In recent years, cases where an EHR was encrypted and care was forced to halt have been reported in Japan. Why are hospitals such easy targets? This article organizes the reasons and realistic measures you can begin right away.
Why hospitals become targets
Because hospitals deal with lives, a system halt has severe impact, so attackers tend to see them as targets from whom money is easy to extract. A large number of terminals and external connections, meaning many intrusion routes, is also a factor.
Cases where vulnerabilities in VPN equipment or maintenance connection routes became the entry point have been reported, so measures must extend to peripheral equipment as well.
Basic measures to start now
Before adopting advanced mechanisms, firming up the basics is what curbs damage. The following two in particular greatly affect whether you can recover after an attack.
- Take backups isolated from the network and rehearse recovery
- Patch device vulnerabilities and minimize access privileges
Preparing an incident-ready structure
No amount of prevention makes damage zero. That is precisely why deciding in advance on a reporting chain when infection is detected, and procedures to switch to paper operation during a system halt, is the key to continuing care.
The cloud-foundation option
Setups reliant on on-site servers tend to take time to recover after an attack. Moving to a robust cloud foundation and building in remote backups and continuous monitoring — an approach that raises resilience against damage — is spreading.
Summary
Ransomware defense starts with mastering the basics — backups, vulnerability management, and an incident-ready structure. While checking the latest national guidance, it is also worth considering options like Sakigake Platform to raise resilience with a cloud foundation.
RELATED