Ransomware Attack Associated With Disruptions at Adjacent Emergency Departments in the US.

Ransomware Attack Associated With Disruptions at Adjacent Emergency Departments in the US.
复制标题

DOI:
10.1001/jamanetworkopen.2023.12270
复制
发表时间:
2023-05-01
期刊:
影响因子:
13.8
通讯作者:
Longhurst, Christopher A.
Longhurst, Christopher A.
中科院分区:
医学1区
文献类型:
--
作者:
Dameff, Christian;Tully, Jeffrey;Chan, Theodore C.;Castillo, Edward M.;Savage, Stefan;Maysent, Patricia;Hemmen, Thomas M.;Clay, Brian J.;Longhurst, Christopher A.

文献摘要

参考文献

相似文献

在勒索软件网络攻击下,与医疗保健系统相邻的医院的相关区域医疗保健中断是什么?这项队列研究对2个邻近医疗保健提供组织的学术城市急诊科(ED)进行了为期一个月的勒索软件攻击,评估了未受影响的艾德的19857次艾德就诊:攻击前阶段6114次,攻击和恢复阶段7039次,攻击后阶段6704次。在袭击和袭击后阶段,病人普查、救护车到达、候诊室时间、病人离开而没有被看到、病人住院总时间、全州紧急医疗服务转移等方面的人数显著增加,在未受影响的ED中观察到急性中风护理指标。这项研究表明,医疗保健网络攻击(如勒索软件)与地区医院的更大中断有关,应被视为灾害,需要协调规划和应对努力。对医疗保健提供机构的网络攻击越来越频繁,越来越复杂。勒索软件感染与严重的运营中断有关,但据我们所知,描述这些网络攻击与邻近医院的区域关联的数据此前尚未报告。在对地理位置接近但独立的医疗保健提供组织进行为期一个月的勒索软件攻击期间,检查机构的急诊科(艾德)患者数量和卒中护理指标。这项前后队列研究比较了2021年5月1日勒索软件攻击前4周内2名美国城市学术ED的成人和儿童患者数量以及卒中护理指标(2021年4月3日至30日),以及发作和恢复期间(2021年5月1日至28日)和发作和恢复后4周(2021年5月29日至6月25日)。这两个急诊科对超过70000次护理接触和圣地亚哥县11%的急性住院总出院人数进行了合并平均年度普查。勒索软件针对的医疗保健提供机构约占该地区住院患者出院人数的25%。对4家邻近医院进行了长达一个月的勒索软件网络攻击。急诊科就诊量(普查)、时间吞吐量、急诊医疗服务(EMS)的区域转移和卒中护理指标。本研究评价了19 857例未受影响艾德的艾德访视:(平均[SD]年龄:49.6 [19.3]岁; 2931例[47.9%]女性患者; 1663例[27.2%]西班牙裔、677例[11.1%]非西班牙裔黑人和2678例[43.8%]非西班牙裔白色患者),7039(平均[SD]年龄:49.8 [19.5]岁; 3377例[48.0%]女性患者; 1840例[26.1%]西班牙裔、778例[11.1%]非西班牙裔黑人和3168例[45.0%]非西班牙裔白色患者)在发作期和恢复期,6704例(平均[SD]年龄,48.8 [19.6]岁; 3326例[49.5%]女性患者; 1753例[26.1%]西班牙裔,725例[10.8%]非西班牙裔黑人和3012例[44.9%]非西班牙裔白色患者)。与发作前相比,在发作期,每日平均(SD)艾德计数显著增加(218.4 [18.9] vs 251.4 [35.2]; P < .001),EMS到达(1741 [28.8] vs 2354 [33.7]; P < .001),(1614 [26.4] vs 1722 [24.5]; P = .01),患者离开时未被发现(158 [2.6] vs 360 [5.1]; P < .001),而患者违背医嘱离开(107 [1.8] vs 161 [2.3]; P = .03)。与发作前相比,发作期的候诊时间中位数也有显著增加(21分钟[IQR,7-62分钟] vs 31分钟[IQR,9-89分钟]; P < .001)和住院患者的总艾德住院时间(614分钟[IQR,424-1093分钟] vs 822分钟[IQR,497-1524分钟]; P < .001)。与发作前相比,发作期卒中代码激活也显著增加(59 vs 102; P = 0.01),确诊卒中也显著增加(22 vs 47; P = 0.02)。这项研究发现,受勒索软件攻击影响的医疗保健提供机构附近的医院可能会看到患者人口普查的增加,并且可能会遇到资源限制,影响急性中风等疾病的时间敏感性护理。这些发现表明,有针对性的医院网络攻击可能与社区内非目标医院的医疗服务中断有关,应被视为区域性灾难。这项队列研究检查了一家医院急诊科(艾德)的患者数量和中风护理指标,该医院在地理位置接近但独立的医疗保健提供组织上进行了长达一个月的勒索软件攻击。
What are the associated regional health care disruptions in hospitals adjacent to health care systems under ransomware cyberattack? This cohort study of 2 academic urban emergency departments (EDs) adjacent to a health care delivery organization under a month-long ransomware attack evaluated 19 857 ED visits at the unaffected ED: 6114 in the preattack phase, 7039 in the attack and recovery phase, and 6704 in the postattack phase. During the attack and postattack phases, significant increases in patient census, ambulance arrivals, waiting room times, patients left without being seen, total patient length of stay, county-wide emergency medical services diversion, and acute stroke care metrics were seen in the unaffected ED. This study suggests that health care cyberattacks such as ransomware are associated with greater disruptions to regional hospitals and should be treated as disasters, necessitating coordinated planning and response efforts. Cyberattacks on health care delivery organizations are increasing in frequency and sophistication. Ransomware infections have been associated with significant operational disruption, but data describing regional associations of these cyberattacks with neighboring hospitals have not been previously reported, to our knowledge. To examine an institution’s emergency department (ED) patient volume and stroke care metrics during a month-long ransomware attack on a geographically proximal but separate health care delivery organization. This before and after cohort study compares