Ransomware targeting health systems in more 'sophisticated' ways
Skip to main content
MDHC_Logotype_white
Subscribe
  • My Account
  • Login
  • Subscribe
  • News
    • This Week's News
    • COVID-19
    • Providers
    • Insurance
    • Government
    • Finance
    • Technology
    • Safety & Quality
    • People
    • Regional News
    • Digital Edition
    • merrill goozner
      Biden's COVID-19 plan 
a test of American resolve
      Avocado
      Avocado a day keeps the doctor away
      A phone screen showing the question, "Mary we hope this information was helpful and we'd like to keep guiding you. Are you interested in knowing when it's your turn to receive the vaccine?"
      Chatbots, texting campaigns help manage influx of COVID vax questions
      50% of Americans make resolutions. Fewer than 27% keep them over time.
      Data Points: Sticking with your resolutions
    • A phone screen showing the question, "Mary we hope this information was helpful and we'd like to keep guiding you. Are you interested in knowing when it's your turn to receive the vaccine?"
      Chatbots, texting campaigns help manage influx of COVID vax questions
      Dr. Karen DeSalvo
      Next Up Podcast: What to expect with telehealth and healthcare technology in the next 4 years
      Two travel nurses wearing personal protective equipment.
      Healthcare providers face high costs, demand for agency staff as COVID-19 rages
      An older man wearing a mask receiving a vaccine.
      Want more diversity in clinical trials? Start with the researchers
    • Health suffers as rural hospitals close
      Medicare ACO participants fell in 2021
      Louisiana gets reports vaccine providers are discriminating
      'We know this is real': New clinics aid virus 'long-haulers'
    • Last-minute COVID costs cut into UnitedHealthcare's $396 million operating income
      CMS approves rule forcing insurers to ease prior authorization
      COVID-19 still a big uncertainty for insurers in 2021
      Health insurers' outlook boosted after Dems' Georgia win
    • It's a secret: California keeps key virus data from public
      lacewell_linda_supertinendent_dept_of_financial_services_8.47.jpg
      New York state investigates drug price spikes during pandemic
      Health experts blame rapid expansion for vaccine shortages
      HHS freezes rule targeting community health centers' drug discounts
    • By the Numbers: 20 largest healthcare investment banks in 2020
      Providers await new HHS coronavirus grant reporting deadline
      Operation Warp Speed Dr. Moncef Slaoui, Pfizer Group President Angela Hwang, Moderna CEO Stephane Bancel, CVS Health Executive Vice President Karen Lynch and McKesson CEO Brian Tyler participate in a panel discussion on the COVID-19 vaccine.
      Hospitals, drug companies strive to stand out virtually at JPM
      Intermountain, Trinity, Memorial Hermann behind $300M private equity fund
    • Dr. Karen DeSalvo
      Next Up Podcast: What to expect with telehealth and healthcare technology in the next 4 years
      Next Up Podcast: What to expect with telehealth and healthcare technology in the next 4 years - Transcript
      A man in a room with servers.
      Momentum grows to outsource hospital tech functions in 2021
      5 things to know about Google's $2.1B Fitbit acquisition
    • Avocado
      Avocado a day keeps the doctor away
      50% of Americans make resolutions. Fewer than 27% keep them over time.
      Data Points: Sticking with your resolutions
      An older man wearing a mask receiving a vaccine.
      Want more diversity in clinical trials? Start with the researchers
      U.K. chief scientist says new virus variant may be more deadly
    • Cerner names Erceg as new CFO
      Elizabeth Richter will serve as acting CMS administrator
      Providence names new chief financial officer
      Wisconsin's top health official departing for federal job
    • Midwest
    • Northeast
    • South
    • West
  • Insights
    • ACA 10 Years After
    • Best Practices
    • InDepth Special Reports
    • Innovations
    • The Affordable Care Act after 10 years
    • New care model helps primary-care practices treat obesity
      doctor with patient
      COVID-19 treatment protocol developed in the field helps patients recover
      Rachel Wyatt
      Project to curb pressure injuries in hospitals shows promise
      Yale New Haven's COVID-19 nurse-staffing model has long-term benefits
    • Michellene Davis
      Healthcare leadership lacks the racial diversity needed to reduce health disparities
      Dr. James Hildreth
      How medical education can help fight racism
      Modern Healthcare InDepth: Breaking the bias that impedes better healthcare
      Videos: Healthcare industry executives describe their encounters with racism
      Quotes from rebadged employees
      Outsourcing IT, revenue cycle takes toll on internal culture
    • A phone screen showing the question, "Mary we hope this information was helpful and we'd like to keep guiding you. Are you interested in knowing when it's your turn to receive the vaccine?"
      Chatbots, texting campaigns help manage influx of COVID vax questions
      A woman with a wearable sensor talking to her provider.
      Wearable sensors help diagnose heart rhythm problems in West Virginia
      self service station
      COVID-19 pushes patient expectations toward self-service
      Targeting high-risk cancer patients with genetics
  • Transformation
    • Patients
    • Operations
    • Care Delivery
    • Payment
    • Highmark Health inks six-year cloud, tech deal with Google
      Study: 1 in 5 patients report discrimination when getting healthcare
      HHS proposes changing HIPAA privacy rules
      Android health records app launches at 230 health systems
    • California hospitals prepare ethical protocol to prioritize lifesaving care
      Amazon, JPMorgan Chase, Berkshire Hathaway disband Haven
      Digital pathways poised to reshape healthcare continuum in 2021
      Healthcare was the hardest hit by supply shortages across all U.S. industries
