• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

运用失效模式与影响分析(Failure Modes and Effects Analysis,FMEA)对放射肿瘤学勒索软件攻击响应风险进行分析。

Radiation Oncology Ransomware Attack Response Risk Analysis Using Failure Modes and Effects Analysis.

机构信息

Department of Radiation Oncology, Thomas Jefferson University, Philadelphia Pennsylvania.

Department of Radiation Oncology, University of Colorado School of Medicine, Aurora, Colorado.

出版信息

Pract Radiat Oncol. 2024 Sep-Oct;14(5):e407-e415. doi: 10.1016/j.prro.2024.03.001. Epub 2024 Mar 19.

DOI:10.1016/j.prro.2024.03.001
PMID:38508451
Abstract

PURPOSE

There have been numerous significant ransomware attacks impacting Radiation Oncology in the past 5 years. Research into ransomware attack response in Radiation Oncology has consisted of case reports and descriptive articles and has lacked quantitative studies. The purpose of this work was to identify the significant safety risks to patients being treated with radiation therapy during a ransomware attack scenario, using Failure Modes and Effects Analysis.

METHODS AND MATERIALS

A multi-institutional and multidisciplinary team conducted a Failure Modes and Effects Analysis by developing process maps and using Risk Priority Number (RPN) scores to quantify the increased likelihood of incidents in a ransomware attack scenario. The situation that was simulated was a ransomware attack that had removed the capability to access the Record and Verify (R&V) system. Five situations were considered: 1) a standard treatment of a patient with and without an R&V, 2) a standard treatment of a patient for the first fraction right after the R&V capabilities are disabled, and 3) 3 situations in which a plan modification was required. RPN scores were compared with and without R&V functionality.

RESULTS

The data indicate that RPN scores increased by 71% (range, 38%-96%) when R&V functionality is disabled compared with a nonransomware attack state where R&V functionality is available. The failure modes with the highest RPN in the simulated ransomware attack state included incorrectly identifying patients on treatment, incorrectly identifying where a patient is in their course of treatment, treating the incorrect patient, and incorrectly tracking delivered fractions.

CONCLUSIONS

The presented study quantifies the increased risk of incidents when treating in a ransomware attack state, identifies key failure modes that should be prioritized when preparing for a ransomware attack, and provides data that can be used to guide future ransomware resiliency research.

摘要

目的

在过去的 5 年中,已经发生了许多重大的勒索软件攻击事件,影响了放射肿瘤学。放射肿瘤学中对勒索软件攻击的反应研究包括案例报告和描述性文章,缺乏定量研究。本研究的目的是使用失效模式和影响分析(Failure Modes and Effects Analysis)来确定在勒索软件攻击场景下对接受放射治疗的患者造成的重大安全风险。

方法和材料

一个多机构和多学科的团队通过开发流程图并使用风险优先数(RPN)得分来量化在勒索软件攻击场景中事件发生的可能性,进行了失效模式和影响分析。模拟的情况是勒索软件攻击已删除访问记录和验证(Record and Verify,R&V)系统的功能。考虑了五种情况:1)在有和没有 R&V 的情况下对患者进行标准治疗,2)在 R&V 功能被禁用后立即对患者进行首次分次治疗,以及 3)需要进行 3 种计划修改的情况。比较了有和没有 R&V 功能的 RPN 得分。

结果

数据表明,与 R&V 功能可用的非勒索软件攻击状态相比,当 R&V 功能被禁用时,RPN 得分增加了 71%(范围为 38%-96%)。在模拟的勒索软件攻击状态下,RPN 得分最高的失效模式包括错误识别治疗中的患者、错误识别患者在治疗过程中的位置、治疗错误的患者以及错误跟踪已完成的分次治疗。

