/em><\/p>\n\n\n\n<p class=\"has-text-align-center\"><em>California Baptist University, Riverside, CA, United States; Independent Researcher<\/em><\/p>\n\n\n\n<p class=\"has-text-align-center\"><em> ORCID: 0009-0007-2825-7755<\/em><\/p>\n\n\n\n<p><strong>Citation:<\/strong> Sucharitrak, C. (2026).&nbsp;Cybersecurity threats to hospital information systems: A narrative review of risks, patient-safety impacts, and defensive strategies with implications for the United States. <em>Canadian Journal of Nursing Informatics, 21<\/em>(3).&nbsp;https:\/\/cjni.net\/journal\/?p=17359<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"640\" height=\"420\" src=\"https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Crissinee-Sucharitrak.png\" alt=\"Cybersecurity Threats to Hospital Information Systems\" class=\"wp-image-17393\" srcset=\"https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Crissinee-Sucharitrak.png 640w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Crissinee-Sucharitrak-300x197.png 300w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Crissinee-Sucharitrak-150x98.png 150w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/figure><\/div>\n\n\n<h2 class=\"wp-block-heading has-text-align-center\"><strong>Abstract<\/strong><\/h2>\n\n\n\n<p><strong>Background:<\/strong> United States (U.S.) hospitals are rapidly embracing technology in clinical processes. However, cybersecurity in hospitals is too often considered from an information-technology (IT) perspective instead of a patient safety perspective.<\/p>\n\n\n\n<p><strong>Objectives:<\/strong> This narrative review provides a synthesis of current evidence on cyber threats to hospital information systems, the impacts of cyberattacks on patient safety, the vulnerabilities used by attackers in human and technical domains, and defenses against those threats.<\/p>\n\n\n\n<p><strong>Methods:<\/strong> Peer-reviewed, open-access articles from PubMed and Europe PMC on hospital cyber threats, patient-safety impacts, vulnerabilities, and defenses were purposively selected and narratively synthesized.<\/p>\n\n\n\n<p><strong>Results:<\/strong> Ransomware attacks, phishing attacks, and data breaches form the threat landscape; human error and insecurely connected medical devices are the main vectors of cyberattacks. The attackers harm hospitals in more ways than just financial losses and privacy violations, but through evident damage to the patients\u2019 treatment delays, ambulance diversion, higher death rates within the hospitals, and worse results of out-of-hospital cardiac arrests even at hospitals close by.<\/p>\n\n\n\n<p><strong>Conclusions:<\/strong> The cybersecurity of hospital information systems is a patient-safety issue, not an IT issue. Layered defenses in socio-technical systems in the form of incident-response preparation, governance, security culture, ongoing workforce training, and emerging technical defense mechanisms should be adopted by U.S. hospitals.<\/p>\n\n\n\n<p><strong>Keywords:<\/strong><em> <\/em>cybersecurity; ransomware; hospital information systems; patient safety; data breach; medical device security; HIPAA; United States; health informatics<\/p>\n\n\n\n<h2 class=\"wp-block-heading has-text-align-center\">Background<\/h2>\n\n\n\n<p>Health care stands out as one of the most technologically advanced, and consequently, most attacked industries in the world economy. In particular, the introduction of electronic health records (EHRs), various medical devices, telemedicine technologies, and cloud-based analytics made the operation of those information systems integral parts of the clinical workflow, and thus any interruption of their work would be a question of patients&#8217; safety. Ransomware attacks against hospitals happen several times per week all over the world (<a href=\"https:\/\/doi.org\/10.1001\/jamanetworkopen.2025.10180\">Jiang et al., 2025<\/a>; <a href=\"https:\/\/doi.org\/10.1136\/tsaco-2026-002293\">Martin et al., 2026<\/a>). The U.S. health care sector is well integrated in this interconnected environment. EHRs are widely adopted; interoperability and the information-blocking regulations of the 21st Century Cures Act promote the exchange of patient data between the institutions, and the emerging Trusted Exchange Framework and Common Agreement (TEFCA) promises national interoperability, thus enabling exchange of patient data between an increasing number of institutions. Interconnectedness means greater exposure.<\/p>\n\n\n\n<p>These risks are concrete, not abstract. Several attacks on health care institutions in the United States occurred since the country experienced various threats to its health care sector, ranging from massive theft of patient data to ransomware events causing long-term hospital outages. Thus, the February 2024 attack on Change Healthcare affected the claim processing, prescription fulfillment, and payment capabilities for about 192.7 million people, and it can be seen as the largest health care data breach in the country&#8217;s history. Moreover, ransomware attacks on health care entities such as Ascension and CommonSpirit led to ambulance diversions and significant outages of electronic health records (EHR). Consequently, digitization is double-edged: the interoperability that makes it possible to coordinate care across organizations also allows vulnerabilities to spread more easily than in a fragmented, paper-based system. Thus, this narrative review aims to provide a synthesis of evidence on (i) the cyber-threat landscape facing hospital information systems, (ii) the impact of attacks on patient safety, (iii) the human and technical vulnerabilities exploited by the attackers, and (iv) protective measures against those threats, considering all of those aspects within the framework of U.S. law and regulation and the U.S. health system structure in order to provide actionable guidance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Scope and approach <\/strong><\/h2>\n\n\n\n<p>The current work presents a narrative, not a systematic, review. Peer-reviewed articles freely available on PubMed\/Europe PMC, as well as other databases relevant to the topic under consideration during the last decade, were selectively used in this paper with special attention paid to systematic reviews, scoping reviews, empirical studies, and incidents&#8217; analysis. Then, the results were grouped according to the categories: threats, impact, vulnerabilities, and mitigation measures, as well as were further analyzed based on the United States laws and regulations, i.e. HIPAA, HITECH Act, and the FDA&#8217;s cybersecurity jurisdiction over medical devices. The aim is to systematize knowledge that would be relevant for U.S. health informatics professionals, rather than conduct an overview of the whole literature on the topic. In total, the synthesis draws on 31 peer-reviewed sources published between 2015 and 2026.