Trends in Ransomware Attacks on US Hospitals, Clinics, and Other Health Care Delivery Organizations, 2016-2021.

Trends in Ransomware Attacks on US Hospitals, Clinics, and Other Health Care Delivery Organizations, 2016-2021.
复制标题

DOI:
10.1001/jamahealthforum.2022.4873
复制
发表时间:
2022-12-02
期刊:
JAMA health forum
影响因子:
--
通讯作者:
Nikpay SS
Nikpay SS
中科院分区:
其他
文献类型:
--
作者:
Neprash HT;McGlave CC;Cross DA;Virnig BA;Puskarich MA;Huling JD;Rozenshtein AZ;Nikpay SS

文献摘要

被引文献

相似文献

医疗保健提供组织遭受勒索软件攻击的频率如何,以及勒索软件攻击的特征如何随时间变化?在这项对374次勒索软件攻击的队列研究中,从2016年到2021年,每年针对医疗保健提供机构的勒索软件攻击数量增加了一倍多,暴露了近4200万患者的个人健康信息。在研究期间,勒索软件攻击暴露了大量的个人健康信息,并且更有可能影响拥有多个设施的大型组织。研究结果表明,对医疗保健提供组织的勒索软件攻击的频率和复杂性正在增加;勒索软件攻击期间的护理中断可能会威胁到患者的安全和结果。轶事证据表明,医疗保健提供组织面临着来自勒索软件攻击的日益增长的威胁,这些攻击旨在破坏医疗服务,并可能因此威胁到患者的治疗结果。量化勒索软件对医疗保健提供组织的攻击频率和特征。这项队列研究使用了跟踪医疗勒索软件事件和特征数据库的数据,以检查2016年至2021年医疗保健提供组织遭受勒索软件攻击的数量和特征。Logistic和负二项回归量化了影响医疗保健提供组织的勒索软件攻击特征随时间的变化。勒索软件攻击的日期、勒索软件攻击的公开报告、个人健康信息(PHI)暴露、攻击后加密/被盗数据的状态、受影响的医疗保健提供组织的类型以及勒索软件攻击期间的运营中断。从2016年1月到2021年12月,针对美国医疗服务机构的374次勒索软件攻击暴露了近4200万患者的PHI。从2016年到2021年,勒索软件攻击的年度数量从43次增加到91次,翻了一番多。近一半(166 [44.4%])的勒索软件攻击扰乱了医疗保健的提供,常见的中断包括电子系统停机(156 [41.7%]),预定护理取消(38 [10.2%])和救护车改道(16 [4.3%])。从2016年到2021年,对医疗保健提供组织的勒索软件攻击越来越多地影响到拥有多个设施的大型组织(年边际效应[ME],0.08; 95%CI,0.05-0.10; P < .001),暴露了更多患者的PHI(ME,66 385.8; 95% CI,3400.5-129 371.2; P = .04),不太可能从数据备份中恢复(ME,−0.04; 95% CI,−0.06至−0.01; P = 0.002),更有可能超过强制性报告时限(ME,0.06; 95%CI,0.03-0.08; P < .001),并且越来越多地与预定护理的延迟或取消相关(ME,0.02; 95%CI,0-0.05; P = .02)。这项针对勒索软件攻击的队列研究记录了其频率和复杂性的增长。勒索软件攻击会破坏医疗服务并危及信息完整性。目前的监测/报告工作提供的信息有限,可以扩大范围,以便更全面地了解这种日益增多的网络犯罪形式如何影响保健服务的提供。这项队列研究检查了勒索软件攻击医疗保健提供组织的频率和特征。
How frequently do health care delivery organizations experience ransomware attacks, and how have the characteristics of ransomware attacks changed over time? In this cohort study of 374 ransomware attacks, the annual number of ransomware attacks on health care delivery organizations more than doubled from 2016 to 2021, exposing the personal health information of nearly 42 million patients. During the study period, ransomware attacks exposed larger quantities of personal health information and grew more likely to affect large organizations with multiple facilities. The study results suggest that ransomware attacks on health care delivery organizations are increasing in frequency and sophistication; disruptions to care during ransomware attacks may threaten patient safety and outcomes. Anecdotal evidence suggests that health care delivery organizations face a growing threat from ransomware attacks that are designed to disrupt care delivery and may consequently threaten patient outcomes. To quantify the frequency and characteristics of ransomware attacks on health care delivery organizations. This cohort study used data from the Tracking Healthcare Ransomware Events and Traits database to examine the number and characteristics of ransomware attacks on health care delivery organizations from 2016 to 2021. Logistic and negative binomial regression quantified changes over time in the characteristics of ransomware attacks that affected health care delivery organizations. Date of ransomware attack, public reporting of ransomware attacks, personal health information (PHI) exposure, status of encrypted/stolen data following the attack, type of health care delivery organization affected, and operational disruption during the ransomware attack. From January 2016 to December 2021, 374 ransomware attacks on US health care delivery organizations exposed the PHI of nearly 42 million patients. From 2016 to 2021, the annual number of ransomware attacks more than doubled from 43 to 91. Almost half (166 [44.4%]) of ransomware attacks disrupted the delivery of health care, with common disruptions including electronic system downtime (156 [41.7%]), cancellations of scheduled care (38 [10.2%]), and ambulance diversion (16 [4.3%]). From 2016 to 2021, ransomware attacks on health care delivery organizations increasingly affected large organizations with multiple facilities (annual marginal effect [ME], 0.08; 95% CI, 0.05-0.10; P < .001), exposed the PHI of more patients (ME, 66 385.8; 95% CI, 3400.5-129 371.2; P = .04), were less likely to be restored from data backups (ME, −0.04; 95% CI, −0.06 to −0.01; P = .002), were more likely to exceed mandatory reporting timelines (ME, 0.06; 95% CI, 0.03-0.08; P < .001), and increasingly were associated with delays or cancellations of scheduled care (ME, 0.02; 95% CI, 0-0.05; P = .02). This cohort study of ransomware attacks documented growth in their frequency and sophistication. Ransomware attacks disrupt care delivery and jeopardize information integrity. Current monitoring/reporting efforts provide limited information and could be expanded to potentially yield a more complete view of how this growing form of cybercrime affects the delivery of health care. This cohort study examines the frequency and characteristics of ransomware attacks on health care delivery organizations.