It’s time to switch off the healthcare hacker life support

If you were in any doubt of the critical state of the healthcare industry as far as cybersecurity is concerned, look no further than a new analysis from Forescout’s Vedere Labs that examined 734 breaches.

This revealed that, on average, more than 3 million individuals were impacted during every attack. Delving deeper, 47 different ransomware groups were implicated, and stolen healthcare data is traded online at a cost of between £3 and £75 a pop.

That, of course, doesn’t take into account any ransoms that have been paid along the way. The US, with 90% of the incidents, along with Australia and the UK, are the primary targets for healthcare hackers.

Look after your healthcare technology

Like many others, I have a vested interest in the healthcare system as I suffer from a debilitating chronic illness. Regardless of the country you live in or the type of healthcare that is available to you, we can all agree that this is not something to be messed with.

Yet a chronic illness is impacting the sector worldwide: an illness called criminal greed that drives attackers with no moral compass, no compassion and no brains to target hospitals and health service providers.

Thinks no brains is a bit harsh? Not really, what if a ransomware attack against a hospital service prevented one of their loved ones, their family, from getting life-saving treatment? Yeah, not so clever now.

I could list dozens of such attacks as they really are becoming that commonplace, but instead let’s focus on the most recent.

Earlier this week, Kettering Health, which operates 14 medical centres and employs 1,800 doctors across Ohio in the US, had to cancel elective procedures due to a ransomware attack. Beyond the ransomware aspects of the incident, Kettering Health stated that it had “confirmed reports that scam calls have occurred from persons claiming to be Kettering Health team members requesting credit card payments for medical expenses”.

These scumbag criminals really are the lowest of the low.

Healthcare as ransomware targets

“The healthcare sector continues to be disproportionately targeted by ransomware groups,” Gunter Ollmann, CTO at Cobalt, warned, “because it presents a high-pressure environment where disruption can immediately impact patient lives.”

It’s precisely this urgency, this life and death balance, that increases the likelihood of ransom payment, Ollmann concluded, “making hospitals prime targets for attackers looking for quick returns”.

Looking at how attackers gain access to healthcare systems, the three key vectors are undoubtedly social engineering, known internet-facing vulnerabilities and third-party connections. That’s what Clarity research has shown, anyway.

“In almost all of the nearly 500 recent attacks analysed,” Ty Greenhalgh, Industry Principal of Healthcare, at Claroty said, “one of these three vectors was exploited.”

“We keep seeing healthcare systems pushed to the brink, not by medical emergencies, but by cyberattacks that disable basic operations,” Debbie Gordon, CEO at Cloud Range said, recommending that the Kettering Health attack is yet another example of why tabletop exercises and simulation-based training programs are essential.

“Responding to ransomware is not only about technology,” Gordon warned, “it’s about people knowing what to do when systems go down.”

NHS anti-ransomware guidance to healthcare providers

In the UK, NHS England and the Department of Health and Social Care, has sent a letter to all suppliers calling on them to sign a voluntary charter regarding cybersecurity good practice.

“Many providers operate with decades-old IAM systems, scattered data sources,” Wade Ellery, Field CTO, with Radiant Logic, explained, “and minimal visibility into who has access to what and why.”

Identity observability offers a path forward, Ellery suggests, unifying and monitoring all identity and access data in real-time “so threats like ransomware don’t go undetected until it’s too late”.

Meanwhile, Forescout’s Vedere Labs recommended the following mitigations to help cut off life support for the healthcare ransomware hackers:

  • Encrypt all sensitive data in transit and at rest, especially personally identifiable information (PII), protected health information (PHI) and financial data.
  • Continuously identify and assess the risk and exposure of all network-connected assets that store or process sensitive data.
  • Harden these assets by applying patches, replacing weak credentials and disabling unnecessary services.
  • Identify and restrict network connectivity to assets storing or processing sensitive data by implementing network segmentation and network access control.
  • Monitor traffic to and from assets with sensitive data to detect and respond to potential breaches in real-time.

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.