Background <p>Ransomware is a leading cyber threat to U.S. health care. Compromises of HIPAA business associates (BAs) can propagate disruptions across multiple providers, but the HHS-OCR breach portal lacks structured fields to identify “ransomware” or BA involvement, obscuring this risk.</p> Objective <p>To quantify BA involvement in provider-reported ransomware incidents (2016–2024) and compare breach size between BA-involved and provider-only events.</p> Methods <p>We analyzed HHS-OCR provider filings, using narrative coding to identify ransomware and BA involvement. Trends were analyzed with logistic and modified-Poisson models; breach magnitude was analyzed with negative binomial and Gamma GLMs and quantile regression.</p> Results <p>Among 831 ransomware incidents, 33.8% (281) involved a BA. BA involvement spiked in 2020 (predicted share ≈0.70) and declined thereafter. BA-involved breaches were smaller on average (incidence-rate ratios ≈0.39–0.51, <i>p</i> &lt; .001) but were significantly larger conditional on being very large (≥ 100,000 individuals affected).</p> Conclusions <p>BA exposure is significant in healthcare ransomware, demonstrating a hub-and-spoke risk model. To improve governance, OCR reporting should add structured fields for ransomware and BA involvement. Health systems must tier vendors by potential disruption and align oversight accordingly.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Third-party risk in U.S. health care ransomware incidents: business associate involvement and breach size

  • Gilbert Munoz Cornejo

摘要

Background

Ransomware is a leading cyber threat to U.S. health care. Compromises of HIPAA business associates (BAs) can propagate disruptions across multiple providers, but the HHS-OCR breach portal lacks structured fields to identify “ransomware” or BA involvement, obscuring this risk.

Objective

To quantify BA involvement in provider-reported ransomware incidents (2016–2024) and compare breach size between BA-involved and provider-only events.

Methods

We analyzed HHS-OCR provider filings, using narrative coding to identify ransomware and BA involvement. Trends were analyzed with logistic and modified-Poisson models; breach magnitude was analyzed with negative binomial and Gamma GLMs and quantile regression.

Results

Among 831 ransomware incidents, 33.8% (281) involved a BA. BA involvement spiked in 2020 (predicted share ≈0.70) and declined thereafter. BA-involved breaches were smaller on average (incidence-rate ratios ≈0.39–0.51, p < .001) but were significantly larger conditional on being very large (≥ 100,000 individuals affected).

Conclusions

BA exposure is significant in healthcare ransomware, demonstrating a hub-and-spoke risk model. To improve governance, OCR reporting should add structured fields for ransomware and BA involvement. Health systems must tier vendors by potential disruption and align oversight accordingly.