• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

  • Opinion
  • Health IT
    • Behavioral Health
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Patient Engagement
    • Population Health Management
    • Revenue Cycle Management
    • Social Determinants of Health
  • Digital Health
    • AI
    • Blockchain
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • M&A
  • Value-based Care
    • Accountable Care (ACOs)
    • Medicare Advantage
  • Life Sciences
  • Research

Why Ransomware Poses a Threat to Both Providers & Patient Health​

by Gary Ogasawara, CTO, Cloudian 05/20/2021 Leave a Comment

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print
Why Ransomware Poses a Threat to Both Healthcare Organizations and Patient Health​
Gary Ogasawara, CTO, Cloudian

Ransomware attacks continue to wreak havoc on all types of organizations across almost every industry. The healthcare sector in particular has emerged as one of the top targets for ransomware gangs, and the impact can be more dire than for most others. According to new research by Tenable, ransomware is responsible for 46% of all data breaches in the healthcare sector, compared to 35% of data breaches across all verticals. 

Just last month, a major hospital in Maryland lost access to a variety of its IT systems after a ransomware attack. It took officials a full month to restore the hospital’s Electronic Health Record system. Even worse, in October, six separate hospitals across the US – from Oregon to New York – were infected with ransomware within a 24-hour period. The event was severe enough to prompt the US Cybersecurity and Infrastructure Security Agency to issue an advisory to healthcare organizations warning about the rising risk of ransomware.

When hospitals and healthcare providers fall victim to ransomware, they often lose access to critical IT systems, slowing down or even temporarily stopping operation. The malware can take months to fully remove, too often subjecting the organization to significant economic loss. Emsisoft published a report finding that, in 2019, ransomware attacks on healthcare organizations each lasted an average of 287 days and cost an average of $8.1 million. 

During a deadly global pandemic, it’s not just the healthcare organization’s bottom line that is in jeopardy, but also patient health. Ransomware attacks can severely disrupt operations for hours or even days, putting patients’ lives at risk. With ICUs across the country now reaching capacity with COVID patients, the stakes are higher than ever.

Malware defenses such as firewalls and employee phishing training are critical, but by themselves they often fail to stop attacks. Ransomware needs to only get through once to infiltrate and cripple an organization. Over the past couple years, hackers have innovated the means to circumvent endpoint security software and elude seasoned IT staff and well-trained users. Email is the most common attack vector, with victims deceived into either providing corporate login credentials (a phishing attack) or downloading an infected file. In the past, these types of emails were easy to spot, but that’s not so true anymore. In advanced whaling attacks, cybercriminals credibly imitate C-level and other high-ranking executives, bypassing spam filters and increasing the likelihood of fooling employees. These sophisticated email-based ransomware attacks can even include personal details taken from social media profiles. In the healthcare sector, such emails may promise information about COVID vaccines or PPE availability. This increases their urgency and authenticity, thus boosting the chances that an employee will take the bait.

Ultimately, the only way for healthcare organizations to really guard against ransomware is to protect data where it lives – at the storage layer.

Healthcare organizations must leverage immutable storage to protect their backup data. This is the only approach that can ensure rapid recovery from ransomware attacks, without the need to pay ransom. Fortunately, immutable storage is both cost effective and easy to use: Once a backup data copy is written, that backup cannot be altered or erased, which makes it impossible for ransomware to encrypt that data. If a ransomware attack does occur, organizations can quickly restore from the most recent backup via a simple recovery process. There’s no need to pay a ransom, no downtime and, most importantly, far less disruption in patient care. 

Ransomware-proof storage can be achieved through the use of Object Lock, a new feature that is supported by select enterprise storage systems. Because Object Lock leverages the industry-standard S3 API, there are a variety of storage vendors, data protection software vendors and cloud providers that support it.  With Object Lock-enabled systems, your backup data can be protected from ransomware as part of an automated workflow, with no manual intervention required. 

