To protect patients, Washington must treat healthcare cybersecurity as a priority

The next cyberattack is not a matter of if but when, and our collective preparedness must rise to meet that certainty. 

A hospital is brought to its knees, not by a natural disaster or mass casualty event, but by a cyberattack. Screens go dark. The network collapses. Young physicians, trained in a digital-first world, are suddenly reduced to fumbling with fax machines. Lab orders vanish into piles of paper. Communication fractures at every level. And in the chaos, a life-threatening diagnosis is missed. 

Fans of HBO Max’s The Pitt may recognize this as the plot of an episode from this season, but unfortunately, scenes like this aren’t fictional. They’re playing out across the country more and more, as cyberattacks on healthcare organizations reach staggering highs. 

In 2025 alone, the sector faced more than 700 reported attacks, putting more than 50 million individuals at risk. The financial impacts are also staggering and far surpass any other industry. In 2024, the average healthcare data breach cost $9.77 million, more than double the $4.88 million global, cross-industry average. This marked the fourteenth consecutive year the United States healthcare system has disproportionately faced the highest cyber-attack costs. With everything from protected health information to life support systems at risk, there is no economic sector facing greater stakes to protect our fellow Americans from cyber harms. 

The administration has recently taken action to combat cybercrime, including the White House’s release of the Cyber Strategy for America and the Department of Health and Human Services’ March memo

But as attacks from state-sponsored actors intensify, so does the threat to patient safety and access to care — making it clear that more must be done. 

Healthcare organizations have taken real action, but cybersecurity can’t be a one-sided fight. Now it’s time for the public sector to step up to help repel these increasingly sophisticated adversaries. 

Through the report Cybersecurity in Healthcare: Defining Private and Public Sector Responsibility, the Healthcare Leadership Council and Manatt assessed the growing regulatory burden alongside escalating cyber threats. Their conclusion is clear: Stronger alignment between government and industry is essential.

Lawmakers and the administration should take three immediate steps to strengthen healthcare cybersecurity: 

Streamline and harmonize breach reporting requirements

The healthcare sector continues to make great strides in bolstering its cyber defenses, adhering to extensive regulatory requirements that are well aligned with the administration’s priorities. Hospitals, insurers, and other covered entities must conduct annual cyber risk analyses and comply with dozens of requirements under the Health Insurance Portability and Accountability Act (HIPAA) Security Rule. Many vendors follow the same standards and even pursue additional certifications. Across the sector, organizations also align with widely recognized frameworks like the National Institute of Standards and Technology’s (NIST) Cybersecurity Framework 2.0 and the Health Industry Cybersecurity Practices (HICPs).

Yet when bad actors break through — and they will — the healthcare sector is often treated as a culprit during response and recovery. Organizations face a patchwork of complex, overlapping federal and state reporting requirements that are cumbersome and can even hinder response efforts.

Harmonizing these requirements into a unified framework that preempts conflicting state laws would reduce unnecessary administrative burden and allow healthcare organizations to focus on what matters most: restoring systems and protecting patient care. Without reform, current policies risk penalizing victims of cyberattacks and further jeopardizing care delivery.

Establish safe harbor protections for proven cybersecurity practices 

Healthcare organizations are already investing heavily in cybersecurity and implementing rigorous safeguards. Policymakers should recognize and reward these efforts by establishing safe harbor protections for organizations that meet recognized standards such as the NIST Cybersecurity Framework.

Providing regulatory relief and liability protections would not only incentivize continued investment in cybersecurity but also create clearer expectations across the sector. Entities that take proactive, good-faith measures to secure their systems should be supported — not penalized — when facing increasingly sophisticated adversaries.

Expand real-time threat intelligence sharing 

Cyber threats to healthcare are not confined by borders. As attacks from state-sponsored actors intensify, the U.S. must treat cybercrime as a fundamental threat to patient safety.

Internationally, this means the U.S. must take a whole-of-government approach to combatting these threats, making it a top priority in diplomatic talks with allies and adversaries. 

At home, information sharing is the key to combating cyberattacks. Government agencies must clearly communicate about foreign and state-sponsored threats and provide real-time, industry-wide alerts. Locally, stronger emergency networks would help healthcare organizations quickly share critical information during an attack. 

Investing in the cyber workforce is also essential to sustain these efforts. With more than 500,000 unfilled cybersecurity jobs nationwide, expanding education and training pipelines will be key to strengthening the sector’s long-term resilience.

Healthcare organizations are strengthening defenses to protect patients, but they need help. A stronger, more accountable public-private partnership is essential. The next cyberattack is not a matter of if but whenand our collective preparedness must rise to meet that certainty. 

Maria Ghazal serves as president and CEO of the Healthcare Leadership Council. Paul Luehr co-leads Manatt’s AI practice.

Copyright © 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.

Related Stories