Honeywell Technologies Honeywell Technologies
  • Who We Are
    • About Honeywell Join Honeywell on the Journey to Autonomy
    • Leadership Our senior leadership team
    • Partners Our partners in delivering value and transformation.
    Newsroom
    Explore our latest news
    Honeywell Expands Fire Portfolio with Advanced Smoke Control and Connected Life Safety Innovations
    Honeywell and MIT Find Digital Technologies can Help Increase Energy Supply, Reduce Energy Production Cost by Tens of Billions Annually
    Honeywell Technologies Hosts 2026 Investor Day; Provides New Three-Year Financial Framework
  • What We Do
    • Buildings Creating the next era of building automation
    • Industrial Driving the autonomous plant forward
    • Process Creating new energy opportunities
    Insights Hub
    Explore our latest insights
    Earn The Employee Commute Back to the Office
    CLSS is a Game-changer for Fire System Testing
    Honeywell Predicts The Top Three Building Trends of 2024
  • Honeywell Forge
  • Accelerator OS
  • Investors
  • People
    • Careers Help us build a better future
    • Life at Honeywell Discover our employee values
    • Your Career Journey When you grow, we grow
    • In the Community How we support our communities
    • Inclusion & Engagement Global perspectives for a diverse workforce
    • Integrity & Compliance Creating a culture of trust and transparency
    • Job Opportunities Find a new career with Honeywell
    • Meet Our People Get to know our truly amazing talent

    Job Opportunities

    Help shape the future of Honeywell Technologies
    Find a Career
    Professional portrait of an individual seated at a desk with a laptop against a clean background with subtle color gradient in corner.
  • Newsroom
  • Solutions
    Industries
    • Buildings
    • Chemicals + Materials
    • Data Centers
    • Healthcare
    • Heavy Industries
    • Hospitality
    • Life Sciences
    • LNG
    • Manufacturing
    • Oil + Gas
    • Low Carbon Energy
    • Utilities
    Outcomes
    • Asset Management
    • Energy Innovation
    • Operational Efficiency
    • OT Cybersecurity
    • Life Safety & Security
    • Workforce Excellence
    Businesses
    • Building Automation
    • Industrial Automation
    • Process Automation & Technology
    View All Solutions →

    Honeywell Forge

    AI-Powered, enterprise-level outcomes.
    Explore Honeywell Forge
    Vertical abstract red background with gradient tones and glowing accents, suitable for corporate visuals, digital assets, and design layouts.
    • Americas

        • Brazil - Portuguese
        • Canada - English
        • Canada - French
        • Mexico - Spanish
        • United States - English
    • APAC

        • Australia - English
        • Japan - Japanese
        • Malaysia - English
        • Republic of Korea - Korean
        • Singapore - English
    • Europe

        • Czech Republic - Czech
        • Czech Republic - English
        • Denmark - English
        • France - French
        • Germany - German
        • Italy - Italian
        • Netherlands - Dutch
        • Netherlands - English
        • Poland - Polish
        • Romania - Romanian
        • Romania - English
        • Spain - English
        • Spain - Spanish
        • United Kingdom - English
    • META

        • Saudi Arabia - Arabic
        • Saudi Arabia - English
        • Turkey - English
        • Turkey - Turkish
        • United Arab Emirates - Arabic
        • United Arab Emirates - English
    • India

        • India - English
    • China

        • China - Chinese
  • Contact
  • Support

You are browsing the product catalog for

You are viewing the overview and resources for

Sign in

to view parts associated with your account

  • Home
  • Insights
  • Cybersecurity Requirements for Healthcare Organizations

Cybersecurity Requirements for Healthcare Organizations

Healthcare organizations are highly vulnerable to cyberattacks, and must fortify their OT systems against cyberthreats to make sure protective measures are in place.

