• About
  • Advertise
  • Contact
Saturday, September 23, 2023
24Newsy.com | Daily News
No Result
View All Result
  • International
  • Auto
  • Business
  • Entertainment
  • Gaming
  • Health
  • Lifestyle
  • Travel
  • Technology and Science
  • Sports
24Newsy.com | Daily News
  • International
  • Auto
  • Business
  • Entertainment
  • Gaming
  • Health
  • Lifestyle
  • Travel
  • Technology and Science
  • Sports
No Result
View All Result
24Newsy.com | Daily News
No Result
View All Result
Home Health

Is your hospital ready for 3-4 weeks of downtime?

24 Newsy by 24 Newsy
2 weeks ago
in Health
0
Is your hospital ready for 3-4 weeks of downtime?

Is your hospital ready for 3-4 weeks of downtime?

Share on FacebookShare on Twitter

BOSTON – John Riggi, national advisor for cybersecurity and risk for the American Hospital Association, kicked off the 2023 HIMSS Healthcare Cybersecurity Forum here on Thursday with a data-rich and provocative discussion that focused largely on the need for local and regional planning for healthcare cyberattacks.

Ahead of the conference, Riggi said he’s had growing concern about a “dramatic increase” in the high-impact ransomware attacks on hospitals and health systems that shut down hospital computer networks and deny clinicians access to very much-needed patient information.

Related posts

DEA suggests 2nd comment period for post-PHE online Rx registration

DEA suggests 2nd comment period for post-PHE online Rx registration

23/09/2023
Roundup: Pacific Health Info Hub project launched and more briefs

Roundup: Pacific Health Info Hub project launched and more briefs

22/09/2023

In his keynote, Riggi addressed risk anticipation, identification, avoidance, confrontation and recovery – skills he said he’s practiced since he grew up in nearby Lynn, Massachusetts, and took with him into a lengthy career in the FBI and CIA, and takes now to the AHA.

He described the scope of the current threat landscape – with bad actors stealing data and causing massive disruptions to patient care, and intensifying ransomware attacks that are now assigned the same federal priority level as terrorist attacks – thanks in large part to Riggi and the AHA’s urging. 

Cyberattacks and breaches are no longer a white-collar, victimless crime, but a critical patient safety risk. 

“Ultimately, we can’t defend our way out of this problem,” said Riggi, who urged the healthcare industry and the U.S. government to take a more offensive posture.

100 million patients could be impacted by data breaches this year

Riggi said he looks to the U.S. Department of Health and Human Services Office for Civil Rights as a “pulse check.” OCR data statistics can help guide resource deployment in the fight against cyber bad actors, he said. 

This week the data indicates that there have been 66.3 million individuals in 2023 – up 50% from last year – with an average 180,000 individuals affected per hack.

At that rate, the projection is 100 million individuals will be impacted by a cyber data breach this year, Riggi said.

The majority of attacks are foreign-based, and 25% are ransomware attacks with data theft extortion, he said. Nation state-affiliated gangs and spies in Russia, China, North Korea and Iran, and sometimes in collusion with state agencies like the Russian equivalent of the FBI, conduct hacks against healthcare networks. 

Riggi reviewed a number of incidents like the ransomware group Clop extorting vulnerabilities in MOVEit file transfer software. Earlier this year, Clop also stole patient data from Community Health Systems, one of the largest publicly-traded hospital systems in the United States, by attacking them through Fortra’s GoAnywhere MFT.

Where is patient data?

While 8% of patient data is stolen from electronic health records, most are stolen from network servers and email outside of the electronic health record, Riggi said.

“One good thing is, our [EHRs] are pretty safe,” he said. “At least they are not being penetrated nearly as much as the servers and email.”

The soft spot is hospital servers and networks. “Our data is everywhere throughout our networks.”

The other challenge is that data is lying outside the EHR unencrypted, he said. 

“Probably not a reportable event,” he added.

The “bad guys” are looking at Internet-facing resources. They are not all sophisticated and able to exploit Zero-Day.

“Yes there is some of that,” he said, but, “they are hacking before we patch. 

“Folks, the bad guys get patch Tuesday updates as well. And they’re faster. They’re faster at delivering malware before we patch.”

Cyber actors are not just stealing protected health information, they are going after personally identifiable information, medical research and other valuable data sets.

The latest sinister development, Riggi said, is the extortion of individual patients for ransom. 

Dr. Eric Liederman, Kaiser Permanente’s director of medical informatics, will address that challenge Friday at the Cybersecurity Forum in his session on personal safety, culture and generating trust in the healthcare system.

Three simple questions

The loss of diagnostic data, PACS systems and other IT infrastructure shuts down the delivery of patient care. Other sources of aggregated data, especially third-party business associates, leave hospitals and health systems vulnerable to high-impact attacks.

“We have learned some hard lessons,” said Riggi.

As has been shown with some recent high-profile attacks, it can take three to four weeks for major IT systems to come back online and get a hospital up and running again.

