Author:
Munoz Cornejo Gilbert,Lee Joonghee,Russell Benjamin A.
Abstract
Abstract
Purpose
To characterize the patterns, vulnerabilities, and responses associated with ransomware incidents in U.S. hospitals.
Methods
The study employs qualitative thematic analysis of ransomware incidents in U.S. hospitals from 2016 to 2022. Data were collected from the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) public portal, and 65 cases were analyzed using NVivo 14 software.
Findings
Seven major themes emerged: (1) scale of ransomware, with incidents impacting a large number of individuals through diverse methods such as phishing and exploiting server vulnerabilities; (2) extent of protected health information vulnerability, with incidents often compromising sensitive health data, treatment records, and personal identifiers; (3) response and notification protocols, where hospitals demonstrate systematic responses including mandatory notifications to HHS, the media, and affected individuals; (4) implementation of safeguards, where hospitals have implemented immediate and long-term security measures post-attack; (5) investigation and regulatory compliance, where each attack is internally investigated, or with third-parties, while OCR conducts compliance reviews to guide corrective actions; (6) third-party involvement, highlighting the significant role of business associates (BAs) in incidents; (7) victim support and services, where hospitals frequently provide credit monitoring and identity protection services.
Conclusions
The study reveals the increasing prevalence of ransomware attacks targeting hospitals, highlighting significant vulnerabilities and the critical need for enhanced security measures. The findings suggest areas for future research, including the effectiveness of security practices and the long-term impacts on affected individuals.
Funder
Appalachian State University
Publisher
Springer Science and Business Media LLC
Reference58 articles.
1. Cartwright A, et al. An investigation of individual willingness to pay ransomware. J Financ Crime. 2023;30(3):728–741.
2. Hernandez-Castro J, Cartwright A, Cartwright E. An economic analysis of ransomware and its welfare consequences. R Soc Open Sci. 2020:7(3);190023.
3. Berris PG, Gaffney JM. Ransomware and federal law : cybercrime and cybersecurity, in Report / Congressional Research Service R46932. 2021:1 online resource.
4. Cybersecurity and Infrastructure Security Agency. Stop Ransomware Guide. [cited. 2024 April]; https://www.cisa.gov/stopransomware/ransomware-guide.
5. U.S. Department of Health & Human Services (HHS) Fact Sheet: Ransomware and HIPAA. 2021.
Cited by
1 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献