The fuel shortages and rising gas prices generated by the Colonial Pipeline ransomware attack in May foreshadow the disastrous and far-reaching effects of cyberattacks on critical infrastructure. SolarWinds, JBS, Kaseya, and a torrent of other high-profile cyber incidents have captured the attention of the American public and the highest levels of government, leading to a flurry of federal actions, including the nomination of the first-ever National Cyber Director, formal attribution of the SolarWinds attack to Russia, the release of an executive order imposing new security standards for software on federal procurement lists, and a host of legislative proposals to improve the nations cybersecurity.
Though these prominent cyber incidents have triggered several cybersecurity initiatives, policymakers have paid relatively little attention to the considerable potential cyber risks in the healthcare sector. The WannaCry ransomware attack which took down the United Kingdoms National Health Service in 2017 served as a wake-up call to healthcare organizations around the world, illuminating the urgent need for proactive investments in cybersecurity. And yet, healthcare organizations in the U.S. remain a vulnerable target, lagging behind other industries on key measures of cyber-readiness.
As the resurgence of COVID-19 cases stretch hospital capacity to the limit, it provides a fresh reminder of just how critical it is for our healthcare infrastructure to be resilient in times of crises. With the sharp uptick in ransomware attacks on healthcare organizations during the pandemic, and the first death attributed to a ransomware attack in 2020, it is clear that that malicious actors are capable of compromising mission-critical healthcare infrastructure, from the automated refrigerators that store blood products for surgeries to the CT scans that are vital for triaging trauma patients.
Indeed, the recent surge in cyberattacks on healthcare organizations prompted the Cybersecurity and Infrastructure Security Agency, the FBI, and the Department of Health and Human Services (HHS) to release a joint advisory warning of an increased and imminent cybercrime threat to U.S. hospitals and healthcare providers. At the same time, many hospitals are once again reaching surge capacity due to the Delta variant, making cybersecurity more important than ever before.
In 2017, the Health Care Industry Cybersecurity (HCIC) Task Force established by HHS issued a report to Congress in which they claimed that healthcare cybersecurity is in critical condition. Four years later, the Task Forces assessment still rings true. Since the onset of the COVID-19 pandemic, the rate of ransomware attacks has soared across all industries, and healthcare has been the disproportionate target of such attacks. The 2020 HIMSS Cybersecurity Survey revealed that 70% of hospitals surveyed had experienced a significant security incident within the past twelve months, including phishing and ransomware attacks that resulted in the disruption of IT operations (28%) and business functions (25%), as well as data breaches (21%) and financial losses (20%).
Healthcare organizations are an inviting target for financially motivated threat actors because their broad attack surfaces make it relatively easy for cybercriminals to find vulnerabilities and monetize their exploits. The passage of the HITECH Act in 2009 incentivized investments in health information technology to modernize the U.S. healthcare system, leading to unprecedented connectivity and an expansion in the usage of medical devices. Today, Electronic Health Record systems are the heart of the healthcare organization, connecting medical devices with other applications to provide a more wholistic picture of patient well-being. Additionally, the U.S. boasts an average of 10 to 15 networked medical devices per hospital bed, meaning large healthcare organizations face the herculean task of securing tens of thousands of medical devices, many of which are quite easy to hack. The digitization of healthcare infrastructure catalyzed major advancements in patient care, but also created major opportunities for attack. A single vulnerable asset can provide a threat actor with a foothold into the organization and compromise the confidentiality, integrity, and availability of patient data and medical services.
At the same time, protected health information is far more lucrative than credit card information. Criminals can garner anywhere from $10 to $1,000 per stolen medical record, depending on their completeness. This combination of a broad attack surface and strong financial incentives make healthcare organizations an appealing target for threat actors.
To make matters worse, cybersecurity is underprioritized by many healthcare organizations due to competing priorities and finite resources. The 2020 HIMMS Cybersecurity Survey reveals that cybersecurity professionals may not necessarily have access to the security solutions and other tools they need in order to fully secure the environment due to tight and stagnant IT budgets. Moreover, researchers have found that the average healthcare organization spends about 5% of its IT budget on cybersecurity, while the rest is devoted to the adoption of new technologies. Alarmingly, this means that organizations are expanding their attack surface despite lacking the tools to adequately defend their digital estate.
Consequently, the healthcare industry has fallen behind many other sectors in its ability to detect, prevent, and mitigate cyberattacks. For example, healthcare organizations take an average of 236 days to detect a data breach and 93 days to mitigate the damage, compared to an industry average of 207 days to identify and 73 days to contain an attack. Due to their failure to proactively invest in cybersecurity, healthcare organizations hit with cyberattacks have paid steep costs to mitigate the threat. IBMs 2021 Cost of a Data Breach Report revealed that the healthcare industry had the highest cost of a data breach for the eleventh year in a row, with an average cost of $9.23 million in 2021. Studies have demonstrated that proactive investments in cybersecurity lead to long-term saving, but cybersecurity spending can be hard for healthcare administrators to justify when faced with other compelling priorities, like staff increases to meet the demands of a once-in-a-century pandemic.
