image_pdfimage_print
Understanding the landscape of cybersecurity threats and ways to mitigate those threats can seem daunting. New threats are emerging all the time, as bad actors seek to gain access to the valuable data collected and stored by healthcare organizations, including health systems and hospitals.
 
Two trusted leaders in the field of cybersecurity reveal the most underrated threats to the health sector, and offer guidance on building a “cybersecurity culture,” including suggested policies and procedures. “We have to really start with leadership,” said Shawn Belovich, a managing director in the technology and business transformation services practice at BDO. “We need to embrace cybersecurity and we need to push it across the board.”
 
In the first half of 2018, U.S. healthcare organizations reported 176 large-scale data breaches. With the widespread adoption of electronic health records (EHRs) and introduction of many other connected technologies in the health setting, hospitals and health systems are vulnerable to cyberattacks. For instance, the number of connected medical devices is estimated at 10 billion, and will reach 50 billion by 2028, according to BDO. Meanwhile the cost of cyber liability insurance continues to climb along with the number and frequency of attacks. As a result of this threat, healthcare organizations are beginning to re-evaluate operations, Belovich said.
 
Types of attacks and their prevalence in healthcare
In order to adequately prepare, healthcare organizations should understand the cyber threat landscape, said John Riggi, senior advisor for cybersecurity and risk at the American Hospital Association (AHA). Riggi identified the top seven general categories of attacks as:
· Denial of service attacks
· Business email compromise
· Supply chain attacks
· Internal threats
· Crypto hijacking
· Ransomware
· Computer intrusions
 
Denial of service attacks make a machine or network resource unavailable to intended users, disrupting their work and processes. Denial of service attacks can sometimes be amplified by criminal services available on the Dark Web, Riggi explained, making them more damaging, luckily these have not been too prevalent in healthcare. However, a growing category of threat is supply chain attacks, wherein an adversary attempts to compromise a vendor’s technology or network connections to penetrate the network of the vendor’s customer. Given the large number of vendors and the variety of technology and services moving in and out of hospitals every day, this type of attack may represent a significant vulnerability for hospitals and health systems. “Before resources are diverted from defending against external threats to defending against internal threats, one has to understand what constitutes an internal-threat related incident reported to HHS,” Riggi said. These types of data losses include stolen unsecured laptops or, for example, staff mistakenly emailing unencrypted spreadsheets containing protected health information.
 
Crypto hijacking, on the other hand, is a growing threat that is not well-known in the healthcare sector, Riggi said. This “cryptojacking” malware harnesses an organization’s vast computing power, network resources, and energy to illegally mine lucrative digital currency While the malware itself may not intentionally do harm to a computer system, its energy and computing power drain may disrupt important services that hospitals provide and compromise care delivery or patient safety, Riggi said.
 
Ransomware continues to be the best-known and perhaps the greatest cyber threat to hospitals. Belovich noted that ransomware services can be purchased on the Dark Web, allowing for the easy entry of new threat actors. Another major and perhaps the most significant threat to hospitals are computer intrusions originating from external, mainly foreign based criminal organizations. Based upon a June 2018 study of Federal data published by the American Medical Informatics Association, hacks account for just 15 percent of all cyber incidents in healthcare, but 85 percent of stolen records, Riggi said.
 
Who’s behind the threats?
Hacktivists, criminals and nation-states are the three broad categories of cyber adversaries who are conducting these types of cyberattacks. For hospitals and health systems, criminals are the biggest threat, because they tend to go after high-value targets of patient health data, to sell on the dark web and monetize through other frauds. Criminals may also deny access to critical information such as patient records by encrypting those records through the deployment of ransomware. However, nation-states are also a significant cyber threat and have increased their targeting of hospitals and health systems. “They’re being targeted by hostile nation-states for theft of intellectual property related to medical research, innovations, cancer studies, population health studies, research for precision medicine and clinical trials, and also potentially for conversion for military use such as biological weapons,” explained Belovich and Riggi.
 
Additionally, nation-states may be looking for individual health records of high-value targets such as leaders of our military or government, Riggi explained. He recalled having a conversation with the CEO of a small, rural hospital in the Midwest who felt that his hospital would never be the target of a nation-state.
 
“When I asked the location, I realized immediately that they were positioned right outside a sensitive government military installation,” Riggi said, adding that the personnel with high level security clearances and their families associated with this base may be treated at the local hospital. “I guaranteed this CEO that his hospital and all his network connections had already been mapped, probably by China and Russia, seeking to gain those health records.”
 
As with this rural hospital CEO, many healthcare leaders underestimate the threat from nation-states. In a survey by the AHA of 475 hospitals, only 7 percent of respondents named nation-states among their top three cyber adversaries. The most cited were external criminal cyber adversary (52%), internal threat (38%) and hacktivist (10%). It’s interesting that hacktivists were cited more often than nation states as a top cyber adversary, but reports show that very few hacktivists target hospitals, Riggi and Belovich said.
 
At BDO, we’re committed to helping our clients with all their risk mitigation demands—and especially with a cybersecurity risk management program.