---
title: Employee Awareness Is Critical in Defending Against Ransomware Attacks
description: Ransomware attacks in healthcare can be disruptive and costly, even impacting patient safety and care. With simple precautions, employees can be the first line of defense.
image: https://files.norcal-group.com/hubfs/computer-ransomware-attack_soc.jpeg
---

- [Sign In](https://secure.proassurance.com?hsLang=en-us)
- g

Search Site

[Contact Us](https://www.proassurance.com/contact-us/?hsLang=en-us): **844-466-7225**

[![PRA-MMI-Logo®-RGB](https://www.norcal-group.com/hs-fs/hubfs/PRA-MMI-Logo%C2%AE-RGB.png?width=215&height=62&name=PRA-MMI-Logo%C2%AE-RGB.png)](https://www.norcal-group.com?hsLang=en-us)

 

- [About](https://norcal-group.com/about) 
    - [About Us](https://norcal-group.com/about)
- [Coverages](https://norcal-group.com/state)
- [Claims](https://www.proassurance.com/report-a-claim/)
- [Resources](https://www.norcal-group.com/resources) 
    - [HIPAA Resources](https://proassurance.com/hipaa)
    - [Website Accessibility](https://proassurance.com/accessibility)
- [Pay](https://www.norcal-group.com/pay)

## [Resource Library](https://www.norcal-group.com/library?hsLang=en-us)

# Employee Awareness Is Critical in Defending Against Ransomware Attacks

 March 25, 2024

- [Tweet](https://twitter.com/share)

In the digital practice — where sensitive business and patient information is stored electronically — ransomware is one of the most devastating forms of malware. It works by [encrypting or blocking access to sensitive files](https://www.fbi.gov/how-we-can-help-you/scams-and-safety/common-scams-and-crimes/ransomware) and demanding payment to restore access.1 The loss to a healthcare practice — and its patients if medical records access is blocked — could be devastating. If the attack is successful, it is nearly impossible to recover the data without paying the ransom.

![computer-ransomware-attack_soc](https://files.norcal-group.com/hubfs/computer-ransomware-attack_soc.jpeg)

In 2023, the FBI’s Internet Crime Complaint Center (IC3) reported receiving 1,193 complaints of ransomware attacks from organizations in a critical infrastructure sector.2 The healthcare and public health sector accounted for 249 of those attacks — 21% of the total and the largest share of any sector.2

Adding to the difficulty for HIPAA-covered entities and business associates, a ransomware attack on electronic protected health information (PHI) that is encrypted and controlled by the attacker [is presumed to be a breach](https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity/ransomware-fact-sheet/index.html) under the HIPAA Breach Notification Rule.3 For organizations not covered by HIPAA, [it could be considered a security breach](https://www.cisa.gov/stopransomware/ransomware-guide) under the FTC’s Health Breach Notification Rule.4

## Ransomware Costs In Healthcare Go Beyond the Financial

A cyberattack on a healthcare organization can be disruptive and costly. The average total cost for the most expensive cyberattack on healthcare organizations surveyed in a 2023 Ponemon Institute study was $5M, while the average of the costliest ransoms paid was estimated at nearly $1M.5 Unfortunately, paying the ransom does not guarantee restoration of access. The ransomware attack on Change Healthcare in February 2024 reportedly resulted in [a $22M ransom payment](https://krebsonsecurity.com/2024/03/blackcat-ransomware-group-implodes-after-apparent-22m-ransom-payment-by-change-healthcare/) but the affiliate holding the data refused to release it claiming that he didn’t receive his share of the ransom.6

While these costs are significant, attacks that block access to medical records or essential patient care services could also put patient safety at risk. The Ponemon study found that disruption to normal healthcare operations was the single biggest cost of an attack averaging 27% of the total cost.5 Of the organizations surveyed in the study, 68% of organizations experiencing a ransomware attack said the attack impacted patient safety and care, including:5

- 28% reported an increase in mortality rate
- 59% reported delays in procedures and tests have resulted in poor outcomes
- 44% reported an increase in complications from medical procedures
- 48% reported longer length of stay
- 46% reported an increase in patients transferred or diverted to other facilities

## Employee Security Awareness is Essential

Ransomware attacks often begin when [unwitting individuals are induced](https://www.crowdstrike.com/cybersecurity-101/ransomware/) through phishing emails or social engineering to click on malicious links that infect their computers.7 While IT staff can deploy measures to protect systems from attack (such as anti-virus software, spam filters, and ad blockers), employees using company computers to access sensitive data are a critical part of any security effort.

All employees should learn ways to avoid these attacks. The following tips can help. They may even be part of the employee handbook or company policies. If you are suspicious of a potential attack, contact your IT staff:

1. **Do not access company information (such as documents or email) on unauthorized devices**. Check with IT staff before using your personal mobile devices or computers for business.
2. **Be wary of unexpected emails with attachments or links, even if they appear to be from someone you know**. Criminal hackers can [disguise email addresses and other information](https://www.fbi.gov/how-we-can-help-you/safety-resources/scams-and-safety/common-scams-and-crimes/spoofing-and-phishing) in subtle ways to avoid detection.8 If you are not expecting a file or link from someone, call or text the sender to verify the email or contact IT.
3. **Do not install unauthorized software, including applications, toolbars, or extensions**. Malware often poses as legitimate programs like games, tools, and even antivirus software. Check with IT before installing anything.
4. **Do not respond to emails requesting passwords or confidential information**. Bank and credit card providers will never ask for your account number, Social Security number, or passwords [through email](https://us.norton.com/blog/online-scams/what-is-phishing).9 Bad guys are successful because they are convincing, and neither IT staff nor legitimate businesses should ever ask for your password. Report any suspicious requests to IT.