Published on 04-22-2024 Published on 04-22-2024 2 min read

Healthcare organizations are highly vulnerable to cyberattacks, averaging 1,463 cyberattacks per week in 2022, up 74% compared to the previous year [i]. The healthcare industry has also ranked highest in data breach costs for 12 years in a row [ii]. The potential impact of a cyber incident is not just financial–the consequences can be fatal [iii].

Hospitals are targeted for several reasons. First, they are vulnerable targets as attackers seek to exploit them for the notoriety of claiming they successfully shut down such critical facilities. Healthcare data is also in high demand on the dark web and can fetch a hefty sum for attackers.

Another major reason hospitals are targeted is that they have large operational technology (OT) environments with thousands of entry points. On the medical side, this includes a vast array of equipment, from MRI machines to ventilators. On the building side, it includes assets like fire and life safety systems, HVAC and access control. The sheer volume of assets provides an attack surface far larger than almost any other industry. Moreover, many of these systems operate on legacy frameworks, making them more susceptible to exploitation.

U.S. Department of Health and Human Services considers new requirements

In response to this increasing threat, the United States Department of Health and Human Services (HHS) published a concept paper [iv] introducing new measures designed to help protect the sector from cyberattacks.

These measures include:

1. Establish voluntary cybersecurity performance goals for the healthcare sector to help healthcare organizations prioritize cybersecurity practices.

2. Provide resources to incentivize and implement cybersecurity practices such as the establishment of an upfront investments program to help high-need providers.

3. Implement an HHS-wide strategy to support greater enforcement and accountability. Including potential increased financial penalties for HIPAA violations.

4. Expand and mature the one-stop shop within HHS for healthcare sector cybersecurity, thereby increasing HHS’ incident-response capabilities.

The intent is to better equip hospitals with cybersecurity education and resources, as well as discourage noncompliance by strengthening HHS’ enforcement authority.

Healthcare organizations don’t know what they don’t know

A big security hole at many hospitals is lack of awareness. They may think their OT systems are secure when they’re not. For instance, the systems may be air-gapped, which means they’re not connected to the internet, but most of them must be patched or updated regularly. This might mean that, on the first of every month, the systems are connected to the internet to download the patches or updates and thus they are not truly air-gapped.

Even if the patching and updating are done via USB, those OT systems may still not be safe. A Honeywell study found that OT assets face a significant and escalating risk from malware infiltrating through USB media [v] . Another risk is that many cyberattacks target third-party OT systems whose providers may have access rights to perform maintenance and upgrades. This opens the door to yet another threat.

Three steps healthcare organizations should take now

The pressure is on for hospitals to fortify their systems against cyberthreats and put all necessary defense measures in place. Here are the top three steps they should take to get started:

1. Create an incident response plan. This is essential for hospitals to swiftly recover if they’re hit with downtime or if critical equipment, such as ventilators or HVAC systems, are targeted in a cyberattack. Without a plan in place, a hospital can’t get back up and running quickly and efficiently, and make sure its patients and staff are safe.

2. Be aware of full asset inventory. The reality is that most OT systems have an IP connection However, IT doesn’t monitor these connections for cyberthreats as closely as it monitors its own systems. It’s essential that hospitals know exactly what they have running in their environment in both IT systems and OT systems so they have better visibility into all their systems and all the threats and vulnerabilities they face.

3. Have a trusted partner. Before allowing third-party vendors to access their systems, hospitals need to understand the specifics of what vendors are doing. Do they know what type of computers their vendors are using? Are there proper checks and balances in place to keep their operations safe and secure? Hospitals should establish clear communication channels with their partners for continuous transparency and accountability.

Safety and security are paramount in a healthcare environment. As a trusted partner, Honeywell can help healthcare organizations solve cybersecurity challenges and stay compliant with new regulations as they are introduced.

Talk to one of our experts today to learn how Honeywell can help you improve your healthcare organization’s cybersecurity.

Not yet ready to talk to an expert? Click here to learn more about how comprehensive OT cybersecurity protection can benefit your hospital.

