Reactions to the Ascension Healthcare Ransomware Attack and Suggestions for Healthcare Organizations

The Ascension health system data breach can’t be easily separated from the United Healthcare Change Health breach that recently caused a huge financial and medical impact across the healthcare sector and may have breached the personal information for a third of Americans. Because the Ascension breach is still being investigated, very little information has been released, but we know that ambulances are being diverted, putting lives at risk, and medical procedures are being delayed.Both breaches are just symptoms of a weak regulatory system that has let healthcare providers and health plans get away with failing to adequately protect the personal data of millions of people.Many think it is unfair to blame the victims but it is often justified. The US Senate heard the weak excuses of the United Healthcare CEO who admitted Change Healthcare had not secured its Citrix systems with multifactor authentication (MFA) even though they had a written policy to do so, and that they failed to notify data breach victims by the HIPAA and state data breach law deadlines.