Having personally spent time at Baragwanath, Charlotte Maxeke and Helen Joseph hospitals, I could not help noticing how inadequate systems leaves these health facilities open to massive breaches and cyber-attacks. A recent article written by Guðrún Vaka Helgadóttir brings the point home, where he explains how a cyber-attack on a Finnish healthcare facility caused irreparable damage.
Hackers have no shame!
Thousands of psychotherapy patients a private healthcare company called Vastaamo in Finland recently reported getting extortion notes from a hacker, or hackers.
The hackers stole confidential treatment records, including recordings of doctor-patient sessions.
The cyber criminals demanded a ransom payment and when Vastaamo refused they sought out the patients themselves.
Extorting clients is an unprecedented method for hackers. Usually they only demand ransom from the company from which they’ve stolen the data.
These psychotherapy patients are in a much more vulnerable position.
It’s not just their money or credit score that’s at risk, it’s their peace of mind, it’s their health, their most intimate privacy, it’s something that they can never get back if it leaks out.
It is therefore more important for the healthcare industry than any other sector to keep data safe.
Patient data is not the only thing at risk.
Devices and important machines, such as pacemakers, ventilators, and surgical robots, are now connected and can be forced to stop or malfunction with devastating consequences.
Covid-19 increases the risk of a cyber-attacks on healthcare and carries along with it another kind of infectious risk.
What does that mean for the health care institutions that we need to keep us safe?
Doctors and other healthcare workers are working under extreme pressure and in unprecedented circumstances.
They rely more than ever on their own private devices for communication and search for the latest news and research on treatments.
For this reason, they are easily scammed if they have not been trained in cyber security awareness.
And with everybody wearing masks and protective gear within healthcare facilities, tailgating is now an even bigger risk than before.
A recent physical attack on a Croatian COVID-19-hospital left doctors and patients in the dark and without electricity for a few hours after someone broke in and turned off the main switch.
This kind of breach focuses our attention on the importance of physical security too, and the importance of having a strong security culture.
Are cyber-attacks on healthcare inevitable?
For years cybersecurity experts have been pointing out the fact that both public and private healthcare facilities are using outdated and poorly maintained systems.
Healthcare facilities tend to run on old legacy software.
Some even use software that has been discontinued and is therefore not updated anymore.
This puts patient data in a lot of risk.
Covid-19 has introduced a massive collaboration between the public and private sectors.
Patient information is being collected and shared like never before.
This further increases the opportunity for hackers to find weak links and chinks in the proverbial armour.
This further increases the opportunity for hackers to find and exploit weak links.
If nothing is done to minimize the risk, we will see even more cyber-attacks on the healthcare industry.
Pharmaceutical companies are also a target.
They may have stronger security systems and better software in place, but they have still experienced attacks and security breaches.
This is most likely due to a lack of security culture.
Their employees might accidentally click on phishing emails or accept downloads from compromised websites.
Yet another reason why healthcare employees need rigorous security awareness training.
How to avoid cyber-attacks on healthcare?
The first step to any cyber security resilience plan is to remember the “holy trinity” of cyber security:
People (training) Processes (systems) Technology (security)
Healthcare facilities need to invest in the right technology to keep their sensitive information safe. This is technology like cloud based anti-virus software and spam-filters.
This also means upgrading to a software that is patched regularly.
Healthcare facilities need to train all their employees in how to use email and the internet safely and create a strong security culture among their employees.
Part of patient care should be caring for the patient’s data and privacy as if their lives depended on it. Because they do.
CyberAweh offers a ready-made cyber security awareness training program for healthcare.
It consists of 25 training subjects that cover both physical and cybersecurity threats.
Cyber security awareness training goes hand in hand with POPI, HIPAA and GDPR compliance as well.
