Back Bankinfosecurity Why Ransomware Recovery Must Emphasize Patient Care, Trust
Electronic Healthcare Records , Fraud Management & Cybercrime , Governance & Risk Management
Restoring hospital IT systems after a ransomware attack is only part of the recovery process. Healthcare organizations also must restore patient care, reconcile clinical records and - importantly - rebuild trust, said Dr. Mark Yoffe, practicing internist and certified information systems security professional.
See Also: Know Thy Enemy: Threats to Cyber Resilience
A functioning IT system may still lack critical data captured during downtime. Clinicians also may need to electronically input care that was delivered and documented on paper records during system outages, address delayed imaging or procedures and reconnect with patients whose appointments were disrupted.
Healthcare organizations should measure recovery against normal clinical operations rather than whether servers, applications and electronic health records are available, he said.
"Recovery from an IT standpoint is quite different from clinical operations recovery. What we need to do is reconcile those two things and make sure that they go lockstep with one another," Yoffe said.
In this video interview with ISMG, Yoffe also discussed:
Why effective healthcare ransomware recovery must account for missing records, deferred care and lost patient trust;
How care delivery continuity planning helps hospitals maintain patient services when electronic health records, imaging systems or other technology becomes unavailable;
Why healthcare executives should test, audit and assign ownership for continuity plans while accounting for ransomware attacks against critical vendors and interconnected healthcare services.
Yoffe combines clinical practice with cybersecurity expertise. His work focuses on bringing clinical and IT teams together so healthcare organizations can maintain care delivery, test continuity plans, and restore operations after technology disruptions.
Electronic Healthcare Records
Fraud Management & Cybercrime
Governance & Risk Management
Marianne Kolbasuk McGee
Executive Editor, HealthcareInfoSecurity, ISMG
McGee is executive editor of Information Security Media Group's HealthcareInfoSecurity.com media site. She has 30 years of IT journalism experience, with a focus on healthcare information technology issues for more than 15 years. Before joining ISMG in 2012, she was a reporter at InformationWeek magazine and news site and played a lead role in the launch of InformationWeek's healthcare IT media site.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
