| Literature DB >> 35746951 |
O'Brien Niki1, Ghafur Saira1, Sivaramakrishnan Arvind2, Durkin Mike1.
Abstract
Cyber-attacks on healthcare institutions have increased in recent years and have made headlines through the COVID-19 pandemic. With the fallout of attacks increasingly reported in academic research and in the media, there is a real urgency to address cyber-threats that must be augmented across and within health systems. Until now, clinical healthcare professionals have considered cyber-attacks on healthcare organisations a predominantly information and communication technology issue, but this perception is no longer fit-for-purpose. This commentary provides insights into the scale of cyber-attacks and their impact on staff wellbeing, arguing that cybersecurity education for all staff in healthcare organisations must be improved through online resources, simulation, and gaming. The role of national educators, policymakers, and multilateral organisations in achieving this is outlined alongside implications for future policy and practice.Entities:
Keywords: Education; health communications; health informatics; online; technology
Year: 2022 PMID: 35746951 PMCID: PMC9210086 DOI: 10.1177/20552076221104665
Source DB: PubMed Journal: Digit Health ISSN: 2055-2076
Common types of cyber-attacks and recent examples from healthcare.
| Type of attack | Example from the health sector | |
|---|---|---|
| Phishing attack | Phishing describes a particular type of scam where an attacker sends a fraudulent email or text message from a seemingly trusted individual or organisation. The aim of a phishing attack is to trick the recipient into clicking an attachment which allows the attacker to do something the recipient may not be aware of (e.g. the stealing of credentials/ passwords).
| In March 2020, a phishing attack on the World Health Organization was identified. A group of cyber-attackers launched a malicious website mimicking the WHO's internal email system with the intention of stealing passwords from WHO staff.
|
| Ransomware attack | Ransomware is a type of malicious software (malware) that makes systems unusable until the victim makes a payment.
| In May 2021, a Conti ransomware attack on the Irish health system affected more than 80% of its IT infrastructure, stealing data, and locking healthcare staff out of systems essential for healthcare delivery, as well as non-clinical systems like finance and procurement.
|
Figure 1.Summary of threat message activity during a 1-month period reported by Priestman et al. Reproduced under licence: CC BY-NC.