Cargando…

Ransomware Recovery and Imaging Operations: Lessons Learned and Planning Considerations

In this era, almost all healthcare workflows are digital and rely on robust institutional networks; a ransomware attack in a healthcare system can have catastrophic patient care consequences. The usual downtime processes in an institution might not address the breadth of this disruption and timeline...

Descripción completa

Detalles Bibliográficos
Autores principales: Chen, Po-Hao, Bodak, Robert, Gandhi, Namita S.
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Springer International Publishing 2021
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8218969/
https://www.ncbi.nlm.nih.gov/pubmed/34159418
http://dx.doi.org/10.1007/s10278-021-00466-x
_version_ 1783710839596908544
author Chen, Po-Hao
Bodak, Robert
Gandhi, Namita S.
author_facet Chen, Po-Hao
Bodak, Robert
Gandhi, Namita S.
author_sort Chen, Po-Hao
collection PubMed
description In this era, almost all healthcare workflows are digital and rely on robust institutional networks; a ransomware attack in a healthcare system can have catastrophic patient care consequences. The usual downtime processes in an institution might not address the breadth of this disruption and timelines for recovery. This article shares our lessons learned from ransomware recovery. From this experience, a four-phase recovery planning framework has been developed. The primary focus is on acute patient care, incident communication, and emergency imaging operations in the initial phase. In the next phase, continued digital asset unavailability necessitates a transition to long-term analog workflows. In the infrastructure recovery and reconciliation phases, each taking weeks or months, the emphasis is on rebuilding a ransomware-free environment and reconciling the data accrued during extended downtime. In preparation for future events, we have initiated a continuous readiness process. A response task force has been formed to guide physicians, technologists, nurses, and informatics units on recovery workflows appropriate for extended downtime and keeping these procedures updated. Incident command structure has been discussed for communications and resource allocation during a ransomware attack, possibly in the context of a multi-incident scenario such as that involving concurrent staffing shortage amidst a pandemic. Finally, we discuss considerations for tabletop simulation, which may be valuable to the planning process.
format Online
Article
Text
id pubmed-8218969
institution National Center for Biotechnology Information
language English
publishDate 2021
publisher Springer International Publishing
record_format MEDLINE/PubMed
spelling pubmed-82189692021-06-23 Ransomware Recovery and Imaging Operations: Lessons Learned and Planning Considerations Chen, Po-Hao Bodak, Robert Gandhi, Namita S. J Digit Imaging Commentary In this era, almost all healthcare workflows are digital and rely on robust institutional networks; a ransomware attack in a healthcare system can have catastrophic patient care consequences. The usual downtime processes in an institution might not address the breadth of this disruption and timelines for recovery. This article shares our lessons learned from ransomware recovery. From this experience, a four-phase recovery planning framework has been developed. The primary focus is on acute patient care, incident communication, and emergency imaging operations in the initial phase. In the next phase, continued digital asset unavailability necessitates a transition to long-term analog workflows. In the infrastructure recovery and reconciliation phases, each taking weeks or months, the emphasis is on rebuilding a ransomware-free environment and reconciling the data accrued during extended downtime. In preparation for future events, we have initiated a continuous readiness process. A response task force has been formed to guide physicians, technologists, nurses, and informatics units on recovery workflows appropriate for extended downtime and keeping these procedures updated. Incident command structure has been discussed for communications and resource allocation during a ransomware attack, possibly in the context of a multi-incident scenario such as that involving concurrent staffing shortage amidst a pandemic. Finally, we discuss considerations for tabletop simulation, which may be valuable to the planning process. Springer International Publishing 2021-06-22 2021-06 /pmc/articles/PMC8218969/ /pubmed/34159418 http://dx.doi.org/10.1007/s10278-021-00466-x Text en © Society for Imaging Informatics in Medicine 2021
spellingShingle Commentary
Chen, Po-Hao
Bodak, Robert
Gandhi, Namita S.
Ransomware Recovery and Imaging Operations: Lessons Learned and Planning Considerations
title Ransomware Recovery and Imaging Operations: Lessons Learned and Planning Considerations
title_full Ransomware Recovery and Imaging Operations: Lessons Learned and Planning Considerations
title_fullStr Ransomware Recovery and Imaging Operations: Lessons Learned and Planning Considerations
title_full_unstemmed Ransomware Recovery and Imaging Operations: Lessons Learned and Planning Considerations
title_short Ransomware Recovery and Imaging Operations: Lessons Learned and Planning Considerations
title_sort ransomware recovery and imaging operations: lessons learned and planning considerations
topic Commentary
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8218969/
https://www.ncbi.nlm.nih.gov/pubmed/34159418
http://dx.doi.org/10.1007/s10278-021-00466-x
work_keys_str_mv AT chenpohao ransomwarerecoveryandimagingoperationslessonslearnedandplanningconsiderations
AT bodakrobert ransomwarerecoveryandimagingoperationslessonslearnedandplanningconsiderations
AT gandhinamitas ransomwarerecoveryandimagingoperationslessonslearnedandplanningconsiderations