
How health care can fight life-threatening data breaches
With healthcare data breaches approaching a boiling point, care providers need to adopt an approach that prioritizes operational continuity.
Even with a staggering
In August 2021, the
Operational resiliency
Data breaches disrupt patient treatment schedules and the transferring of medical data. Since health care providers legally own patient medical records, what are patients supposed to do if they can’t access their medical records in the event of a data breach? In most countries, a patient can’t even book an appointment at another clinic or medical center without the relevant medical records to justify the need for it.
Such breaches can be fatal. Imagine a patient of Memorial Health had a heart transplant operation canceled due to the ransomware attack and had to wait an additional two weeks. In that time, the health of the patient’s heart could begin to deteriorate, triggering a near-deadly heart attack, and complicating a future heart transplant.
Beyond financial damage, this kind of ransomware attack on a health care organization negatively affects the quality of patient care, and can even represent the difference between life and death. On top of that, the hospital or health care organization will likely suffer irreparable reputational damage, which is why many don’t report hacks and payments made for ransomed data.
Hospitals and health care organizations of all types must find ways to absorb the blows of data breaches and continue their operations.
Doctors, nurses, health care administrators, and patients need a system that offers a backup plan, in the inevitable event a data breach occurs. This means ensuring patients, and ideally doctors and health care administrators too, always have easy access to medical records through automatic external backups. With proper preparation for these types of security threats, the health care industry can maintain operations and continue serving its patients while also fortifying its own credibility.
Taking action
To find the right solutions to ensure operational continuity, the industry must focus on interoperability and exchange of medical data while also prioritizing the strengthening of its existing IT infrastructure. Furthermore, health care organizations’ ultimate priority must be the satisfaction of its staff, patients, and family.
This starts with finding a technology solution that provides a fully-automated, external, and attack-resilient backup of all medical documents – especially patient records – in real-time. This way, if a hospital or health care network suffers a data breach, its patients can still access their health records and take them to another clinic or hospital without depending on the breach to be resolved first. This also enables hospitals to quickly maintain operations through backup servers, avoiding prolonged pauses in operations which can be the nail in the coffin for smaller organizations.
Health care providers must prepare for all worst-case scenarios. In addition to automating the backing up of all documents, the rising threats faced by health care organizations means they must come up with backup plans for everything from Internet of Things devices, which are rapidly
Care providers can further bolster their plans for operational resiliency by taking actionable steps to monitor their health care IT systems, such as investing in expanding their IT department to better handle future attacks. Health care IT is a growing niche industry thanks to the COVID-19 pandemic, and hospitals and health care providers can boost their operational resiliency by addressing it the same way they would the trauma unit, or any other medical department.
The health care sector paid a ransom in
This ensures patients won’t miss a crucial surgery or operation due to a cyberattack and reduces the value of the ransomed data. Over time this will disincentivize cyber gangs from targeting health care data and institutions.
For health care organizations, operational resiliency, and patient satisfaction remain their chief priority. Hospitals, clinics, and other health care providers can ill-afford to continue paying ransoms for their data and endure the reputational damage they cause. And patients can’t afford to pay the price with their own health.
Allen Alishahi is cofounder and president of
Newsletter
Stay informed and empowered with Medical Economics enewsletter, delivering expert insights, financial strategies, practice management tips and technology trends — tailored for today’s physicians.



















