Social Engineering Is Most Significant Cybersecurity Threat, Cybersecurity Expert Says

March 5, 2025
HIMSS’ senior principal, cybersecurity and privacy, addresses the press during the annual HIMSS conference

Lee Kim, senior principal, cybersecurity and privacy, with HIMSS, addressed the press on March 4 at the annual HIMSS conference about cybersecurity. HIMSS recently published its 2024 healthcare cybersecurity report.

“This year’s survey shows that tools alone are not enough—stronger governance is essential, with critical areas including artificial intelligence, insider threat management, and third-party risk management. The weakest link in any security program is the people, so education, tools, and policies remain the most important lines of defense. We are making progress, but we must do more to stay ahead of today’s evolving threats and to be prepared for future threats,” the HIMSS report stated.

Kim said that the most significant cybersecurity threat is social engineering. This is general email phishing and phishing through social media. Organizations need security awareness training. “Boards and directors are getting more informed in terms of overseeing cybersecurity risks,” Kim noted.

Regarding what we have learned since the Change Healthcare attack, Kim answered that healthcare CISOs are asking questions concerning vendors and having a backup. “We have clinical and financial ramifications that signal what kind of plan is needed,” Kim explained.

Sponsored Recommendations

Six Cloud Strategies to Combat Healthcare's Workforce Crisis

The healthcare workforce shortage is a complex challenge, but cloud communications offer powerful solutions to address it. These technologies go beyond filling gaps—they are transformin...

Transforming Healthcare with AI Powered Solutions

AI-powered solutions are revolutionizing healthcare by enhancing diagnostics, patient monitoring, and operational efficiency - learn how to integrate these innovations into your...

Enhancing Healthcare Through Strategic IT and AI Innovations

Learn how strategic IT and AI innovations are transforming healthcare - join Tomas Gregorio as he explores practical applications that enhance clinical decision-making, optimize...

The Intersection of Healthcare Compliance and Security in the Age of Deepfakes

As healthcare regulations struggle to keep up with rapid advancements in AI-driven threats like deepfakes, the security gaps have never been more concerning.