Article 43

 

Thursday, May 11, 2023

Medical Record Cyberattacks

image: hippa

Medical record security?  I don’t think so.

My first experience was at FLORIDA HOSPITAL.  At the billing window, they tried to pressure me to sign a disclosure form giving the hospital blanket rights to to share my personal and patient info with “anyone for any reason.” So much for HIPPA laws.

Next came a visit to an URGENT CARE place.  I was coughing so bad, and vomiting so much, I couldn’t sleep for days.  Since something like that isn’t a LIFE THREATENING emergency, a hospital emergency room visit would have gotten my claim denied, regardless who they shared my PERSONALLY IDENTIFIABLE INFO (PII) with. On the bottom of the statement and all its copies was my name, address, birthdate, social security number, and phone number they must have gotten from the insurance company. 

Why isn’t an insurance ID number enough for all those paper copies?

Well, some places doesn’t even give you one.

My dental insurance card says “Member ID: USE SOCIAL SECURITY NUMBER.” And sharing that information includes selected partners, whoever they are, and WHATEVER COUNTRY they may be in.

It’s as bad as the sad state of TELECOM, COMPUTER and NETWORK security.

I’m almost happy when some place gets its data scrambled by a RANSOMWARE cyberattack, because now I don’t have to worry about my personal information getting loose on the DARKNET.

If they’re foolish or ignorant enough do do things like freely sharing your PII, can you IMAGINE what their I.T. departments must be like?

If the bad guys would target places that practically broadcast your personal info - like hospitals, urgent care centers and insurance companies - maybe those stupid practices would get a little more attention than just paying fines.

---

Cyberattacks on health care are increasing. Inside one hospital’s fight to recover

By Farah Yousry
NPR
May 8, 2023

It was October 2021 and the staff at JOHNSON MEMORIAL HEALTH were hoping they could finally catch their breaths. They were just coming out of a weeks-long surge of COVID hospitalizations and deaths, fueled by the Delta variant.

But on Friday, October 1, at 3 a.m., the hospital CEO’s phone rang with an urgent call.

“I remember like it was yesterday,” says DR. DAVID DUNKLE, CEO of the health system based in Franklin, Indiana. “My chief of nursing said, ‘Well, it looks like we got hacked.’”

The information technology team at Johnson Memorial discovered a ransomware group had infiltrated the health system’s networks. The hackers left a ransom note on every server, demanding the hospital pay $3 million in Bitcoin in the next few days.

The note was signed by the “Hive,” a prominent ransomware group that has TARGETED more than 1,500 hospitals, school districts and financial firms in over 80 countries, according to the U.S. Department of Justice.

Johnson Memorial was just one victim in a rising wave of cyberattacks on hospitals across the country. One STUDY found that cyberattacks on U.S. health care facilities more than doubled between 2016 and 2022.

In the aftermath, the focus frequently falls on the risk of confidential patient information being exposed, but these attacks can also leave hospitals hemorrhaging MILLIONS OF DOLLARS in the months that follow, and also cause DISRUPTIONS to patient care, POTENTIALLY PUTTING LIVES AT STAKE.

In Indiana alone, 27 hospitals were hit by cyberattacks between 2010 and 2023, according to data provided by the Indiana Hospital Association.

After its own attack, the staff at Johnson Memorial suddenly had to revert back to low-tech ways of patient care. They relied on pen and paper for medical records and notes, and sent runners between departments to take orders and deliver test results. The impacts were felt for weeks.

“You ask many CEOs across the country, ‘What keeps you up at night?’ Of course, [they’re] talking about workforce, financial pressures, and they say, ‘The possibility of a cyberattack,’” says JOHN RIGGI, the national adviser for cybersecurity and risk at the AMERICAN HOSPITAL ASSOCIATION.

The hacker’s ransom: to pay or not to pay

A few hours after that 3 a.m. call, Dunkle was on the phone with cybersecurity experts and the FBI.

The burning question on his mind: Should his hospital pay the $3 million ransom to minimize disruptions to its operations and patient care?

“[FBI agents] want you to know that if you pay a ransom to what is deemed a terrorist organization, you can open yourself up down the line to a fine,” he says.

Dunkle is referring to POTENTIAL FINES levied by the U.S. Department of the Treasury’s Office of Foreign Assets Control if an organization facilitates or makes a payment to cybercriminals.

Dunkle also worried about possible lawsuits, because the hackers claimed that they stole sensitive patient information they’d release to the “dark web” if Johnson Memorial did not pay up. Other health-data breaches have led to CLASS-ACTION LAWSUITS from patients.

The Office for Civil Rights can also IMPOSE FINANCIAL PENALTIES against hospitals if HIPAA-protected patient data is divulged.

“It was information overload,” Dunkle recalls. All the while, he had a hospital full of patients needing care and employees wondering what they should do.

