Skip to main content

When One Hospital Gets Ransomware, Others Feel the Pain – Dark Reading

Errol Weiss, Chief Security Officer, quote on MFA alongside a Dark Reading article on hospital ransomware.

Without key security defenses, including backup recovery and multifactor authentication implementation, all parties, including neighboring hospitals and patients, suffer.

When a healthcare organization is hit by ransomware, the crisis extends far beyond the initially targeted institution. The chaos and confusion that arise when systems and applications are offline are bad enough for the victim organization, but surrounding hospitals and entities often have to deal with the spillover effects, as well. Diverted ambulances drop off patients at their emergency doors. Unscheduled walk-ins increase. Patient volume overall can reach unmanageable heights, especially for organizations working with limited resources and tight funding.

Pulled Health-ISAC quotes:

The effect could be worse in rural communities than urban hospitals because it may take hours for ambulances to get to available facilities, thus delaying treatment. That could lead to long-term health effects for sick patients, warns Errol Weiss, CSO of Health-Information Sharing and Analysis Center (ISAC). 

“If their primary location is not open, they just deal with what they have, and that issue may get worse,” he says. “It may have been curable at the present time, but delays can cause a more chronic situation.”

Prioritizing certain security protocols can help elevate the sector’s overall security posture — for example, implementing mandatory multifactor authentication (MFA) for remote and privileged account access. Both the Ascension attack and the one against United Health Change Healthcare can be tied to lack of MFA for remote access, Weiss says.

“Have it on, and audit as much as possible to make sure it’s enabled,” he urges.

While that may have helped in retrospect, starting with the basics is best. Understand where the environment’s greatest weaknesses and vulnerabilities are, then focus on basic cyber hygiene protocols, Weiss says. That means staying up to date on patches, testing backups, and practicing recovery plans. Security mindsets need to change to combat the current threat landscape. 

Read the article in DarkReading. Click Here