AI & Tech

Who Should Manage a Hospital Cyberattack?

[post_content]


Disclaimer: This article has been automatically aggregated from

The malware attack was over. It was the only thing anyone could talk about during my weekend shift at a midsize hospital. Our hospital had spent the last 3 weeks relying on paper charts and written orders, but Epic was finally back up and the relief was palpable.

There were a few small caveats. Only one in four computers was working. Access to events during the attack was spotty. Oh, and the Picture Archiving and Communication System was still down.

The physician coming off call led me to radiology’s lair, down a circuitous path I couldn’t replicate without GPS. “You have to pull up the images here, like the old days,” he said sheepishly.

The pilgrimages to radiology of the bad old days were before my time, as were pagers and illegibly scribbled progress notes. I, like many Gen Z and Millennial healthcare professionals, was trained in a setting where most facets of medical care were integrated into an electronic medical record (EMR). We rely on it to provide safe, accurate care. Most of us don’t know how to navigate medicine without it.

Cyber-criminals know that. They count on it. And it’s getting easier for them to exploit it.

If just your EMR is affected by a ransomware attack, consider yourself lucky. Sometimes it’s phone lines and emails and literal door access. Once the hospital is crippled, the ransom demand comes in. Often it’s double extortion: you have to pay to decrypt your data and to prevent them from releasing the protected health information they hacked. Healthcare systems then must decide how to respond to this while staff is standing at the bedside with a patient in anaphylaxis because no one can see the allergy list and the nurse can’t call an operator to overhead a code.

One recent study of Medicare claims data found a 34%-to-38% relative increase in mortality for patients already admitted to a given hospital during an attack. Emergency department diversions and surgical case cancellations at the involved institution also lead to increased burden on surrounding hospitals that can impact time-sensitive care. It’s a domino effect of increasing strain on health systems at their limits.

The FBI and HHS discourage ransom payments. In the abstract, of course hospitals shouldn’t pay extortionists. Payouts encourage future attacks and perpetuate the cycle. Still, when the patients you’ve given an oath to protect are at risk, how do you say no?

Regulators identify hospitals as critical infrastructure, and yet they are treated as individual businesses who are largely responsible for their own cybersecurity. HIPAA-regulated hospitals are required to use “reasonable and appropriate” safeguards to protect confidentiality and availability of protected health information. What the rules don’t prescribe is specific architecture or technologies.

HHS’s Healthcare Cybersecurity Performance Goals are more detailed but voluntary. They urge hospitals to consider offline backups inaccessible from their main networks, multi-factor authentication, and incident response planning. Many of these recommendations are part of a proposed overhaul of HIPAA security, which was put forth in December 2024. The plan has met major pushback from within the healthcare industry due to the cost of the changes, which are predicted to top $20 billion within the first 3 years. Final action on the proposal is now targeted for July 2027.

Even disclosure of an attack is partly at the discretion of the hospital. Patients whose protected health information has been exposed in a breach must be notified along with HHS, and if over 500 patients are involved the healthcare entity is required to report the incident to the media. Law enforcement involvement is currently voluntary. The Cyber Incident Reporting for Critical Infrastructure Act of 2022 would make it mandatory to report cyber incidents to the Cybersecurity and Infrastructure Security Agency within 72 hours and ransom payments within 24 hours. It’s yet to be implemented 4 years later.

The patchwork nature and competing interests of our healthcare system make sweeping changes difficult. But these problems aren’t going away: they’re accelerating. Large language models will soon allow small groups of criminals to automate large-scale ransomware attacks. And your local hospital probably isn’t ready for it.

But you know who could be? The national institutions designed to protect critical infrastructure.

It’s time to institute the Health Insurance Portability and Accountability Act (HIPAA) security overhaul. Require all hospitals to have the ability to maintain clinical continuity during a cyberattack. Set clear technological standards. Federally subsidize their implementation, so that small rural hospitals aren’t forced to choose between security and solvency. Mandate not only government reporting but federal assistance in ransomware negotiations.

We assume hostage negotiations are handled by law enforcement as a matter of course: it would seem bizarre if a regional bank manager was haggling for the release of 10 employees being held at gunpoint. Lives are on the line here too. And right now, a health system’s best option may be to hire a breach response company or specialized negotiation services in the case of an attack — but this can require time and extensive resources.

Centralizing negotiations would recruit the expertise of organizations experienced in cyber defense. It would aggregate intelligence and allow coordinated responses across multiple events. A private negotiator or cyber insurance firm may be able to lower a ransom demand. They can’t seize a crypto wallet or extradite the offender.

Relinquishing control can be uncomfortable, but we do it all the time in healthcare. We measure the quality of our care against guidelines set by our professional societies. We order consults and send our patients to operating rooms and intensive care units where critical choices are in the hands of other physicians. We delegate these decisions because we understand that standardization and domain expertise protect our patients from injury and us from error. Cyber defense and ransom negotiations should be no different.

None of this is guaranteed to stop the potential release of sensitive patient data. Even if attackers are paid, even if they claim they’ve destroyed the records, protected health information can be used to target individual victims for additional financial gain. The only way to genuinely protect patients is to prevent future attacks. Hospitals can’t do that alone. Deterrence requires the resources of the federal government.

I’m standing in the OR, about to operate. I ask the nurse to pull up the CT. I’ve seen it already, but I always check one last time for good measure. She clicks on the link. Nothing happens.

for informational purposes only. We do not claim ownership, accuracy, or liability for the content provided. All rights belong to the original publisher.