Steve Wood, Aruba vice president for the Asia-Pacific region, delivers solutions tips to help healthcare organizations better protect their centers from cyberattacks, by especially teaching healthcare professionals the basic rules of cybersecurity.
Half of the health organizations attacked had struggled with malware
According to a new global study carried out by the IT company Aruba, « The Internet of Things: Today and Tomorrow« , 87% of health organizations will adopt IoT technology by 2019.
Although the transition to a future model of care, which includes a technology-driven approach to better meet the demands of diverse regions, is a positive development, experts are concerned about the cybersecurity.
89% of healthcare organizations suffered an IoT-related security breach and 49% of them have struggled with malware, the authors of the report said.
Cyber attack: human error is common
The study also revealed that human error was concerns, as did DDoS, that kind of attacks from multiple sources. As hackers begin to deploy intricately planned targeted attacks, whether by breaching confidential systems or attacking websites, these can cause healthcare organizations to come to a standstill, in the worst case, endanger the health of the patient.
A global attack on health organizations
« Recently, we have seen a global ransomware attack that disabled healthcare workers of Britain’s National Health Service, as well as hospitals in China, Indonesia and Japan, from accessing patient records, and resulting in canceled appointments and even delayed emergency operations, » said Steve Wood (Aruba, Asia-Pacific).
The reasons for this attack can be multiple:
- MRI machines and CT scanners are primarily designed for data collection and not for security;
- Users are often too careless to observe basic cybersecurity protocols, such as connecting on non-encrypted wifi connections.
Aruba’s advice to limit the risk of cyberattack
How can we assure industry leaders that their healthcare organizations are protected from cybercriminals? Mr Wood introduces six cybersecurity solutions that he believes healthcare organizations should adopt to propose safer practices to ensure optimal operations and reassure patients.
1. Know what connected devices are up to
« In an environment where patients use mobile devices and healthcare workers track medical processes, having IT know which devices are connected to the network and what they are used for helps to sieve out possible loopholes for hackers. »
2. Separate wifi access for patients and families
« As the number of devices connecting to an unsecured network increases, it is important to introduce policies to segment guest traffic from hospital traffic to ensure that data can be accessed by the right people, at the same time exposure to threats are managed. »
3. Educate user digital hygiene
As users of digital devices become more and more dependent, they tend to overlook cybersecurity protocols to save a few extra seconds. Prevention is paramount in this area, Steve Wood said. It is necessary to « perform endpoint health checks to ensure that laptops are fully compliant with internal requirements, and always check for the latest software patches and updates before devices connect ».
4. Establish a security culture
« With most attacks, a single user can cause an entire organization’s shutdown by giving them access to the database. Make sure that employees are guided on how to recognize suspicious emails, corrupted files, unsecured websites, and other red flags (…). »
5. Strike partnerships with the experts
« Any outage in technology can potentially lead to fatal consequences. Having partnerships with the right technology companies will go a long way in building a secure yet comprehensive ecosystem of medical devices and healthcare apps that are always ready for the needs of both patients and staff. »
6. Have a comprehensive approach to cybersecurityy
« Accessing patient information on personal or hospital-issued devices are becoming commonplace, so ensuring that these devices are configured with the appropriate permissions are key. Simple perimeters such as user roles, devices, location, application usage and time of the day help manage these connections. »