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The Cyber-Threat Landscape in Hospital Information Systems<\/strong><\/h2>\n\n\n\n<p>Three kinds of threats prevail in the health care cybersecurity literature, namely ransomware, phishing, and data breaches, and they tend to overlap (<a href=\"https:\/\/doi.org\/10.1001\/jamanetworkopen.2025.10180\">Jiang et al., 2025<\/a>; <a href=\"https:\/\/doi.org\/10.1136\/tsaco-2026-002293\">Martin et al., 2026<\/a>). Ransomware locks down hospital information systems, and then demands ransom for access to the systems, sometimes in a \u201cdouble-extortion\u201d variant, in which data are exfiltrated before encryption (<a href=\"https:\/\/doi.org\/10.1136\/tsaco-2026-002293\">Martin et al., 2026<\/a>). Table 1 provides an overview of the most common types of attacks, their mechanisms, and the risks associated with them.<\/p>\n\n\n\n<p><strong>Table 1<\/strong><\/p>\n\n\n\n<p><em>Principal Cyber-Threats to Hospital Information Systems: Mechanisms, Hospital-Specific Risk, and Relevance to the U.S. Setting<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><a href=\"https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table1.png\"><img decoding=\"async\" loading=\"lazy\" width=\"838\" height=\"1024\" src=\"https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table1-838x1024.png\" alt=\"Table 1\nPrincipal Cyber-Threats to Hospital Information Systems: Mechanisms, Hospital-Specific Risk, and Relevance to the U.S. Setting\n\" class=\"wp-image-17466\" srcset=\"https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table1-838x1024.png 838w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table1-246x300.png 246w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table1-123x150.png 123w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table1-768x938.png 768w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table1.png 875w\" sizes=\"(max-width: 838px) 100vw, 838px\" \/><\/a><\/figure>\n\n\n\n<p>It is crucial to appreciate the stages of development in a typical hospital ransomware attack since at each stage there is room for a possible preventative measure (Figure 1). Most of the ransomware attacks on the health care organizations begin with the initial intrusion into the hospital network via phishing e-mails to gain credentials or install malware, or exposing remote access ports (<a href=\"https:\/\/doi.org\/10.1001\/jamanetworkopen.2019.0393\">Gordon et al., 2019a<\/a>; <a href=\"https:\/\/doi.org\/10.1001\/jamanetworkopen.2025.10180\">Jiang et al., 2025<\/a>). Other activities often include lateral movement inside the network, privilege escalation, and reconnaissance due to the flat architecture of most hospital networks (<a href=\"https:\/\/doi.org\/10.1177\/08404704231195804\">Clarke &amp; Martin, 2023<\/a>). Afterward, large amounts of information are exfiltrated to increase the pressure created by double extortion (<a href=\"https:\/\/doi.org\/10.1136\/tsaco-2026-002293\">Martin et al., 2026<\/a>). Finally, the ransomware is deployed, usually at night or weekends when there is reduced manpower, with the intent of encrypting the electronic health record (EHR) system, the image repository, laboratory systems, and backups. Viewing the ransomware attack as a kill chain transforms cybersecurity into a process in which the attack can be stopped at multiple checkpoints: phishing prevention, multi-factor authentication of remote access, network isolation, data-exfiltration detection, and assured backup availability.<\/p>\n\n\n\n<p><strong>Figure 1<\/strong><\/p>\n\n\n\n<p><em>Hospital Ransomware Kill Chain and Defensive Checkpoints<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><a href=\"https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Figure1.png\"><img decoding=\"async\" loading=\"lazy\" width=\"916\" height=\"274\" src=\"https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Figure1.png\" alt=\"Figure 1\nHospital Ransomware Kill Chain and Defensive Checkpoints\n\" class=\"wp-image-17470\" srcset=\"https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Figure1.png 916w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Figure1-300x90.png 300w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Figure1-150x45.png 150w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Figure1-768x230.png 768w\" sizes=\"(max-width: 916px) 100vw, 916px\" \/><\/a><\/figure>\n\n\n\n<p><em>Note. <\/em>The typical hospital ransomware kill chain and the defensive checkpoint that can interrupt each stage. Because every stage must succeed for the attack to succeed, each layered control is an independent opportunity to stop the intrusion (<a href=\"https:\/\/doi.org\/10.1177\/08404704231195804\">Clarke &amp; Martin, 2023<\/a>; <a href=\"https:\/\/doi.org\/10.1001\/jamanetworkopen.2019.0393\">Gordon et al., 2019a<\/a>; <a href=\"https:\/\/doi.org\/10.1001\/jamanetworkopen.2025.10180\">Jiang et al., 2025<\/a>; <a href=\"https:\/\/doi.org\/10.1136\/tsaco-2026-002293\">Martin et al., 2026<\/a>). EHR = electronic health record.<\/p>\n\n\n\n<p>Phishing is the main type of attack and usually serves as the entry point for the others: many cases in health care involve emails aimed at stealing credentials or deploying malware. Busy health care practitioners are an easy prey for phishing (<a href=\"https:\/\/doi.org\/10.1001\/jamanetworkopen.2019.0393\">Gordon et al., 2019a<\/a>; <a href=\"https:\/\/doi.org\/10.1001\/jamanetworkopen.2025.10180\">Jiang et al., 2025<\/a>). Data breach, regardless of whether it occurs due to external sources, insiders or compromise of third-party vendors, act as the vehicle through which health data becomes exposed (<a href=\"https:\/\/doi.org\/10.1001\/jamanetworkopen.2025.10180\">Jiang et al., 2025<\/a>). Organization-specific characteristics influence the target population: a population-based study has found out that larger hospitals, teaching hospitals and trauma centers were the most susceptible to ransomware attacks due to their high value (<a href=\"https:\/\/doi.org\/10.1093\/haschl\/qxad037\">McGlave et al., 2023<\/a>). Why does health care suffer disproportionately from cyberattacks? There are at least three sector-specific factors which make it a highly attractive target for cybercriminals. First, clinical data fetch high prices on illicit markets due to the uniqueness of their nature: they combine financial, identity and medical information that cannot be reset. Second, the need for uninterrupted, life-critical operations pressures victims to pay quickly to restore function. Third, the sector has gone through rapid digitalization while investing far less in security (<a href=\"https:\/\/doi.org\/10.1007\/s10877-023-01013-5\">Cartwright, 2023<\/a>; <a href=\"https:\/\/doi.org\/10.1177\/08404704231195804\">Clarke &amp; Martin, 2023<\/a>).