I'm Gary and Colby Seckman, the executive editor at Information Security Media Group. Today I'm speaking with the training sessions of law firm Baker Hostetler. We'll be discussing a new annual data security incident response report examining data breach and related security trends. So Lynn, I understand that the 2024 report is based on data that Baker Hostetler analyzed from incidents that the firm managed over several sectors in the prior year.
What were some of the key findings that stick out and what were the biggest surprises and concerning trends over all that you saw? So I think first and foremost, healthcare is still number one. That has been consistent in our findings over the 10 years that we've been doing the data security incident response report and healthcare is absolutely a target of threat actors and other bad guys that are looking to get into healthcare systems or getting data out of the system. So I think that's probably the biggest takeaway from here and certainly 2024 has demonstrated that with the incidents that we've seen.
So two, I think one of the biggest surprises were the number of business email compromises and phishing incidents that we saw this past year. So we felt like with the advent of multi-factor authentication and with our clients implementing multi-factor authentication, we saw a big decrease in business email compromises where they were back with a theory last year and particularly in the healthcare space. So even though most of our clients did implement MFA, we saw that that guys were able to bypass the MFA in a variety of different ways and get into emails, email accounts, and then pivot into other areas of the organization's network. And then two, I think another surprise that a lot of people see are the size of the organizations that are representative in our report.
So many people think that, oh, I'm too small, I'm not a target for these threat actors, or I'm so big that I'm too big to fail. And if you look at the data that's in the DSIR, you'll see that the largest organization is probably make up, I want to say like 13% of the incidents that we handled last year. Part of the reason is because they spend a lot of money on security, but they're not infallible, right? We certainly have seen that again this year with the change.
Healthcare matter being part of the United Health Group, that even large large organizations are not immune to being attacked. But similarly, what I said is the smaller organizations are not either. So if they're data rich or if there's something that a bad guy sees of value, then they're going to figure out a way to get in or they're looking for a crime of opportunity. So I think that that's the takeaway I look at each year and always surprises me is to see not only who we represent, but the size of those organizations are.
So then I understand that the report also kind of dived into ransom payments and the amounts of payments and so on and so forth compared with other industries, how likely were health sector entities to pay a ransom and why? So it's very interesting. I get on calls with clients whether I'm doing proactive work for them or when we're in the heat of a ransomware attack and nobody wants to pay these criminals, right? Like there is, I never get on a call and say, and someone says, oh, I'm ready to pay a criminal in the other part of the world.
But we do look at things very carefully. So I would say, you know, our data would probably suggest, and this is just a little bit of a sit-balling, that it's about 50-50, right? So nobody, you start off with zero, nobody wants to pay. And then you look at the specific factors as to what would impact a healthcare organization.
One of the things that makes healthcare very vulnerable in this scenario is that they've got to take care of patients 24-7, right? So if there's an impact of their operations through encryption, which nowadays we are mostly seeing these threat actors do double extortions. So they will encrypt the data and they will take data from you. So they've got two reasons in which they try to strongarm you into paying.
So if our clients need the decryption key to get their operations back up and running and presumably back up and running more quickly than if they rebuilt from scratch or restored from backup, then you will see them pay for the decryption key. Our normal stance is if you're just paying for the suppression of data, don't just pay for the suppression of data. Because as we found with change healthcare, sometimes there are things that can go wrong and your data still gets published. But we do talk with our clients and it's a very back specific scenario based on their specific operations, what data may have been taken or impacted, and making decisions around whether they should pay or not to pay.
And some of it's just the culture of the organization. I have many clients who are like, we are no way, no how are we going to pay these threat actors no matter what they do to try to strongarm us into doing so. And we've definitely seen the tactics change where these threat actors are concerned in trying to pressure in particular healthcare organizations into paying them. So as we saw in the change healthcare situation, it was reported that United Health Group paid a ransom and then behind the scenes an affiliate of Black Cat, V claimed that that affiliate didn't get their promise to share of the ransom.
And then blow and behold, another group, Ransom Hub, pops up and says, oh, we actually have that data that the affiliate had. And now we want another ransom. That's what it looked like it was playing out. United Health Group did say that it paid a ransom, but didn't say how much it didn't say to whom.
But the bottom line is how much assurance is there for an entity when they pay? Have you heard of other incidents in healthcare where a healthcare organization paid, but then they still didn't get promises of their data being destroyed, or not leaked, or not getting an effective decrypt key? Like, how much can these cyber criminals really be trusted? So really before the very public change healthcare, Renee on the ransom payment, when I would talk with clients about how trustworthy and you can't see me but I'm making air quotes, how trustworthy these criminals are.
