
Ransomware is hitting the healthcare field more frequently than any other industry, because hackers and criminals understand that healthcare data is precious. What I want to talk about is why ransomware is particularly successful in healthcare environments, and the relatively straightforward steps your office should be taking or reviewing regularly to make sure your valuable patient data is safe.
Doctors want to protect their patients, to keep their patient records from criminals, and to preserve a trusting environment where patients can share what is really going on so proper diagnoses are made and treatments administered. As a business owner, you worry about your office being up and running when it is supposed to be, so treatments are done on time but also so billing goes out and payments come in. But in talking to doctors and administrators, what I have found is that many worry their data systems are not keeping up with even basic security.
Security should not be an extra
What the majority of healthcare offices tell me is that while they are concerned with being compliant, they do not have the time or the resources to keep their networks secure. My answer is that security should not be an extra. Healthcare IT security should not be something you seek a la carte. It should be something you expect with the main course.
If your ongoing support is doing what they are supposed to, if they understand your business strategy, know where your vulnerabilities lie, and prioritize fixing critical security risks, you would not have any problems securing your network from ransomware. The reason IT security feels too expensive is because you are not dealing with a team that is trained in healthcare, trained in security, and finding strategic ways to protect your data without increasing spending.
Patching, blocking and monitoring
I am always surprised to see clinic, hospital, and healthcare office networks without critical security patches applied. Criminals are exploiting systems that have not been updated simply by walking their network and entering it undetected. Even worse, criminals add organizations that have been attacked because of unpatched networks to their list of places to attack again. More often than not, clinics that were attacked once get reinfected with newer, more potent viruses a second and even third time.
On blocking unwanted traffic, I would say that over 60% of the offices I have had to remediate from CryptoWall had not updated their antivirus, and while many organizations have a firewall, most are outdated and not doing much to prevent contemporary attacks. On monitoring, many healthcare organizations have no idea what a normal day looks like on their network, which makes it impossible to understand when computers are getting infected or a virus is moving.
Responding to an attack
Another big vulnerability healthcare faces is responding to an attack. You will need to recover files from backups and restore your records so doctors can continue to give exceptional patient care. The problem is that many healthcare organizations have not planned for disaster, or have inadequate plans that have never been tested.
When you get ransomed, more often than not when we come in to assist, the incumbent IT support is clueless and your administrators or office staff have no idea what they should do, who they should contact, and how they should move forward. Having a backup and disaster recovery plan, often referred to as a business continuity plan, is essential.