<\/p>\n\n\n\n<p>All these factors are additionally amplified by structural features: legacy information technology (IT) infrastructure, unpatched software, flattened networks that allow lateral movement, lack of proper separation of traffic, and underfunding of security personnel predictably create the openings attackers exploit (<a href=\"https:\/\/doi.org\/10.1177\/08404704231195804\">Clarke &amp; Martin, 2023<\/a>). Third-party and supply chain dependence expands the scope of possibilities of attackers even further: compromising a software vendor, a cloud provider or an outsourced service can result in subsequent compromise of all hospitals using it. This was the case in a number of large data breaches in the United States, including the 2024 Change Healthcare incident: compromise of a vendor compromised thousands of health-care organizations that depended on it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The COVID-19 Stress Test<\/strong><\/h2>\n\n\n\n<p>The COVID-19 pandemic served as a global stress test of health-care cybersecurity, and its lessons remain useful for resilience planning. A scoping review of cybersecurity in the \u201cclimate of COVID-19\u201d indicated that the rapid shift to telehealth and remote work enlarged the attack surface much faster than it could be secured, which cybercriminals actively exploited (<a href=\"https:\/\/doi.org\/10.2196\/21747\">He et al., 2021<\/a>). In the United States, where telehealth became popular thanks to the Medicare and Medicaid waiver programs and some flexibilities were later made permanent, this message is especially important: any expansion of telehealth should be accompanied by security investments right away.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Patient Safety and Care Delivery Impacts<\/strong><\/h2>\n\n\n\n<p>There is one important shift in the contemporary evidence base in comparison to earlier times: today, a cyberattack is considered a patient-safety event, not just a data incident. Previously, cybersecurity in health care was defined by confidentiality and measured by breaches and fines; now it is clear that the availability and integrity of clinical systems are what determines whether it is possible to deliver safe care: inability to use the EHR, laboratories, imaging and drug management systems makes safe care far harder to deliver (<a href=\"https:\/\/doi.org\/10.1001\/jamanetworkopen.2025.10180\">Jiang et al., 2025<\/a>; <a href=\"https:\/\/doi.org\/10.1136\/tsaco-2026-002293\">Martin et al., 2026<\/a>). The impacts include canceled and delayed procedures and diagnostics, ambulance diversion, longer hospital stays, a shift to error-prone manual work, and, most importantly, higher in-hospital mortality (<a href=\"https:\/\/doi.org\/10.7759\/cureus.83614\">Aldosari, 2025<\/a>; <a href=\"https:\/\/doi.org\/10.1001\/jamanetworkopen.2025.10180\">Jiang et al., 2025<\/a>).<\/p>\n\n\n\n<p>The information security triad of confidentiality, integrity, and availability can help localize clinical harm. Availability problems are the most obvious: when the EHR becomes inaccessible, clinicians switch to paper documentation and lose key sources of information such as medication histories and allergy lists (<a href=\"https:\/\/doi.org\/10.3389\/fdgth.2024.1321485\">Abbou et al., 2024<\/a>). Integrity problems are less obvious but potentially more harmful: manipulated data, incorrect laboratory results or wrong patient identity can lead to incorrect decisions even after recovery.<\/p>\n\n\n\n<p>Importantly, the harm is not confined to the attacked institution. After a ransomware attack in one health system, the incidence and outcomes of out-of-hospital cardiac arrest worsened at untargeted neighboring hospitals because of patient diversion (<a href=\"https:\/\/doi.org\/10.1097\/cce.0000000000001079\">Pham et al., 2024<\/a>). This kind of \u201cspillover\u201d is particularly important for the United States where there are several regional referral centers and Level I trauma hospitals forming networks with other community hospitals; halting a hub leads to overflow of adjacent hospitals that are already overloaded.<\/p>\n\n\n\n<p>All these results show that cybersecurity is an important element of clinical governance: the cyberattack disrupts the processes which are the subject of quality-and-safety programs (<a href=\"https:\/\/doi.org\/10.7759\/cureus.83614\">Aldosari, 2025<\/a>). In the United States, where safety-net and rural hospitals operate with narrow margins, this vulnerability directly impacts access for the patients: people who cannot afford a delayed visit or a diverted ambulance are the very people these hospitals serve.<\/p>\n\n\n\n<h1 class=\"wp-block-heading has-text-align-center\"><strong>Human and Technical Vulnerabilities<\/strong><\/h1>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The Human Factor<\/strong><\/h2>\n\n\n\n<p>Human behavior is the most reliably exploited vulnerability, and by design: most successful intrusions rely on a person opening an attachment, reusing a password, or falling for social engineering. Thus, the workforce represents the largest attack surface and the key defense line, which is why technical means alone cannot prevent cyberattacks. A large multicenter simulation study of the susceptibility to phishing attacks in U.S. hospitals showed meaningful click rates, and even more importantly, that repeated exposure decreases the susceptibility (<a href=\"https:\/\/doi.org\/10.1001\/jamanetworkopen.2019.0393\">Gordon et al., 2019a<\/a>). However, such change does not happen automatically: a mandatory training program targeting the most vulnerable employees failed to produce statistically significant change, which means that broader approaches are needed (<a href=\"https:\/\/doi.org\/10.1093\/jamia\/ocz005\">Gordon et al., 2019b<\/a>). Another single-center study showed that realistic and tailored phishing lures work better and that a full-fledged awareness program, not just compliance training, is required (<a href=\"https:\/\/doi.org\/10.1177\/20552076221081716\">Rizzoni et al., 2022<\/a>).<\/p>\n\n\n\n<p>There are two particularities of the clinical setting which make this process more complicated. First, clinicians are subjected to time pressure and have high cognitive load, and this is what makes the attacks effective: a carefully crafted phishing lure posing as a colleague or a patient exploits exactly this situation. Second, the clinical settings are known to have poor credential practices (shared workstations, written-down passwords for quick access, and reused login credentials) that make technical controls ineffective, which is why multi-factor authentication and single sign-on are always recommended. If clinicians see security as an IT problem, their compliance becomes reluctant and workarounds appear, and cyber hygiene methodology is proposed to address this issue (<a href=\"https:\/\/doi.org\/10.2196\/41294\">Argyridou et al., 2023<\/a>). Contemporary research highlights the dual dynamics of the problem: on the one hand, advancement of artificial intelligence (AI) makes phishing more sophisticated, providing localization of the attacks on a large scale; on the other hand, it also provides additional tools to fill data gaps and improve the human security posture; at the same time, AI in clinical settings creates attack vectors for hackers (<a href=\"https:\/\/doi.org\/10.1371\/journal.pdig.0001063\">Jalali &amp; Largman, 2025<\/a>), and intelligent medical devices pose unique cybersecurity challenges (<a href=\"https:\/\/doi.org\/10.2147\/rmhp.s544523\">Di Palma et al., 2025<\/a>).