2024HIMSSHealthcareCybersecurity Survey Table of Contents Executive Summary...........................................................................................................3Methodology and Demographics......................................................................................4Methodology.................................................................................................................4Demographics...............................................................................................................4Levels of Responsibility.................................................................................................5Types of Organizations Represented............................................................................5Economics of Healthcare Cybersecurity...........................................................................6Budgets are Improving..................................................................................................6Overall IT Budgets are Modestly Improving.............................................................6Allocation of current IT budget to cybersecurity......................................................7Comparing 2023 to 2024: Cybersecurity Budget Allocations.......................................8Trends in Cybersecurity Budget Allocations.................................................................9Cybersecurity Budgets Projected to Rise....................................................................10Changes to cybersecurity budget in 2025...............................................................10Effect of Cybersecurity Budget Increases in 2025..................................................11Security Awareness.........................................................................................................12Security Awareness Programs.....................................................................................12Effectiveness of security awareness programs.......................................................13Security Incidents............................................................................................................14Significant Security Incidents......................................................................................14Initial Points of Compromise...................................................................................14Testing of Incident Response Plans.............................................................................15Stakeholder Participation in Tabletop Exercises.....................................................16What’s Happening with Ransomware............................................................................17Present State...............................................................................................................172024 Ransomware Trends......................................................................................17Ransomware Trends: 2022-2024............................................................................18To Pay or Not to Pay–Ransomware Payments......................................................19Proactive vs. Reactive Security Measures...............................................................20Future State.................................................................................................................21AI Adoption in Healthcare...............................................................................................22Allowing the Use of AI in Healthcare..........................................................................22 To Govern or Not: Organizational Approaches to AI..............................................22AI Technology Use Cases.............................................................................................23AI Guardrails................................................................................................................24Approval Process for AI Technology.......................................................................24Active Monitoring of AI Technology.......................................................................25Acceptable Use Policy for AI Technology................................................................25Future Concerns Regarding AI....................................................................................26Managing Third-Party Risks............................................................................................27Third-Party Risk Management Programs....................................................................27Third-Party Security Incidents.....................................................................................28Impacts of Third-Party Security Incidents...............................................................29Insider Threat Programs.....................................................................................