AI Cyberattacks on Hospitals Are a CFO Problem, Not an IT Problem

Five cybersecurity stories came out of healthcare this past week. Every one of them has a revenue cycle consequence, but all of the focus was on AI as the attackers. Let’s talk about the billing implications.

The American Hospital Association said hospitals cannot afford to defend themselves against attackers using AI. Two AI companies offered to help pay for it. A phishing campaign is impersonating the most trusted brand in patient billing. And a new executive order made it clear that most hospitals cannot say what equipment is running inside their own buildings.

I want to walk through all four. Then I want to talk about what a cyberattack actually does to your cash, because I lived through the Change Healthcare cyberattack, and I want to make sure we don’t all forget.

Can hospitals actually afford to defend against AI-powered attacks?

According to the AHA, no.

James "Scott" Gee, deputy national adviser for cybersecurity and risk at the AHA, told Becker's Hospital Review that hospitals cannot afford the tools required to defend against an adversary armed with AI. He does not believe hospitals can solve it alone.

Three things changed on the attack side:

  • Phishing got clean. AI writes emails without the spelling and grammar errors staff were trained to spot.

  • Voices got fake. Health systems are reporting AI-generated voices calling IT help desks and impersonating employees to get credentials reset.

  • The clock got short. Ransomware operators are building working attacks against newly published vulnerabilities within 24 hours. That used to take weeks or months.

Gee also pointed to a Five Eyes intelligence warning that AI models could overwhelm existing cyber defenses in months rather than years. Agency leaders signed that alert themselves, which is not how those things usually go.

His comments came a day after OpenAI, Microsoft, and more than 100 technology and security companies published a joint call for stronger defenses. That letter named hospitals specifically among the critical infrastructure at risk.

What are OpenAI and Anthropic offering hospitals?

Both frontier AI labs moved on this within four days of each other.

Anthropic introduced Enterprise Frontier Safeguards on Sept. 1. It was built with feedback from healthcare organizations and more than a hundred other enterprise customers. It pairs zero data retention with automated monitoring for stolen credentials, attempts to develop offensive cyber capability, and AI agents behaving destructively across multiple sessions. Activity logs stay in the customer's own cloud storage, under the customer's own encryption keys. Flagged activity routes to the customer's security team rather than to Anthropic. Rollout is phased starting this fall.

OpenAI committed $1 billion two days later through a program called Daybreak for Frontline Defenders. That covers subsidized access to its Daybreak cyber models, plus training and technical support. The target population is almost word for word what Gee described: water utilities, community banks, health systems, and local governments. There is a pilot with MS-ISAC, whose membership includes public hospitals. OpenAI expects the full billion to be spent within six months.

Take the help. If you run a critical access hospital with two people in security and a budget set before any of this existed, these are the most useful offers anybody has made you this year.

Look. A subsidy buys you time. But that’s about it.

Also, remember: the companies subsidizing your defense are the same ones building models capable of finding and exploiting software vulnerabilities. They are open about that. Read into that what you will.

Why is MyChart a phishing target if Epic was not hacked?

Because the brand reaches almost everybody. MyChart is licensed by thousands of hospitals and clinics, so one templated email plausibly lands in the inbox of a huge share of U.S. patients no matter which health system they actually use.

Epic's platform was not breached. No patient data leaked. Even so, more than forty health systems have warned patients about the same campaign. Becker's tracked the count from seven in mid-August, to twenty-one, to past forty by early September.

The emails offer a free "Senior Health Package" with subject lines about a MyChart Medicare kit. They point to a fake site that copies the real MyChart code. Some of them sign off from a "MyChart Health Network" at an address in Verona, Wisconsin, which is Epic's actual headquarters. (I’ve gotten the email myself.)

Because there is no underlying vulnerability, there is no patch and no central incident. Every health system found the campaign independently, usually after a patient forwarded a suspicious email. Then each one wrote its own warning with its own staff.

The scam works because it is boring. Health systems spent a decade training patients to receive real lab results, real appointment reminders, real statements, and real Medicare correspondence through that portal.

Revenue cycle owns the consequence here. When a patient gets burned, what she loses is confidence in the next real bill you send. She stops opening billing email. She stops paying in the portal. She waits for paper. The balance ages into bad debt and nobody ever speaks to her about it. That is a lifetime value problem sitting inside a security story.

Does the new power grid executive order affect hospitals?

Probably, and most hospitals cannot yet tell you how much.

An executive order signed Aug. 26 declared a national emergency over foreign-made equipment in the U.S. bulk-power system. It gives the Energy Department authority to restrict certain acquisitions and to impose conditions on equipment already installed, up to isolating, disconnecting, or replacing it. Implementing rules are due within 120 days.

The order excludes local electricity distribution, so most hospitals sit downstream of the main thrust. But its definition of covered equipment reaches backup generators, battery energy storage, uninterruptible power supplies serving critical infrastructure, and industrial control systems, along with the software, firmware, and remote access that come with them.

Muhammad Siddiqui, CIO of Reid Health in Richmond, Indiana, explained to Becker's why hospitals cannot answer the scope question. UPS units, generators, automatic transfer switches, and chillers were bought years ago out of facilities capital budgets and installed by general contractors. They never crossed an IT or cybersecurity desk. The nameplate on the cabinet tells you who integrated the equipment. It will not tell you who built the controller board, whose code is on the firmware, or whether a live cellular modem is sitting inside for vendor maintenance.

