A joint cybersecurity advisory updated in July 2026 warns that Iranian-affiliated cyber actors are conducting sustained attacks against internet-connected operational technology devices — specifically programmable logic controllers — across multiple US critical infrastructure sectors. Healthcare facilities that operate building automation, medical gas systems, HVAC, or other OT-connected equipment fall within the advisory's scope, making this a direct concern for practice administrators and security teams regardless of organization size.
What the advisory describes
Programmable logic controllers are embedded computing devices that manage physical processes — water flow, temperature regulation, power switching, pressure controls — in industrial and facility environments. When those devices are exposed to the internet without adequate access controls, they become reachable targets for adversaries who do not need to breach an IT network first.
The advisory documents disruptions to PLCs across several critical infrastructure sectors. The authoring agencies characterize the targeting as ongoing, not historical, and describe the actors as affiliated with Iranian government interests. The advisory carries a TLP: Clear designation, meaning the full document is intended for broad distribution and organizations are encouraged to share it internally.
Why healthcare OT exposure is a distinct problem
Healthcare facilities rely on OT systems in ways that differ from most other critical infrastructure sectors. HVAC and environmental controls affect sterile conditions in operating rooms and pharmacies. Medical gas pressure systems feed oxygen and nitrous oxide to patient care areas. Power management equipment governs uninterruptible power supplies and generator failover. A disruption to any of these systems can translate directly into patient safety events, not merely operational inconvenience.
Many of these devices were installed before internet connectivity was considered standard and were not designed with authentication or encrypted communications in mind. Facilities that later added remote monitoring or management capabilities may have exposed devices that have no meaningful access controls and no mechanism for firmware updates.
The advisory does not require a sophisticated intrusion to succeed. Publicly available scanning tools can identify internet-facing PLCs within minutes, and default or weak credentials remain common across installed device populations.
What the advisory signals for independent practices
The updated advisory reflects an escalation in both frequency and sector breadth. Independent hospitals, ambulatory surgery centers, and specialty practices that manage their own facilities — rather than operating within a large health system with a dedicated OT security team — are the organizations least likely to have inventoried their internet-facing devices or applied compensating controls.
Key areas the advisory directs organizations to examine:
- Asset inventory covering OT and building systems. Any device that controls a physical process and communicates over a network should be included, not just clinical IT equipment.
- Remote access discipline. OT devices should not be directly accessible from the public internet. Where remote management is operationally necessary, access should route through network segmentation controls and require multi-factor authentication.
- Default credential elimination. Vendor-default usernames and passwords on PLCs and associated human-machine interfaces should be changed before deployment and audited periodically thereafter.
- Network segmentation between IT and OT. Clinical networks and building automation networks should not share a flat network topology. Lateral movement from one environment to the other should require explicit policy allowances.
- Monitoring for anomalous OT traffic. Facilities with the capability should establish a baseline of expected OT communications and alert on deviations, particularly unexpected outbound connections.
Where this lands for compliance and risk programs
HIPAA's Security Rule does not explicitly address OT devices, but the required risk analysis under 45 CFR 164.308(a)(1) covers all systems that affect the confidentiality, integrity, and availability of electronic protected health information. A PLC disruption that takes down clinical HVAC or power management can create conditions that force patient diversion or procedure cancellation — events that affect both care delivery and, in some configurations, systems that process or transmit ePHI.
Facilities that have not previously included OT and building systems in their HIPAA risk analysis have an opening to address that gap now, while the advisory provides both a documented threat basis and publicly available technical guidance to reference in the risk documentation. The full advisory is available through CISA and should be reviewed alongside any existing facility security assessment.