With an ever-increasing attack surface, compelling financial incentives for attackers, and under-budgeted, substandard cybersecurity operations, the US healthcare system is indeed in critical condition. Public-private partnerships and increased investments in healthcare cybersecurity will be key to shoring up the healthcare industry and safeguarding the nations critical infrastructure.
Just as handwashing is a foundational element of modern medicine, cyber hygiene must be regarded as a basic and essential component of a functioning medical system. At present, healthcare systems are highly vulnerable to cyberattacks and opportunistic threat actors are increasingly taking advantage of the industrys weak security posture to exfiltrate patient data and disrupt key medical systems. With the confidentiality, integrity, and availability of patient data, medical devices, and entire healthcare systems at stake, healthcare organizations must undergo a paradigm shift, placing greater value on cybersecurity and proactively investing in security protections.
Just as handwashing is a foundational element of modern medicine, cyber hygiene must be regarded as a basic and essential component of a functioning medical system
Policymakers can encourage proactivity by providing matching funds to organizations that seek to engage in risk-based planning and bring their practices up to par with state and federal regulations. Additionally, policymakers can simplify and strengthen the regulatory environment for healthcare security to develop a more unified and comprehensive set of standards that healthcare organizations can easily navigate. Federal agencies must also continue to collaborate with healthcare industry partners to develop robust contingency plans to avert catastrophe in the event of a serious cyber incident.
In the end, however, the fate of healthcare security comes down to whether organizations are willing to make significant investments in cybersecurity. If the healthcare sector is to move the needle on cybersecurity, industry leaders must begin to treat digital assets as they would patients. Just as a responsible healthcare professional seeks to identify and treat patients underlying chronic conditions before they cause a serious medical emergency, so too must responsible healthcare organizations address vulnerabilities in their digital infrastructure to prevent cyberattacks. After all, even computers are not immune to viruses.
IBM is a general, unrestricted donor to the Brookings Institution. The findings, interpretations, and conclusions posted in this piece are solely those of the authors and not influenced by any donation.
Original post:
Why hospitals and healthcare organizations need to take cybersecurity more seriously - Brookings Institution
- Reell Precision Manufacturing Names Chet Zaslow as Business Development Manager for Medical Technology [Last Updated On: January 31st, 2013] [Originally Added On: January 31st, 2013]
- FastWay [Last Updated On: December 25th, 2018] [Originally Added On: December 25th, 2018]
- PaperPk jobs in Pakistan 2018 in newspaper ads daily ... [Last Updated On: December 25th, 2018] [Originally Added On: December 25th, 2018]
- Health technology in the United States - Wikipedia [Last Updated On: January 2nd, 2019] [Originally Added On: January 2nd, 2019]
- McLEOD SCHOOL OF MEDICAL TECHNOLOGY - Pee Dee Area Health ... [Last Updated On: January 29th, 2019] [Originally Added On: January 29th, 2019]
- Medical technologist - Wikipedia [Last Updated On: January 29th, 2019] [Originally Added On: January 29th, 2019]
- Medical Technology Ireland [Last Updated On: January 29th, 2019] [Originally Added On: January 29th, 2019]
- Medical Laboratory Science/ Medical Technology at APSU [Last Updated On: February 5th, 2019] [Originally Added On: February 5th, 2019]
- RWJBarnabas Health - Comprehensive Healthcare in New Jersey [Last Updated On: February 5th, 2019] [Originally Added On: February 5th, 2019]
- Home - Secaucus, NJ [Last Updated On: February 5th, 2019] [Originally Added On: February 5th, 2019]
- Ultrasound - Wikipedia [Last Updated On: February 14th, 2019] [Originally Added On: February 14th, 2019]
- Indian Health Service | Indian Health Service (IHS) [Last Updated On: February 14th, 2019] [Originally Added On: February 14th, 2019]
- Medical Technology | Statista [Last Updated On: February 19th, 2019] [Originally Added On: February 19th, 2019]
- Medical Technician Career Guide | All Allied Health Schools [Last Updated On: February 19th, 2019] [Originally Added On: February 19th, 2019]
- Medical Technology Insurance | Travelers [Last Updated On: February 19th, 2019] [Originally Added On: February 19th, 2019]
- The Field of Medical Technology : : About the Program ... [Last Updated On: February 19th, 2019] [Originally Added On: February 19th, 2019]
- Technology Essay Sample: Medical Technology ... [Last Updated On: February 19th, 2019] [Originally Added On: February 19th, 2019]
