Why Hackers Are Going After Health-Care Providers

Advertisement
By Andrea Peterson, The Washington Post | Updated: 29 March 2016 14:47 IST
Washington, D.C., is reeling from the news of a hack at MedStar, one of the largest medical providers in the area. A computer virus infecting the organization's computer systems forced MedStar to shut down much of its online operations Monday.

The exact nature of the attack is not yet known, but MedStar is just the latest victim in a string of cyber-attacks that have hit the health-care industry hard. Here's what you need to know about how health-care providers became the latest digital battleground.

Why would cybercriminals go after the health-care industry?
The health-care sector has a lot of information that could be valuable to criminals and that makes them a juicy target.

First, they often have a bunch of personal information that could be use for traditional financial fraud things like your name, social security number, and payment information. But they also have health insurance information, which can be sold for even more on online black markets because it can be used to commit medical fraud things like obtaining free medical care or purchasing expensive medical equipment that often isn't caught quite as quickly as credit card or bank account fraud.

Advertisement

A particularly plucky cybercriminal could even find a way to leverage compromising medical information guarded by health-care providers into a blackmail scheme although that hasn't become a major avenue for attack yet, according to Ben Johnson, co-founder and chief security strategist at cyber-security Carbon Black.

Advertisement

However, several US hospitals have also now been hit with ransomware, a type of malicious software that basically lets an attacker hold a computer hostage. Once ransomware gets in a system, it starts quietly using hard-to-break encryption to lock up the information stored there making information inaccessible to the legitimate user. After the software has finished locking things up, it typically pops up with a message demanding a payoff in a difficult-to-track digital currency like bitcoin in exchange for the digital key needed to get back into the data.

This is a particular type of nightmare scenario for health-care providers because more and more of them rely on electronic medical records to keep things up and running.

Advertisement

"Health care is a bit unique in that up-time is really important," said Johnson, which means providers may be more likely than other targets to pay quickly so they can get back to work.

Just how vulnerable is the health-care sector to cyber-attacks?
Things aren't looking good.

Advertisement

According to cyber-security firm TrendMicro, health care was the sector that was hit hardest by data breaches from 2010 through 2015. Not all of those breaches involved hacks two-thirds were actually due to the loss or theft of things like laptops, smartphones, or thumb drives but it still demonstrates a major problem with the way the industry approaches keeping data safe.

"It's a big environment with a lot of different pieces and not a lot of investment in cyber-security," said Johnson.

Part of the problem is that hospitals and doctors' offices often have to oversee a mishmash of different types of equipment running different types of software and they can't always apply standard security practices, like regular updates, without risking instability because it might break the connections between systems, according to Jay Radcliffe, a senior security consultant at cyber-security company Rapid7.

The FBI actually warned health-care providers that they needed to up their digital defenses in April of 2014. "The healthcare industry is not as resilient to cyber-intrusions compared to the financial and retail sectors, therefore the possibility of increased cyber-intrusions is likely," said a private notice the FBI distributed to the sector obtained by Reuters at the time.

In 2015, several big health insurers suffered major breaches. One hack at Anthem, the nation's second-largest health insurer, left information on up to 80 million people exposed. Another at Premera exposed data on 11 million people, including medical information in some cases.

Last month a ransomware attack hit Hollywood Presbyterian Hospital in California. Staff was forced to resort to paper record-keeping for a week and divert patients to other hospitals, according to local reports. The hospital eventually paid the attackers roughly $17,000 to get access back to their data. Two other hospitals in Southern California were also reportedly hit with similar ransomware this month as was a Kentucky hospital, which declared an "internal state of emergency" after the attack.

And to make matters worse, the health-care providers are also having to grapple with the problem of securing connected medical devices: A hacked pacemaker or drug pump could have potentially life-threatening consequences for patients, and even other types of networked devices could end up helping a cybercriminal find a surreptitious way to get access to a hospital's computer systems.

"That can be the weak spot in your network and in a lot of cases, a hospital might not even realize it was connected," said Radcliffe.

What is the health-care sector doing to fix all this?
The industry has its own groups dedicated to helping coordinate how it responds to cyber-security threats, including the National Health Information Sharing and Analysis Center, or NHISAC, which was founded in 2010. Those sort of efforts are useful because they can help industries work together to help stem the spread of a particular type of threat early on.

And there is at least one bright side of all the recent breaches and hacks in the health-care sector: "They're really waking up to the fact that they are a huge target," said Johnson.

But, unfortunately, that awareness is just part of the problem. Even once an organization has committed the funds to build up their digital defenses, it can be difficult to plot the best path forward, according to Johnson, because it takes time to figure out which tools to put in place and whom to hire.

The latter part can be difficult for health-care providers because there's a shortage of security professional across all industries.

"I've literally talked to health-care organizations that have 300 open security positions, and are struggling to fill even a handful of them," said Johnson.

"It's going to be a rough few years," he said.

© 2016 The Washington Post

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon Great Indian Festival Sale: Deals on Smartphones, Laptops Teased
  2. Realme Watch 5 Design, Key Features Leaked Ahead of Debut
  3. YouTube Reportedly Cracks Down on Premium Family Plan Sharing
  4. From iPhone 17 to New Apple Watch Models: What to Expect from Apple Event
  5. Motorola Razr 60, Buds Loop With Swarovski Crystals Debut in India
  6. Razer Pro Click V2 and V2 Vertical Review
  7. Redmi 15 5G, Note 14 Pro Prices Dropped During Diwali With Xiaomi Sale
  8. IFA 2025 Begins This Week: All the Announcements We Expect
  9. Apple Hebbal: First-Ever Apple Store in Bengaluru is Now Open
  1. BCCI Says Crypto, Real Money Gaming Platforms Can’t Bid for Team India’s Title Sponsorship
  2. Scientists Discover Hidden Mantle Layer Beneath the Himalayas Challenging Century-Old Theory
  3. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  4. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  5. Su From So OTT Release: When and Where to Watch This Kannada-Language Horror-Comedy Online
  6. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
  7. Call of Duty Film Adaption Said to Be a 'Priority' at Paramount, Negotiations on to Acquire Rights
  8. Cannibal Solar Storm May Trigger Auroras as Powerful Geomagnetic Storm to Hit Earth Soon
  9. Apple's iPhone 8 Plus Listed as Vintage Product Ahead of iPhone 17 Launch, 11-Inch MacBook Air Now Obsolete
  10. Hidden Reason Behind Portugal’s Deadly Earthquakes Finally Explained
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.