Cipher of Cyber
Our word of the day comes from the Greek kubernētēs (κυβερνήτης), which literally means "steersman" or "pilot." It came to signify the concept of governance or control. In fact, the word “govern” is philologically related to the original Greek term cited above, with the “k” reasonably morphing into a hard “g” sound and the “b” converting to “v”—a common occurrence in word transition from one language to another. So, “kubern” becomes “govern.” So, then, we see that the cyber concept carries the connotation of control. And few would dispute the level of control the cybernetic world has over our lives today.
The modern scientific use of "cyber" began with Norbert Wiener in 1948, who coined the term “cybernetics” to describe the study of communication and control in animals and machines. Cybernetics focused on feedback systems, regulation and automated control, bridging biology, engineering and social systems. By the 1960s, "cyber" began appearing in science fiction. The term cyborg (a combining and shortening of “cybernetic organism”) was coined in 1960 to describe a human-machine hybrid. From the 1990s onward, "cyber" became widely used as a prefix for technology-related terms, including cybersecurity and cyberattack.
So, when we speak of “cyber” in the healthcare context, that includes computers, digital technology, information systems, internet access, electronic data files, etc. Alright, there’s our etymology lesson; now it’s on to the latest cyberthreats.
Sabotaging of Cyber
John Riggi, a highly decorated 28-year veteran of the FBI, now works with the American Hospital Association (AHA) as their national advisor for cybersecurity and risk, helping to secure America’s health infrastructure. He has recently released an advisory relating to the most critical cyber risks for the healthcare industry in 2026. They are summarized in the paragraphs below.
Geopolitical Tensions. According to Mr. Riggi, current geopolitical tensions with Russia, Iran, China and North Korea may incentivize these countries to attack the U.S. via cyber means, though not directly. Rather, they may direct or facilitate “unattributable criminal cyber proxies to conduct ransomware attacks or other types of disruptive cyberattacks against healthcare organizations, mission critical third-party providers and the supply chain.” He says they may also conduct attacks against critical infrastructure sectors, such as energy, water and telecommunications, “which may have a regional or national cascading disruptive effect on healthcare.”
Cyberattacks Against Third Parties. Mr. Riggi believes that criminal ransomware groups will continue to target healthcare third-party mission-critical technology, service and supply chain providers “to steal large aggregations of healthcare data and target them for ransomware attacks to cause maximum disruption across the entire healthcare sector.” The ensuing disruption may extend to their customers and patients. Riggi calls this the “ransomware blast radius” effect. He noted that cyberattacks against Change Healthcare and the blood/plasma sector in 2024, as well as Stryker in 2026, are recent examples.
AI Cyberattacks. According to Microsoft, artificial intelligence (AI) that is autonomous is the type of AI that can make decisions and take actions on its own, without human input. “Unlike traditional AI, which requires people to guide it, autonomous AI learns from data, adapts to new situations and operates independently.” In 2026, Mr. Riggi believes we will see expanded instances of AI-generated audio and video deep fakes, as well as AI-assisted vulnerability detection and malware development. “We may see AI being used by sophisticated cyber adversaries to launch cyberattacks throughout the entire attack cycle.” He noted that Anthropic documented the first such “autonomous” attack last year.
In summation, cyberattacks against hospitals, health systems and mission-critical healthcare third-party providers have surged in recent years. While these attacks often involve theft of patient data and medical research, the most concerning are high-impact ransomware attacks that continue to shut down critical medical systems, resulting in disruption and delays to healthcare delivery.
But there is a silver lining in the midst of these serious threats, according to Riggi; and that is the fact that “we have a great deal of battle experience and tough lessons learned, which has helped us collaborate to harden systems and prepare for impact and recovery.” He concludes, “We at the AHA, working with victims, the field and the federal government, have also been able to reliably identify strategic cyber risk related to third parties, patient safety and supply chain.”
Hopefully, this collective threat analysis will help to thwart future rounds of cyberattacks directed against the healthcare system.