That equipment stays in service 15 to 25 years. No hospital is taking its electrical infrastructure offline to satisfy a compliance timeline.

Every house has one kitchen drawer nobody can inventory. (The packet drawer.) Batteries of unknown charge, a key to a house you sold in 2011, four takeout menus. For a lot of health systems, that drawer is the electrical room. The systems that submit your claims, post your remits, and run your patient portal all sit physically on top of it.

What does a cyberattack actually cost a hospital's revenue cycle?

I have been writing about this for years, and it is why I gave cybersecurity its own chapter in RCM 2030.

Go back to February 2024. Ransomware took down Change Healthcare, the clearinghouse behind roughly a third of all U.S. health claims. An AHA survey of nearly a thousand hospitals found 94% disrupted. Almost 60% reported losses of a million dollars a day or more. Nearly 193 million individuals were affected. UnitedHealth advanced more than $6 billion to providers and still took an $872 million hit itself in the first quarter.

Here is the mechanical damage, in order:

  1. Claims stop. Timely filing deadlines keep running. That revenue is gone even after systems recover.

  2. Remits freeze. You cannot post payments, which means you cannot cover payroll or vendor invoices.

  3. Portals go dark. Most patients will not call or mail a check. They wait. The balance ages into bad debt.

  4. Documentation locks up. Coders cannot assign codes without operative notes and lab results. Appeal teams cannot substantiate medical necessity.

  5. The backlog arrives. Even after restoration, you add weeks of cash delay digging out.

Attackers know this. Ransomware often hits at month end or quarter end, when cash flow matters most.

For RCM executives, cybersecurity is not a compliance box. It is a financial risk at the same level as payer mix, denials, or AR days.

What should a hospital CFO actually do about this?

Five things, ordered by how fast you can start.

1. Put a number on downtime. Calculate what one week of billing downtime costs your organization in delayed cash, expired timely filing, and bad debt conversion. Tampa General has done this work publicly, quantifying cyber risk in dollar terms for its board. That number moves a security budget faster than any framework I have ever presented.

2. Translate for your CISO. Your CISO is carrying clinical uptime, ransomware prevention, and regulatory survival at the same time. Next to that list, your billing platform reads as one more application. Reframe it. A ransomware hit on billing is a denial of service on cash. A vendor with no exit plan is an open back door.

3. Define your crown jewels. Not every system matters equally. If you lose a reporting dashboard, it is annoying. If you lose the claims submission gateway or the payment posting platform, it is catastrophic. Decide now which systems get restored first.

4. Count what you have. Inventory the AI already running in your environment, because it is in there whether leadership knows it or not. Then ask facilities for a list of every piece of powered infrastructure with a network port or an internal radio. Whatever comes back, including nothing, tells you where you stand.

5. Run a revenue cycle tabletop. Most incident response exercises focus on how fast the EHR comes back online. Practice the billing moves too. When do you flip to contingency billing? How do you tell patients about payment delays? Can you keep claims moving manually?

Frequently asked questions

Are AI-powered cyberattacks on hospitals happening now, or is this a future risk? Now. The AHA reports ransomware operators building working attacks against newly disclosed vulnerabilities within 24 hours, AI-generated phishing without the usual language errors, and AI voice impersonation targeting IT help desks.

Is cybersecurity a CFO responsibility or a CISO responsibility? Both, and the gap between them is where hospitals lose money. The CISO owns the technical defense. The CFO owns the financial consequence and has to fund it. Neither works without a shared risk assessment measured in dollars.

How much did the Change Healthcare attack cost hospitals? An AHA survey of nearly a thousand hospitals found 94% disrupted, with almost 60% reporting losses of a million dollars or more per day. Nearly 193 million individuals had data exposed.

Was Epic hacked in the MyChart scam? No. Epic's platform was not breached and no data leaked. Attackers are impersonating the MyChart brand in phishing emails because it is licensed by thousands of hospitals, which means one templated message reaches a large share of U.S. patients.

Does the August 2026 power executive order require hospitals to replace equipment? Not yet. The order directs the Energy Department to publish implementing rules within 120 days. It excludes local electricity distribution, but its definition of covered equipment includes backup generators, battery storage, UPS systems serving critical infrastructure, and industrial control systems. Scope depends on the final rule.

What is the first thing a hospital should do? Build an inventory. Every expert quoted this week gave the same first instruction, whether the subject was AI tools or facilities hardware. You cannot defend, budget for, or contract around equipment you have never counted.

April Wilson is the author of RCM 2030: Strategy and Survival for Revenue Cycle Leaders and its companion guides. She has spent 24 years using data to take companies to the next level, including 13 years in healthcare and technology leadership. She writes RCM 2030 Weekly*, a Sunday briefing for CFOs and revenue cycle leaders.*

Chapter 6 of RCM 2030 covers cybersecurity as a cash flow discipline, including a CFO-to-CISO translation guide. Free tools, including the AI Renewal Checklist for vendor contract reviews, are in the Resources section.

Previous
Previous

Every model was right. The bill was still wrong.

Next
Next

RCM 2030 Predictions: My Own Report Card, Including the Ones I Blew