结论

本研究量化了在勒索软件攻击状态下治疗时事件风险增加的情况,确定了在准备勒索软件攻击时应优先考虑的关键失效模式,并提供了可用于指导未来勒索软件恢复力研究的数据。

相似文献

1
Radiation Oncology Ransomware Attack Response Risk Analysis Using Failure Modes and Effects Analysis.运用失效模式与影响分析(Failure Modes and Effects Analysis,FMEA)对放射肿瘤学勒索软件攻击响应风险进行分析。
Pract Radiat Oncol. 2024 Sep-Oct;14(5):e407-e415. doi: 10.1016/j.prro.2024.03.001. Epub 2024 Mar 19.
2
How to Respond to a Ransomware Attack? One Radiation Oncology Department's Response to a Cyber-Attack on Their Record and Verify System.如何应对勒索软件攻击?一个放射肿瘤学部门对其记录和验证系统遭受网络攻击的应对措施。
Pract Radiat Oncol. 2022 Mar-Apr;12(2):170-174. doi: 10.1016/j.prro.2021.09.011. Epub 2021 Oct 10.
3
Implementing a new scale for failure mode and effects analysis (FMEA) for risk analysis in a radiation oncology department.在放射肿瘤学部门实施用于风险分析的失效模式和影响分析(FMEA)新量表。
Strahlenther Onkol. 2020 Dec;196(12):1128-1134. doi: 10.1007/s00066-020-01686-w. Epub 2020 Sep 19.
4
Failure modes and effects analysis of pediatric I-131 MIBG therapy: Program design and potential pitfalls.儿童 I-131 MIBG 治疗的失效模式和影响分析:方案设计和潜在问题。
Pediatr Blood Cancer. 2022 Dec;69(12):e29996. doi: 10.1002/pbc.29996. Epub 2022 Sep 14.
5
A method for empirically validating FMEA RPN scores in a radiation oncology clinic using physics QC data.一种使用物理质量控制数据在放射肿瘤学临床中对 FMEA RPN 评分进行实证验证的方法。
J Appl Clin Med Phys. 2024 Aug;25(8):e14391. doi: 10.1002/acm2.14391. Epub 2024 Jul 10.
6
A bi-institutional multi-disciplinary failure mode and effects analysis (FMEA) for a Co-60 based total body irradiation technique.一家机构的基于 Co-60 的全身照射技术的双机构多学科失效模式和影响分析(FMEA)。
Radiat Oncol. 2021 Nov 19;16(1):224. doi: 10.1186/s13014-021-01894-3.
7
Quality Assurance with Plan Veto: reincarnation of a record and verify system and its potential value.质量保证计划否决:记录和验证系统的再现及其潜在价值。
Int J Radiat Oncol Biol Phys. 2014 Apr 1;88(5):1161-6. doi: 10.1016/j.ijrobp.2013.12.044.
8
Evaluation of safety in a radiation oncology setting using failure mode and effects analysis.使用失效模式与效应分析评估放射肿瘤学环境中的安全性。
Int J Radiat Oncol Biol Phys. 2009 Jul 1;74(3):852-8. doi: 10.1016/j.ijrobp.2008.10.038. Epub 2009 May 4.
9
Failure mode and effects analysis in a paperless radiotherapy department.无纸放射治疗科的失效模式与效应分析
J Med Imaging Radiat Oncol. 2018 Oct;62(5):707-715. doi: 10.1111/1754-9485.12762. Epub 2018 Jul 27.
10
Improved safety and quality in intravascular brachytherapy: A multi-institutional study using failure modes and effects analysis.提高血管内近距离放射治疗的安全性和质量:使用失效模式和影响分析的多机构研究。
Brachytherapy. 2023 Nov-Dec;22(6):779-789. doi: 10.1016/j.brachy.2023.07.009. Epub 2023 Sep 15.

引用本文的文献

1
Systematic review of prospective hazard analysis in radiation therapy.放射治疗中前瞻性危害分析的系统评价
Med Phys. 2025 Sep;52(9):e18110. doi: 10.1002/mp.18110.

本文引用的文献

1
A National Cyberattack Affecting Radiation Therapy: The Irish Experience.一起影响放射治疗的全国性网络攻击:爱尔兰的经历
Adv Radiat Oncol. 2022 Aug 6;7(5):100914. doi: 10.1016/j.adro.2022.100914. eCollection 2022 Sep-Oct.
2
The Impact of a Cyberattack at a Radiation Oncology Department: Immediate Response and Future Preparedness.放射肿瘤学部门遭受网络攻击的影响:即时响应与未来准备
Adv Radiat Oncol. 2022 Jun 17;7(5):100896. doi: 10.1016/j.adro.2022.100896. eCollection 2022 Sep-Oct.
3
Impact of and Response to Cyberattacks in Radiation Oncology.
放射肿瘤学中网络攻击的影响及应对措施
Adv Radiat Oncol. 2022 Jun 18;7(5):100897. doi: 10.1016/j.adro.2022.100897. eCollection 2022 Sep-Oct.
4
Readiness for Radiation Treatment Continuity: Survey on Contingency Plans Against Cyberattacks.放射治疗连续性准备情况:针对网络攻击的应急计划调查
Adv Radiat Oncol. 2022 Sep 16;7(5):100990. doi: 10.1016/j.adro.2022.100990. eCollection 2022 Sep-Oct.
5
Emerging Cybersecurity Threats in Radiation Oncology.放射肿瘤学中新兴的网络安全威胁
Adv Radiat Oncol. 2021 Sep 20;6(6):100796. doi: 10.1016/j.adro.2021.100796. eCollection 2021 Nov-Dec.
6
How to Respond to a Ransomware Attack? One Radiation Oncology Department's Response to a Cyber-Attack on Their Record and Verify System.如何应对勒索软件攻击?一个放射肿瘤学部门对其记录和验证系统遭受网络攻击的应对措施。
Pract Radiat Oncol. 2022 Mar-Apr;12(2):170-174. doi: 10.1016/j.prro.2021.09.011. Epub 2021 Oct 10.
7
Cancer Care in the Wake of a Cyberattack: How to Prepare and What to Expect.网络攻击后的癌症护理:如何准备和预期。
JCO Oncol Pract. 2022 Jan;18(1):23-34. doi: 10.1200/OP.21.00116. Epub 2021 Aug 2.
8
Development of Rapid Response Plan for Radiation Oncology in Response to Cyberattack.制定应对网络攻击的放射肿瘤学快速响应计划。
Adv Radiat Oncol. 2020 Nov 19;6(1):100613. doi: 10.1016/j.adro.2020.11.001. eCollection 2021 Jan-Feb.
9
Benchmarking failure mode and effects analysis of electronic brachytherapy with data from incident learning systems.基于不良事件学习系统数据的电子近距离放射治疗失效模式和效果分析的基准测试。
Brachytherapy. 2021 May-Jun;20(3):645-654. doi: 10.1016/j.brachy.2020.11.014. Epub 2021 Jan 19.
10
Mortality due to cancer treatment delay: systematic review and meta-analysis.癌症治疗延迟导致的死亡率:系统评价与荟萃分析
BMJ. 2020 Nov 4;371:m4087. doi: 10.1136/bmj.m4087.