And these are conversations I have with CEOs and boards of directors when you're making these decisions is they treat this lack of business, right? Like this is a business model for them, such that the kingpin at the very top of this crime syndicate gets paid the most money, but then there's the the person that runs the website that is transacting the business and essentially doing the communications with the victim. And then you've got these affiliates that are some of them are stealing data, some of them are figuring out ways to get into their systems. And frankly, everybody in the chain is supposed to get paid.
And we would say like, we've got statistics, the FBI keeps statistics, we have bigger keeps statistics, some of our negotiation partners and security partners also keep statistics on how trustworthy these groups are. So I have no doubt that when when change was making these types of decisions, they were being informed by advisors on how trustworthy these groups were, including the FBI. And it is a little disconcerting to talk about trustworthy criminals, but that's, you know, the kind of conversations you have in these types of scenarios. And really up until that point in time, we would say, look, they've got a 90% track record, 100% track record, you know, you're going to pay them $22 million, you're probably going to get what you paid for, right?
And that is typically what we have seen, is that you get what you pay for it. You ask for a decryption key, you get the decryption key back. If you ask for them to suppress the data, that group doesn't automatically go and publish the data on the dark web. Now, one of the things there was another group that was brought down by the FBI earlier this year.
And as they unpacked the evidence that they had, they identified that data was that was supposedly deleted was still in their possession. And that's one thing I tell clients all the time, if you're paying solely for the suppression of data, if you don't need the decryption key, so you can get your operations back up and running. But if you're solely paying for suppression of the data, don't think for a second, these people are not keeping your data. And are they going to come back five years from now and try to demand ransom from you again?
So I think one of the things that came out of the change issue is that we did see that actually play out where someone in the chain of criminals did not get their pay. And they're like, heck, we deserve to get paid. And so they found another sponsor in the form of ransom hub to try to extract that extortion money from change a second time. And it gives me another talking point, quite frankly, when I'm counseling clients on whether to pay or not to pay.
So as I mentioned earlier, we've seen this kind of tick and tactics that they've used. They're doing things like reaching out directly to patients via email and trying to extort out of them when an organization does a pay. We've seen them go to the media with data dumps, very sensitive information that came out of the data that they extracted. They go and look for sensitive data in the real departments and other departments of the health systems trying to find what they would consider to be sensitive data.
Because nowadays, I think we as Americans probably feel like, you know, our social security numbers probably out on the dark web. How many of those letters have we received with an offer of credit monitoring over the last decade. But there's something very, very private and sensitive about our health information. And in some instances, it may be your cancer treatment or it could be some other something else that's your mental health treatment.
Things are really considered sensitive in the healthcare space that these bad guys may may claim to have. We had one client at the end of last year that the right actor did what at the time I didn't know what this meant threatened to swat some of its patients, which was as I learned from FBI is essentially creating an environment that a SWAT team shows up to the person's house. And when they have no idea what's going on, presumably they then become the target of a SWAT action. So these are horrible horrible things that we're seeing these threat actors really resorting to try to convince our clients to pay.
And I think that aggressive nature is only going to continue to increase. So Lynn, I understand that when it comes to attacks involving extortion, the average ransom demand in healthcare was about 3.5 million. But the average ransom paid was less than a million about 858,000. What do you attribute the $2.6 million gap to between the average demand versus what's paid?
Does that reflect ransoms being negotiated downward? Does that reflect, some entities where they're getting demands of less than a million dollars or more likely to pay than when a ransom is higher? What's going on? Yeah, that's a terrific question.
And it's really kind of all of those things, right? So we do see that these threat actors, when they find a victim, they do a little bit of homework on them and have a pretty decent understanding of how big the organization is, what type of organization it is. They may even look for your financials. A lot of the non-for-profit healthcare systems, their financial information is out on publicly available, even some of the for-profits, right?
Like your financial information may be publicly available. So we know they do their homework. So when they make a demand, it's usually in line with the size of the organization. So what that number that you are seeing though in our report reflects is, as I mentioned, maybe 50% of our clients are in healthcare space or paying ransom.
So you may have a very, very high demand, and that high demand never gets negotiated down or never gets paid. But yes, you're absolutely correct. Those numbers get negotiated off of, and that's actually part of the early conversations that we're having with FBI, with the ransom negotiation firms and security firms, is based on your experience, what have you seen this particular group negotiate down from? So if I had to speculate knowing Black Cat and Alpha V, the initial demand may have been double what changed ultimately paid.