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Vulnerable Medical Devices and the Internet of Medical Things<\/strong><\/h2>\n\n\n\n<p>Networked medical devices represent a large part of the attack surface. Devices such as infusion pumps and imaging systems often come with default or hardcoded credentials and outdated software versions, which makes them much more vulnerable than regular IT products (<a href=\"https:\/\/doi.org\/10.1038\/s41598-023-45927-1\">Bracciale et al., 2023<\/a>; <a href=\"https:\/\/doi.org\/10.2147\/MDER.S50048\">Williams &amp; Woodward, 2015<\/a>). Originally created for standalone use, these devices become exposed to the threats they were never designed to defend against after becoming connected to the hospital network (<a href=\"https:\/\/doi.org\/10.2147\/MDER.S50048\">Williams &amp; Woodward, 2015<\/a>). Remediation prioritization approaches are developing: the Common Vulnerability Scoring System adjusted to the biomedical technology environment (CVSS BTE) allows for quantification of the cyber risk of medical devices in clinically meaningful units (<a href=\"https:\/\/doi.org\/10.1038\/s41598-025-26898-x\">Bracciale et al., 2025<\/a>).<\/p>\n\n\n\n<p>Results of the scoping review and systematic review of Internet of Medical Things (IoMT) cybersecurity have shown that the approaches of risk assessment are maturing but are inconsistently applied, and machine learning is used increasingly for detection of abnormal device behavior (<a href=\"https:\/\/doi.org\/10.7717\/peerj-cs.414\">Hameed et al., 2021<\/a>; <a href=\"https:\/\/doi.org\/10.2147\/JMDH.S459987\">Svandova &amp; Smutny, 2024<\/a>); meanwhile, implementation of medical device security programs with inventory, procurement policies, patching and lifecycle governance is recommended but is not common practice yet (<a href=\"https:\/\/doi.org\/10.2345\/0899-8205-56.3.92\">Youssef, 2022<\/a>). The result is many medical devices that are difficult to patch, replace, and disconnect, especially in resource-poor institutions which rely on aging equipment. Many imaging, laboratory, and monitoring systems in U.S. hospitals run operating systems that no longer receive vendor updates yet remain in service, so the practical near-term defense is network isolation. Procurement is another tool which is underutilized: embedding security requirements into the purchase contract (such as password management, update requirements, and end-of-support notification) defines the risk of a device throughout its lifespan, and the FDA now mandates pre-market cybersecurity for networked medical devices.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The U.S. Regulatory and Health-System Context<\/strong><\/h2>\n\n\n\n<p>Regulation of health care cybersecurity in the United States is based on HIPAA and its implementing regulations. The HIPAA Security Rule mandates that covered entities and their business associates implement administrative, physical and technical safeguards for electronic protected health information (ePHI), such as risk analysis, access controls, audit logging and contingency planning. The Breach Notification Rule, introduced by the HITECH Act of 2009, requires that the covered entities notify the affected individuals of a breach within 60 days of discovery, and to report the breach to the Secretary of Health and Human Services, as well as to media if more than 500 individuals were affected, with the Office for Civil Rights (OCR) publishing the notifications publicly. OCR investigates breaches and can impose civil monetary penalties, while the Healthcare and Public Health Sector is designated as critical infrastructure and can draw on Cybersecurity and Infrastructure Security Agency (CISA) and U.S. Department of Health and Human Services (HHS) resources, including 405(d) Health Industry Cybersecurity Practices and premarket cybersecurity requirements for medical devices mandated by the FDA. In the United States, therefore, a hospital data breach is a failure in regulatory compliance, a potential critical-infrastructure incident, and a crime committed by the attackers: a triple threat that raises the stakes for hospital executives. Table 2 shows the major legislative and policy instruments and their practical implications for hospitals.<\/p>\n\n\n\n<p><strong>Table 2<\/strong><\/p>\n\n\n\n<p><em>Principal U.S. Legal and Policy Instruments Governing Hospital Cybersecurity and Their Practical Implications<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><a href=\"https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table2.png\"><img decoding=\"async\" loading=\"lazy\" width=\"797\" height=\"1024\" src=\"https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table2-797x1024.png\" alt=\"Table 2\nPrincipal U.S. Legal and Policy Instruments Governing Hospital Cybersecurity and Their Practical Implications\n\" class=\"wp-image-17506\" srcset=\"https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table2-797x1024.png 797w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table2-234x300.png 234w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table2-117x150.png 117w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table2-768x986.png 768w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table2.png 876w\" sizes=\"(max-width: 797px) 100vw, 797px\" \/><\/a><\/figure>\n\n\n\n<p>HIPAA breach notification requirements change the purpose of incident response. A 60-day period coupled with media notifications and posting on the OCR website for substantial breaches means that hospitals cannot begin building detection, escalation, and reporting processes only after a cyberattack occurs; hence, hospitals should be equipped with monitoring capabilities that will allow detecting breaches, analyzing their scale, and establishing communication channels. In other words, the need to comply with \u201creasonable and appropriate\u201d safeguard standards transforms encryption, access controls, and audit logging into regulatory standards. Moreover, using cloud services and forming business associate relationships adds one more element to compliance because, along with uploading ePHI to cloud services and sharing it in order to develop AI, there are compliance problems related to business associate agreements, data governance, and data localization (<a href=\"https:\/\/doi.org\/10.2196\/58338\">Kaushik et al., 2025<\/a>).<\/p>\n\n\n\n<p>The first thing is that enforcing these responsibilities has proven to be very evident: the Office for Civil Rights (OCR) has imposed settlements and civil monetary penalties in six and seven figures in relation to non-compliance with the Security Rule, including the failure in risk analysis, encryption, and access controls after ransomware attacks and phishing. HIPAA\u2019s Security and Breach Notification Rules are being enforced, and hospitals need to regard them as mandatory and not optional or simply administrative. The review of the policies on digital health, cyber security regulations and their relation to artificial intelligence shows that having a clear framework of regulation is required for incorporating such technologies; however, without the ability to enforce this regulation, regulation itself is meaningless (<a href=\"https:\/\/doi.org\/10.7759\/cureus.80676\">Virk et al., 2025<\/a>). Yet organizational readiness does not always match regulatory ambitions, and there is inequality in this regard. While being characterized by the most advanced health cybersecurity environment, the United States shows evident inequalities in terms of cybersecurity capabilities among organizations. Budgets for cybersecurity, experience, and technological tools for implementing it are usually found in larger and integrated delivery networks and academic medical centers. Critical access and small hospitals and safety net hospitals that hold sensitive information and participate in regional and national data exchange do not have specialists who can deal with cybersecurity. Being part of the interconnected system, they make the whole system vulnerable.