    • A phone screen showing the question, "Mary we hope this information was helpful and we'd like to keep guiding you. Are you interested in knowing when it's your turn to receive the vaccine?"
      Chatbots, texting campaigns help manage influx of COVID vax questions
      A woman with a wearable sensor talking to her provider.
      Wearable sensors help diagnose heart rhythm problems in West Virginia
      New care model helps primary-care practices treat obesity
      How hospitals are building on COVID-19 telehealth momentum
    • Regional insurers bet big on virtual-first plans
      MedPAC votes to boost hospital payments, freeze or cut other providers
      Most Next Gen ACOs achieved bonuses in 2019
      Congress recalibrates Medicare Physician Fee Schedule after lobbying
  • Data/Lists
    • Rankings/Lists
    • Interactive Databases
    • Data Points
    • Health Systems Financials
      Executive Compensation
      Physician Compensation
  • Op-Ed
    • Bold Moves
    • Breaking Bias
    • Commentaries
    • Letters
    • Vital Signs Blog
    • From the Editor
    • Wellstar CEO calls adapting for the pandemic her bold move
      Howard P. Kern
      Recognizing the value of telehealth in its infancy
      Dr. Stephen Markovich
      A bold move helped take him from family doctor to OhioHealth CEO
      Dr. Bruce Siegel
      Why taking a hospital not-for-profit was Dr. Bruce Siegel’s boldest move
    • Barry Ostrowsky
      Ending racism is a journey taken together; the starting point must be now
      Laura Lee Hall and Gary Puckrein
      Increased flu vaccination has never been more important for communities of color
      John Daniels Jr.
      Health equity: Making the journey from buzzword to reality
      Mark C. Clement and David Cook
      We all need to 'do something' to fight inequities and get healthcare right, for every patient, every time
    •  Alan B. Miller
      Looking ahead with optimism as we continue to transform healthcare
      Dr. Bruce Siegel
      By protecting the healthcare safety net, Biden can put us on the path to a stronger country
      Healing healthcare: some ideas for triage by the new Congress, administration
      Dr. Sachin H. Jain
      Medicare for All? The better route to universal coverage would be Medicare Advantage for All
    • Letters: Eliminating bias in healthcare needs to be ‘deliberate and organic’
      Letters: Maybe dropping out of ACOs is a good thing for patients
      Letters: White House and Congress share blame for lack of national COVID strategy
      Letters: VA making strides to improve state veterans home inspections
    • Sponsored Content Provided By Optum
      How blockchain could ease frustration with the payment process
      Sponsored Content Provided By Optum
      Three steps to better data-sharing for payer and provider CIOs
      Sponsored Content Provided By Optum
      Reduce total cost of care: 6 reasons why providers and payers should tackle the challenge together
      Sponsored Content Provided By Optum
      Why CIOs went from back-office operators to mission-critical innovators
  • Awards
    • Award Programs
    • Nominate
    • Previous Award Programs
    • Other Award Programs
    • Best Places to Work in Healthcare Logo for Navigation
      Nominations Open - Best Places to Work in Healthcare
      Nominations Open - Health Care Hall of Fame
      Nominations Open - 50 Most Influential Clinical Executives
    • 100 Most Influential People
    • 50 Most Influential Clinical Executives
    • Best Places to Work in Healthcare
    • Health Care Hall of Fame
    • Healthcare Marketing Impact Awards
    • Top 25 Emerging Leaders
    • Top 25 Innovators
    • Top 25 Minority Leaders
    • Top 25 Women Leaders
    • Excellence in Nursing Awards
    • Design Awards
    • Top 25 COOs in Healthcare
    • 100 Top Hospitals
    • ACHE Awards
  • Events
    • Conferences
    • Galas
    • Webinars
    • COVID-19 Event Tracker
    • Leadership Symposium
    • Healthcare Transformation Summit
    • Women Leaders in Healthcare Conference
    • Workplace of the Future Conference
    • Strategic Marketing Conference
    • Social Determinants of Health Symposium
    • Best Places to Work Awards Gala
    • Health Care Hall of Fame Gala
    • Top 25 Minority Leaders Gala (2022)
    • Top 25 Women Leaders Gala
  • Listen
    • Podcast - Next Up
    • Podcast - Beyond the Byline
    • Sponsored Podcast - Healthcare Insider
    • Video Series - The Check Up
    • Sponsored Video Series - One on One
    • Dr. Karen DeSalvo
      Next Up Podcast: What to expect with telehealth and healthcare technology in the next 4 years
      Carter Dredge
      Next Up Podcast: Ready, set, innovate! Innovation and disruption in healthcare
      Next Up Podcast: COVID-19, social determinants highlight health inequities — what next?
      Next Up Podcast: Saving Rural Health
    • Beyond the Byline: Regulators aim to boost value push with fraud and abuse law updates
      An older man wearing a mask receiving a vaccine.
      Beyond the Byline: Verifying information on the chaotic COVID-19 vaccine rollout
      doctor burnout
      Beyond the Byline: How healthcare supply chain struggles contribute to employee burnout
      Beyond the Byline: Covering race and diversity in the healthcare industry
    • Leading intention promote diversity and inclusion
      Introducing Healthcare Insider Podcast
    • The Check Up: Chip Kahn
      The Check Up: Chip Kahn of the Federation of American Hospitals
      The Check Up: Trenda Ray
      The Check Up: Trenda Ray of the University of Arkansas for Medical Sciences
      The Check Up: Dr. Kenneth Davis
      The Check Up: Dr. Kenneth Davis of Mount Sinai Health System
      The Check Up: Dr. Thomas McGinn
      The Check Up: Dr. Thomas McGinn of CommonSpirit Health
    • Video: Ivana Naeymi Rad of Intelligent Medical Objects
  • MORE +
    • Advertise
    • Media Kit
    • Newsletters
    • Jobs
    • People on the Move
    • Reprints & Licensing
MENU
Breadcrumb
  1. Home
  2. Cybersecurity
January 24, 2020 11:38 AM

