Suppr超能文献

[德国大学医院的医院信息技术攻击抵御能力:一次演练的结果]

[Resilience against IT attacks in hospitals : Results from an exercise in a German university hospital].

作者信息

Pfenninger E G, Schmidt S A, Rohland C, Peters S, McNutt D, Kaisers U X, Königsdorfer M

机构信息

Stabsstelle Katastrophenschutz, Universitätsklinikum Ulm, Albert-Einstein-Allee 29, 89081, Ulm, Deutschland.

Klinik für Diagnostische und Interventionelle Radiologie, Universitätsklinikum Ulm, Ulm, Deutschland.

出版信息

Anaesthesiologie. 2023 Dec;72(12):852-862. doi: 10.1007/s00101-023-01331-y. Epub 2023 Sep 19.

Abstract

BACKGROUND

According to the legal definition healthcare systems and their components (e.g., hospitals) are part of the critical infrastructure of modern industrial nations. During the last few years hospitals increasingly became targets of cyber attacks causing severe impairment of their operability for weeks or even months. According to the German federal strategy for protection of critical infrastructures (KRITIS strategy), hospitals are obligated to take precautions against potential cyber attacks or other IT incidents.

OBJECTIVE

This article describes the process of planning, execution and results of an advanced table-top exercise which took place in a university hospital in Germany and simulated the first 3 days after a cyber attack causing a total failure of highly critical IT systems.

MATERIAL AND METHODS

During a first stage lasting about 8 months IT-dependent processes within the clinical routine were identified and analyzed. Then paper-based and off-line back-up processes and workarounds were developed and department-specific emergency plans were defined. Finally, selected central facilities such as pharmacy, laboratory, radiology, IT and the hospitals crisis management team took part in the actual disaster exercise. Afterwards the participants were asked to evaluate the exercise and the hospitals cyber security using a questionnaire. On this basis the authors visualized the hospital's resilience against cyber incidents and defined short-term, medium-term and long-term needs for action.

RESULTS

Of the participants 85% assessed the exercise as beneficial, 97% indicated that they received adequate support during the preparations and 75% had received sufficient information; however, only 34% had the opinion that the hospital's and their own preparedness against critical IT failures were sufficient. Before the exercise took place, IT-specific emergency plans were present only in 1.7% of the hospital facilities but after the exercise in 86.7% of the clinical and technical departments. The highest resilience against cyber attacks was not surprisingly reported by facilities that still work routinely with paper-based or off-line processes, the IT department showed the lowest resilience as it would come to a complete shutdown in cases of a total IT failure.

CONCLUSION

The authors concluded that the planning phase is the most important stage of developing the whole exercise, giving the best opportunity for working out fallback levels and workarounds and through this strengthen the hospitals resilience against cyber attacks and comparable incidents. A meticulous preparedness can minimize the severe effects a total IT failure can cause on patient care, staff and the hospital as a whole.

摘要

背景

根据法律定义,医疗保健系统及其组成部分(如医院)是现代工业国家关键基础设施的一部分。在过去几年中,医院越来越成为网络攻击的目标,导致其运营能力严重受损数周甚至数月。根据德国联邦关键基础设施保护战略(KRITIS战略),医院有义务对潜在的网络攻击或其他信息技术事件采取预防措施。

目的

本文描述了在德国一家大学医院进行的一次高级桌面演练的计划、执行过程和结果,该演练模拟了导致高度关键信息技术系统完全故障的网络攻击后的头3天。

材料与方法

在持续约8个月的第一阶段,确定并分析了临床常规中依赖信息技术的流程。然后制定了纸质和离线备份流程及变通方法,并确定了各部门的应急预案。最后,药房、实验室、放射科、信息技术部门和医院危机管理团队等选定的核心设施参加了实际的灾难演练。之后,要求参与者使用问卷对演练和医院的网络安全进行评估。在此基础上,作者直观展示了医院对网络事件的恢复能力,并确定了短期、中期和长期的行动需求。

结果

85%的参与者认为演练有益,97%的参与者表示在准备过程中得到了充分支持,75%的参与者获得了足够的信息;然而,只有34%的人认为医院及其自身对关键信息技术故障的准备是充分的。在演练之前,只有1.7%的医院设施制定了针对信息技术的应急预案,但在演练之后,86.7%的临床和技术部门都制定了预案。不出所料,仍常规使用纸质或离线流程的设施报告的对网络攻击的恢复能力最高,信息技术部门的恢复能力最低,因为在信息技术完全故障的情况下它将完全关闭。

结论

作者得出结论,规划阶段是开展整个演练最重要的阶段,为制定备用方案和变通方法提供了最佳机会,从而增强医院对网络攻击和类似事件的恢复能力。精心准备可以将信息技术完全故障对患者护理、工作人员和整个医院可能造成的严重影响降至最低。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/26bd/10691995/dbd9c158b9c1/101_2023_1331_Fig1_HTML.jpg

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验