October is Cybersecurity Awareness Month, an annual campaign that encourages organizations and individuals to improve their security habits. Cybersecurity Awareness Month in healthcare is a good time to evaluate common cyber threats and review your safeguards. Healthcare organizations store sensitive patient information and depend on their systems to deliver care, which makes them a common target for attackers.
Compliancy Group hosted a Cybersecurity Awareness Month webinar with Fred Morton, a Cybersecurity Strategist, and Brian Burton, our Chief Compliance and Privacy Officer, to discuss these threats. In this article, we explore the threats they discussed, the free federal resources you can use, and how this work supports your HIPAA compliance
Table of Contents
- Key Takeaways
- Table of Contents
- Which Cyber Threats Are Affecting Healthcare in 2026?
- What Free Resources Does CISA Offer Healthcare Organizations?
- How CISA’s Vulnerability Scanning Works
- How to Use the Known Exploited Vulnerabilities Catalog
- How Does Cybersecurity Work Map to the HIPAA Security Rule?
- Required and Addressable Safeguards Today
- Why OCR Starts With the Risk Analysis
- Frameworks That Can Guide Your Safeguards
- How Should Your Risk Assessment Account for Vendors?
- What a Business Associate Agreement Covers
- Questions To Include in Your Risk Assessment
- What Should Healthcare Teams Do for Cybersecurity Awareness Month?
- Watch the Cybersecurity Awareness Month Webinar On Demand
- Keep Your HIPAA Security Records in One Place
- Frequently Asked Questions
- Does HIPAA require cybersecurity awareness training?
- Is CISA vulnerability scanning enough for a HIPAA risk analysis?
- Do small practices have to follow NIST CSF 2.0 or the HPH Cybersecurity Performance Goals?
- About the Author: Arissa Shanganlall
- Related Posts
Which Cyber Threats Are Affecting Healthcare in 2026?
Healthcare remains one of the most targeted sectors for cyberattacks. Patient records are valuable to attackers, and many organizations cannot pause care while their systems are down. Most healthcare organizations also rely on vendors, staff email accounts, and connected systems; each of these can give an attacker a way in. During the webinar, Fred walked through three common types of attack and one recent vendor breach.
Ransomware and Data Theft
Ransomware is one of the most common attacks in healthcare. Comparitech, a research firm that tracks ransomware incidents, counted 410 attacks on healthcare organizations worldwide in the first half of 2026. That was nearly 14% more than in the second half of 2025. Attacks on businesses that support care delivery (such as billing companies and health technology firms) rose almost 35%. Many ransomware groups exfiltrate data before encrypting systems, so attacks are likely to become a reportable breach even after systems are restored.
Phishing and Stolen Credentials
Phishing emails and stolen login credentials let attackers sign in as a legitimate user. Several of the largest breaches reported in June 2026 involved phishing, including one at a business associate. Email accounts were the second most common location of breached protected health information (PHI) that month, after network servers. Once an attacker gains access to a mailbox, patient information in messages and attachments can be exposed. Multi-factor authentication and regular staff training reduce this risk, although they do not remove it.
Exploited Software Vulnerabilities
Attackers also exploit known weaknesses in internet-facing systems that have not been patched. Verizon’s 2026 Data Breach Investigations Report found that about 20% of healthcare breaches started with an exploited vulnerability. Maintaining automated systems patching, checking your systems against the KEV catalog, and reviewing CISA’s scan reports show which of these weaknesses apply to you. Organizations should make patching IT systems a top priority to reduce vulnerabilities and threats to security posture. This is typically managed by your IT team or a vendor; compliance programs should monitor KPIs in this area.
What Happened in the Aesto Health Breach
A vendor breach can involve any of these threats and affect many healthcare providers at once. Aesto Health provides data migration, electronic health record (EHR) exchange, and legacy data archiving services to healthcare providers. Between December 2 and 18, 2025, an unauthorized party accessed and took data from its Amazon Web Services environment. Aesto reported the breach to OCR as affecting 9,540,683 individuals. That makes it the second-largest confirmed healthcare breach of 2026 so far. More than two dozen of Aesto’s provider clients were affected, even though the providers were not attacked directly. Their patient records were exposed because Aesto stored archived data on their behalf. For these compliance teams, this means over 9M notification letters are required; the postage alone is likely to be over $4M. Not to mention the cost of offering credit monitoring, which will likely result in fines or settlements with the OCR. Then Aesto’s internal costs to increase security posture and cyber liability insurance premiums will likely dramatically increase.
Staff training helps employees recognize phishing emails and protect their login credentials. Compliancy Group’s healthcare security awareness training lets you assign courses by role and track each employee’s progress.
What Free Resources Does CISA Offer Healthcare Organizations?
The Cybersecurity and Infrastructure Security Agency (CISA) offers several free services and resources that healthcare organizations can use during Cybersecurity Awareness Month and throughout the year.
The table below summarizes the resources most useful to healthcare compliance teams.
| Resource | What it does | How to start | Limitation |
|---|---|---|---|
| Cyber Hygiene Vulnerability Scanning | Scans your internet-facing systems for known vulnerabilities on a recurring schedule | Email CISA to request enrollment | Covers only systems reachable from the internet |
| Known Exploited Vulnerabilities (KEV) catalog | Lists vulnerabilities that attackers are known to have used | Compare it against your systems and vendor products | Requires a current inventory of your hardware and software |
| Healthcare and Public Health toolkit and advisories | Collects CISA and Department of Health and Human Services (HHS) guidance for healthcare | Browse CISA’s healthcare page | Guidance is general and needs to be applied to your environment |
Start with one or two of these resources this month, and record what each one finds for your risk analysis.