<\/p>\n\n\n\n<p>Experiences in the U.S. shows the trade-off between connectivity and vulnerability. This issue gets even clearer with the national interoperability: health information exchange programs, information blocking from the Cures Act, and TEFCA move towards seamless data exchange, meaning that a breach at one node will cause data exposure and interruption at another one. Despite the existence of strong governance structures, organizations have different levels of workforce competency, cybersecurity culture, preparedness for incident management and legacy system mitigation; all these areas have been proved to be the riskiest according to research (<a href=\"https:\/\/doi.org\/10.1177\/08404704231195804\">Clarke &amp; Martin, 2023<\/a>).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Defensive Strategies<\/strong><\/h2>\n\n\n\n<p>The literature shows a consensus on defense in depth, a layered socio-technical defense strategy rather than reliance on a single control solution (<a href=\"https:\/\/doi.org\/10.1177\/08404704231195804\">Clarke &amp; Martin, 2023<\/a>; <a href=\"https:\/\/doi.org\/10.3389\/fdgth.2022.862221\">Wasserman &amp; Wasserman, 2022<\/a>). Because no safeguard is perfect, controls are layered so that the failure of one control (for instance, clicking on the phishing email link) will be detected and addressed by another one (network segmentation preventing lateral movement; offline backups allowing restoration of the compromised system). The term \u201csocio-technical\u201d implies that the people and processes matter just as much as the technology: an organization that has advanced tools but no security culture, no incident response plan, and no skilled workforce remains vulnerable. Table 3 presents the layers of defense in the U.S. setting and a realistic implementation horizon.<\/p>\n\n\n\n<p><strong>Table 3<\/strong><\/p>\n\n\n\n<p><em>Layered Socio-Technical Defenses, Their Relevance to the U.S. Context, and a Realistic Implementation Horizon<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><a href=\"https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table3.png\"><img decoding=\"async\" loading=\"lazy\" width=\"780\" height=\"1024\" src=\"https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table3-780x1024.png\" alt=\"Table 3\nLayered Socio-Technical Defenses, Their Relevance to the U.S. Context, and a Realistic Implementation Horizon\n\" class=\"wp-image-17515\" srcset=\"https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table3-780x1024.png 780w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table3-229x300.png 229w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table3-114x150.png 114w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table3-768x1008.png 768w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table3.png 891w\" sizes=\"(max-width: 780px) 100vw, 780px\" \/><\/a><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Incident-response preparedness<\/strong> <\/h2>\n\n\n\n<p>Plans based on an established lifecycle of preparation, detection and analysis, containment and eradication, recovery, and post-incident review help hospitals run safely in an attack. Health-care incident responses require clear continuity plans that prioritize restoring safe, essential systems first. Downtime procedures are supposed to be rehearsed, not improvised on the spot (<a href=\"https:\/\/doi.org\/10.1177\/08404704231195804\">Clarke &amp; Martin, 2023<\/a>; <a href=\"https:\/\/doi.org\/10.1136\/tsaco-2026-002293\">Martin et al., 2026<\/a>; <a href=\"https:\/\/doi.org\/10.1038\/s41598-021-98576-7\">Willing et al., 2021<\/a>). In the United States, conformity of these plans with the HIPAA breach notification timeline makes it both a compliance and a safety issue.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Governance, self-assessment, and accountability<\/strong><\/h2>\n\n\n\n<p>Effective programs assign shared ownership across information technology, administration, and clinical leadership, define roles and responsibilities explicitly, allocate adequate resources, and secure board-level accountability, so that cybersecurity is managed as an enterprise-wide risk rather than a departmental concern (<a href=\"https:\/\/doi.org\/10.1177\/08404704231195804\">Clarke &amp; Martin, 2023<\/a>; <a href=\"https:\/\/doi.org\/10.2345\/0899-8205-56.3.92\">Youssef, 2022<\/a>). Structured self-assessment instruments let hospitals, particularly smaller ones, gauge and raise their security posture without commissioning an external audit (<a href=\"https:\/\/doi.org\/10.1186\/s12911-024-02551-x\">Burke et al., 2024<\/a>). Such tools fit resource-limited U.S. settings well: rural and Critical Access hospitals can pinpoint their weakest controls and invest in affordable, targeted fixes instead of a costly wholesale overhaul. Networked medical devices, in turn, require dedicated programs built around procurement standards, asset inventories, and disciplined patch management (<a href=\"https:\/\/doi.org\/10.1038\/s41598-025-26898-x\">Bracciale et al., 2025<\/a>; <a href=\"https:\/\/doi.org\/10.2345\/0899-8205-56.3.92\">Youssef, 2022<\/a>).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Security culture and workforce training<\/strong><\/h2>\n\n\n\n<p>Considering the human factor, consistent, realistic, role-based training and regular phishing simulations are required, and there is evidence that they need to be conducted not once but regularly to cause behavioral changes (<a href=\"https:\/\/doi.org\/10.1001\/jamanetworkopen.2019.0393\">Gordon et al., 2019a<\/a>, <a href=\"https:\/\/doi.org\/10.1093\/jamia\/ocz005\">2019b<\/a>; <a href=\"https:\/\/doi.org\/10.1177\/20552076221081716\">Rizzoni et al., 2022<\/a>). Apart from the individual training, creating an organizational security culture is crucial; a multi-site survey of health-care critical infrastructures designed instruments to measure and improve security culture (<a href=\"https:\/\/doi.org\/10.3390\/healthcare10020327\">Gioulekas et al., 2022<\/a>), as well as cyber-hygiene methodologies to raise awareness (<a href=\"https:\/\/doi.org\/10.2196\/41294\">Argyridou et al., 2023<\/a>).