Many ransomware attacks in the healthcare sector

Many ransomware attacks in the healthcare sector
Advertising

Share post

Cyber ​​attacks on the healthcare sector are on the rise. The Health Sector Cybersecurity Coordination Center of the US Department of Health and Human Services recorded 2021 ransomware incidents in the healthcare sector as early as the beginning of 82, and many more followed. Almost 60 percent related to the US market. But after the US, European countries are targeted. 

The effects were devastating. Large hospitals had an average downtime of 6,2 hours and costs of $21.500 per hour. Midsize hospitals averaged nearly 45.700 hours of downtime and the cost more than doubled at $XNUMX an hour, according to a study by Philips and CyberMDX.

Advertising
Perfect SME cybersecurity
How small and medium-sized enterprises defend against AI-led attacks with tailored security

Health data – the new gold

Cyber ​​criminals know that universities and healthcare institutions manage, process and store large amounts of protected health information (PHI), personally identifiable information (PII) and intellectual property (IP). To ensure they are protected against intrusion, compromise, disruption and data exfiltration, IT security provider Lookout says hospital systems need to rethink the way they use cybersecurity.

Growing attack surfaces

University and government healthcare systems no longer have the luxury of managing limited network infrastructures where applications, data and devices reside within a well-defined perimeter. The rise of telemedicine, cloud computing, electronic health records, IoT devices and wearables has created new risks and privacy requirements.

Advertising

Subscribe to our newsletter now

Read the best news from B2B CYBER SECURITY once a month



By clicking on "Register" I agree to the processing and use of my data in accordance with the declaration of consent (please open for details). I can find more information in our Privacy Policy. After registering, you will first receive a confirmation email so that no other person can order something you don't want.
Expand for details on your consent
It goes without saying that we handle your personal data responsibly. If we collect personal data from you, we process it in compliance with the applicable data protection regulations. Detailed information can be found in our Privacy Policy. You can unsubscribe from the newsletter at any time. You will find a corresponding link in the newsletter. After you have unsubscribed, your data will be deleted as soon as possible. Recovery is not possible. If you would like to receive the newsletter again, simply order it again. Do the same if you want to use a different email address for your newsletter. If you would like to receive the newsletter offered on the website, we need an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter. Further data is not collected or only collected on a voluntary basis. We use newsletter service providers, which are described below, to process the newsletter.

CleverReach

This website uses CleverReach to send newsletters. The provider is CleverReach GmbH & Co. KG, Schafjückenweg 2, 26180 Rastede, Germany (hereinafter “CleverReach”). CleverReach is a service that can be used to organize and analyze the sending of newsletters. The data you enter for the purpose of subscribing to the newsletter (e.g. email address) will be stored on the CleverReach servers in Germany or Ireland. Our newsletters sent with CleverReach enable us to analyze the behavior of the newsletter recipients. This can include It is analyzed how many recipients have opened the newsletter message and how often which link in the newsletter was clicked. With the help of so-called conversion tracking, it can also be analyzed whether a previously defined action (e.g. purchase of a product on this website) took place after clicking on the link in the newsletter. Further information on data analysis by CleverReach newsletter is available at: https://www.cleverreach.com/de/funktionen/reporting-und-tracking/. The data processing takes place on the basis of your consent (Art. 6 Para. 1 lit. a DSGVO). You can revoke this consent at any time by unsubscribing from the newsletter. The legality of the data processing operations that have already taken place remains unaffected by the revocation. If you do not want an analysis by CleverReach, you must unsubscribe from the newsletter. For this purpose, we provide a corresponding link in every newsletter message. The data you have stored with us for the purpose of subscribing to the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and deleted from the newsletter distribution list after you have canceled the newsletter. Data stored by us for other purposes remain unaffected. After you have been removed from the newsletter distribution list, your e-mail address may be stored by us or the newsletter service provider in a blacklist if this is necessary to prevent future mailings. The data from the blacklist is only used for this purpose and is not merged with other data. This serves both your interest and our interest in complying with the legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR). Storage in the blacklist is not limited in time. You may object to the storage if your interests outweigh our legitimate interest. For more information, see the privacy policy of CleverReach at: https://www.cleverreach.com/de/datenschutz/.

