Lower Your Healthcare Organization's Profile As A Ransomware Target

In May 2023, a ransomware data theft attack targeted Norton Healthcare, which operates multiple hospitals and care facilities in Kentucky and Indiana. The attack exposed the personal and protected health information of nearly 2.5 million current and former patients and employees via the Alphv/BlackCat group.

Suits were filed in response in both state and federal courts for negligence and failure to protect sensitive data.

Norton Healthcare subsequently agreed on a proposed settlement in the amount of $11 million for unreimbursed out-of-pocket losses up to $2,500 per victim, and up to $80 for documented lost time at $20 per hour for each victim, a minimum $5 cash payment per claimant, and a three-year provision of medical account monitoring services for eligible individuals being notified of the breach.

Source: https://www.govinfosecurity.com/norton-healthcare-to-pay-11m-to-settle-blackcat-lawsuit-a-30788

Commentary

In the Norton Healthcare BlackCat incident, ransomware was the type of malware that led to the loss. Below are some best practices for healthcare organization cybersecurity that lower your organization's risk to malware, including ransomware:

  • Conduct regular security risk assessments to identify and address vulnerabilities within systems and processes
  • Implement strict access controls based on the principle of least privilege, ensuring employees and participants can access only necessary data
  • Enforce multi-factor authentication to add an additional layer of security beyond passwords
  • Encrypt sensitive data both at rest and in transit to protect information from unauthorized access
  • Segment networks to limit lateral movement of attackers and contain potential breaches
  • Provide ongoing employee training on phishing, social engineering, password hygiene, and data management best practices
  • Conduct simulated phishing exercises to reinforce employee vigilance and identify areas needing further training
  • Deploy continuous monitoring and threat detection systems that analyze behavior and network activity for anomalies
  • Establish and routinely test an incident response plan to ensure swift containment, mitigation, and regulatory compliance
  • Perform due diligence on third-party vendors thoroughly, enforcing strict contractual security requirements and regular compliance audits
  • Maintain up-to-date patching and system updates to close known vulnerabilities promptly
  • Implement secure mobile device management solutions to enforce security policies on mobile access points
  • Use firewalls, antivirus, and intrusion detection/prevention systems to proactively block unauthorized access and malware
  • Integrate advanced detection technologies such as behavioral data loss prevention and AI-driven monitoring tools
  • Develop clear data disposal protocols for secure destruction of electronic and physical patient records beyond retention periods

The final takeaway is that investing in proactive security measures and testing response plans, along with documented progress in compliance, helps minimize the chances of a breach.

Finally, your opinion is important to us. Please complete the opinion survey:

What's New

AI, Public Wi-Fi, And Shared Screens: Hidden Dangers Of Personal Use At Work

A survey shows workers use their work devices for personal tasks. We comment on how new tools and habits magnify old risks and what policies must now cover.

Safer Because You Use A Mac? Beware Of The FlexibleFerret

A macOS malware chain is stealing credentials and maintaining remote access on Macs. We examine.

Are Vampire Bots Stalking Job Seekers In Your Midst?

Security researchers have documented a malware campaign in which a Vietnamese cybercriminal group known as BatShadow targets job hunters and digital marketing professionals with a Go?based remote access trojan called Vampire Bot.

Latest Numbers

  • Unemployment Rate
    4.3% in Jan 2026
  • Payroll Employment
    +130,000(p) in Jan 2026
  • Average Hourly Earnings
    +$0.15(p) in Jan 2026
  • Employment Cost Index (ECI)
    +0.7% in 4th Qtr of 2025
  • Productivity
    +4.9% in 3rd Qtr of 2025

Source: Department of Labor