Holyrood

Health Target

Data collected on your health is a target for cyber criminals

- By Jane Bradley

M MOST PEOPLE WOULD NOT CONSIDER the cyber security impact of either their weekly food shop or a visit to the doctors. But for Anne-marie Vine-lott, Director of Health for Vodafone Business, the personal data risk of visiting either could be similar. “From the point of view of a cyber criminal, healthcare organisati­ons collect valuable, sensitive data about individual­s,” she says. “It’s not dissimilar to signing up for a loyalty card with a supermarke­t where the data collected provides informatio­n and insight about habits, preference­s and spend profiles. When you think about someone’s health profile it’s the same: you’re getting an immense amount of informatio­n.”

As a result, the healthcare industry has become a key target for cyber criminals with one Us-based report citing that between 2015 and 2019 almost 80 per cent of all recorded data breaches were in the health sector, three times as many as in education, finance, retail, and government sectors combined.

Here in the UK, the NHS has found itself vul- nerable to attacks on a number of occasions – from personal data breaches to problems affecting entire software systems such as Adastra, which forced call handlers to resort to pen and paper to keep ambulance services running during a breach in 2022.

In 2017, the worldwide Wannacry ransomware attack targeted PCS running Windows in 150 countries, affecting hundreds of companies and public services. Microsoft had issued a patch to protect computers some months earlier, however those who had not downloaded the update, or whose machines were running on older versions of Windows, were not protected.

Among UK health boards affected was NHS Lanarkshir­e, which had to cancel almost 500 patient appointmen­ts and procedures as a result of the attack.

Vine-lott is only too aware of how vulnerable healthcare organisati­ons can be, particular­ly in the public sector. “Vodafone is dedicated to strengthen­ing the cyber security position across the UK’S critical national infrastruc­ture and we want to do more to support the NHS,” she says. “The NHS has become – and will always be – a target, and as we increasing­ly look to create an environmen­t where everyone is better connected at an individual and organisati­onal level, you have to ensure that there is appropriat­e security in place.”

Vodafone in Health is a new division within Vodafone Business, establishe­d in April 2023, to specifical­ly address the needs of the sector in driving digital accelerati­on and reducing health inequaliti­es. This sense of purpose is aligned to Vodafone’s everyoneco­nnected campaign, helping people and businesses gain more access to digital technology. Working across all parts of the UK in Health, in the NHS, the private and third sectors, the new division wants to expand its services to protect the nation’s healthcare system as well as helping to scale new technologi­es to reduce pressure on the sector.

Vodafone recently announced its collabo- ration with econsult Health, with the aim of improving patient access to care through digital A&E triage.

Vine-lott understand­s that health boards, faced with soaring costs and increasing­ly squeezed budgets, may not have the capacity to deal with the potential impact of cyber security. Yet this, she warns, plays into the hands of criminals and fraudsters. “It’s known that the UK healthcare system suffers from under investment,” she says. “It’s challengin­g to balance operationa­l or patient risk that is immediatel­y evident versus the risk of something that you can’t see, but you know may be brewing in the background.” Faced with that dilemma, the tendency is to go for the risk that you can see.

“But if a system is breached and has to be shut down, it has an absolutely huge impact, not just in terms of, for example, operations being cancelled, but the cost of actually trying to get up services and running again, safely.”

The long history of the NHS compared to some countries’ healthcare systems has meant it has been more difficult to modernise and to create a successful digital system. “The NHS started in 1948 and it’s changed and evolved constantly since that time. If you had to start from scratch, you’d never design it in the same way.” She points to countries such as Estonia, where the healthcare system has been created and designed in more modern times, following the country’s independen­ce from the USSR in 1989 – resulting in a more coherent digital system – but she also highlights that Estonia is more centralise­d and still has challenges in the integratio­n of services.

Meanwhile, an increasing number of people in the UK are topping up their NHS care by using private healthcare providers for some issues, with the rollout of “private healthcare lite” benefits such as online GP appointmen­ts which are becoming standard in a growing number of workplaces. In a post-pandemic world, even within the NHS, some appointmen­ts, particular­ly in primary care, are available online or via the phone.

“The upside,” says Vine-lott, “is that people can access services far more easily, especially since Covid. However, from a cyber perspectiv­e, this does open up risk, with a plethora of systems being used as multiple points of access. “In England there has been an ongoing drive towards collaborat­ion with the creation of group Health Trusts into Integrated Care Systems.

“We are supporting these groups to look at cyber challenges more holistical­ly to reduce risk.”

Vodafone is offering cyber assessment­s to better understand potential vulnerabil­ities and concerns. She adds: “I would encourage everyone to consider cyber security as a high priority. Whilst it is often difficult to clearly articulate the business case for things that may not happen, it’s better to have invested in the right support to have assurance that they won’t.” •

‘‘The NHS has become – and will always be – a target, and as we increasing­ly look to create an environmen­t where everyone is better connected at an individual and organisati­onal level, you have to ensure that there is appropriat­e security in place.”

Anne-marie Vine-lott, Director of Health

for Vodafone Business

 ?? ??
 ?? ??

Newspapers in English

Newspapers from United Kingdom