CNA:帮助医院提高对勒索软件的抵御能力(2025) 4页

VIP文档

ID:74024

阅读量:0

大小:0.61 MB

页数:4页

时间:2025-07-02

金币:1

上传者:PASHU
March 2024
Unlimited distribution
IMM-2024-U-037878-Final
Copyright © 2024 CNA Corporation 3003 Washington Boulevard, Arlington, VA 22201 | 703-824-2000 | www.cna.org
Helping Hospitals Improve Resilience to Ransomware
Jamie Biglow and Dawn Thomas
On January 31, 2024, Lurie Children’s Hospital in Chicago was the victim of a ransomware attack by the
ransomware-as-a-service
group Rhysida. Lurie is a pediatric acute care hospital with 360 beds, 1,665
physicians covering 70 sub-specialties, and 4,000 medical staff and employees. It is one of the most
important pediatric hospitals in the country, providing care for more than 200,000 children annually.
Lurie detected the attack and preemptively shut down its phones, email service, electronic health record
(EHR) system, and MyChart patient portal to protect its data. The hospital reverted to a first-come, first-
served approach, prioritizing emergency situations. Scheduled procedures were delayed, ultrasound and
CT scan results were unavailable, and prescriptions were given in paper form. Parents expressed frustration
with the inability to communicate with their children’s doctors or access the patient portal. In a few cases,
surgeons operated on pediatric patients without some of the high-tech assistive devices they would usually
use.
Despite these challenges, the effects of the Lurie cyberattack could have been worse; the hospital could have
been forced to shut its doors. The speed with which hospital staff were able to make decisions and take
steps to keep their doors open, including setting up a call center and switching to manual processes,
suggests that Lurie had planned for a potential cyber incident and taken steps to prepare for it. Other
notable cyberattacks on hospitals in recent months have been more destructive, including the November
2023 cyberattack on Ardent Health Services
, a 30-hospital health system, which resulted in hospitals in
three states having to reroute ambulances to hospitals that could accommodate patients.
Targeting the Healthcare Sector
Hackers are targeting the healthcare sector with increasing frequency. According to the US Department of
Health and Human Services
(HHS), from 2018 to 2022, there was a 93 percent increase in large breaches
reported (369 to 712), with a 278 percent increase in such breaches involving ransomware. The Federal
Bureau of Investigation received more reports of ransomware attacks on organizations in the healthcare
and public health sector in 2022 (the most recent year available) than for any other critical infrastructure
sector, with the number of attacks rising in the two years since then. In their recent report, The State of
Ransomware in the U.S., Emsisoft Malware Lab reported that in 2023, 46 hospital systems with a total of 141
hospitals were affected by ransomware attacks. Finally, in a survey conducted by the Ponemon Institute in
2023, 88 percent of surveyed healthcare organizations reported having experienced at least one
cyberattack in the past year.
Unfortunately, many hospitals are vulnerable to these increasingly persistent threats. Hospital cyber
capacity and capabilities vary widely, which complicates the development and implementation of cyber
standards. In addition, hospitals have a large attack surface, made up of a series of interconnected systems
(including EHR, remote patient monitoring technology, imaging equipment, and telemedicine platforms),
that increases their vulnerability to cyberattack. Partner organizations can also be a source of cyber
disruption. For example, Change Healthcare, the insurance claims processing system that processes
50
percent of all medical claims in the US, was hit by a ransomware attack on February 21, 2024, disrupting
the ability of medical providers across the country, including those of many hospitals, to make insurance
claims and get paid.
资源描述:

2024年1月31日,芝加哥的卢里儿童医院遭勒索软件即服务组织Rhysida攻击。医院检测到攻击后, preemptively关闭了电话、电子邮件服务、电子健康记录系统和患者门户网站,优先处理紧急情况,导致预定程序延迟,检查结果无法获取,处方改为纸质形式,给患者和家长带来不便。 黑客对医疗行业的攻击频率不断增加,医院面临诸多挑战,如网络容量和能力差异大、攻击面广、合作伙伴也可能导致网络中断等。勒索软件攻击对医院的健康和财务都会造成影响,可能导致患者死亡、并发症增加、住院时间延长等,同时平均成本也在上升。 联邦监管机构已推动医疗行业改善网络安全,一些机构提供了相关指南和资源。医院需要制定网络中断应对计划,包括考虑潜在威胁、审查关键任务功能、制定决策标准、制定应急计划、建立内外沟通计划等,且计划应定期测试。CNA可帮助医院和医疗组织制定和实施网络事件应对计划。

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