The Arizona Republic

Info to emerge slowly in US hospital cyberattac­k

- Kathleen Foody and Kimberlee Kruesi

CHICAGO – Details of an apparent cyberattac­k on one of the largest health systems in the U.S. were slow to emerge as security experts on Friday warned that it often takes time to assess the full impact on patients and hospitals.

Last week, CommonSpir­it Health confirmed it experience­d an “IT security issue” but it has yet to answer detailed questions about the incident, including how many of its 1,000 care sites that serve 20 million Americans may have been affected. The health system giant, which is the second largest nonprofit health system in America, has 140 hospitals in 21 states.

“It actually takes a while to fully know the scope because you’re in the middle of trying to restore all your systems,” said Allan Liska, an analyst with the cybersecur­ity firm Recorded Future. “You’re trying to get patient care up and running. You’re trying to get your nurses and your doctors back to the systems they need.”

Health care organizati­ons are an appealing target for cyberattac­kers – particular­ly those who use malware to lock up a victim organizati­on’s files and leverage the informatio­n for a payment. Ransomware has remained a persistent threat for the industry, which is among the 16 sectors the U.S. government classifies as critical infrastruc­ture.

Health care systems in 2021 saw an unusually high amount of attacks, with 285 publicly reported worldwide, Liska added. So far, Liska’s firm has tracked 155 this year with an average of 20 attacks happening a month. However, he estimated that only about 10% of ransomware attacks are publicized.

Cybersecur­ity experts said years of work have built health care leaders’ trust in the FBI and other federal agencies focused on cyber crime. An FBI spokespers­on declined to comment.

John Riggi, the American Hospital Associatio­n’s national advisor for cybersecur­ity and risk, said he could not discuss CommonSpir­it specifical­ly. In general, though, he said it can take days, weeks or more to discover how an attacker gained access, determine the damage and prevent further harm.

Riggi, who spent nearly 30 years with the FBI, called any significan­t cyberattac­k on a hospital “a potential risk to patient safety” and said the U.S. government takes that seriously. Their goal, he said, is to identify the attacker and make their identity and methodolog­y public.

“They don’t want to show their hand, what they know about the bad guys,” he said. “You’re really processing a crime scene in real time.”

But there are risks to victims who fail to communicat­e their response plan and strategies for recovery, said Mike Hamilton, the chief informatio­n security officer with Critical Insights Cybersecur­ity in Washington state.

The reaction of patients, staff and affiliated health care operations to the chain’s handling of the incident can affect its future survival, he said.

“Here’s how close we are to resolution, here’s where we’re diverting, here are the other hospitals we’re partnering with,” Hamilton said. “They need to be sure they’re communicat­ing … because so many people are being impacted by this.”

Newspapers in English

Newspapers from United States