How Ransomware Threatens Hospital Care Devices

119 views
β€’
August 22, 2022
by
RSAC Cybersecurity
YouTube video player
How Ransomware Threatens Hospital Care Devices

TL;DR

Ransomware targeting hospitals can interrupt records, monitoring, treatment, and communication, creating risks that extend from financial loss to delayed care and loss of life. With millions of connected devices in hospital environments and continued growth expected, defenders must prepare for attacks that could move beyond general networks toward critical medical devices and centralized care systems.

Transcript

Thank you so much. Uh, we're excited to be here, having a chance to talk at RSA for the first time. Uh, we're gonna talk about some medical device research that we've done and kinda how that correlates to the current threat landscape. Hopefully, there's something in here interesting for everybody, uh, and you enjoy the talk. Uh, so to get started..... Read More

Key Insights

  • Healthcare networks present an enormous attack surface, with the presenters citing approximately 15 million devices per hospital and 10 billion medical devices worldwide. Managing such scale leaves substantial room for errors, overlooked systems, and network exposure that threat actors can exploit.
  • The Internet of Medical Things is expected to expand sharply, with the worldwide medical-device total projected to reach 50 billion by 2028. Continued growth means hospitals must prepare for a larger and more complex environment rather than expecting their current security challenges to diminish.
  • Underground markets respond to supply and demand, and leaked medical data can reduce demand for paid records. The presenters say ransomware groups such as Conti released stolen information for free, contributing to the decline of some markets for medical data and logins.
  • Healthcare is a high-value target because breaches are both costly and operationally damaging. The presenters describe the medical industry as a top-three targeted sector for many years and as having the highest breach cost for 11 consecutive years, at roughly nine million dollars per breach.
  • Ransomware in healthcare creates direct human consequences, including delayed care, patient harm, and possible loss of life. Technical disruption becomes a clinical safety problem when essential records, communications, monitoring systems, or treatment workflows become inaccessible to hospital personnel.
  • The Spring Hill Medical Center attack made electronic health records unavailable and forced staff to use paper charts. Less-experienced personnel needed immediate training from senior nursing staff, demonstrating how a cyberattack can suddenly require unfamiliar manual procedures while clinicians are already under pressure.
  • Centralized patient monitoring depends on reliable communication between bedside devices and nursing stations. When that connection failed at Spring Hill, nurses had to visit each patient individually, slowing recognition of complications and delaying decisions that sometimes needed to occur immediately.
  • Recovery from a hospital ransomware attack can remain incomplete for weeks. The University of Vermont Medical Center required more than 40 days to recover fully, while the first two weeks involved urgent efforts to restore processes and resume care for patients whose treatments had been disrupted.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can ransomware attacks affect patient care in hospitals?

Ransomware can make electronic health records unavailable, interrupt communication between medical devices and central monitoring stations, force staff to adopt paper procedures, and cause hospitals to turn patients away. These disruptions can delay treatment and critical decisions. The presenters emphasize that the consequences include degraded care, patient harm, substantial mental strain on staff, and, in the worst situations, loss of life.

Q: Why are connected medical devices an attractive attack surface?

Connected medical devices create an attractive attack surface because hospitals must manage them at extraordinary scale. The presenters cite about 500,000 purchasing options, approximately 15 million devices per hospital, and 10 billion devices worldwide. Every added system increases operational complexity and room for error, giving attackers more potential opportunities to gain leverage within a medical network.

Q: What happened during the Spring Hill Medical Center ransomware attack?

Spring Hill Medical Center was targeted by Ryuk in 2019. Electronic health records became unavailable, staff resorted to paper charting, and experienced nurses had to teach younger personnel how to use the manual process. Patient monitors in labor and delivery also lost communication with the central nursing station, requiring nurses to inspect patients individually at their bedsides.

Q: How did failed patient monitoring contribute to clinical harm?

When bedside monitors could no longer communicate with the central monitoring station, nurses lost the ability to observe every patient's vital signs from one location. They had to visit patients individually, creating a slower and more complicated process. In situations requiring immediate decisions about delivery complications, the delay prevented timely action and, in at least one instance, led to the loss of a baby.

Q: How long did recovery take at the University of Vermont Medical Center?

Full recovery at the University of Vermont Medical Center took more than 40 days after the Ryuk attack on October 28, 2020. During the first two weeks, personnel were still reacting urgently, determining how to restore processes and bring patients back. The incident also forced the institution to turn away some patients who required chemotherapy and similar treatment.

Q: Why is communication difficult during a hospital ransomware incident?

Hospital leaders may initially withhold details because they do not yet understand the attack and may suspect an insider threat. Consequently, staff might not know that ransomware is active or have enough information to assess risk. Patients may also remain unaware, preventing a fully informed decision about whether to seek care at that institution while its systems and services are disrupted.

Q: How is free leaked medical data changing underground markets?

Underground medical-data markets operate through supply and demand. The presenters explain that ransomware groups such as Conti breached medical facilities and released stolen information for free. When buyers can obtain the same material without paying, demand for purchased medical records and credentials falls. As a result, some underground markets for medical data have begun to shrink or disappear.

Q: What should healthcare defenders prepare for next?

Healthcare defenders should prepare for threats that extend beyond conventional hospital networks to critical care devices and the systems connecting them. The examples show that disabling records or centralized monitoring can already disrupt treatment and endanger patients. With the worldwide medical-device population projected to reach 50 billion by 2028, security planning must account for growing scale, operational dependencies, recovery procedures, and communication during incidents.

Summary & Key Takeaways

  • Healthcare organizations face an unusually large attack surface because their networks contain vast numbers of connected medical devices. The presenters cite about 500,000 device options, approximately 15 million devices per hospital, and 10 billion worldwide, with the global total projected to reach 50 billion by 2028.

  • Ransomware can disrupt much more than administrative computing. At Spring Hill Medical Center, unavailable electronic health records forced paper charting, while disconnected patient monitors required nurses to check patients individually at the bedside. These disruptions degraded care and, in at least one reported instance, contributed to the loss of a baby.

  • The University of Vermont Medical Center attack disrupted services, including chemotherapy treatment, and required more than 40 days for full recovery. Communication difficulties intensified the incident because staff and patients lacked complete information, limiting risk assessment, informed choices, and the institution's ability to protect people during the ongoing attack.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š