Skip to main content
News

Federal Shutdown Threatens Health Care Cybersecurity Readiness

As the federal government shutdown stretches on, health care leaders are growing increasingly alarmed about mounting cybersecurity risks and operational disruptions tied to reduced federal agency support. Experts warn that if the shutdown persists, it could leave health care providers dangerously exposed to cyber threats while delaying regulatory and compliance activities across the sector.

Errol Weiss, chief security officer at the Health Information Sharing and Analysis Center (Health-ISAC), cautioned that adversaries may seize the moment. “Health-ISAC has been tracking ransomware incidents since 2020. For 2025, we're going to witness a record-breaking number of ransomware attacks,” Weiss said. “When there’s a disruption like this, human lives are at stake.”

The Department of Health and Human Services (HHS) has furloughed 41% of its workforce, according to its contingency plan, retaining only those essential to “the safety of human life and protection of property.” While HHS’ Office for Civil Rights continues Health Insurance Portability and Accountability Act (HIPAA) investigations, staffing shortages may delay enforcement, rulemaking, and technical guidance, experts note. Privacy attorney Adam Greene predicts prolonged investigations and slower progress on long-awaited updates to the HIPAA Privacy and Security Rules.

Beyond HHS, the Cybersecurity and Infrastructure Security Agency (CISA) has retained just 35% of its workforce, stalling many of the threat advisories and coordination efforts that hospitals rely on. Jackie Mattingly, senior director at Clearwater, noted that “only staff considered ‘mission critical’ stay on,” meaning proactive cybersecurity guidance and interagency coordination are on hold.

The impact is especially severe for smaller health care organizations that depend on free federal services like CISA’s Cyber Hygiene scans. Without regular alerts, advisories, and shared intelligence, these providers may be left unaware of critical vulnerabilities already under active exploitation.

Experts recommend that health care executives strengthen internal threat monitoring, engage with information-sharing groups like Health-ISAC, and maintain communication with technology vendors during the shutdown. While federal operations will eventually resume, the lag in coordination and intelligence-sharing could persist, leaving the sector vulnerable even after funding is restored.

Health care executives should assume a prolonged lapse in federal cybersecurity support and proactively bolster internal defenses, ensure vendor readiness, and leverage sector collaboration networks to maintain resilience.

Reference

Kolbasuk McGee M. Experts: shutdown strains healthcare cyber defenses. BankInfoSecurity. October 3, 2025. Accessed October 6, 2025. https://www.bankinfosecurity.com/experts-shutdown-strains-healthcare-cyber-defenses-a-29643