Home HealthCybersecurity Experts to Hospital Leaders: Think Beyond Traditional Disaster-Recovery Planning

Cybersecurity Experts to Hospital Leaders: Think Beyond Traditional Disaster-Recovery Planning

by Staff Reporter
0 comments


As healthcare organizations increasingly lean on connected technology, hospital leaders need to think beyond traditional disaster-recovery planning and prepare for prolonged technology outages. That was the message of cybersecurity experts who met last week to discuss today’s most pressing threats to healthcare data and infrastructure at a healthcare summit hosted by Rubrik.

Rubrik is a cybersecurity and data management company based in Palo Alto, California.

The timing of this conversation is notable. Last month, senators reintroduced the Health Infrastructure Security and Accountability Act, which applies baseline minimum cybersecurity requirements for healthcare organizations, along with $1.3 billion to help hospitals bolster their defenses. In August, a cyberattack on Boston Scientific disrupted manufacturing and supply chains, highlighting how attacks can have far-reaching impacts on healthcare operations. 

Throughout the summit, experts echoed the same concern: AI-driven cybersecurity attacks pose a new level of risk for hospitals and health systems. These supercharged attacks could disrupt clinical operations for weeks, potentially leaving patients waiting for care. 

Nicole Perlroth, bestselling author and host of the To Catch a Thief podcast, expounded on her concerns regarding AI cyberattacks. 

“What we can really expect is that any vulnerability or any misconfiguration or any human error that you have in managing your security estate will be discovered at machine speed and exploited at machine speed.”

John Riggi, national adviser for cybersecurity and risk at the American Hospital Association, added to the gloomy picture, calling cyberattacks on healthcare organizations a “threat to life”. He called out how these attacks can disrupt operations in every step of the healthcare delivery workflow, to the point that patient care is badly delayed – which could be life-threatening.

When technology fails due to some design failure because it wasn’t designed securely, 

“but which the bad guys have exploited or found today at machine speed — when those systems go down, there is an immediate disruption and delay to healthcare delivery,” Riggi warned.

Cybersecurity threats are also manifold in that they can come from a variety of sources: they could emanate from foreign actors in Russia, China, North Korea, and Iran who want to target healthcare entities, particularly now that AI tools offer less-sophisticated attackers the opportunity to launch significant operations. 

Speakers suggested interventions to bolster cybersecurity within healthcare systems. They emphasized that hospitals must be prepared to operate without IT for prolonged periods of 30 days or more, and encouraged regular testing of downtime and continuity plans, as well as strengthening backup systems. 

However, this heightened era of threats could also have a positive outcome in the future of healthcare of healthcare cybersecurity i

“Long term, I hope that we basically get to a place we’ve never been before,” Perlroth said. “That this forces us to do the things we have talked about to death over the past few years in terms of secure-by-design, formal methods, patching, backups, real time backups, backup intelligence, et cetera.”

Photo: Traitov, Getty Images

You may also like

Leave a Comment

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More