And in some areas of the western United States the next nearest Level 1 trauma center could be more than 800 miles away – posing significant risk to patient safety and public health.

Riggi urged emergency-management planning, both locally and regionally, and leveraging resources like mutual aid agreements to address the insufficient integration with clinical continuity.

“Business continuity is not the same as clinical continuity, and we need to be prepared to carry on operations for up to four weeks,” he said. 

A lot of organizations do not have plans for how they will deliver safe, effective, quality care for up to four weeks, he said. Nor have they considered the external impacts to clinics and labs. 

They need to think: “What is the technology we depend on?”

Also: “What are the external impacts?”

Riggi said he advises asking three simple questions if the internet and internal network are lost in a cyberattack – for each department in the event of a high-impact ransomware attack. 

“What will work? What won’t work? And, What’s the plan?” 

He also advises downtime coaches and downtime safety officers for every department.

Andrea Fox is senior editor of Healthcare IT News.
Email: afox@himss.org
Healthcare IT News is a HIMSS Media publication.

ShareTweet
Previous Post

Hellboy: Web Of Wyrd Hopes To Mix Hades Gameplay With Comic Book Visuals

Next Post

63 Best White Elephant Gifts That’ll Cost You Less Than $25

Next Post
63 Best White Elephant Gifts That’ll Cost You Less Than

63 Best White Elephant Gifts That'll Cost You Less Than $25

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

Review: Jennifer Lawrence and ‘No Hard Feelings’ deliver a just right summer sex comedy

Review: Jennifer Lawrence and ‘No Hard Feelings’ deliver a just right summer sex comedy

3 months ago
45 Best Gifts For Your First Valentine’s Day as a Couple

45 Best Gifts For Your First Valentine’s Day as a Couple

8 months ago
Adaptable airliner seat accepts passengers’ wheelchairs as needed

Adaptable airliner seat accepts passengers’ wheelchairs as needed

4 months ago
Amazon CEO Andy Jassy in 2022  took a sharp cut in salary and earned only 1.3 million  In 2021, including shares, he earned more than 200 million.

Amazon CEO Andy Jassy in 2022 took a sharp cut in salary and earned only 1.3 million In 2021, including shares, he earned more than 200 million.

5 months ago

BROWSE BY CATEGORIES

  • Auto
  • Business
  • Entertainment
  • Gaming
  • Health
  • International
  • Lifestyle
  • Others
  • Sports
  • Technology and Science
  • Travel

BROWSE BY TOPICS

2023 AI Benjamin Irish Bigfoot Bigfoot Bob Gymlan Bob Gymlan Call Of Duty ChatGPT China Club of Angry Patriots DocsGPT electric vehicles Erdogan Gamers8 Games Google Street View Holidays HSBC Igor Girkin jacket Jocko Willink Lithuania London Lord Of The Rings Maldives mattresses Mercedes Metaverse Microsoft NBA Octopath Traveler 2 OpenAI PVC Restoring Rexfel Russia Safari SEO SVB Taiwan The Mukaab Ukraine Wagner Group war Warren Buffett

POPULAR NEWS

  • Irish sustains head injury in car accident

    Irish sustains head injury in car accident

    0 shares
    Share 0 Tweet 0
  • It’s Called Crash Casting

    0 shares
    Share 0 Tweet 0
  • The Metaverse: What it is and Why it Matters

    0 shares
    Share 0 Tweet 0
  • China’s role in the Russia-Ukraine conflict: promoting peace and negotiations

    0 shares
    Share 0 Tweet 0
  • Five tips for municipalities to prepare for the electric mobility era

    0 shares
    Share 0 Tweet 0
24Newsy.com | Daily News

24Newsy.com | Daily News

Follow us on social media:

DEA suggests 2nd comment period for post-PHE online Rx registration

DEA suggests 2nd comment period for post-PHE online Rx registration

23/09/2023
The 7 Best Running Strollers According to One Running, Stroller-ing Dad

The 7 Best Running Strollers According to One Running, Stroller-ing Dad

23/09/2023

Category

  • Auto
  • Business
  • Entertainment
  • Gaming
  • Health
  • International
  • Lifestyle
  • Others
  • Sports
  • Technology and Science
  • Travel
  • About
  • Advertise
  • Contact

@ 2023 | 24Newsy.com | Daily News Tiksaviems.LT - EntreNosotros.ES - CBDnutzen.DE - 365Nachrichten.DE - mobellex.DE - CBDtropf.DE - Rexfel.COM

No Result
View All Result
  • Home
  • International
  • Auto
  • Business
  • Gaming
  • Entertainment
  • Travel
  • Technology and Science
  • Health
  • Lifestyle
  • Sports

@ 2023 | 24Newsy.com | Daily News Tiksaviems.LT - EntreNosotros.ES - CBDnutzen.DE - 365Nachrichten.DE - mobellex.DE - CBDtropf.DE - Rexfel.COM