• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

评估医院对网络攻击的恢复能力。

Assessing resilience of hospitals to cyberattack.

作者信息

Ghayoomi Hadi, Laskey Kathryn, Miller-Hooks Elise, Hooks Charles, Tariverdi Mersedeh

机构信息

Department of Civil, Environmental and Infrastructure Engineering, George Mason University, Fairfax, VA, USA.

Department of Systems Engineering and Operations Research, George Mason University, Fairfax, VA, USA.

出版信息

Digit Health. 2021 Nov 29;7:20552076211059366. doi: 10.1177/20552076211059366. eCollection 2021 Jan-Dec.

DOI:10.1177/20552076211059366
PMID:34868621
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC8638073/
Abstract

OBJECTIVE

This paper investigates the impact on emergency hospital services from initiation through recovery of a ransomware attack affecting the emergency department, intensive care unit and supporting laboratory services. Recovery strategies of paying ransom to the attackers with follow-on restoration and in-house full system restoration from backup are compared.

METHODS

A multi-unit, patient-based and resource-constrained discrete-event simulation model of a typical U.S. urban tertiary hospital is adapted to model the attack, its impacts, and tested recovery strategies. The model is used to quantify the hospital's resilience to cyberattack. Insights were gleaned from systematically designed numerical experiments.

RESULTS

While paying the ransom was found to result in some short-term gains assuming the perpetrators actually provide the decryption key as promised, in the longer term, the results of this study suggest that paying the ransom does not pay off. Rather, paying the ransom, when considered at the end of the event when services are fully restored, precluded significantly more patients from receiving critically needed care. Also noted was a lag in recovery for the intensive care unit as compared with the emergency department. Such a lag must be considered in preparedness plans.

CONCLUSION

Vulnerability to cyberattacks is a major challenge to the healthcare system. This paper provides a methodology for assessing the resilience of a hospital to cyberattacks and analyzing the effects of different response strategies. The model showed that paying the ransom resulted in short-term gains but did not pay off in the longer term.

摘要

目的

本文研究了一场影响急诊科、重症监护室及辅助实验室服务的勒索软件攻击从发起至恢复期间对医院急诊服务的影响。比较了向攻击者支付赎金并随后进行恢复以及从备份进行内部全系统恢复这两种恢复策略。

方法

采用一个基于患者、资源受限的典型美国城市三级医院多单元离散事件模拟模型,对攻击及其影响以及测试的恢复策略进行建模。该模型用于量化医院对网络攻击的恢复能力。通过系统设计的数值实验收集见解。

结果

虽然发现支付赎金在假定犯罪者实际按承诺提供解密密钥的情况下会带来一些短期收益,但从长远来看,本研究结果表明支付赎金并不划算。相反,在事件结束且服务完全恢复时考虑支付赎金,会使更多急需治疗的患者无法得到救治。还注意到重症监护室的恢复与急诊科相比存在滞后。在应急预案中必须考虑到这种滞后情况。

结论

易受网络攻击是医疗系统面临的一项重大挑战。本文提供了一种评估医院对网络攻击恢复能力以及分析不同应对策略效果的方法。该模型表明支付赎金带来了短期收益,但从长远来看并不划算。

