With ransomware attacks increasingly targeting health care institutions, practices must protect themselves by developing a cybersecurity response plan.
Cyberattacks targeting health care organizations have increased in scope and impact over the last decade. These include “ransomware” attacks in which hackers lock organizations out of their own internet-connected files, systems, or networks until they pay a ransom. These attacks disrupt patient care and stress regional health care ecosystems.1,2
The February 2024 cyberattack on Change Healthcare, a UnitedHealth Group subsidiary, demonstrated how such attacks can not only impact one hospital or health system but also ripple across all health care sectors due to consolidation in the industry. While much of the literature focuses on cyberattacks disrupting care for acute emergencies such as heart attack, stroke, or sepsis, they can also cause serious problems for patient health and clinic finances in primary care.3,4 Family medicine clinics increasingly rely on systems connected to the internet — EHRs, pharmacy portals, laboratory systems, clinical image viewers, etc. — and the abrupt absence of these tools can drastically disrupt workflows if the practice is not prepared. Scheduled downtime intended for brief updates to computer systems is not sufficient preparation for cyberattacks, which can affect multiple technological systems for weeks or even months with no warning.5,6
Preventing cyberattacks requires a detailed, multipronged approach that is beyond the scope of this article (for that, we recommend this 2023 federal report. Below, we offer guidance on how practices can keep patient care and revenue flowing even if a cyberattack causes prolonged tech outages.
KEY POINTS
- Cyberattacks on health care organizations are increasing, and family medicine clinics should prepare for the possibility of prolonged technological outages.
- Practices should create a cybersecurity plan that identifies work-flows with tech vulnerabilities and outlines technology-independent backup plans.
- Practices should test their cybersecurity plan each year with a simulated cyberattack and update the plan as they introduce new technology.
CREATING A CYBERSECURITY RESPONSE PLAN
Clinics should prepare for the possibility of cyberattacks by creating a cybersecurity response plan, which involves the following:
1. Identify workflows with tech vulnerabilities. List the key workflows your practice follows before, during, and after a patient visit, and identify those that rely on internet-connected systems. This includes scheduling patients, accessing their contact information, checking patients in and out, processing orders (for referrals, labs, imaging, medications/refills, etc.), documenting visits, billing payers and patients, and reporting quality metrics.
Read the full article
Get immediate access, anytime, anywhere.
Choose a single article, issue, or full-access subscription.
Earn up to 5 CME credits per issue.