 


[i] Check Point, Check Point Software Releases its 2023 Security Report Highlighting Rise in Cyberattacks and Disruptive Malware, February 8, 2023 [Accessed March 1, 2024]

[ii] UpGuard, What is the Cost of a Data Breach in 2023?, October 25, 2023 [Accessed March 1, 2024]

[iii] WIRED, The untold story of a cyberattack, a hospital and a dying woman, November 11, 2020 [Accessed March 1, 2024]

[iv] United States Department of Health and Human Services, Healthcare Sector Cybersecurity, December 2023 [Accessed March 1, 2024]

[v] Honeywell Forge, Industrial Cybersecurity USB Threat Report 2023 [Accessed March 1, 2024]


Related Content
  • A warehouse worker uses a handheld barcode scanner to manage inventory efficiently in a busy storage environment. Perfect for enhancing supply chain operations.
    Healthcare
    How Honeywell & SOTI Drive Faster, Smarter Mobile Operations

    Discover how Honeywell and SOTI integrate mobile tech and software to boost speed, data insights, and efficiency across logistics, retail, and healthcare.

  • Smoke Detectors Plant
    Buildings
    We Make Cool Things in Juarez, Mexico: Devices That Power Buildings Worldwide

    Our teams build innovation from the circuit board up—designing, assembling and testing smart building technologies, including more than 3 million smoke detectors a year.

  • A medical professional in a lab coat works on a computer, analyzing data displayed on multiple monitors in a modern office setting. The screens show graphs and data tables related to health information.
    Healthcare
    How Automation Simplifies Regulatory Compliance in Hospitals

    Automation can empower hospitals to meet evolving regulations, helping them to streamline compliance, enhance safety and scale with confidence.

  • Show More
Healthcare professional using a laptop

Three Ways Healthcare Organizations Can Prepare for New Cybersecurity Requirements

Who We Are
toggle view
  • About Honeywell
  • Leadership
  • Patents
  • Partners
  • Trust Center
What We Do
toggle view
  • Buildings
  • Industrial
  • Process
Forge
toggle view
Accelerator OS
toggle view
Investors
toggle view
People
toggle view
  • Careers
  • Life at Honeywell
  • Your Career Journey
  • In The Community
  • Inclusion & Engagement
  • Integrity & Compliance
  • Job Opportunities
  • Meet Our People
Businesses
toggle view
  • Building Automation
  • Industrial Automation
  • Process Automation & Technology
News
toggle view
  • Articles
  • Events
  • Press Releases
Industries
toggle view
  • Buildings
  • Chemical & Materials
  • Data Centers
  • Healthcare
  • Heavy Industries
  • Hospitality
  • Life Sciences
  • LNG
  • Low-Carbon Energy
  • Manufacturing
  • Oil & Gas
  • Utilities
Outcomes
toggle view
  • Asset Management
  • Energy Innovation
  • Life Safety & Security
  • Operational Efficiency
  • OT Cybersecurity
  • Workforce Excellence
Legal
toggle view
  • Accessibility
  • Certifications
  • Patents
  • Suppliers
  • Warranties
Support
toggle view
Contact Us
toggle view
  • Business Inquiries
  • Employee Access
  • Retiree Access
Honeywell Technologies horizontal logo allowing users to navigate to the homepage of honeywell.com.
Honeywell Technologies horizontal logo allowing users to navigate to the homepage of honeywell.com.
toggle view
  • Contact Us
Follow Us
  • LinkedIn
  • Facebook
  • YouTube
  • Instagram

Copyright © 2026 Honeywell International Inc

Terms & Conditions
Privacy Statement
Your Privacy Choices
Cookie Notice
Global Unsubscribe

We use cookies and similar tracking online technologies to improve website performance, record website activities, facilitate information sharing on social media and offer advertising tailored to your interest. For more information, see our Cookie Notice and Terms and Conditions. You can also customize your browser’s cookie settings. Please note that if you refuse cookies, it may affect site functionality and performance.