相似文献

1
Assessing resilience of hospitals to cyberattack.评估医院对网络攻击的恢复能力。
Digit Health. 2021 Nov 29;7:20552076211059366. doi: 10.1177/20552076211059366. eCollection 2021 Jan-Dec.
2
Ransomware Attack Associated With Disruptions at Adjacent Emergency Departments in the US.美国相邻急诊部因勒索软件攻击而中断。
JAMA Netw Open. 2023 May 1;6(5):e2312270. doi: 10.1001/jamanetworkopen.2023.12270.
3
Dealing with digital paralysis: Surviving a cyberattack in a National Cancer center.应对数字瘫痪:在国家癌症中心应对网络攻击。
J Cancer Policy. 2024 Mar;39:100466. doi: 10.1016/j.jcpo.2023.100466. Epub 2024 Jan 2.
4
When all computers shut down: the clinical impact of a major cyber-attack on a general hospital.当所有计算机都关闭时:一次重大网络攻击对一家综合医院的临床影响。
Front Digit Health. 2024 Feb 16;6:1321485. doi: 10.3389/fdgth.2024.1321485. eCollection 2024.
5
Ransomware Cyberattack Associated With Cardiac Arrest Incidence and Outcomes at Untargeted, Adjacent Hospitals.与非目标相邻医院心脏骤停发生率及转归相关的勒索软件网络攻击
Crit Care Explor. 2024 Apr 10;6(4):e1079. doi: 10.1097/CCE.0000000000001079. eCollection 2024 Apr.
6
Economic Impact of a Hospital Cyberattack in a National Health System: Descriptive Case Study.国家卫生系统中医院网络攻击的经济影响:描述性案例研究
JMIR Form Res. 2023 Jun 30;7:e41738. doi: 10.2196/41738.
7
Disruption of Library Services Due to Hospital Cyberattack: A Case Study.医院网络攻击导致图书馆服务中断:案例研究。
Med Ref Serv Q. 2022 Apr-Jun;41(2):204-212. doi: 10.1080/02763869.2022.2054198.
8
The crippling effects of a cyberattack at an academic level 1 trauma center: An orthopedic perspective.学术 1 级创伤中心遭遇网络攻击的严重后果:骨科视角。
Injury. 2023 Apr;54(4):1095-1101. doi: 10.1016/j.injury.2023.02.022. Epub 2023 Feb 10.
9
How to Respond to a Ransomware Attack? One Radiation Oncology Department's Response to a Cyber-Attack on Their Record and Verify System.如何应对勒索软件攻击?一个放射肿瘤学部门对其记录和验证系统遭受网络攻击的应对措施。
Pract Radiat Oncol. 2022 Mar-Apr;12(2):170-174. doi: 10.1016/j.prro.2021.09.011. Epub 2021 Oct 10.
10
Hospital cybersecurity risks and gaps: Review (for the non-cyber professional).医院网络安全风险与差距:综述(面向非网络专业人员)
Front Digit Health. 2022 Aug 11;4:862221. doi: 10.3389/fdgth.2022.862221. eCollection 2022.

引用本文的文献

1
Clinicians' Perspectives on Healthcare Cybersecurity and Cyber Threats.临床医生对医疗保健网络安全和网络威胁的看法。
Cureus. 2023 Oct 14;15(10):e47026. doi: 10.7759/cureus.47026. eCollection 2023 Oct.

本文引用的文献

1
Models for Assessing Strategies for Improving Hospital Capacity for Handling Patients during a Pandemic.评估大流行期间提高医院收治患者能力策略的模型
Disaster Med Public Health Prep. 2022 Jan 10;17:e110. doi: 10.1017/dmp.2022.12.
2
Cybersecurity Challenges and the Academic Health Center: An Interactive Tabletop Simulation for Executives.网络安全挑战与学术健康中心:面向高管的互动桌面模拟。
Acad Med. 2021 Jun 1;96(6):850-853. doi: 10.1097/ACM.0000000000003859.
3
Cybersecurity of Hospitals: discussing the challenges and working towards mitigating the risks.
医院的网络安全:探讨挑战并努力降低风险。
BMC Med Inform Decis Mak. 2020 Jul 3;20(1):146. doi: 10.1186/s12911-020-01161-7.
4
Healthcare Data Breaches: Insights and Implications.医疗保健数据泄露:见解与影响
Healthcare (Basel). 2020 May 13;8(2):133. doi: 10.3390/healthcare8020133.
5
A retrospective impact analysis of the WannaCry cyberattack on the NHS.对英国国民医疗服务体系(NHS)遭受的“想哭”勒索病毒网络攻击的回顾性影响分析。
NPJ Digit Med. 2019 Oct 2;2:98. doi: 10.1038/s41746-019-0161-6. eCollection 2019.
6
Strategies for Improved Hospital Response to Mass Casualty Incidents.改善医院应对大规模伤亡事件的策略。
Disaster Med Public Health Prep. 2018 Dec;12(6):778-790. doi: 10.1017/dmp.2018.4. Epub 2018 Mar 19.