Skip to main content

Healthcare Under Attack: The Ransomware Epidemic

Written by: Kelly Buckman

Most of us are familiar with this common scenario: An individual or a company employee is working in an application on their pc when a menacing message appears advising them that their computer has been locked and that they will have to pay a fee to regain access. It’s called ‘ransomware’, a type of malicious software designed to block access to a computer system until an amount of money or ‘ransom’ is paid.

Ransomware attacks are carried out through a technique known as crypto viral extortion, in which the victim’s files are encrypted, making them inaccessible until a ransom is paid to decrypt them. Since 2012, the prevalence of ransomware scams has grown globally. One example of ransomware, crypto locker was especially successful, extorting an estimated $3 million before it was removed by authorities. Another, Crypto Wall, was estimated by the FBI to have accrued over $18 million by June of 2015 (per Wikipedia).

Pretty scary stuff for both the individual consumer and for businesses, for whom the ransom can be especially steep and potentially cripple day to day operations.

Now imagine a health information exchange (HIE) system being held ransom by such an attack. Not only business operations but also patient care could potentially be compromised. You may think that such an attack is rare with all the safeguards hospitals have in place to protect patient data. But according to a Healthcare IT New Verizon 2017 Data Breach Investigations Report, of all the malware attacks on the healthcare industry in 2016, 72% were caused by ransomware. In fact, ransomware attacks have doubled in frequency across all industries and are the 5th most common specific malware variety.

According to a report in Healthcare IT News, the healthcare industry was the 2nd most targeted industry at 15 percent of incidents, just behind the financial sector, which reported 24% of total incidents in 2016. It has even been reported that in 2015, 1 in 3 people had a healthcare record compromised. One of the most notable instances of ransomware in the healthcare industry affected Hollywood Presbyterian; the attack caused the organization to declare an internal emergency and pay hackers $17,000 to restore access to the system (healthcareitnews.com).

Contributing to the steep increase in ransomware attacks on the healthcare industry last year was the introduction of ‘Ransomware-as-a-Service’. Indeed as ominous as it sounds, this inside threat involves developers providing customized ransomware ‘kits’ to hackers, in exchange for a percentage of the proceeds. Paying the ransom doesn’t always guarantee that information will be restored. There is even a variant of ransomware that deletes files even if the victim pays. In the wake of such a pervasive and malignant threat, how can any part of the healthcare industry be safe?

-It may seem obvious, but performing regular data backups cannot be emphasized enough here. Beyond data backups, healthcare organizations can go a step further and back up their systems and configurations, commonly referred to in the industry as a “gold image”. The data backup will contain all of the current data, while a gold image will reset the system back to the beginning.

-All healthcare organizations should create a risk assessment and business impact analysis that details worst case scenarios should the system come under ransomware attack. This would include a listing of all systems that would create substantial hardship should they stop functioning. Ideally, the analysis should take a tiered approach, where tier 1 lists systems that the organization can afford to have down for an hour, tier 2 would be down for a day, etc. Build the plan for the system that is most critical.

-In today’s high risk technological climate, it is important to not only have internal resources that can assist in the event of an attack, but also an external team of experts on ransomware. Some organizations even consult two or more cybersecurity companies to get different views. Keep in mind when developing a protection plan that one and done is not likely to cut it. According to David Finn, Health IT Officer at Symantec a multi-layer defense strategy is advisable. With a multi-layered approach, if your end-point protection doesn’t stop a ransomware attack, your network protection may. When you can correlate data from multiple products, a firewall log, an end-point log, a network log, etc., you can use the information gleaned to better protect your organization from debilitating ransomware attacks. Unfortunately, in today’s world, it’s also important to remember to protect against insider threats.

-Once you have a plan to protect against ransomware attacks you’re good to go, right? Not quite. It’s very important to test your security plan with your employees and systems before implementing.