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Technical resilience and emerging safeguards<\/strong><\/h2>\n\n\n\n<p>Encryption, network segmentation (including the isolation of vulnerable devices), fast patching, and backup solutions minimize both the probability and consequences of a cyberattack (<a href=\"https:\/\/doi.org\/10.1038\/s41598-023-45927-1\">Bracciale et al., 2023<\/a>; <a href=\"https:\/\/doi.org\/10.2147\/JMDH.S459987\">Svandova &amp; Smutny, 2024<\/a>; <a href=\"https:\/\/doi.org\/10.2147\/MDER.S50048\">Williams &amp; Woodward, 2015<\/a>) and comply with the technical safeguard requirements of the HIPAA Security Rule. Strong backups that are stored offline and\/or in an immutable manner and are tested by frequent restoration procedures make it possible to recover from ransomware without paying any money, depriving attackers of their means of blackmail based on encryption. Multi-factor authentication for remote logins and privileged users prevents two major attack surfaces, while network segmentation limits the possibility of lateral movement. Zero Trust security, which relies on verification of every attempt without assuming trust within the internal network, is now being applied in health care (<a href=\"https:\/\/doi.org\/10.1177\/11786329231187826\">Vukotich, 2023<\/a>). All these advances will help to strengthen the existing foundation of good governance and human factors. A hospital without backups, multi-factor authentication and qualified staff will not benefit much from these advanced analytics.<\/p>\n\n\n\n<h1 class=\"wp-block-heading has-text-align-center\"><strong>Discussion<\/strong><\/h1>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Gaps and Recommendations for U.S. Hospitals<\/strong><\/h2>\n\n\n\n<p>In view of the synthesized research evidence in the context of U.S. hospitals, there are a variety of gaps and areas of concern that can be identified. First, the issue of cybersecurity needs to be integrated into the processes of hospital accreditation and clinical governance as a safety parameter for patients and not be seen as an IT-only activity (<a href=\"https:\/\/doi.org\/10.7759\/cureus.83614\">Aldosari, 2025<\/a>; <a href=\"https:\/\/doi.org\/10.1007\/s10877-023-01013-5\">Cartwright, 2023<\/a>). Second, considering the key role of humans in the process, it would be reasonable to provide employees with obligatory and continuous phishing awareness training along with other measures to promote the cybersecurity culture (<a href=\"https:\/\/doi.org\/10.3390\/healthcare10020327\">Gioulekas et al., 2022<\/a>; <a href=\"https:\/\/doi.org\/10.1001\/jamanetworkopen.2019.0393\">Gordon et al., 2019a<\/a>; <a href=\"https:\/\/doi.org\/10.1177\/20552076221081716\">Rizzoni et al., 2022<\/a>). Third, the programs of cybersecurity in relation to medical devices and IoMT need to be developed; the first step could be the development of an inventory of assets, connectivity mapping, procurement criteria, and risk assessment (<a href=\"https:\/\/doi.org\/10.1038\/s41598-025-26898-x\">Bracciale et al., 2025<\/a>; <a href=\"https:\/\/doi.org\/10.2147\/JMDH.S459987\">Svandova &amp; Smutny, 2024<\/a>; <a href=\"https:\/\/doi.org\/10.1186\/s12911-020-01259-y\">Willing et al., 2020<\/a>; <a href=\"https:\/\/doi.org\/10.2345\/0899-8205-56.3.92\">Youssef, 2022<\/a>). Fourth, the hospitals must work on creating and practicing the plans for dealing with the incident and downtime (<a href=\"https:\/\/doi.org\/10.3389\/fdgth.2024.1321485\">Abbou et al., 2024<\/a>; <a href=\"https:\/\/doi.org\/10.1038\/s41598-021-98576-7\">Willing et al., 2021<\/a>). Fifth, the small hospitals need to conduct self-assessment activities to develop a proper posture as well as to rationally allocate resources (<a href=\"https:\/\/doi.org\/10.1186\/s12911-024-02551-x\">Burke et al., 2024<\/a>; <a href=\"https:\/\/doi.org\/10.2196\/47311\">Hasegawa et al., 2024<\/a>). Sixth, the government, payers, and health care systems will have to ensure that the capacity building process is combined with current regulations to achieve the goal of becoming resilient (<a href=\"https:\/\/doi.org\/10.1177\/08404704231195804\">Clarke &amp; Martin, 2023<\/a>; <a href=\"https:\/\/doi.org\/10.2196\/10059\">Jalali &amp; Kaiser, 2018<\/a>; <a href=\"https:\/\/doi.org\/10.7759\/cureus.80676\">Virk et al., 2025<\/a>). All the abovementioned priorities can be realized step-by-step. Table 4 presents them in the form of recommendations for U.S. hospital leaders.<\/p>\n\n\n\n<p><strong>Table 4<\/strong><\/p>\n\n\n\n<p><em>Key priorities for U.S. hospital cybersecurity<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><a href=\"https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table4.png\"><img decoding=\"async\" loading=\"lazy\" width=\"864\" height=\"762\" src=\"https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table4.png\" alt=\"Table 4\nKey priorities for U.S. hospital cybersecurity\n\" class=\"wp-image-17536\" srcset=\"https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table4.png 864w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table4-300x265.png 300w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table4-150x132.png 150w, https:\/\/cjni.net\/journal\/wp-content\/uploads\/2026\/09\/Sucharitrak-Table4-768x677.png 768w\" sizes=\"(max-width: 864px) 100vw, 864px\" \/><\/a><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Limitations<\/strong><\/h2>\n\n\n\n<p>Several limitations are evident with respect to this review. As it has taken a narrative form, the literature has been selected based on purposeful selection instead of systematic selection. This means that there is a chance that relevant literature might have been overlooked and selection bias cannot be excluded. Limiting the scope to freely available, English-language articles ensured that every cited source could be independently verified, although relevant findings in subscription or non-English publications may have been missed. The most solid empirical data is that available for developed nations, and some statements regarding U.S. regulation and the national incident landscape rest on legislative and regulatory documents rather than peer-reviewed empirical studies. Because cybersecurity evolves rapidly, some developments may postdate the reviewed literature, and further U.S.-focused empirical research on the prevalence, costs, and effectiveness of hospital countermeasures is needed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading has-text-align-center\"><strong>Conclusion<\/strong><\/h2>\n\n\n\n<p>Cyberattacks on hospital information systems evolved from incidents related to data privacy and confidentiality into patient-safety events capable of causing delayed treatment, disruption of emergency services, and an increase in the mortality rate even among patients who visited other hospitals that were not affected by the attacks. Consequently, the issues of cybersecurity should not be considered in terms of breaches of confidentiality but in terms of availability and integrity that can be measured by clinical outcomes. The most important vulnerabilities are human, procedural, and cultural, not technological. The major online risks, including ransomware, phishing, data breaches, and insecure connectivity, exploit vulnerabilities that are well-known and solvable. The United States has the framework of regulations in the field of health-care cybersecurity (HIPAA, the HITECH Act, and FDA regulation of medical devices), but making this framework work requires the acquisition of competencies, cybersecurity culture, incident preparedness, governance of the medical devices, and modernization of legacy systems; these tasks are unevenly distributed among integrated delivery networks, academic medical centers, and resource-poor rural and safety-net hospitals. As U.S. health care keeps digitizing, cybersecurity should be considered an essential part of safe and equitable care delivery.