With these simple precautions, employees can go from being an easy point of attack to the first line of defense in securing the digital practice.

## References

1. Federal Bureau of Investigation. “[Ransomware](https://www.fbi.gov/how-we-can-help-you/scams-and-safety/common-scams-and-crimes/ransomware).” Undated.

2. Internet Crime Complaint Center (IC3). [*2023 Internet Crime Report*](https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf). Federal Bureau of Investigation. (PDF)

3. Office for Civil Rights. “[Fact Sheet: Ransomware and HIPAA](https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity/ransomware-fact-sheet/index.html).” U.S. Department of Health and Human Services. Content last reviewed September 20, 2021.

4. Cybersecurity and Infrastructure Security Agency. “[#StopRansomware Guide](https://www.cisa.gov/stopransomware/ransomware-guide).” Undated.

5. Ponemon Institute. “[Cyber Insecurity in Healthcare: The Cost and Impact on Patient Safety and Care 2023](https://www.proofpoint.com/sites/default/files/threat-reports/pfpt-us-tr-cyber-insecurity-healthcare-ponemon-report.pdf).” (PDF)

6. Brian Krebs. “[BlackCat Ransomware Group Implodes After Apparent $22M Payment by Change Healthcare](https://krebsonsecurity.com/2024/03/blackcat-ransomware-group-implodes-after-apparent-22m-ransom-payment-by-change-healthcare/).” *Krebs on Security*. March 5, 2024.

7. Kurt Baker. “[What Is Ransomware?](https://www.crowdstrike.com/cybersecurity-101/ransomware/)” CrowdStrike. January 30, 2023.

8. Federal Bureau of Investigation. “[Spoofing and Phishing](https://www.fbi.gov/how-we-can-help-you/safety-resources/scams-and-safety/common-scams-and-crimes/spoofing-and-phishing).” Undated.

9. Clare Stouffer. “[What Is Phishing? + How to Spot and Avoid It](https://us.norton.com/blog/online-scams/what-is-phishing).” *Norton Blog*. September 12, 2023.

 Filed under: [Digital Health](https://www.norcal-group.com/library/topic/digital-health), [Article](https://www.norcal-group.com/library/topic/article), [Practice Manager](https://www.norcal-group.com/library/topic/practice-manager)

###  Topics 

Please select Bad Outcomes & Complications Business Continuity Business Operations Community Health Consultations Cosmetic & Reconstructive Procedures Cultural Competency & Cultural Respect Cybersecurity Diagnosis & Testing Digital Practice Electronic Health Records (EHR) General Liability HIPAA Privacy & Confidentiality Industry Trends Information Security Informed Consent Leadership Litigation & Claims Marketing & Practice Building Medical Errors & Apology Medical Ethics Medical Records & Documentation Medication Errors Opioids Pain Management Patient Communication Patient Relationship Personal Finance & Career Philanthropy & Community Involvement Physician Burnout Physician Ratings Physician Wellness Practice Communication Practice Drift Practice Management Prescribing & Medication Public Relations & Communication Regulation & Compliance Reputation Management Unanticipated Outcomes Vicarious Liability

###  Specialties 

Please select Emergency Medicine Family Practice Mental & Behavioral Health Obstetrics & Gynecology Oncology Ophthalmology Orthopedics Pain Management Specialist Pediatrics Plastic & Cosmetic Surgery Radiology

### Recently Added

Interested in NORCAL Group?

**Contact Your Agent/Broker** or call 844.4NORCAL today

* NORCAL Group, now part of ProAssurance, includes NORCAL Insurance Company and its affiliated companies.

[![AM Best](https://www.norcal-group.com/hubfs/Norcal_Mutual_Images/graphic_am-best.png)](https://www.norcal-group.com/ambest?hsLang=en-us)

- [About](https://norcal-group.com/about) 
    - [About Us](https://norcal-group.com/about)
- [Coverages](https://norcal-group.com/state)
- [Claims](https://www.proassurance.com/report-a-claim/)
- [Resources](https://www.norcal-group.com/resources) 
    - [HIPAA Resources](https://proassurance.com/hipaa)
    - [Website Accessibility](https://proassurance.com/accessibility)
- [Pay](https://www.norcal-group.com/pay)

© 2001 - 2024 ProAssurance  
All rights reserved

- [844-466-7225 ](tel:18444667225)
- [Privacy Policy](https://proassurancegroup.com/privacy-policy?hsLang=en-us)
- [Terms of Use](https://www.norcal-group.com/terms?hsLang=en-us)
- [Website Accessibility](https://www.norcal-group.com/accessibility?hsLang=en-us)

```json
{
  "@context" : "http://schema.org",
  "@type" : "InsuranceAgency",
  "contactPoint" : {
    "@type" : "ContactPoint",
    "contactType" : "customer service",
    "telephone" : "1.844.466.7225"
  },
  "description" : "The NORCAL Group of companies provide medical professional liability insurance to physicians, health care extenders, medical groups, hospitals, community clinics and allied health care facilities throughout the country.",
  "foundingDate" : "1975-01-01",
  "foundingLocation" : "California",
  "legalName" : "NORCAL Mutual Insurance Company",
  "logo" : "https://files.norcal-group.com/hubfs/Website/Logos/NORCAL-Group-Logo-X-18.png",
  "name" : "NORCAL Group",
  "potentialAction" : {
    "@type" : "SearchAction",
    "query-input" : "required name=search_term_string",
    "target" : "http://www.norcal-group.com/search?search={search_term_string}"
  },
  "subOrganization" : [ "Medicus", "FD Insurance", "NORCAL Specialty Insurance Company", "PMSLIC" ],
  "url" : "http://www.norcal-group.com"
}
```