While we may feel inundated with alarming news about escalating cyber threats against healthcare organizations, there is also some good news. Let’s explore how hospitals — through greater attention to clinical continuity and collaboration — have been building the defensive measures and resilience needed to prevent and recover from cyberattacks.

Maintaining Clinical Continuity

With our increased dependency on network- and internet-connected technology and data, there is heightened risk when that technology becomes suddenly unavailable for an extended period — such as during a ransomware attack. That lack of access increases risk to care delivery and patient safety. Hundreds of ransomware attacks against hospitals and their mission-critical third parties have demonstrated that we need to be prepared to deliver safe and quality care for 30 days or longer without connected technology.

Many hospitals are now focusing on emergency preparedness to ensure they can maintain clinical continuity — the ability to continue delivering high-quality care even without technology. This raises questions such as: 

  • What is the plan to diagnose a stroke patient when the Picture Archiving and Communications System is down and the computer tomography scanner’s screen is not of diagnostic quality?
  • How will your organization safely dispense medications from internet-connected drug cabinets?
  • How will your organization understand patients’ medical history, treatment plans and safety protocols without access to their electronic medical records?
  • How will your organization provide time-sensitive radiation oncology treatments without linear accelerators, which require network connectivity to function?

These questions are reflective of the hard lessons learned from our work with hundreds of ransomware-victim hospitals and health systems.

To better understand your hospital’s readiness to sustain care during a cyber-related technology outage, take the free Cyber Resilience Readiness assessment, developed by the AHA and Joint Commission.

Some Good News: Increasing Awareness, Collaboration and Resiliency

U.S. government agencies are demonstrating stronger coordination on cyber law enforcement and disruption operations, and the pace of these operations appears to have increased significantly, especially from the FBI Cyber Division. Government agencies are also sharing more classified and unclassified information with the healthcare sector. They truly understand that ransomware attacks that disrupt and delay healthcare delivery are more than "data crimes"; they are "threat-to-life" crimes.

We believe we will continue to see more effective information sharing and operational collaboration across the healthcare sector and government. We also believe the healthcare sector will need to be more self-reliant and continue to develop novel approaches derived from private-sector solutions to bolster cybersecurity. A key example of this is the program developed by the AHA and Microsoft to bring free and heavily discounted cybersecurity services to rural hospitals, at no expense to the taxpayer.

One team, one fight!

Learn about this and other ways the AHA and its partners are supporting organizations’ cybersecurity programs.

Additional Support for Your Security Efforts from the AHA’s Cybersecurity and Risk Experts

Our team offers a wide variety of strategic cybersecurity and risk advisory services to assist AHA members, many of which are included with your AHA membership.

We are also available anytime, including after hours, at no cost, should your AHA member organization need urgent assistance, guidance or introduction to trusted government contacts as a result of a cyber or risk incident.

Headline
The AHA provided comments Sept. 30 to the Senate Homeland Security and Governmental Affairs Subcommittee on Disaster Management, District of Columbia and…
Headline
Two new AHA briefs outline field-tested strategies on strengthening supply chain resilience and hospital capacity readiness to maintain quality of care during…
Headline
The FBI Sept. 29 announced an arrest of one of the alleged leaders of ShinyHunters, a cybercriminal group linked to cyberattacks in the U.S. and…
Headline
The FBI and the Cybersecurity and Infrastructure Security Agency have released a fact sheet for critical infrastructure organizations on ways to reduce risk…
Headline
The AHA will host a webinar Sept. 30 at 1 p.m. ET on ways healthcare organizations can build an effective, closed-loop cybersecurity program designed…
Headline
New guidance from the Cybersecurity and Infrastructure Security Agency encourages healthcare organizations to consider internal network and internet facing…