Suppr超能文献

一项关于医院网络攻击应急行动准备情况的全国性调查。

A National Survey of Hospital Cyber Attack Emergency Operation Preparedness.

作者信息

Sullivan Natalie, Tully Jeffery, Dameff Christian, Opara Chibuzo, Snead Mackenzie, Selzer Jordan

机构信息

Department of Emergency Medicine, George Washington University, School of Medicine, Washington, DC, USA.

Department of Anesthesiology, Division of Perioperative Informatics, University of California San Diego, School of Medicine, La Jolla, California, USA.

出版信息

Disaster Med Public Health Prep. 2023 Mar 22;17:e363. doi: 10.1017/dmp.2022.283.

Abstract

OBJECTIVE

Cyberattacks on healthcare systems are increasing in frequency and severity. Hospitals need to integrate cybersecurity preparedness into their emergency operations planning and response to mitigate adverse outcomes during increasingly likely cyber events. No data currently exist regarding the level of preparedness of United States hospital systems for cybersecurity attacks. We surveyed hospital emergency managers to assess cybersecurity preparedness for these events.

METHODS

Fifty-seven emergency managers representing hospitals across the United States participated in an online Qualtrics survey regarding current preparedness and response procedures for cybersecurity hazards.

RESULTS

Survey responses between April 2019 and May 2021 demonstrated that a majority of hospital systems surveyed included cybersecurity disasters in their HVA (82.4%; 47/57), and most ranked it as 1 of their top 5 priorities (57.4%; 27/47). However, over half denied specifically mentioning cybersecurity in their Emergency Operations Plans (EOPs; 52.6%; 30/57). Fourteen of the 57 hospital systems (24.5%) endorsed previously activating an emergency response for a cybersecurity incident unrelated to information technology (IT) failure.

CONCLUSIONS

The survey results suggest that American hospitals are currently underprepared for cybersecurity disasters. We emphasize the importance of prioritizing cybersecurity in Hazard Vulnerability Analyses (HVAs) and implementing specific EOP annexes for cybersecurity emergencies.

摘要

目的

针对医疗系统的网络攻击在频率和严重程度上都在增加。医院需要将网络安全防范措施纳入其应急行动规划和应对工作中,以减轻在日益可能发生的网络事件期间的不良后果。目前尚无关于美国医院系统应对网络安全攻击的防范水平的数据。我们对医院应急管理人员进行了调查,以评估针对这些事件的网络安全防范情况。

方法

来自美国各地医院的57名应急管理人员参与了一项关于网络安全危害当前防范和应对程序的在线Qualtrics调查。

结果

2019年4月至2021年5月期间的调查回复表明,接受调查的大多数医院系统在其危害脆弱性分析(HVA)中纳入了网络安全灾难(82.4%;47/57),并且大多数将其列为前五大优先事项之一(57.4%;27/47)。然而,超过一半的医院否认在其应急行动预案(EOP)中特别提及网络安全(52.6%;30/57)。57个医院系统中有14个(24.5%)认可此前曾针对与信息技术(IT)故障无关的网络安全事件启动应急响应。

结论

调查结果表明,美国医院目前对网络安全灾难准备不足。我们强调在危害脆弱性分析(HVA)中优先考虑网络安全以及为网络安全紧急情况实施特定的应急行动预案附件的重要性。

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验