Search

Hongke's latest articles

HongKe

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

[Hongke Insights] When Hackers Target Healthcare Teams: The New Front Line of Cybersecurity in Digital Healthcare

A single cybersecurity incident is enough to plunge a company into financial losses, reputational damage, and business disruptions. However, in the healthcare industry, the consequences are even more far-reaching: once systems go down, prescriptions cannot be issued, and medical services are forced to halt, it is not only sensitive data that is at risk, but also the lives of patients.

According to KnowBe4’s latest white paper, “When Hackers Target Healthcare Teams: The New Cybersecurity Frontline in Digital Healthcare,” as telemedicine, decentralized operations, and AI Agents With the widespread adoption of [technology], the security perimeter in the healthcare industry has been redefined. The lines of defense that now require the most attention have long extended beyond the local networks within hospitals to include remote employees located in various locations, as well as AI agents deeply involved in clinical diagnosis and administrative processes.

Why Has Medical Data Become the Top Target for Cyberattackers?

Medical records contain a large amount of highly sensitive information, including personal identifying information, insurance details, diagnostic results, treatment plans, and family relationships. Unlike passwords or credit card numbers, a patient’s medical history and treatment records cannot be “reset” or “replaced” once they are compromised. If hackers steal this private data, it can easily be exploited over the long term for identity theft, insurance fraud, or extortion.

The white paper emphasizes that on the dark web, a medical record can sell for as much as a credit card number 10 to 40 times. At the same time, modern healthcare systems rely heavily on digital systems that must operate without interruption. Disruptions to medical services caused by hackers and the resulting risks to patient safety have significantly increased the pressure on healthcare institutions to pay ransom demands.

Highly valuable medical data, the urgent need for medical care, and increasingly complex network infrastructures have collectively made healthcare organizations prime targets for cybercrime groups.

The Heavy Cost of Cyberattacks: Far More Than Just Data Breaches

The white paper shows that the number of major data breaches in the healthcare industry reached a record high in 2025. According to data from the *2025 IBM Cost of a Data Breach Report*, the average cost per data breach for healthcare organizations worldwide was as high as $7.42 million...topping all industries for 14 consecutive years; while in the United States, the average loss per incident has risen to $9.8 millionThe

On average, it takes a healthcare organization as long as 279 days. A response period lasting several months not only means steadily rising investigation and recovery costs, but also gives hackers ample time to penetrate deeper into the system, expand the scope of their attacks, and steal more critical data.

Of greatest concern is the real threat to patients' lives. A study cited in the white paper indicates that when hospitals are hit by ransomware attacks, the relative increase in in-hospital mortality rates among inpatients can reach as high as 34% to 38%(This figure represents the relative increase in mortality rate, not an increase of 34 to 38 percentage points.) Among these patients, those requiring complex or emergency care are particularly vulnerable to disruptions in medical services.

This clearly demonstrates that cybersecurity in the healthcare sector is no longer merely an IT issue, but rather a critical cornerstone for ensuring the continuity of clinical care and protecting patients' lives.

Why Has the Security Perimeter Been Expanded to Include Employees and AI Agents?

In the past, healthcare institutions primarily built their security systems around local area networks. However, with telemedicine physicians, administrative staff, finance teams, and third-party vendors now frequently using a variety of devices and platforms to collaborate, the physical boundaries of hospitals no longer encompass the actual scope of their digital operations.

Hackers have also adapted their intrusion methods accordingly. They can steal employee credentials through phishing emails, impersonate IT support staff to trick users into taking certain actions, or launch a barrage of multi-factor authentication (MFA) prompts to force frustrated employees to click and grant authorization. Once attackers have obtained legitimate access, they can infiltrate core systems, steal sensitive patient data, or even implant ransomware.

Healthcare workers are constantly exposed to high-pressure work environments where every second counts. Staff shortages, physical and mental exhaustion, and occupational burnout further impair their ability to make sound judgments. Cyberattackers exploit these psychological vulnerabilities, turning a seemingly urgent email or authentication prompt into a breach that compromises security defenses.

At the same time, AI agents are being widely used to generate consultation summaries, update medical records, schedule appointments, and coordinate insurance claims. While AI agents enhance operational efficiency, they also require access to large amounts of sensitive data and core systems. If they were to be compromised, Prompt Injection Attacks...or if granted excessive system privileges, it may execute abnormal commands and even lead to a data breach.

Therefore, the cybersecurity strategy of modern healthcare organizations must comprehensively address the daily behaviors and interactions of both human employees and AI agents.

How Should Healthcare Organizations Implement Cybersecurity Measures?