<\/p>\n\n\n\n<h2 class=\"wp-block-heading has-text-align-center\"><strong>Acknowledgments<\/strong><\/h2>\n\n\n\n<p>AI software (Claude, Anthropic) was used only for citation assistance. All references were independently validated by the author against their sources. Literature review and manuscript writing were conducted independently by the author, and the author alone is responsible for the correctness of the references presented.<\/p>\n\n\n\n<h2 class=\"wp-block-heading has-text-align-center\"><strong>Declarations<\/strong><\/h2>\n\n\n\n<p>Ethics approval and consent to participate. Not applicable. This review uses only articles that have already been published and peer reviewed; it does not include any experiments on humans or animals and does not use primary data; therefore, ethics-committee approval or consent to participate was unnecessary for this review.<\/p>\n\n\n\n<p>Funding. This research did not receive financial support from any public, private, or non-governmental organization.<\/p>\n\n\n\n<p>Conflict of interest. The author declares no competing interests.<\/p>\n\n\n\n<p>Data availability. No new data or materials were generated. All data and materials cited are peer-reviewed, open access articles referenced in the References list.<\/p>\n\n\n\n<p>Author contributions. CS is the sole author and performed the conceptualization, literature search and screening, analysis, interpretation, and manuscript preparation herself and approved the final version of the manuscript.<\/p>\n\n\n\n<h2 class=\"wp-block-heading has-text-align-left\"><strong>References<\/strong><\/h2>\n\n\n\n<p>Abbas, H. S. M., Qaisar, Z. H., Ali, G., Alturise, F., &amp; Alkhalifah, T. (2022). Impact of cybersecurity measures on improving institutional governance and digitalization for sustainable healthcare. <em>PloS One<\/em>, <em>17<\/em>(11), e0274550. <a href=\"https:\/\/doi.org\/10.1371\/journal.pone.0274550\">https:\/\/doi.org\/10.1371\/journal.pone.0274550<\/a><\/p>\n\n\n\n<p>Abbou, B., Kessel, B., Ben Natan, M., Gabbay-Benziv, R., Dahan Shriki, D., Ophir, A., Goldschmid, N., Klein, A., Roguin, A., &amp; Dudkiewicz, M. (2024). When all computers shut down: The clinical impact of a major cyber-attack on a general hospital. <em>Frontiers in Digital Health, 6<\/em>, 1321485. <a href=\"https:\/\/doi.org\/10.3389\/fdgth.2024.1321485\">https:\/\/doi.org\/10.3389\/fdgth.2024.1321485<\/a><\/p>\n\n\n\n<p>Abdelhamid M. (2020). The role of health concerns in phishing susceptibility: Survey Design study. <em>Journal of Medical Internet Research<\/em>, <em>22<\/em>(5), e18394. https:\/\/doi.org\/10.2196\/18394<\/p>\n\n\n\n<p>Aldosari, B. (2025). Cybersecurity in healthcare: New threat to patient safety. <em>Cureus<\/em>. https:\/\/doi.org\/10.7759\/cureus.83614<\/p>\n\n\n\n<p>Argyridou, E., Nifakos, S., Laoudias, C., Panda, S., Panaousis, E., Chandramouli, K., Navarro-Llobet, D., Mora Zamorano, J., Papachristou, P., &amp; Bonacina, S. (2023). Cyber hygiene methodology for raising cybersecurity and data privacy awareness in health care organizations: Concept study. <em>Journal of Medical Internet Research, 25<\/em>, e41294. https:\/\/doi.org\/10.2196\/41294<\/p>\n\n\n\n<p>Bracciale, L., Loreti, P., &amp; Bianchi, G. (2023). Cybersecurity vulnerability analysis of medical devices purchased by national health services. <em>Scientific Reports, 13<\/em>(1), 19509. https:\/\/doi.org\/10.1038\/s41598-023-45927-1<\/p>\n\n\n\n<p>Bracciale, L., Riozzi, S., Panico, G., Raso, E., Bianchi, G., &amp; Loreti, P. (2025). Quantifying medical device cybersecurity risk with CVSS BTE. <em>Scientific Reports, 15<\/em>(1), 42635. https:\/\/doi.org\/10.1038\/s41598-025-26898-x<\/p>\n\n\n\n<p>Burke, W., Stranieri, A., Oseni, T., &amp; Gondal, I. (2024). The need for cybersecurity self-evaluation in healthcare. <em>BMC Medical Informatics and Decision Making, 24<\/em>(1), 133. https:\/\/doi.org\/10.1186\/s12911-024-02551-x<\/p>\n\n\n\n<p>Cartwright, A. J. (2023). The elephant in the room: Cybersecurity in healthcare. <em>Journal of Clinical Monitoring and Computing, 37<\/em>(5), 1123-1132. https:\/\/doi.org\/10.1007\/s10877-023-01013-5<\/p>\n\n\n\n<p>Clarke, M., &amp; Martin, K. (2023). Managing cybersecurity risk in healthcare settings. <em>Healthcare Management Forum, 37<\/em>(1), 17-20. https:\/\/doi.org\/10.1177\/08404704231195804<\/p>\n\n\n\n<p>Di Palma, G., Scendoni, R., Ferorelli, D., De Benedictis, A., Tambone, V., &amp; De Micco, F. (2025). AI-induced cybersecurity risks in healthcare: A narrative review of blockchain-based solutions within a clinical risk management framework. <em>Risk Management and Healthcare Policy, 18<\/em>, 3479-3497. https:\/\/doi.org\/10.2147\/rmhp.s544523<\/p>\n\n\n\n<p>Gioulekas, F., Stamatiadis, E., Tzikas, A., Gounaris, K., Georgiadou, A., Michalitsi-Psarrou, A., Doukas, G., Kontoulis, M., Nikoloudakis, Y., Marin, S., Cabecinha, R., &amp; Ntanos, C. (2022). A cybersecurity culture survey targeting healthcare critical infrastructures. <em>Healthcare, 10<\/em>(2), 327. https:\/\/doi.org\/10.3390\/healthcare10020327<\/p>\n\n\n\n<p>Gordon, W. J., Wright, A., Aiyagari, R., Corbo, L., Glynn, R. J., Kadakia, J., Kufahl, J., Mazzone, C., Noga, J., Parkulo, M., Sanford, B., Scheib, P., &amp; Landman, A. B. (2019a). Assessment of employee susceptibility to phishing attacks at US health care institutions. <em>JAMA Network Open, 2<\/em>(3), e190393. https:\/\/doi.org\/10.1001\/jamanetworkopen.2019.0393<\/p>\n\n\n\n<p>Gordon, W. J., Wright, A., Glynn, R. J., Kadakia, J., Mazzone, C., Leinbach, E., &amp; Landman, A. (2019b). Evaluation of a mandatory phishing training program for high-risk employees at a US healthcare system. <em>Journal of the American Medical Informatics Association, 26<\/em>(6), 547-552. https:\/\/doi.org\/10.1093\/jamia\/ocz005<\/p>\n\n\n\n<p>Hameed, S. S., Hassan, W. H., Abdul Latiff, L., &amp; Ghabban, F. (2021). A systematic review of security and privacy issues in the Internet of Medical Things; The role of machine learning approaches. <em>PeerJ Computer Science, 7<\/em>, e414. https:\/\/doi.org\/10.7717\/peerj-cs.414<\/p>\n\n\n\n<p>Hasegawa, K., O&#8217;Brien, N., Prendergast, M., Ajah, C. A., Neves, A. L., &amp; Ghafur, S. (2024). Cybersecurity interventions in health care organizations in low- and middle-income countries: Scoping review. <em>Journal of Medical Internet Research, 26<\/em>, e47311. https:\/\/doi.org\/10.2196\/47311<\/p>\n\n\n\n<p>He, Y., Aliyu, A., Evans, M., &amp; Luo, C. (2021). Health care cybersecurity challenges and solutions under the climate of COVID-19: Scoping review. <em>Journal of Medical Internet Research, 23<\/em>(4), e21747. <a href=\"https:\/\/doi.org\/10.2196\/21747\">https:\/\/doi.org\/10.2196\/21747<\/a><\/p>\n\n\n\n<p>Ignatovski M. (2024). For-profit versus non-profit cybersecurity posture: Breach types and locations in healthcare organisations. <em>Health Information