Ransomware isn’t going away, as attacks continue to increase. Before the COVID pandemic, cybercriminals had already begun to target the healthcare sector – they knew that healthcare providers prioritize patient care and assumed these providers would be more likely to pay ransom as a result. With the coronavirus outbreak, the industry is under much greater pressure, and ransomware gangs have capitalized by significantly stepping up their attacks. Fortunately, with Object Lock-enabled storage, we have the means to eliminate ransom payments and thereby stop these attacks for good. 


About Gary Ogasawara

Gary Ogasawara is Cloudian’s Chief Technology Officer, responsible for setting the company’s long-term technology vision and direction. Before assuming this role, he was Cloudian’s founding engineering leader. Prior to Cloudian, Gary led the Engineering team at eCentives, a search engine company. He also led the development of real-time commerce and advertising systems at Inktomi, an Internet infrastructure company. Gary holds a Ph.D. in Computer Science from the University of California at Berkeley, specializing in uncertainty reasoning and machine learning.

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

Tagged With: Cybersecurity, Healthcare Ransomware

Tap Native

Get in-depth healthcare technology analysis and commentary delivered straight to your email weekly

Reader Interactions

Primary Sidebar

Subscribe to HIT Consultant

Latest insightful articles delivered straight to your inbox weekly.

Submit a Tip or Pitch

Featured Insights

2025 EMR Software Pricing Guide

2025 EMR Software Pricing Guide

Featured Interview

Kinetik CEO Sufian Chowdhury on Fighting NEMT Fraud & Waste

Most-Read

Blue Cross Blue Shield of Massachusetts Launches "CloseKnit" Virtual-First Primary Care Option

Blue Cross Blue Shield of Massachusetts Launches “CloseKnit” Virtual-First Primary Care Option

Osteoboost Launches First FDA-Cleared Prescription Wearable Nationwide to Combat Low Bone Density

Osteoboost Launches First FDA-Cleared Prescription Wearable Nationwide to Combat Low Bone Density

2019 MedTech Breakthrough Award Category Winners Announced

MedTech Breakthrough Announces 2025 MedTech Breakthrough Award Winners

WeightWatchers Files for Bankruptcy to Eliminate $1.15B in Debt

WeightWatchers Files for Bankruptcy to Eliminate $1.15B in Debt

KLAS: Epic Dominates 2024 EHR Market Share Amid Focus on Vendor Partnership; Oracle Health Sees Losses Despite Tech Advances

KLAS: Epic Dominates 2024 EHR Market Share Amid Focus on Vendor Partnership; Oracle Health Sees Losses Despite Tech Advances

'Cranky Index' Reveals EHR Alert Frustration Peaks Midweek, Highest Among Admin Staff

‘Cranky Index’ Reveals EHR Alert Frustration Peaks Midweek, Highest Among Admin Staff

Madison Dearborn Partners to Acquire Significant Stake in NextGen Healthcare

Madison Dearborn Partners to Acquire Significant Stake in NextGen Healthcare

Wandercraft Begins Clinical Trials for Physical AI-Powered Personal Exoskeleton

Wandercraft Begins Clinical Trials for Physical AI-Powered Personal Exoskeleton

Chipiron Secures $17M to Transform MRI Access with Portable Scanner

Chipiron Secures $17M to Transform MRI Access with Portable Scanner

Abbott to Integrate FreeStyle Libre Glucose Data with Epic EHR

Abbott to Integrate FreeStyle Libre Glucose Data with Epic EHR

Secondary Sidebar

Footer

Company

  • About Us
  • Advertise with Us
  • Reprints and Permissions
  • Submit An Op-Ed
  • Contact
  • Subscribe

Editorial Coverage

  • Opinion
  • Health IT
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Population Health Management
    • Revenue Cycle Management
  • Digital Health
    • Artificial Intelligence
    • Blockchain Tech
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • Value-Based Care
    • Accountable Care
    • Medicare Advantage

Connect

Subscribe to HIT Consultant Media

Latest insightful articles delivered straight to your inbox weekly

Copyright © 2025. HIT Consultant Media. All Rights Reserved. Privacy Policy |