-Lastly, be sure to train your end users in cyber security; otherwise, your plan may be useless. It may seem like common sense, but not all users are aware of the risk of clicking on phishing emails, visiting suspicious websites, or using USB flash drives that are not from a trusted source. It only takes one impulsive click of the mouse to infect an entire system. In one typical scenario, a user clicks on a file attached to an email, which triggers an Enable Content bar. When the user clicks the bar, malicious software locks internal files with a password or key that only the cybercriminal possesses. As easy as it is to introduce ransomware into the system, you can see how important it is to offer periodic cybersecurity training.

With all there is at risk, the healthcare IT industry as a whole cannot afford to ignore the threat. Nor can we assume that there is nothing we can do to prevent attack. Whether a large multi-facility or small community hospital, with a bit of planning and education, we can protect healthcare organizations and the patients they serve from this menace.
--

Kelly Buckman is a healthcare IT expert and field expert blogger for Barracuda Consulting.

Kelly has almost a decade of experience as a Technical Support Engineer/ Analyst in the field of Healthcare IT, over 20 years in IT Support, and several years of experience in Project Management. She has a B.A. from Mount Holyoke, Masters degree from UMass Amherst, and lists her skills as the ability to analyze and resolve various types of application, server and network issues, and to communicate complex ideas effectively.

She is also the mother of 3 sons, ages 19, 17, and 11, lives in western Massachusetts, and enjoys solving puzzles, reading, and travelling.

Please leave your comments below. If you would like to subscribe to our newsletter, click here: https://tinyletter.com/barracuda-consulting. To purchase a full report on this subject, or to access our complete suite of healthcare, and IT advisory services please contact us: https://www.barracuda-consulting.net/contact.

Comments

Popular posts from this blog

Ramping Up Real Estate: Post-Election Projections

Written By: Jacquelyn Annete García Vadnais 2020 has undoubtedly been a challenging and unpredictable year for all sectors of the economy. Given the Covid-19 pandemic, there have been many closures causing certain companies and industries to remain unpredictable. In addition to the Covid-19 pandemic, there is another factor at play in the United States and it is one of the most difficult Presidential elections in generations. Many investors in diverse industries are trying to calculate how the Presidential election’s outcome will have an impact on their portfolios. This is particularly true for real estate investors given the many factors that are impacting the real estate market with no clear end in sight due to the severity of the pandemic. For real estate investors that are trying to make difficult decisions during both the Covid-19 pandemic and the Presidential election, it is wise to consider the factors below: Most Important Areas to Watch Both During and After the Presidential E...

Raising the Resale Value of Your Home

Written By: Jacquelyn Annete García Vadnais It can be challenging to consider how to increase the value of a home that an existing homeowner wants to sell. The reason for this is that there may have been many changes made during the period of ownership that should be updated or perhaps some of the aspects of the home are outdated and unappealing to the current real estate buyers. It is wise for homeowners that are looking to increase the value of their home to consider researching extensively or consulting an expert in order to figure out which modifications are worthwhile to increase the value of their existing property. In order to learn more about strategic ways to increase the resale value of a home, please review the information below: Strategic Ways to Increase the Resale Value of Your Home Consider Improving Your Home’s Curb Appeal Curb appeal is a very important investment to make because it is the first impression that a prospective buyer has of a home. Curb appeal can includ...

Yields in Yerevan: Real Estate in Yerevan, Armenia

Written By: Jacquelyn Annete García Vadnais There has been a great deal of development in the Eurasia region when it comes to global real estate investment opportunities. This is particularly true for countries that had challenging conflicts that are just bouncing back. One such country is Armenia, which has made impressive strides towards opening up its economy to more foreign direct investment and creating attractive policies for positive economic growth. Yerevan, in particular, is offering ideal real estate investment opportunities. For real estate investors that are considering whether opportunities in Yerevan, Armenia are an ideal fit for their portfolio, it is wise to review the information below: History of Armenia Armenia has a diverse and unique history , which is one of the many reasons it offers a great appeal to so many visitors today. Armenia is actually one of the oldest countries in the world since it has history that dates back at least 3,500 years. The oldest recorded ...