Management: Journal of the Health Information Management Association of Australia<\/em>, <em>53<\/em>(3), 198\u2013205. https:\/\/doi.org\/10.1177\/18333583231158886<\/p>\n\n\n\n<p>Jalali, M. S., &amp; Kaiser, J. P. (2018). Cybersecurity in hospitals: A systematic, organizational perspective. <em>Journal of Medical Internet Research, 20<\/em>(5), e10059. https:\/\/doi.org\/10.2196\/10059<\/p>\n\n\n\n<p>Jalali, M. S., &amp; Largman, K. (2025). Bridging data gaps and tackling human vulnerabilities in healthcare cybersecurity with generative AI. <em>PLOS Digital Health, 4<\/em>(10), e0001063. https:\/\/doi.org\/10.1371\/journal.pdig.0001063<\/p>\n\n\n\n<p>Jiang, J. X., Ross, J. S., &amp; Bai, G. (2025). Ransomware attacks and data breaches in US health care systems. <em>JAMA Network Open, 8<\/em>(5), e2510180. https:\/\/doi.org\/10.1001\/jamanetworkopen.2025.10180<\/p>\n\n\n\n<p>Kaushik, A., Barcellona, C., Mandyam, N. K., Tan, S. Y., &amp; Tromp, J. (2025). Challenges and opportunities for data sharing related to artificial intelligence tools in health care in low- and middle-income countries: Systematic review and case study from Thailand. <em>Journal of Medical Internet Research, 27<\/em>, e58338. https:\/\/doi.org\/10.2196\/58338<\/p>\n\n\n\n<p>Martin, M. J., Patel, P. P., &amp; Egodage, T. (2026). Ransomware attacks and cybersecurity concerns in modern hospitals: Vulnerabilities and impacts on trauma centers and patient care. <em>Trauma Surgery &amp; Acute Care Open, 11<\/em>(Suppl 1), e002293. https:\/\/doi.org\/10.1136\/tsaco-2026-002293<\/p>\n\n\n\n<p>McGlave, C. C., Nikpay, S. S., Henning-Smith, C., Rydberg, K., &amp; Neprash, H. T. (2023). Characteristics of short-term acute care hospitals that experienced a ransomware attack from 2016 to 2021. <em>Health Affairs Scholar, 1<\/em>(3), qxad037. https:\/\/doi.org\/10.1093\/haschl\/qxad037<\/p>\n\n\n\n<p>Pham, T. T., Loo, T. M., Malhotra, A., Longhurst, C. A., Hylton, D., Dameff, C., Tully, J., Wardi, G., Sell, R. E., &amp; Pearce, A. K. (2024). Ransomware cyberattack associated with cardiac arrest incidence and outcomes at untargeted, adjacent hospitals. <em>Critical Care Explorations, 6<\/em>(4), e1079. <a href=\"https:\/\/doi.org\/10.1097\/cce.0000000000001079\">https:\/\/doi.org\/10.1097\/cce.0000000000001079<\/a><\/p>\n\n\n\n<p>Radanliev, P., &amp; De Roure, D. (2022). Advancing the cybersecurity of the healthcare system with self-optimising and self-adaptative artificial intelligence (part 2). <em>Health and Technology<\/em>, <em>12<\/em>(5), 923\u2013929. https:\/\/doi.org\/10.1007\/s12553-022-00691-6<\/p>\n\n\n\n<p>Rizzoni, F., Magalini, S., Casaroli, A., Mari, P., Dixon, M., &amp; Coventry, L. (2022). Phishing simulation exercise in a large hospital: A case study. <em>Digital Health, 8<\/em>, 20552076221081716. <a href=\"https:\/\/doi.org\/10.1177\/20552076221081716\">https:\/\/doi.org\/10.1177\/20552076221081716<\/a><\/p>\n\n\n\n<p>Selvarajan, S., &amp; Mouratidis, H. (2023). A quantum trust and consultative transaction-based blockchain cybersecurity model for healthcare systems. <em>Scientific Reports<\/em>, <em>13<\/em>(1), 7107. https:\/\/doi.org\/10.1038\/s41598-023-34354-x<\/p>\n\n\n\n<p>Svandova, K., &amp; Smutny, Z. (2024). Internet of Medical Things security frameworks for risk assessment and management: A scoping review. <em>Journal of Multidisciplinary Healthcare, 17<\/em>, 2281-2301. https:\/\/doi.org\/10.2147\/JMDH.S459987<\/p>\n\n\n\n<p>Virk, A., Alasmari, S., Patel, D., &amp; Allison, K. (2025). Digital health policy and cybersecurity regulations regarding artificial intelligence (AI) implementation in healthcare. <em>Cureus<\/em>. https:\/\/doi.org\/10.7759\/cureus.80676<\/p>\n\n\n\n<p>Vukotich, G. (2023). Healthcare and cybersecurity: Taking a zero trust approach. <em>Health Services Insights, 16<\/em>, 11786329231187826. https:\/\/doi.org\/10.1177\/11786329231187826<\/p>\n\n\n\n<p>Wasserman, L., &amp; Wasserman, Y. (2022). Hospital cybersecurity risks and gaps: Review (for the non-cyber professional). <em>Frontiers in Digital Health, 4<\/em>, 862221. https:\/\/doi.org\/10.3389\/fdgth.2022.862221<\/p>\n\n\n\n<p>Williams, P., &amp; Woodward, A. (2015). Cybersecurity vulnerabilities in medical devices: A complex environment and multifaceted problem. <em>Medical Devices: Evidence and Research<\/em>, 305. https:\/\/doi.org\/10.2147\/MDER.S50048<\/p>\n\n\n\n<p>Willing, M., Dresen, C., Gerlitz, E., Haering, M., Smith, M., Binnewies, C., Guess, T., Haverkamp, U., &amp; Schinzel, S. (2021). Behavioral responses to a cyber attack in a hospital environment. <em>Scientific Reports, 11<\/em>(1), 19352. https:\/\/doi.org\/10.1038\/s41598-021-98576-7<\/p>\n\n\n\n<p>Willing, M., Dresen, C., Haverkamp, U., &amp; Schinzel, S. (2020). Analyzing medical device connectivity and its effect on cyber security in German hospitals. <em>BMC Medical Informatics and Decision Making, 20<\/em>(1), 246. https:\/\/doi.org\/10.1186\/s12911-020-01259-y<\/p>\n\n\n\n<p>Youssef, A. (2022). A framework for a medical device security program at a healthcare delivery organization. <em>Biomedical Instrumentation &amp; Technology, 56<\/em>(3), 92-97. https:\/\/doi.org\/10.2345\/0899-8205-56.3.92<\/p>\n\n\n\n<h2 class=\"wp-block-heading has-text-align-center\"><strong>Author Biography<\/strong><\/h2>\n\n\n\n<p>Crissinee Sucharitrak holds an MBA and a Master of Science in Information Technology Management (Business Analytics) from California Baptist University in Riverside, California, United States, and is a Certified Nursing Assistant (CNA). Her research interests include health-care cybersecurity, digital health, health informatics, and patient safety in U.S. hospitals.<\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>by Crissinee Sucharitrak<\/p>\n<p>Volume 21 No 3 2026<\/p>\n","protected":false},"author":1,"featured_media":17393,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1,2211,2301],"tags":[2315,1670,2311,900,2313,577,2312,2316,769,1784,2314],"_links":{"self":[{"href":"https:\/\/cjni.net\/journal\/index.php?rest_route=\/wp\/v2\/posts\/17359"}],"collection":[{"href":"https:\/\/cjni.net\/journal\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cjni.net\/journal\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cjni.net\/journal\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cjni.net\/journal\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17359"}],"version-history":[{"count":69,"href":"https:\/\/cjni.net\/journal\/index.php?rest_route=\/wp\/v2\/posts\/17359\/revisions"}],"predecessor-version":[{"id":17556,"href":"https:\/\/cjni.net\/journal\/index.php?rest_route=\/wp\/v2\/posts\/17359\/revisions\/17556"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cjni.net\/journal\/index.php?rest_route=\/wp\/v2\/media\/17393"}],"wp:attachment":[{"href":"https:\/\/cjni.net\/journal\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17359"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cjni.net\/journal\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17359"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cjni.net\/journal\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17359"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}