Is the US health care system a target for cyberterrorism?
December 19, 2012

(Credit: iStockphoto)
Cyber threats are on the rise, and U.S. health care organizations must be better prepared to deal with them, according to an open-access article in Telemedicine and e-Health.
The health care system in the U.S. is a $2.5 trillion industry and depends heavily on communication and the transfer of information via the Internet. This puts it at ever-increasing risk of a cyberterrorism attack, which could jeopardize lives and threaten patient care and privacy, the authors point out.
What Is the risk for Healthcare Targets?
The risk has become more acute in larger healthcare organizations such as hospitals, which have moved away from stand-alone workstations to more tightly integrated platforms attached to networks, according to the authors. It is now common for these networks to link a variety of IT workstations such as admissions, clinical laboratory, pharmacy, radiology, and the billing department.
Networks also connect the IT systems of an organization’s inpatient and outpatient settings as well as a variety of service organizations ranging from acute care to long-term care and home care.
These systems also have links to external networks, which connect and share information with patients, employees, insurers, and business partners. Areas of particular concern to healthcare-related facilities include the potential for cyberterrorism-related events to erase or alter computerized medical, pharmacy, or health insurance records.
Scenario
If terrorists were to attack America’s healthcare IT systems, it probably would not be through the use of one major assault, but rather via a series of small incursions that are much more difficult to detect, the authors suggest. An example of this type of scenario was outlined recently in a cyberterrorism seminar at the University of California, Davis:
- Hackers use ‘‘phishing’’ e-mails to introduce four separate packages of malware into the hospital networks. Once planted, these packages trigger in sequence a few days or weeks apart. The first infects patient record databases and alters doctors’ orders, medication doses, and other information, spreading confusion and possibly causing illness and deaths.
- A few days later, the next program triggers, interfering with portable devices that nurses use to record patient information.
- The third wave attacks the software in intensive care unit monitors, altering the data display and switching off alarms.
- The fourth and final wave infects the software controlling drug infusion pumps and similar devices.
- After a few weeks of these rapidly changing, and different, attacks, the staff in the hospital has no trust in any electronic data, and the IT support staff is totally demoralized.
Comments (2)
by Security Dog
The ultimate backup is portable database workstations on wheels with plain old medical sticker printers for triage – meds and low power deep cycle ups battery on board with solar chargers on the roof recharging backup batteries. Sounds dumb, but it would work in a natural disaster or cyber attack.
by Bennie Beaver
The solution will come as usual by way of a disaster….We hope not this time!
We need a different kind of Internet, quantum computers yesterday, or something. Government, investors, science and technology needs to get on with it even if it takes a new Manhattan Project. Maybe we need a new Steve Job to get the job do.
I’m continually hearing warnings and complaining, but let’s do more sooner than later. Solve the risk.