Data processing

We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract mandated by data privacy laws that guarantees that they process personal data of our website visitors only based on our instructions and in compliance with the GDPR.

Data is found in countless applications today, both on-premises and in the cloud. As healthcare providers and staff work from anywhere, and patients demand anytime, anywhere access, unmanaged devices and networks are used to process PHI, PII, and IP. In Lookout's experience, this has simultaneously opened up new avenues for attacks and severely reduced the effectiveness of perimeter-based security, since healthcare networks are no longer as transparent and controllable as they used to be.

Insufficient security tools

In order to meet the new data protection requirements, university and government healthcare institutions need cybersecurity that works regardless of the location of the data. This is especially necessary as employees work from anywhere with unmanaged devices and networks. Traditional security solutions are tied to boundaries where data and users no longer reside exclusively, and as such offer limited visibility into and control over cloud-centric activities.

Some companies have started implementing security solutions from the cloud, but these solutions are often deployed in isolation. Siled solutions create security vulnerabilities and operational inefficiencies as administrators must switch between different consoles to coordinate information and analyze results. Without a change in strategy, university and state healthcare systems will continue to face the consequences of ransomware attacks like these:

  • In December 2021, a ransomware attack on the Maryland Department of Health crippled its systems and forced many of its services offline for at least three months.
  • In August 2021, a ransomware attack prompted the Memorial Health System emergency room in Marietta, Ohio, to transfer patients to other facilities. The hospital chain was forced to shut down IT systems and cancel emergency surgeries as data from over 200.000 patients was affected.
  • In October 2020, the University of Vermont (UVM) incurred costs of more than $63 million when a ransomware attack took its systems offline, including those at the UVM Medical Center.

A unified approach to data protection

To effectively protect sensitive and regulated data, Lookout believes university and government healthcare organizations need to move beyond perimeter-based tools.

One possible solution could be a security platform that eliminates the need for a patchwork of technologies by consolidating functions that have traditionally resided on-premises in the cloud. Such a platform offers end-to-end data protection and transparency – from user behavior to the endpoints they use to the data they want to access. With a unified solution, these institutions gain comprehensive and consistent visibility and control of their entire system in a single window.

More at Lookout.com

 


About Lookout

Lookout co-founders John Hering, Kevin Mahaffey, and James Burgess came together in 2007 with the goal of protecting people from the security and privacy risks posed by an increasingly connected world. Even before smartphones were in everyone's pocket, they realized that mobility would have a profound impact on the way we work and live.


 

Matching articles on the topic

DDoS attacks: the most important means of cyber warfare

In the second half of 2024, there were at least 8.911.312 DDoS attacks worldwide, according to the results of a recent DDoS Threat Intelligence Report. ➡ Read more

Cybercrime: Russian-speaking underground is leading

A new research report provides a comprehensive insight into the Russian-speaking cyber underground, an ecosystem that has fueled global cybercrime in recent ➡ Read more

Cyber ​​Resilience Act: Companies should act now

The Cyber ​​Resilience Act (CRA) is coming in leaps and bounds. This means that manufacturers will soon no longer be able to ➡ Read more

Use of AI/ML tools increased by 3000 percent

AI/ML tools are popular, according to the findings of a recent threat report. However, their increased use also brings with it security risks. Cybercriminals ➡ Read more

Vishing: Criminals rely on voice phishing attacks

Using AI-generated deepfakes, cybercriminals imitate trusted voices. Vishing exploded in the second half of 2024, according to the results of a ➡ Read more

Digital Trust Index: Trust in digital services is declining

Digital trust or fear of a data breach influences whether consumers turn to or away from brands, according to the results ➡ Read more

Software security is inadequate in half of the companies

The 15th edition of the "State of Software Security Report", which is based on a comprehensive dataset of 1,3 million individual applications and 126,4 million ➡ Read more

Wireless networks: Only 6 percent are secure

Cyberattacks on critical infrastructures are constantly increasing. A recent report has revealed that wireless networks in particular are a major vulnerability ➡ Read more