Innovation

Protecting Healthcare From a Growing Ransomware Threat

Written by Fed Gov Today | Sep 18, 2026, 3:47:15 PM

Presented by Carahsoft

A cyberattack against a healthcare organization can do far more than expose sensitive information. It can divert ambulances, disrupt treatment and affect whether patients receive timely care. Charlee Hess, Director of the Healthcare and Public Health Cybersecurity Division at the Department of Health and Human Services, says strengthening the sector requires practical support for organizations ranging from major hospital systems to small rural providers.

HHS serves as the sector risk management agency for healthcare and public health, one of the nation’s 16 critical-infrastructure sectors. Its responsibilities extend across hospitals, public-health offices, pharmaceutical laboratories, healthcare manufacturing and blood banks.

Speaking at the Billington Cybersecurity Summit 2026, Hess says the diversity of that environment makes the mission particularly challenging. Organizations differ widely in their technology, staffing, funding and level of cybersecurity maturity.

They are also frequent targets. Hess says her team triaged more than 2,200 ransomware attacks during the previous year.

Why Healthcare Remains a Target

Healthcare organizations possess information that is both valuable and deeply personal. Patients may be especially concerned about the release of medical information, making stolen data attractive to extortion groups.

The sector also provides services that cannot tolerate extended disruption. If a threat actor interferes with hospital operations or other lifesaving functions, the incident receives public attention and creates immediate pressure to restore services.

Attackers understand that combination. The sensitivity of the data and the urgency of the mission may make an organization more likely to pay a ransom.

Healthcare technology environments are also expanding. Cloud services, connected medical systems and new digital tools can improve treatment and efficiency, but each advancement can introduce additional risk.

Defenders must keep pace with both technology and the evolving tactics used by attackers.

Helping Rural and Smaller Providers

Large healthcare corporations may employ substantial security teams, but many rural hospitals and small providers operate with limited IT personnel and funding. They cannot approach cybersecurity in the same way as a nationwide hospital system.

Hess says HHS pays particular attention to those resource differences. One of its primary tools is a set of healthcare and public-health cybersecurity performance goals designed to give organizations an accessible path toward stronger security.

The goals are divided into essential and enhanced categories. A provider with limited resources or an early-stage cybersecurity program can begin with the essential protections rather than attempting to implement an overwhelming list of advanced controls.

Once the organization establishes that foundation, it can move toward the enhanced goals.

This staged approach turns cybersecurity into a manageable journey. It also helps leaders decide where to invest first instead of spreading limited resources across too many initiatives.

Smaller providers can also work together. Regional resource sharing allows organizations to combine expertise and learn from peers. Federal vulnerability-scanning services and cybersecurity working groups can provide additional support without requiring each hospital to build every capability internally.

Responding When an Attack Occurs

Preparation cannot prevent every incident. Healthcare leaders also need to know what resources are available when systems fail and patient services are affected.

Hess recommends contacting the FBI or the Cybersecurity and Infrastructure Security Agency after an incident. The FBI can provide law-enforcement support, while CISA can assist with the security and recovery of affected technology.

HHS brings a different perspective. Its team concentrates on the consequences for patients and the healthcare system.

If a hospital begins diverting ambulances, HHS can examine whether appropriate alternatives are nearby. A diversion may be manageable in an urban area with several hospitals, but it could create a serious risk if the nearest alternative is a long distance away.

HHS can also connect an affected healthcare organization with peers that have experienced a similar ransomware attack. Those organizations can share practical lessons about decisions, communications and recovery steps.

That support is especially valuable during the confusion of an active incident. Leaders do not have to solve every problem for the first time while their systems are unavailable.

Healthcare cybersecurity ultimately protects the continuity of care. Technology teams, law enforcement, federal cyber agencies and healthcare experts all contribute different capabilities to that mission.

Key Takeaways

  • Healthcare attacks threaten both sensitive information and the delivery of essential patient services.
  • HHS cybersecurity performance goals give rural and smaller providers a practical, staged roadmap for improving resilience.
  • Effective incident response combines technical support, law enforcement and planning for the consequences to patient care.