Making Headway Toward Cyber Resilience
While we may feel inundated with alarming news about escalating cyber threats against healthcare organizations, there is also some good news. Let’s explore how hospitals — through greater attention to clinical continuity and collaboration — have been building the defensive measures and resilience needed to prevent and recover from cyberattacks.
Maintaining Clinical Continuity
With our increased dependency on network- and internet-connected technology and data, there is heightened risk when that technology becomes suddenly unavailable for an extended period — such as during a ransomware attack. That lack of access increases risk to care delivery and patient safety. Hundreds of ransomware attacks against hospitals and their mission-critical third parties have demonstrated that we need to be prepared to deliver safe and quality care for 30 days or longer without connected technology.
Many hospitals are now focusing on emergency preparedness to ensure they can maintain clinical continuity — the ability to continue delivering high-quality care even without technology. This raises questions such as:
- What is the plan to diagnose a stroke patient when the Picture Archiving and Communications System is down and the computer tomography scanner’s screen is not of diagnostic quality?
- How will your organization safely dispense medications from internet-connected drug cabinets?
- How will your organization understand patients’ medical history, treatment plans and safety protocols without access to their electronic medical records?
- How will your organization provide time-sensitive radiation oncology treatments without linear accelerators, which require network connectivity to function?
These questions are reflective of the hard lessons learned from our work with hundreds of ransomware-victim hospitals and health systems.
To better understand your hospital’s readiness to sustain care during a cyber-related technology outage, take the free Cyber Resilience Readiness assessment, developed by the AHA and Joint Commission.
Some Good News: Increasing Awareness, Collaboration and Resiliency
U.S. government agencies are demonstrating stronger coordination on cyber law enforcement and disruption operations, and the pace of these operations appears to have increased significantly, especially from the FBI Cyber Division. Government agencies are also sharing more classified and unclassified information with the healthcare sector. They truly understand that ransomware attacks that disrupt and delay healthcare delivery are more than "data crimes"; they are "threat-to-life" crimes.
We believe we will continue to see more effective information sharing and operational collaboration across the healthcare sector and government. We also believe the healthcare sector will need to be more self-reliant and continue to develop novel approaches derived from private-sector solutions to bolster cybersecurity. A key example of this is the program developed by the AHA and Microsoft to bring free and heavily discounted cybersecurity services to rural hospitals, at no expense to the taxpayer.
One team, one fight!
Learn about this and other ways the AHA and its partners are supporting organizations’ cybersecurity programs.
Additional Support for Your Security Efforts from the AHA’s Cybersecurity and Risk Experts
Our team offers a wide variety of strategic cybersecurity and risk advisory services to assist AHA members, many of which are included with your AHA membership.
We are also available anytime, including after hours, at no cost, should your AHA member organization need urgent assistance, guidance or introduction to trusted government contacts as a result of a cyber or risk incident.
- John Riggi, national advisor for cybersecurity and risk: jriggi@aha.org
- Scott Gee, deputy national advisor for cybersecurity and risk: sgee@aha.org