Now it's pure speculation on my part, but just kind of based on our experience and looking at the data that we see in the healthcare space, it's not unusual to get a 50% reduction. We may only get a 20% reduction, but those types of conversations take place at the outset at any rate of negotiation discussion. So we can plan a strategy on what's the number that we're targeting. Is it something that the organization can afford?
Do they think it's worth it to pay that? And how long will it take us to get to that number? So that's the other thing too, is I cancel my clients on, it's a time versus money. So if you've got three weeks that you can wait, then we may be able to negotiate off of that $5 million initial demand.
So there's a variety of different things that factor into that number. So that's exactly as you pose the question, it's really kind of all of those things that may come into play when we're in the process of negotiating. So if an organization does pay and they pay for a decryptor key or they perhaps pay to have the data suppressed, they're not going to leak the criminals, they're not going to leak it on the web or whatever dark web, what happens then when it comes to the regulatory and notification aspects? Does anything change?
Because again under HIPAA, being that the attackers had access to that information. It was potentially compromised, HIPAA kicks in, you have to notify. Does anything change on the second half of that end there? Okay, now you're up past the initial attack and you've paid the criminals not to publish your data, but now you still have to deal with breach notification, potential lawsuits, so on and so forth.
How does paying the ransom help or not help for that matter? You get no credit for paying the ransom if it's for the suppression of data. And that also becomes part of the conversation we're having with our clients because you still as you rightfully pointed out, because it's an access or acquisition as a regulation with respect to HIPAA, just the mere access into your protected health. And I'll say this, HIPAA even goes one step further.
You have a presumption of a breach unless you can demonstrate that the protected health information, the PHI as we call it, was not actually viewed required. So I always use the example of a house. So you know, the bad guy comes into my house, that's my network. My PHI is stored in my bedroom.
If I can't prove that he did not go into my bedroom and take in and see that PHI, then I may have to denotification. Now I'm simplifying that drastically in my forensics partners, which we know would be appalled that I've simplified what they do so much. But to a certain extent is that way. So once the bad guys in your system, we then we are then have the burden to prove that PHI was not accessed.
PHI was not acquired by the bad guys. Usually acquisitions pretty easily. Did they take anything? If they took anything, it's easy.
You have to denotification. Access can be a little tougher because it's all contingent on the evidence that's available. And some of that evidence may be encrypted through the ransomware event. So you're spot on.
You still have to denotification, you're still going to get sued and you don't get any credit for paying the ransom. So when you start examining the incidents in healthcare, what are some of the common types of intrusions that play out? What are the particular security shortcomings that often come into play? So certainly healthcare is a pretty open environment.
And if you think about what a caregiver needs to do on the front lines of taking care of a patient or multiple patients, right? Like when you think about a hospital setting, you've got nurses that are taking care of multiple patients, you've got respiratory therapists who are doing that, you've got phlebotomists that are coming in and taking blood, and you've got doctors that are rounding on patients and multiple patients on not just on a single unit, but from floor to floor. And that's the hospital setting. Similarly, in a physician's office, you may have a physician that is going from room to room, seeing multiple patients at any given, you know, at any given time.
So the, the electron medical record environment is pre-open. And as a result of that, you can't really lock down the security. It's a necessary part of taking care of patients and the bad guys had exploited that. And then as we move to a more remote environment, too, where you may have people that have to log in, whether they're radiologists, they're logging in from home to rearrange radiology studies or whatever that may look like, it just opens the environment up even more.
So we've seen exploitations of things like remote desk protocol. We've seen what's called Citrix session hijacks that had taken place in the last year, where basically the bad guys are able to get into a Citrix session and then hijack the whole session and get into the network. This is a way in which they're bypassing multi-factor authentication. So when we look at kind of the standard of care, if you will, and since I'm talking about healthcare, I'll use that term.
When you're talking about a standard of care, we've seen healthcare move into multi-factor authentication as being part of that standard of care. So like basic security. We've seen endpoint monitoring tools now moving into the space. So you can, you've got that perimeter security that's around your network.
So you can see when bad guys are ingressing and egressing into your system, that's becoming more standard of care, but it's not cheap. But then you, if you really think about how networks are built, and I had a forensic friend of mine explained this to me, it's not like when you get a new electronic medical record, you throw everything out and you have a brand new one put in place. It's built on decades old technology that you already have within your systems. And sometimes that decades old technology is not as easily to secure.
