Hospitals and health systems should increase cybersecurity and physical security vigilance amid the ongoing conflict involving Iran, John Riggi, national adviser for cybersecurity and risk at the American Hospital Association, told Becker’s.
The war involving the United States, Israel and Iran began Feb. 28, when U.S. and Israeli forces launched coordinated airstrikes targeting Iranian military and nuclear-related sites, according to reports from The New York Times.
Mr. Riggi said the AHA is not aware of any specific credible threats targeting U.S. healthcare organizations at this time, but the group is advising providers to take precautionary measures in case Iran, its proxies or self-radicalized individuals attempt attacks in the U.S.
“We are also recommending that hospitals and health systems report any suspicious physical activity to local law enforcement and any suspicious cyber activity to their local FBI field office,” he said.
The AHA is in direct contact with federal agencies, including the FBI and HHS, to monitor threats to the healthcare sector.
“The AHA maintains a very robust and ongoing cyber and physical threat information exchange with the federal government, especially with the FBI and HHS,” Mr. Riggi said. “These relationships have proved invaluable in helping defend the healthcare sector in times of elevated threats.”
Mr. Riggi previously told Becker’s in January that geopolitical tensions involving countries such as Iran, Russia and China can increase cyber risk for U.S. healthcare organizations, even when hospitals are not the primary target. In some cases, nation-state actors may rely on cyber proxies or hacktivist groups to conduct disruptive attacks against U.S. sectors or shared technology infrastructure.
The FBI has also reminded critical infrastructure organizations on March 3 to review cybersecurity protections in light of geopolitical tensions involving Iran. A June 2025 fact sheet cited by the agency notes that Iranian-affiliated cyber actors often exploit unpatched or outdated software, known vulnerabilities and default passwords to access U.S. devices and networks.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.