Ransomware targeting health systems in more 'sophisticated' ways

Jessica Kim Cohen
  • Tweet
  • Share
  • Share
  • Email
  • More
    Print
    Modern Healthcare Illustration / Getty Images

    Sometimes, ransomware can feel like the flu. As soon as hospitals find a defense, a new and more sophisticated version appears—making it difficult for hospital leaders to keep up.

    Cryptic names like WannaCry, Petya and SamSam—all variants of ransomware—have become common points of discussion in healthcare. But while those ransomware campaigns targeted businesses across industries, it's becoming more prevalent to see hackers tailor their approaches within the healthcare industry, finding new technical vulnerabilities to exploit at specific hospitals and more closely customizing the phishing emails that deploy malware.

    In 2018, healthcare organizations were the fourth most-common target for ransomware attacks, comprising 7% of attacks overall, after the technology (28%), consumer goods (15%) and manufacturing (11%) industries, according to a report released last year by Cylance, a cybersecurity company that BlackBerry acquired in 2019. But the company's researchers last year noticed an uptick in the sophistication of attacks targeting specific industries, particularly in healthcare and local governments, said Josh Lemos, vice president of research and intelligence at BlackBerry Cylance.

    Because of the potential disruption to patient care, "hospitals and patient-serving environments" are more likely to pay, he added.

    John Riggi, the American Hospital Association's senior adviser for cybersecurity and risk, said he's also noticed an increase in the "sophistication and severity" of ransomware attacks against healthcare organizations.