First, establish the necessary dual-verification mechanisms at key operational stages. Whether updating a supplier’s bank account information, uploading patient medical records in bulk, or processing unusual emergency payments, additional verification or review by a second authorized person should be required. When faced with unexpected change requests, cross-verification should be conducted through independent third-party channels, such as by phone; under no circumstances should actions be taken based solely on the original email.

Second, extend security protection comprehensively to the entire digital ecosystem. Medical devices, third-party testing laboratories, electronic health record (EHR) systems, and telemedicine platforms must all be incorporated into a unified security operations management system. At the same time, threat monitoring and reporting channels should comprehensively cover enterprise collaboration software, short message service (SMS), and calendar applications to enable the immediate identification of cyber scams that exploit urgent matters to lure victims.

At the same time, establish clear authorization boundaries for AI agents. Strictly limit the sensitive data and tools accessible to AI agents, and implement continuous monitoring for anomalous behavior. When highly sensitive information or critical clinical decisions are involved, a “human-in-the-loop” mechanism must be maintained to minimize security risks and data breaches caused by malicious commands or operational errors.

Ongoing Cybersecurity Training: The Key to Significantly Reducing Business Risks

In addition to implementing technical safeguards, continuously fostering cybersecurity awareness among employees is equally essential.

According to data from KnowBe4’s “2026 Industry Phishing Benchmark Report,” the “Phish-Prone Percentage” (PPP) in the North American healthcare and pharmaceutical industries—before security training—reached as high as 44%; and in very large healthcare institutions with 10,000 or more employees, this risk indicator has soared to 54.9%The

However, after undergoing 90 days of systematic training, the overall phishing vulnerability rate across the industry dropped significantly to 20.7%; for organizations with 10,000 or more employees, after one year of ongoing training, the phishing vulnerability rate plummeted even more significantly to 3%, achieving an increase of approximately 94% the rate of decline.

The empirical data cited above clearly demonstrates that cybersecurity awareness is not something that can be achieved overnight; it must be cultivated through regular drills until it becomes an instinctive behavioral habit for employees. Tailoring training content to specific roles, conducting regular simulated phishing exercises, and providing Just-in-Time Warnings when threats arise can effectively help employees accurately identify abnormal situations, rigorously verify suspicious requests, and promptly report them to the IT department.

As digital healthcare continues to evolve, high-quality clinical services must go hand in hand with robust cybersecurity defenses. Only when employees remain vigilant against various types of cyber scams and AI agents operate efficiently within clearly defined authority boundaries can healthcare institutions enjoy the efficiency and convenience brought by digital transformation while simultaneously building a solid, impenetrable defense to protect patients’ lives.

Would you like to gain a deeper understanding of the cybersecurity threats currently facing the healthcare industry and learn how to comprehensively enhance your organization’s defenses through ongoing awareness training and AI governance? Feel free to contact Actable at any time to obtain the full Traditional Chinese version of KnowBe4’s white paper, “When Hackers Target Healthcare Teams: The New Cybersecurity Frontline in Digital Healthcare,” and develop a compliant and secure digital defense solution tailored to your healthcare organization.

Other Articles

Hongke Sharing

[Hongke Insights] How Does TSN Build a Deterministic Foundation for Embodied Intelligence?

Discover how TSN (Time-Sensitive Networking) overcomes the bottlenecks of cable clutter, control latency, and data silos in embodied intelligent robots. Hongke’s TSN IP core offers extreme scheduling precision of ±16 ns and a unified network architecture, enabling precise multi-joint coordination and microsecond-level synchronization to build a highly reliable communication foundation for robots.

Read more
Hongke Case

[Hongke Solutions] AR Smart Healthcare Solution: A Practical Guide to Implementing Remote Consultations and Intraoperative Collaboration

Discover Hongke’s AR Smart Healthcare Solutions! Combining Vuzix AR smart glasses with a remote collaboration platform, these solutions support first-person-view remote consultations, intraoperative demonstrations, pre-hospital emergency care, and medical device after-sales support—freeing up healthcare professionals’ hands and enhancing the efficiency of cross-hospital collaboration. Learn about the key evaluation points for implementation by Hong Kong healthcare institutions today!

Read more
Hongke Dry Goods

[Hongke Solutions] As Phishing Emails Become Increasingly Realistic, How Does KnowBe4 Help Businesses Maintain Email Security?

As AI-generated phishing emails become increasingly realistic, traditional email defenses are no longer sufficient. This article explains how KnowBe4 uses four key mechanisms—Defend, Prevent, cybersecurity awareness training, and HRM+—to turn employees into the strongest first line of defense and master email security best practices for 2026. KnowBe4 uses a four-tier defense system that integrates inbound detection, outbound control, and employee training to help organizations reduce email risks at their root.

Read more

Contact Hongke to help you solve your problems.

Let's have a chat