This page is designed for people and search engines. Switch to the version for AI systems (LLM) →

Recovering from a Cyberattack: How can Hospitals react?

Due to the great value of medical data and hospitals being a part of the critical infrastructure, they are considered high priority targets for cyberattacks. How should hospitals react in case of a successful cyberattack?

The Risk of a Cyberattack for Hospitals

Hospitals are healthcare organizations that process a significant amount of data, including patient data such as diagnosis, treatment information, and personal information [1]. The electronic exchange of data is the foundation for various processes within the hospital. Electronic data is used in imaging, administration, prescription of medicines, and tracking a patient’s health record [2].

System outages can cause serious disruptions in hospital procedures and patient treatment, resulting in increased administrative work, challenges in collecting patient data [3], the cancellation of surgeries, or disruptions in emergency departments [4]. One major threat to hospital systems are ransomware attacks, where access to the system is blocked until a ransom is paid to a cybercriminal [5]. But how can hospitals recover from these attacks?

Case Study of an attacked Israeli Hospital

In October 2021, the Hillel Yaffe Medical Center (HYMC) in Israel was hit by a major ransomware attack, causing a disconnection of all computer systems and forcing a return to paper-based procedures, as well as the cancellation of non-urgent elective procedures [6]. The hospital stated that it was able to recover its systems in record time and that its recovery actions could serve as a model for other healthcare institutions facing similar threats [7].

In their case study, Abbou et al. investigated the recovery actions of the hospital over an 8-week period, compared to an 8-week period before the incident in 2019 [8].

Recovery Timeline of the Hospital System in Israel** after the Cyberattack

The hospital’s IT experts immediately blocked internet access after the attack to prevent further damage. Together with national cyber experts, they decided to build a completely new network, disconnected from the internet, to restore the hospital’s data. Simultaneously, they employed measures to steadily reintroduce system functions and maintain necessary hospital operations (Figure 1) [8].

Figure 1: Reconstruction Process of the Israeli Hospital IT-Systems (Abbou et al. 2024)

Key Events during the System Recovery

During the restoration period, the hospital had significantly lower admissions compared to the reference period in 2019. Four weeks after the incident, patient admission numbers began to rise quickly. By weeks 5–6, they had returned to normal levels. The authors concluded that the restoration of laboratory systems (week 1), imaging systems (week 2), and Electronic Medical Records (EMR) (week 4) were the most important drivers for resuming regular hospital operations [8].

Similar Ransomware Attacks in Britain and Ireland

After the 2017 WannaCry attack in Britain, the NHS responded in three phases based on an Emergency Preparedness, Resilience and Response process:

  1. Securing the emergency care pathway,
  2. Ensuring operability of primary care, and
  3. Ongoing remediation, broader system actions, and antivirus updates.

One critical part of their incident response was a “kill switch” that prevented the malware from spreading to additional devices. During the incident response, national authorities worked together with local IT experts. After the incident, the NHS implemented local cyber support services. [9].

As part of the incident response to the 2017 ransomware attack on the Irish Orthopedic Register (INOR), over 70,000 devices were disconnected from the national healthcare network. The ransomware used was similar to the one in the WannaCry attack. Similar to the Israeli example, systems were restored gradually, and patient appointments had to be postponed. As access to the network was limited, hospitals followed the procedures described in the contingency plan, such as saving patient data in hardcopy records [3].

Implications for other Hospitals affected by a Cyberattack

Both the attacks on the Israeli hospital and the WannaCry attack exploited a known software vulnerability, highlighting the need for ongoing management of network devices, including patch management [8, 9]. In all presented examples, the spread of the malicious software was contained as quickly as possible by cutting the internet connection. It is also important to note that, in all incidents, local IT professionals worked together with central authorities during their incident response [3, 8, 9]. Even though there are regional differences and hospitals have a complex system architecture [10], they should evaluate the incident response strategies of other institutions and incorporate the lessons learned into their own strategies. They should establish disaster recovery plans and contingency plans, conduct continuous backups, and simulate cyberattacks. One example of preparing for a cyberattack is the study by Pfenninger et al., in which they established paper-based fallback solutions and simulated a cyber incident in a German hospital [11].

Outlook

Following these approaches will significantly enhance the capability of hospitals to appropriately react in the event of a cyberattack. Following these approaches will significantly enhance the capability of hospitals to appropriately react in the event of a cyberattack.

References

  1. Maletzky A, Böck C, Tschoellitsch T, Roland T, Ludwig H, Thumfart S, et al. Lifting Hospital Electronic Health Record Data Treasures: Challenges and Opportunities. JMIR Med Inform. 2022;10:e38557. doi:10.2196/38557.
  1. Li E, Clarke J, Ashrafian H, Darzi A, Neves AL. The Impact of Electronic Health Record Interoperability on Safety and Quality of Care in High-Income Countries: Systematic Review. J Med Internet Res. 2022;24:e38144. doi:10.2196/38144.
  1. Russell SP, Fahey E, Curtin M, Rowley S, Kenny P, Cashman J. The Irish National Orthopaedic Register Under Cyberattack: What Happened, and What Were the Consequences? Clin Orthop Relat Res. 2023;481:1763–8. doi:10.1097/CORR.0000000000002643.
  1. Clarke R, Youngstein T. Cyberattack on Britain’s National Health Service – A Wake-up Call for Modern Medicine. N Engl J Med. 2017;377:409–11. doi:10.1056/NEJMp1706754.
  1. Neprash HT, McGlave CC, Cross DA, Virnig BA, Puskarich MA, Huling JD, et al. Trends in Ransomware Attacks on US Hospitals, Clinics, and Other Health Care Delivery Organizations, 2016-2021. JAMA Health Forum. 2022;3:e224873. doi:10.1001/jamahealthforum.2022.4873.
  1. Bannister A. Israeli hospital cancels non-urgent procedures following ransomware attack. 2021. https://portswigger.net/daily-swig/israeli-hospital-cancels-non-urgent-procedures-following-ransomware-attack. Accessed 6 Feb 2025.
  1. Hillel Yaffe Medical Center. In record time: Just one month after the cyberattack, Hillel Yaffe has returned to regular activity. 2021. https://hymc.org.il/eng/?CategoryID=23&ArticleID=1051. Accessed 6 Feb 2025.
  1. Abbou B, Kessel B, Ben Natan M, Gabbay-Benziv R, Dahan Shriki D, Ophir A, et al. When all computers shut down: the clinical impact of a major cyber-attack on a general hospital. Front Digit Health. 2024;6:1321485. doi:10.3389/fdgth.2024.1321485.
  1. Smart W. Lessons learned review of the WannaCry Ransomware Cyber Attack. 2018. https://www.england.nhs.uk/wp-content/uploads/2018/02/lessons-learned-review-wannacry-ransomware-cyber-attack-cio-review.pdf. Accessed 6 Feb 2025.
  1. Tummers J, Tobi H, Catal C, Tekinerdogan B. Designing a reference architecture for health information systems. BMC Med Inform Decis Mak. 2021;21:210. doi:10.1186/s12911-021-01570-2.
  1. Pfenninger EG, Schmidt SA, Rohland C, Peters S, McNutt D, Kaisers UX, Königsdorfer M. Resilienz gegen IT-Angriffe an Kliniken : Ergebnisse einer Stabsrahmenübung an einem Universitätsklinikum. [Resilience against IT attacks in hospitals : Results from an exercise in a German university hospital]. Anaesthesiologie. 2023;72:852–62. doi:10.1007/s00101-023-01331-y.

Also read: **Cybersecurity in Healthcare Advances in NRW**

Related Articles