Suppr超能文献

国家卫生系统中医院网络攻击的经济影响:描述性案例研究

Economic Impact of a Hospital Cyberattack in a National Health System: Descriptive Case Study.

作者信息

Portela Diana, Nogueira-Leite Diogo, Almeida Rafael, Cruz-Correia Ricardo

机构信息

Department of Community Medicine, Information and Health Decision Sciences (MEDCIDS), Faculty of Medicine, University of Porto, Porto, Portugal.

Doctoral Programme in Health Data Science (HEADS), Faculty of Medicine, University of Porto, Porto, Portugal.

出版信息

JMIR Form Res. 2023 Jun 30;7:e41738. doi: 10.2196/41738.

Abstract

BACKGROUND

Over the last decade, the frequency and size of cyberattacks in the health care industry have increased, ranging from breaches of processes or networks to encryption of files that restrict access to data. These attacks may have multiple consequences for patient safety, as they can, for example, target electronic health records, access to critical information, and support for critical systems, thereby causing delays in hospital activities. The effects of cybersecurity breaches are not only a threat to patients' lives but also have financial consequences due to causing inactivity in health care systems. However, publicly available information on these incidents quantifying their impact is scarce.

OBJECTIVE

We aim, while using public domain data from Portugal, to (1) identify data breaches in the public national health system since 2017 and (2) measure the economic impact using a hypothesized scenario as a case study.

METHODS

We retrieved data from multiple national and local media sources on cybersecurity from 2017 until 2022 and built a timeline of attacks. In the absence of public information on cyberattacks, reported drops in activity were estimated using a hypothesized scenario for affected resources and percentages and duration of inactivity. Only direct costs were considered for estimates. Data for estimates were produced based on planned activity through the hospital contract program. We use sensitivity analysis to illustrate how a midlevel ransomware attack might impact health institutions' daily costs (inferring a potential range of values based on assumptions). Given the heterogeneity of our included parameters, we also provide a tool for users to distinguish such impacts of different attacks on institutions according to different contract programs, served population size, and proportion of inactivity.

RESULTS

From 2017 to 2022, we were able to identify 6 incidents in Portuguese public hospitals using public domain data (there was 1 incident each year and 2 in 2018). Financial impacts were obtained from a cost point of view, where estimated values have a minimum-to-maximum range of €115,882.96 to €2,317,659.11 (a currency exchange rate of €1=US $1.0233 is applicable). Costs of this range and magnitude were inferred assuming different percentages of affected resources and with different numbers of working days while considering the costs of external consultation, hospitalization, and use of in- and outpatient clinics and emergency rooms, for a maximum of 5 working days.

CONCLUSIONS

To enhance cybersecurity capabilities at hospitals, it is important to provide robust information to support decision-making. Our study provides valuable information and preliminary insights that can help health care organizations better understand the costs and risks associated with cyber threats and improve their cybersecurity strategies. Additionally, it demonstrates the importance of adopting effective preventive and reactive strategies, such as contingency plans, as well as enhanced investment in improving cybersecurity capabilities in this critical area while aiming to achieve cyber-resilience.

摘要

背景

在过去十年中,医疗保健行业网络攻击的频率和规模不断增加,范围从流程或网络的泄露到限制数据访问的文件加密。这些攻击可能对患者安全产生多种后果,例如,它们可能针对电子健康记录、关键信息的访问以及关键系统的支持,从而导致医院活动延迟。网络安全漏洞的影响不仅威胁患者生命,还会因导致医疗保健系统瘫痪而产生财务后果。然而,关于这些事件量化其影响的公开可用信息却很少。

目的

我们旨在利用葡萄牙的公共领域数据,(1)识别自2017年以来国家公共卫生系统中的数据泄露事件,(2)以一个假设情景为案例研究来衡量其经济影响。

方法

我们从2017年至2022年的多个国家和地方媒体来源检索了有关网络安全的数据,并构建了攻击时间表。在缺乏网络攻击公开信息的情况下,使用针对受影响资源的假设情景以及不活动的百分比和持续时间来估计报告的活动下降情况。估计仅考虑直接成本。估计数据是根据医院合同计划的计划活动生成的。我们使用敏感性分析来说明中级勒索软件攻击可能如何影响医疗机构的日常成本(根据假设推断潜在的值范围)。鉴于我们纳入参数的异质性,我们还为用户提供了一个工具,以便根据不同的合同计划、服务人口规模和不活动比例来区分不同攻击对机构的此类影响。

结果

从2017年到2022年,我们利用公共领域数据在葡萄牙公立医院识别出6起事件(每年1起,2018年2起)。从成本角度获得了财务影响,估计值的最小到最大范围为115,882.96欧元至2,317,659.11欧元(适用的货币汇率为1欧元 = 1.0233美元)。假设不同比例的受影响资源以及不同的工作日数量,同时考虑外部咨询、住院以及门诊和急诊室使用的成本,最多5个工作日,推断出这个范围和规模的成本。

结论

为了增强医院的网络安全能力,提供有力信息以支持决策很重要。我们的研究提供了有价值的信息和初步见解,有助于医疗保健组织更好地理解与网络威胁相关的成本和风险,并改进其网络安全策略。此外,它还证明了采用有效的预防和应对策略(如应急预案)以及在这一关键领域加大对提高网络安全能力的投资以实现网络弹性的重要性。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/58b7/10365569/6f94b3a37410/formative_v7i1e41738_fig1.jpg

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验