    "They now appear to be highly targeted and highly specific attacks against specific hospitals," he said.

    In healthcare, ransomware accounted for more than 70% of all malware—"malicious software"—attacks, according to a data breach report Verizon released last year. Ransomware attacks can come with a hefty price tag for their victims, with hackers demanding thousands to millions of dollars in exchange for decrypting an organization's computer files.

    When a ransomware attack brings down a hospital's IT systems, it doesn't just disrupt internal business processes. It often hits critical medical systems like electronic health records or internet-connected medical devices, forcing hospitals to divert patients to nearby facilities. That pushes hospitals to want to pay the ransom, even if cybersecurity experts, including the Federal Bureau of Investigation, discourage organizations from doing so.

    Just last month, Hackensack Meridian Health, a 17-hospital system based in New Jersey, confirmed it paid hackers an undisclosed sum to regain access to its IT systems. The attack brought down the system's computer network for two days, during which facilities were forced to reschedule some non-emergency procedures and revert to using paper—rather than electronic—medical records.

    "Don't immediately dismiss the option of paying ransom," Hackensack Meridian Health CEO Robert Garrett wrote in an op-ed for Modern Healthcare in December. "You may not have the luxury of time to consider rebuilding your network. We believe it's our duty to ensure patient safety and protect our communities' access to healthcare."

    And ransomware isn't static. New and emerging variants of the software arise—constantly.

    "We're chasing new stuff all the time," said Sri Bharadwaj, chief information security officer at UC Irvine Health in Orange, Calif., and co-director of the leadership in healthcare privacy and security risk management certificate program at the University of Texas at Austin's McCombs School of Business.

    Keeping track of those evolving threats can be overwhelming, with healthcare leaders ranking the emergence of too many new threats as the most challenging barrier to mitigating security incidents, according to a survey the Healthcare Information and Management Systems Society released last year.

    "We're no longer in the era where a single person can humanly read everything that's happening," said Lee Kim, director of privacy and security at HIMSS. She noted hospitals will often use security information management systems, which collect data, to help manage and identify trends from that influx of information.

    One of the latest ransomware variants to target healthcare is Zeppelin, first spotted in November by researchers at Cylance. Rather than being designed to reach a wide breadth of possible victims, Zeppelin has seemingly "carefully chosen tech and healthcare companies in Europe and the U.S.," the researchers wrote.

    Zeppelin is largely distributed through spear-phishing, according to Lemos. Spear-phishing is a tactic in which cybercriminals send malware via email while posing as a trusted entity, such as the recipient's employer.

    Lemos declined to share examples of the types of healthcare organizations being targeted by Zeppelin, as Cylance only discloses information on industry verticals.

    While Zeppelin is just one recent example of ransomware in the industry, it's indicative of hackers' appetite for the healthcare sector, noted Clyde Hewitt, executive advisor at cybersecurity consulting firm CynergisTek.

    To stay up-to-date on emerging threats, many hospital CISOs will rely on alerts from federal agencies, cybersecurity companies and information-sharing groups, which help to distribute timely information about relevant cyberthreats.

    "CISOs need to be plugged into not just one source, but many sources," Hewitt said. He suggested the Health Information Sharing and Analysis Center, the Department of Homeland Security's U.S. Computer Emergency Readiness Team and InfraGard—a partnership between the FBI and the private sector—as examples.

    UC Irvine Health is a member of multiple information-sharing groups and works with outside companies that help to manage network security, Bharadwaj said. While that's proved helpful, he acknowledged that might not be feasible for smaller organizations.

    "Not everybody has the dollars to subscribe to all of the possibilities," he said. The plurality of healthcare organizations—25%—dedicated just 3-6% of their IT budgets toward cybersecurity last year, according to the HIMSS survey.

    One low-cost way to stay updated on cybersecurity threats is to develop a "good network of CISOs that you can connect with" to share information, Bharadwaj said. "It's good to get that information on a daily or weekly basis, so you know what to do."

    Sharing information peer-to-peer is "still a very powerful" way of learning about cyberthreats, even if it sounds old-fashioned, Kim said, adding that's how she first learned about a new phishing technique in which hackers break into real business email addresses and insert themselves into existing email conversations.