How CISA’s Vulnerability Scanning Works
CISA’s Cyber Hygiene Vulnerability Scanning service checks the internet-facing systems your organization controls for known vulnerabilities. CISA sends the results to you in recurring email reports. The service is free for U.S. organizations and does not access your internal network, devices, or stored data. To enroll, you email CISA and provide a point of contact.
Reading these reports and fixing the issues they identify requires IT security expertise. Many practices rely on their IT vendor or a managed security service provider (MSSP) for this work. Compliancy Group’s Advisory Services team can help you record the findings in your risk analysis and plan your corrective actions.
How to Use the Known Exploited Vulnerabilities Catalog
The KEV catalog lists software vulnerabilities that CISA has confirmed attackers are using. CISA adds an entry only when there is clear guidance for fixing it, such as a patch. CISA encourages all organizations to use the catalog to prioritize patching. Ask your IT team or IT vendor to compare the catalog against the systems and software you use. Record which entries apply to you and when each one was fixed.
How Does Cybersecurity Work Map to the HIPAA Security Rule?
Required and Addressable Safeguards Today
Each Security Rule implementation specification is either a standard, required, or addressable, and you must implement required specifications as written. For an addressable specification, you assess whether it is reasonable and appropriate for your organization. If it is, you implement it, and if it is not, you document why and adopt an equivalent alternative where reasonable
Why OCR Starts With the Risk Analysis
OCR routinely requests the risk analysis in Security Rule investigations, and its Risk Analysis Initiative has made it an enforcement focus. That focus has led to enforcement actions such as a February 2026 settlement with an Illinois substance use disorder treatment provider. OCR has also expanded the initiative to include risk management, which looks at whether organizations acted on the risks they found. This is the reason we suggest recording your CISA scan results, KEV checks, and patch dates in your risk analysis and risk management plan.
Frameworks That Can Guide Your Safeguards
Voluntary frameworks can help you decide which safeguards to prioritize in your HIPAA cybersecurity program. They can also help you map those safeguards to the healthcare cybersecurity regulations that apply to you. HHS 405(d) Health Industry Cybersecurity Practices (HICP) matches common healthcare threats to specific practices, with separate guidance for small, medium, and large organizations.
The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0 groups activities into six categories: Govern, Identify, Protect, Detect, Respond, and Recover. These frameworks support your Security Rule compliance but do not replace it.
How Should Your Risk Assessment Account for Vendors?
Your security risk assessment should include every vendor that creates, receives, maintains, or transmits ePHI for your organization. A breach at one of those vendors can expose your patients’ information.
Vendors that store archived records from systems you no longer use are easy to overlook. An old EHR or a past data migration can leave patient data with a vendor for years.
What a Business Associate Agreement Covers
A business associate agreement (BAA) sets the terms for how a vendor protects PHI and reports incidents. You need a signed BAA before a vendor handles PHI on your behalf. Under 45 CFR 164.410, a business associate must notify you of a breach without unreasonable delay. The notice must come no later than 60 days after the vendor discovers the breach. The Covered Entity remains responsible for notifying affected individuals unless you delegate that task to the vendor.
Questions To Include in Your Risk Assessment
Ask these questions for every vendor that handles ePHI:
- Which vendors hold ePHI for you, including archived records from systems you no longer use?
- Where does each vendor host that data, and who can access it?
- When did you last review each vendor, and is a signed BAA on file?
- How does the vendor attest to compliance with Administrative, Technical, and Physical Safeguards defined in the HIPAA Security Rule?
- How quickly will each vendor notify you of an incident, and who is your contact?
What Should Healthcare Teams Do for Cybersecurity Awareness Month?
You don’t need to overhaul your cybersecurity program in October. The steps below will help strengthen your security and improve the documentation behind your HIPAA compliance program.
- Meet with your IT team, IT security team, or cybersecurity vendor to agree on this month’s priorities, and record who owns each task.
- Decide together whether to enroll in CISA’s Cyber Hygiene vulnerability scanning, and assign someone to review each report.
- Ask your IT team or vendor to compare your systems against the KEV catalog and document any patches.
- Update your security risk analysis with the scan results, KEV findings, and remediation dates, and include the results in your compliance reports.
- Review your most recent risk analysis and confirm that each corrective action is tracked until it is implemented.
- Check whether any business, environmental, or technology change since your last assessment requires a new security risk assessment.
- List every vendor that holds ePHI, including archive vendors, and confirm each has a current BAA.
- Assign cybersecurity awareness training to your workforce and keep each completion and attestation on file.
Watch the Cybersecurity Awareness Month Webinar On Demand
If you missed the live session, you can watch the full recording of Cybersecurity Awareness Month: CISA, Current Threats, and HIPAA in Practice. Fred Morton and Brian Burton cover each of these topics in more detail. Watch the full recording
Keep Your HIPAA Security Records in One Place
HIPAA expects you to show what security work was done and when. In many organizations, those records are spread across email, shared drives, and separate training systems. Gathering them for a reviewer can take days. Compliancy Group’s platform, The Guard, helps healthcare organizations build, document, and maintain a defensible HIPAA program in one connected system. That includes the security risk assessment, business associate agreements, and cybersecurity awareness training. Request a demo to see how it works for an organization your size.