adult and pediatric patient volume and stroke care metrics of 2 US urban academic EDs in the 4 weeks prior to the ransomware attack on May 1, 2021 (April 3-30, 2021), as well as during the attack and recovery (May 1-28, 2021) and 4 weeks after the attack and recovery (May 29 to June 25, 2021). The 2 EDs had a combined mean annual census of more than 70 000 care encounters and 11% of San Diego County’s total acute inpatient discharges. The health care delivery organization targeted by the ransomware constitutes approximately 25% of the regional inpatient discharges. A month-long ransomware cyberattack on 4 adjacent hospitals. Emergency department encounter volumes (census), temporal throughput, regional diversion of emergency medical services (EMS), and stroke care metrics. This study evaluated 19 857 ED visits at the unaffected ED: 6114 (mean [SD] age, 49.6 [19.3] years; 2931 [47.9%] female patients; 1663 [27.2%] Hispanic, 677 [11.1%] non-Hispanic Black, and 2678 [43.8%] non-Hispanic White patients) in the preattack phase, 7039 (mean [SD] age, 49.8 [19.5] years; 3377 [48.0%] female patients; 1840 [26.1%] Hispanic, 778 [11.1%] non-Hispanic Black, and 3168 [45.0%] non-Hispanic White patients) in the attack and recovery phase, and 6704 (mean [SD] age, 48.8 [19.6] years; 3326 [49.5%] female patients; 1753 [26.1%] Hispanic, 725 [10.8%] non-Hispanic Black, and 3012 [44.9%] non-Hispanic White patients) in the postattack phase. Compared with the preattack phase, during the attack phase, there were significant associated increases in the daily mean (SD) ED census (218.4 [18.9] vs 251.4 [35.2]; P < .001), EMS arrivals (1741 [28.8] vs 2354 [33.7]; P < .001), admissions (1614 [26.4] vs 1722 [24.5]; P = .01), patients leaving without being seen (158 [2.6] vs 360 [5.1]; P < .001), and patients leaving against medical advice (107 [1.8] vs 161 [2.3]; P = .03). There were also significant associated increases during the attack phase compared with the preattack phase in median waiting room times (21 minutes [IQR, 7-62 minutes] vs 31 minutes [IQR, 9-89 minutes]; P < .001) and total ED length of stay for admitted patients (614 minutes [IQR, 424-1093 minutes] vs 822 minutes [IQR, 497-1524 minutes]; P < .001). There was also a significant increase in stroke code activations during the attack phase compared with the preattack phase (59 vs 102; P = .01) as well as confirmed strokes (22 vs 47; P = .02). This study found that hospitals adjacent to health care delivery organizations affected by ransomware attacks may see increases in patient census and may experience resource constraints affecting time-sensitive care for conditions such as acute stroke. These findings suggest that targeted hospital cyberattacks may be associated with disruptions of health care delivery at nontargeted hospitals within a community and should be considered a regional disaster. This cohort study examines a hospital’s emergency department (ED) patient volume and stroke care metrics during a month-long ransomware attack on a geographically proximal but separate health care delivery organization.
DOI: 10.1001/jamahealthforum.2022.4873
发表时间: 2022-12-02
期刊: JAMA health forum
影响因子: --
作者:
Neprash HT;McGlave CC;Cross DA;Virnig BA;Puskarich MA;Huling JD;Rozenshtein AZ;Nikpay SS
通讯作者: Nikpay SS
DOI: 10.1002/itl2.247
发表时间: 2020-10-14
影响因子: 1.5
作者:
Pranggono B;Arabo A
通讯作者: Arabo A
DOI: 10.1093/intqhc/mzaa117
发表时间: 2021-01-01
影响因子: 2.6
作者:
Muthuppalaniappan, Menaka;Stevenson, Kerrie
通讯作者: Stevenson, Kerrie
DOI: 10.7326/m20-7191
发表时间: 2021-05-01
影响因子: 39.2
作者:
Akselrod, Hana
通讯作者: Akselrod, Hana
DOI: 10.1097/acm.0000000000003859
发表时间: 2021-06-01
期刊: ACADEMIC MEDICINE
影响因子: 7.4
作者:
Maggio, Lauren A.;Dameff, Christian;Tully, Jeffrey
通讯作者: Tully, Jeffrey