- Medical Technology Degree Program | Med Tech Certification [Last Updated On: February 19th, 2019] [Originally Added On: February 19th, 2019]
- Medical Technologist Career Profile - verywellhealth.com [Last Updated On: February 19th, 2019] [Originally Added On: February 19th, 2019]
- B.S. in Medical Technology - Caldwell University, New Jersey [Last Updated On: March 5th, 2019] [Originally Added On: March 5th, 2019]
- 17 Amazing Healthcare Technology Advances of 2017 [Last Updated On: March 12th, 2019] [Originally Added On: March 12th, 2019]
- Department of Medical and Research Technology | University ... [Last Updated On: March 17th, 2019] [Originally Added On: March 17th, 2019]
- Home | FMC Meditech - Medical Technology Recruitment [Last Updated On: March 17th, 2019] [Originally Added On: March 17th, 2019]
- BS in Medical Technology in the Philippines [Last Updated On: April 4th, 2019] [Originally Added On: April 4th, 2019]
- Medical Technologist Jobs, Employment in New Jersey ... [Last Updated On: April 11th, 2019] [Originally Added On: April 11th, 2019]
- Medicine - Scientific American [Last Updated On: April 20th, 2019] [Originally Added On: April 20th, 2019]
- Medical Technologist: Job Description, Duties and Requirements [Last Updated On: May 12th, 2019] [Originally Added On: May 12th, 2019]
- Medical Technologist Jobs, Employment | Indeed.com [Last Updated On: May 19th, 2019] [Originally Added On: May 19th, 2019]
- Medical Technology : College of Nursing and Health ... [Last Updated On: May 20th, 2019] [Originally Added On: May 20th, 2019]
- Salary: Medical Technologist | Glassdoor [Last Updated On: May 20th, 2019] [Originally Added On: May 20th, 2019]
- Medical Technologist Degrees | All Allied Health Schools [Last Updated On: May 20th, 2019] [Originally Added On: May 20th, 2019]
- Online Medical Lab Technician & Medical Technology Degrees [Last Updated On: May 20th, 2019] [Originally Added On: May 20th, 2019]
- Medical Technology Jobs in the U.S. Navy - Navy.com [Last Updated On: May 22nd, 2019] [Originally Added On: May 22nd, 2019]
- New Study in Medical Devices industry of the High-intensity Focused Ultrasound System Market include Strategies, Competitive Research & Growth By... [Last Updated On: October 4th, 2019] [Originally Added On: October 4th, 2019]
- Should investors take a bet on surgical robotics? - The Globe and Mail [Last Updated On: October 4th, 2019] [Originally Added On: October 4th, 2019]
- How Springfield Technical Community College is training medical professionals to respond to crisis situations with robotic patients - MassLive.com [Last Updated On: October 4th, 2019] [Originally Added On: October 4th, 2019]
- The FDA's Critical Focus on Women's Health - FDA.gov [Last Updated On: October 4th, 2019] [Originally Added On: October 4th, 2019]
- Stock In The Spotlight ::Creative Medical Technology Holdings Inc, (OTC:CELZ) - Ws News Publisher [Last Updated On: October 4th, 2019] [Originally Added On: October 4th, 2019]
- Is There Enough Room Left To ::Creative Medical Technology Holdings Inc, (OTC:CELZ) - Ws News Publisher [Last Updated On: October 4th, 2019] [Originally Added On: October 4th, 2019]
- Artificial Intelligence Is Being Used To Diagnose Disease And Design New Drugs - Forbes [Last Updated On: October 4th, 2019] [Originally Added On: October 4th, 2019]
- Axonics Provides Full One-Year Results from ARTISAN-SNM Pivotal Study at AUGS/IUGA Joint Scientific Meeting - Business Wire [Last Updated On: October 4th, 2019] [Originally Added On: October 4th, 2019]
- Time For A Checkup On This Health Care ETF - Benzinga [Last Updated On: October 4th, 2019] [Originally Added On: October 4th, 2019]
- AngioDynamics Acquires Eximo Medical, Ltd. and its Innovative 355nm Laser Atherectomy Technology - Business Wire [Last Updated On: October 4th, 2019] [Originally Added On: October 4th, 2019]
- How to improve screening for social determinants of health - American Medical Association [Last Updated On: October 4th, 2019] [Originally Added On: October 4th, 2019]
- Bipartisan team of lawmakers put the squeeze on medical device tax - Chamber Business News [Last Updated On: October 4th, 2019] [Originally Added On: October 4th, 2019]
- The Rise of the Deep: Eric Topols Deep Medicine To Stand The Test Of Time - Forbes [Last Updated On: October 4th, 2019] [Originally Added On: October 4th, 2019]
- New Technology Makes Moves in the Medical Industry - Machine Design [Last Updated On: October 4th, 2019] [Originally Added On: October 4th, 2019]
- Medical Imaging Diagnosis Market Investigation by Application, Technology and Product Type - The Charterian [Last Updated On: October 7th, 2019] [Originally Added On: October 7th, 2019]
- TIER Mobility raises US$60 million in its Series B led by Mubadala Capital and Goodwater Capital - Business Wire [Last Updated On: October 7th, 2019] [Originally Added On: October 7th, 2019]
- 4 Reasons Why CT is the Best Method for Medical Device Quality Inspection - Quality Magazine [Last Updated On: October 7th, 2019] [Originally Added On: October 7th, 2019]