The hospital goes digitally dark

In the end, the hospital did not pay the ransom. Leaders decided to disconnect after the attack, assess, and then rebuild, which meant taking several critical systems offline. That upended normal operations in various departments.

The emergency department had to divert ambulances with sick patients to other hospitals because the staff couldn’t access patient medical records.

In the obstetrics unit, newborns usually wear security bracelets around their tiny legs to prevent unauthorized adults from moving the infant or leaving the unit with them. When that tracking system went dark, staff members had to physically guard the unit doors.

During one delivery, nurses struggled to communicate with an Afghan refugee who came from the nearby military post to give birth. The remote translation service they typically used was inaccessible because of the cyberattack.

“Stressed-out nurses were using Google Translate to communicate with this woman in labor,” says Stacey Hummel, the maternity department manager. “It was crazy.”

Hummel says it was the hardest challenge she’s ever faced in her 24 years of experience - even worse than COVID. As the cyberattack unfolded, her nursing team was praying “Please don’t let the fetal monitors go down.” And then they did.

The clinical staff suddenly could no longer receive digital notifications outside of the labor rooms, notifications that help them monitor the vital signs of laboring women and their fetuses. That meant critical data points, like a dangerously low heart rate or high blood pressure, could go unnoticed.

“Once that happened, we had to station a nurse in every single room,” Hummel says. “So staffing was a nightmare because you had to stand there and watch the monitor.”

Beefing up staffing at that time was no small feat, as NURSES were in short supply nationwide and labor costs were high.

The hospital’s billing department was also crippled. For months they were unable to bill insurance plans to be paid in a timely fashion.

An IBM REPORT estimated that cyberattacks on hospitals cost an average of $10 million per incident, excluding any ransom payment - the highest among all industries.

Hospital leaders say for this reason, cyberattacks pose an existential threat to the viability of hospitals across the country, especially financially-struggling hospitals or smaller hospitals in rural areas.

Where cyber insurance falls short

Cyber insurance has become a critical part of hospital budgets, according to Riggi of the American Hospital Association. But some institutions are finding the insurance coverage isn’t comprehensive, so even after an attack they remain on the hook for millions of dollars in damages.

At the same time, insurance premiums can soar after a cyberattack.

“The government certainly could help in the space of cyber insurance, perhaps setting up a national cyber insurance fund, just like post-9/11, when folks could not obtain insurance against terrorist attacks, to help with that emergency financial aid,” Riggi says.

The federal government has taken steps to address the threat of cyberattacks against critical infrastructure, including training and AWARENESS campaigns by the federal Cybersecurity and Infrastructure Security Agency. THE FBI HAS TAKEN DOWN several ransomware groups, including the “Hive,” the group behind the attack on Johnson Memorial.

Today, Johnson Memorial is up and running again. But it took nearly six months to resume near-normal operations, according to the hospital’s Chief Operating Officer Rick Kester.

“We worked… every single day in October, every single day. And some days, 12, 14 hours,” Kester says.

The hospital is still dealing with some ongoing costs. Its revenue cycle has not fully recovered yet and its cyber attack insurance claim, submitted nearly two years ago, still hasn’t been paid, Dunkle says. The hospital’s annual insurance premium is up 60 percent since the incident.

“That is an incredible increase in cost over the last three or four years and...when your claims aren’t paid, it can be even more frustrating,” he says. “We are investing so much in cybersecurity right now that I don’t know how small hospitals will be able to afford [to operate] much longer.”

SOURCE

Posted by Elvis on 05/11/23 •
Section Privacy And Rights
View (0) comment(s) or add a new one
Printable viewLink to this article
Home
Page 1 of 1 pages

Statistics

Total page hits 12665938
Page rendered in 0.8169 seconds
41 queries executed
Debug mode is off
Total Entries: 3568
Total Comments: 341
Most Recent Entry: 09/26/2023 10:22 am
Most Recent Comment on: 06/14/2023 06:21 pm
Total Logged in members: 0
Total guests: 10
Total anonymous users: 0
The most visitors ever was 588 on 01/11/2023 03:46 pm


Email Us

Home

Members:
Login | Register
Resumes | Members

In memory of the layed off workers of AT&T

Today's Diversion

Buddhism has the characteristics of what would be expected in a cosmic religion for the future: it transcends a personal God, avoids dogmas and theology; it covers both the natural & spiritual, and it is based on a religious sense aspiring from the experience of all things as a meaningful unity. - Albert Einstein

Search


Advanced Search

Sections

Calendar

September 2023
S M T W T F S
          1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30

Most recent entries

Must Read

RSS Feeds

BBC News

ARS Technica

External Links

Elvis Favorites

BLS and FRED Pages

Reference

Other Links

All Posts

Archives

RSS


Creative Commons License


Support Bloggers' Rights