    But hospital leaders shouldn't get bogged down by trying to implement fixes to emerging cyberthreats piece-by-piece. While new variants of ransomware are a concern, getting basic security practices in place is a necessary first step.

    "Every time that healthcare comes up with a point defense against something, these ransomwares get modified and appear as a different variant," Hewitt said. Rather than focusing in on a specific strain of ransomware, it can be more helpful for CISOs to think about how to "protect overall against malware," he said.

    Standard practices for preventing malware infections include educating staff about how to avoid being tricked by a hacker; segmenting sensitive systems—like those storing patient data—from the broader internet-connected network to limit malware's ability to spread; and conducting risk assessments annually, if not more frequently.

    "If you don't have the basics in place, you're a very soft target," Kim said.

    Letter
    to the
    Editor

    Send us a letter

    Have an opinion about this story? Click here to submit a Letter to the Editor, and we may publish it in print.

    Recommended for You
    Excellus Blue Cross and Blue Shield to pay $5.1M HIPAA penalty
    Excellus Blue Cross and Blue Shield to pay $5.1M HIPAA penalty
    4 cyberscams for hospitals to watch out for
    4 cyberscams for hospitals to watch out for
    Sponsored Content
    Get Free Newsletters

    Sign up for free enewsletters and alerts to receive breaking news and in-depth coverage of healthcare events and trends, as they happen, right to your inbox.

    Subscribe Today

    The weekly magazine, websites, research and databases provide a powerful and all-encompassing industry presence. We help you make informed business decisions and lead your organizations to success.

    Subscribe
    Connect with Us
    • LinkedIn
    • Twitter
    • Facebook
    • RSS
    • Instagram

    Stay Connected

    Join the conversation with Modern Healthcare through our social media pages

    MDHC_Logotype_white
    Contact Us

    (877) 812-1581

    Email us

     

    Resources
    • Contact Us
    • Advertise with Us
    • Ad Choices Ad Choices
    • Sitemap
    Editorial Dept
    • Submission Guidelines
    • Code of Ethics
    • Awards
    • About Us
    Legal
    • Terms and Conditions
    • Privacy Policy
    • Privacy Request
    Modern Healthcare
    Copyright © 1996-2021. Crain Communications, Inc. All Rights Reserved.
    • News
      • This Week's News
      • COVID-19
      • Providers
      • Insurance
      • Government
      • Finance
      • Technology
      • Safety & Quality
      • People
      • Regional News
        • Midwest
        • Northeast
        • South
        • West
      • Digital Edition
    • Insights
      • ACA 10 Years After
      • Best Practices
      • InDepth Special Reports
      • Innovations
    • Transformation
      • Patients
      • Operations
      • Care Delivery
      • Payment
    • Data/Lists
      • Rankings/Lists
      • Interactive Databases
      • Data Points
    • Op-Ed
      • Bold Moves
      • Breaking Bias
      • Commentaries
      • Letters
      • Vital Signs Blog
      • From the Editor
    • Awards
      • Award Programs
        • 100 Most Influential People
        • 50 Most Influential Clinical Executives
        • Best Places to Work in Healthcare
        • Health Care Hall of Fame
        • Healthcare Marketing Impact Awards
        • Top 25 Emerging Leaders
        • Top 25 Innovators
        • Top 25 Minority Leaders
        • Top 25 Women Leaders
      • Nominate
      • Previous Award Programs
        • Excellence in Nursing Awards
        • Design Awards
        • Top 25 COOs in Healthcare
      • Other Award Programs
        • 100 Top Hospitals
        • ACHE Awards
    • Events
      • Conferences
        • Leadership Symposium
        • Healthcare Transformation Summit
        • Women Leaders in Healthcare Conference
        • Workplace of the Future Conference
        • Strategic Marketing Conference
        • Social Determinants of Health Symposium
      • Galas
        • Best Places to Work Awards Gala
        • Health Care Hall of Fame Gala
        • Top 25 Minority Leaders Gala (2022)
        • Top 25 Women Leaders Gala
      • Webinars
      • COVID-19 Event Tracker
    • Listen
      • Podcast - Next Up
      • Podcast - Beyond the Byline
      • Sponsored Podcast - Healthcare Insider
      • Video Series - The Check Up
      • Sponsored Video Series - One on One
    • MORE +
      • Advertise
      • Media Kit
      • Newsletters
      • Jobs
      • People on the Move
      • Reprints & Licensing