- Artificial Joints Market Research and New Innovations in Medical Sector 2019 to 2025 - The Chicago Sentinel [Last Updated On: October 7th, 2019] [Originally Added On: October 7th, 2019]
- Medical Technologist Job in Multiple Locations - Department of the Air Force - LemonWire [Last Updated On: October 7th, 2019] [Originally Added On: October 7th, 2019]
- UI graduate student works to commercialize drug that prevents osteoarthritis - UI The Daily Iowan [Last Updated On: October 7th, 2019] [Originally Added On: October 7th, 2019]
- CONMED Corporation to Announce Third Quarter 2019 Financial Results on October 30, 2019 - BioSpace [Last Updated On: October 7th, 2019] [Originally Added On: October 7th, 2019]
- TE Connectivity Collaborates With Hanhaa and Avnet to Advance Smart Tracking - PRNewswire [Last Updated On: October 7th, 2019] [Originally Added On: October 7th, 2019]
- Medtronic Initiates Worldwide Pivotal Study of a New Approach to Treating Dangerously Fast Heart Rhythms - GlobeNewswire [Last Updated On: October 7th, 2019] [Originally Added On: October 7th, 2019]
- Axonics Broadens EU Commercial Footprint with Recommendation for Reimbursement in France and Supply Contract in Norway - Business Wire [Last Updated On: October 7th, 2019] [Originally Added On: October 7th, 2019]
- Safe Orthopaedics Announces the Approvals of SteriSpine LC and CC in Japan - Business Wire [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Microspheres Market 2019 | Remarkable Growth Factors with Industry Size & Share, New Innovations of Leading Players & Forecast till 2024 -... [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Members Move Medicine: Tackling the underlying barriers to care - American Medical Association [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Why collaboration is key for the medtech industry to deliver life-saving innovations - create digital [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- PhenoMx executes MOU to develop strategic initiatives for Thailand's biotech, life sciences and medical industries - The New Economy [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- X-Ray Detectors Market Report Extensive Analysis 2019 | Specified by Production, Technology, Competition, and Revenue Forecast till 2024 - Elamal News [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- The Future of Proton Beam Therapy - Nature World News [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- GTX merges with NeuroRecovery Technologies to form GTX medical BV - Medical Device Network [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Misonix to Report Fiscal 2020 First Quarter Financial Results and Host Conference Call and Webcast on November 7 - GlobeNewswire [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Private health insurers say cost of medical devices putting pressure on premiums - The Guardian [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- These Apps Say You May Have a Health Disorder. What if Theyre Wrong? - The New York Times [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- The real horror this Halloween is the FDA's drug approval process | TheHill - The Hill [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- OraSure simplifies medical testing worldwide. Why the CEO says theyre still based in Bethlehem. - lehighvalleylive.com [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- 10 Medical Advances That Will Shape the Future of Healthcare - Discover Magazine [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Medical billing is a nightmare, but start-up Ooda is working to make it way easier, and some insurers are optimistic - CNBC [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- What We Know About the Man Accused of Stabbing His Mother to Death in a Plainville Kitchen - NBC10 Boston [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Where Are The Medical CIOs Investing? - Medical Tech Outlook [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Neuronetics and Success TMS Partner to Increase Patient Access to Leading Depression Treatment, NeuroStar Advanced Therapy - The Courier-Express [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Medical Device Security Market Growth Analysis 2019 to Share Key Aspects of the Industry with the details of Influence Factors Forecast to 2024 -... [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- 3Ms Shares Could Cross $200 Next Year Thanks To Acelity Acquisition - Forbes [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Judge to hear motion aiming to temporarily shut down Newton County plant - CBS46 News Atlanta [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- NYC Marathon Runners Turning To Intensive Medical Technology To Reach Peak Performance - CBS New York [Last Updated On: October 28th, 2019] [Originally Added On: October 28th, 2019]
- Misonix to Participate in Three Upcoming Investor Conferences - Associated Press [Last Updated On: November 5th, 2019] [Originally Added On: November 5th, 2019]