So there are just, and this is probably true really of any environment, but I think because of the openness of healthcare, we find that it may be more prevalent needing to have things that may not be able to be patched because they're older technologies or they're missed because they haven't been inventoryed appropriately. But those, the bad guys are able to find, probably through the use of things like artificial intelligence and other types of scanning that they do, they're able to find kind of that one weak link that you have in your systems. And then separate from that, you know, it's just a human element. We still see things very basic like phishing emails coming in, social engineering that has become a little bit more sophisticated in the sense that they're impersonating the individual to get past multi-factor authentication, calling into and help desk pretending to be an employee and able to bypass multi-factor authentication and get into all of the systems.
There's been a big attack even prior to the change issue on the revenue cycle departments of the number of our clients. And so when change happened, I meant this is not shocking to me because it's very clear that these folks in these criminals in other parts of the world have been trying to attack the revenue cycle sector of healthcare for several months now. So with that said, what is your advice for how entities can be better safeguarded against these sorts of incidents and what's your advice for entities to be better prepared in terms of responding to them? So I'm going to go back to the basics and it's going to sound so basic to say this, but HIPAA is actually a very, very good regulatory framework and it's flexible depending on the type of organization that you are.
So it consists of the privacy rule, the security rule, and the breach notification rule. And really, Marianne, what you're asking me about here is the security rule. So go back to the basics on that. Are we doing an annual security risk analysis to identify the risks and vulnerabilities of our entire network?
Wherever it is that we've got PHI and an electronic PHI. Number two, what is our risk management plan so that we can implement on the risk and vulnerability that we identify as part of that risk security risk analysis? Those are basics and kind of fundamentals around HIPAA. And as part of your security risk analysis, you need to inventory as to where it is that you have all of your PHI and EPAHI.
Because until you know where it is, you're not really able to wrap your arms around and say, yes, we're protecting it. We're putting the locks on the doors. We're putting MFA in place. We know where all of our in-res and egress points are, such that a bad guy could get in.
And then look at what is standard to care in the industry. I will tell you, in the 13 years that I've done this, and I've been in healthcare for the 30 years that I've been in practice, but the 13 years that I've really focused my practice on this type of work, we have seen a complete evolution of the information security role within a healthcare organization, such that now they sit in the C-suite or at the C-level. And that is tremendous because they're getting the attention of the folks in the C-suite. They're able to get the dollars behind putting security in place.
They have a voice at the table, and that is critically important, both on the regulatory front, but also to, I think, just in maintaining the security of an organization. So that's what I would say on the security front is really just go back to the basics, identifying what your risk are and addressing and mitigating the risk that you have in your organization. What do you do to prepare for these incidents? So at a minimum, you need to have an incident response plan in place and using multidisciplinary.
The thing that is so critical about a ransomware attack, which is unlike other security incidents that our IT professional deal with on a day-to-day basis, a ransomware attack impacts operations. It actually can impact patient care. And we've seen it now with a vendor like Change that date impacted patient care, even though they're the third party vendor that is not even on our site that's impacting quote operations. But we saw that the inability to get eligibility checks for patients that were coming in from insurance perspective and impact on pharmacy and being able to fill in prescriptions.
So it's quite interesting to me that we've even seen that on the vendor front. But back to the individual health care provider, they got an incident response plan in place. And then to one of the things that we do with number of our clients is we'll do tabletop drills. And it's not just for the IT department.
We'll do tabletop drills with the multidisciplinary group that will include, of course, legal and compliance and privacy, information security. It'll include physical security. So sometimes we have to communicate with with FBI or other law enforcement. It'll include your CFO because we're making decisions about paying perhaps millions of dollars to a criminal.
CEO will oftentimes come to we'll be in the room to make a decision around to pay or not to pay. We've got a communications team. The communications component around these types of incidents are humongous. If you think about all of the stakeholders that health system or even a vendor like Change has to communicate with tremendous communications component of this and what works for one organization may be different from another organization.
So you can see they're just in one I'm describing to you. Oh, we've got to have operations people there. We've got to have the chief medical officer. We've got to have the chief nursing officer so that we're ensuring that we're taking care of patients appropriately.
And depending on how your organization structure, we may have an emergency management team that's in place that incident command team, you know, kind of based on certain structures that may be already existing in our healthcare organization. So we like to be able to proactively do that. We say that if you exercise your muscle memory around this, then you're going to be better when a day comes if something were like this to happen. So it's tremendous.
It's a time commitment on the part of the organization. But we've seen more and more healthcare health care clients of ours wanting to avail themselves to services. And I think it's very smart to do that. Well, thank you so much, Lynn.
I've been speaking to Lynn Sessions. I'm Mary Ann Cobas at McGee of Information Security Media Group. Thanks for joining us.