The healthcare industry is a major target for cybercriminals, due to the highly sensitive data handled on a daily basis. One of the most common threats your practice is likely to encounter is ransomware – a type of attack where data is held hostage. With 29% of businesses still choosing to pay the ransom, it is more important than ever to discuss how these threats can be avoided. One important case study is this year’s attack on Change Healthcare.
The Change Healthcare Ransomware Attack
Change Healthcare is a company that supports healthcare organizations by providing revenue and payment cycle management solutions. In late February of 2024, they experienced a ransomware attack, which they recently confirmed has compromised the personal data of over 100 million people. The incident was first noticed when clinics were unable to access their billing systems on the 21st, due to Change Healthcare attempting to isolate the threat – but the company later realized that the breach itself had taken place a week earlier on the 12th.
A group associated with the ALPHV/BlackCat gang of cybercriminals soon took credit for the attack, and collected a ransom payment of $22 million from Change Healthcare. Despite this, the group did not return the data as promised. This is unfortunately not a unique experience – it is currently reported that only 8% of companies that pay a ransom receive all their data back in exchange.
How to Protect Your Healthcare Organization
Ransomware attacks can have devastating consequences on your organization, but it is possible to reduce your risk of falling victim:
1. Data Backups
Data backups are your first and best line of defense against ransomware. Backups should be performed regularly and stored in multiple locations both onsite and offsite. It is very important to test your recovery processes, as backups often fail. By keeping reliable backup and recovery procedures in place, you will be able to ensure full data recovery in the event of a breach.
2. Multi-Factor Authentication (MFA)
MFA helps prevent unauthorized access to your accounts, by requiring multiple means of verification. Enable MFA whenever possible, and enforce it strictly.
3. Awareness Training
Staff should be made aware of the threat presented by ransomware attacks and phishing scams. Teach them how to recognize these attacks, how to prevent them, and when they should report an incident. Run regular drills to check for gaps in employee knowledge.
4. Access Controls
Use the principle of least privilege (employees should only access information and systems necessary for their roles) and Zero Trust architecture (never trust, always verify) to prevent data breaches. Update user access regularly, especially if someone has just left your organization or if roles have changed.
5. Updates
Regularly update software and apply security patches, to minimize the attack surface. Enable automatic updates whenever possible.
6. Network Segmentation
By segmenting networks into smaller, isolated sections, you can ensure that even if a breach occurs, threat actors will not be able to easily access all systems or data.
7. Email Security
Use email filters and advanced threat protection to stop phishing scams from reaching inboxes. Do not ever click on a link or divulge sensitive information without first verifying the email’s source.
8. Monitor Activity
Continuously monitor network and endpoint activity for suspicious signs that may indicate a cyber threat. Change Healthcare’s ransomware attack went unnoticed for over a week, which allowed the group responsible to cause significant damage. By catching it early, you can minimize harm and ensure continuity.
9. Incident Response Plan
The best security measures in the world still do not guarantee the safety of your data, and it is very easy to panic and pay the ransom if an attack occurs. A thorough, tested incident response plan will help you stay calm and respond quickly and safely.
10. Disable Macros From the Internet
Many ransomware attacks use macros in Microsoft Office files to deliver malware. Disable macros that originate from the internet to reduce this risk.
What if Your Practice Falls Victim?
If you suspect that a ransomware attack is occurring, take these steps immediately:
1. Isolate
Isolate any compromised systems from the rest of your network.
2. Do Not Pay
Never pay a ransom. It can put your practice in dire financial straits, does not guarantee the safety of stolen data, and signals to the group responsible that you are a good target for future attacks.
3. Report
Report the attack to the relevant authorities, and to any parties who may be affected. Explain what steps you are taking in response, and recommend precautionary measures for those affected.
4. Remove Threat
Carefully remove the threat from compromised systems. This may mean changing login credentials or deleting malware. Check that you have thoroughly removed any danger before proceeding to the next step.
5. Restore
Once you are absolutely certain that no threat remains, restore data from backups and begin returning to normal operations. Stop and repeat from step one if you see any signs that the attack is ongoing.
Secure Your Network and Prevent Ransomware Attacks
The Change Healthcare ransomware attack demonstrates the devastating consequences of handling a cyber incident poorly. Preparation and a proactive approach are key to preventing and responding to ransomware without losing data, money, or patient trust. By planning ahead and strengthening your security posture, you can protect your clinic and ensure continuity.
The cybersecurity experts at Ascentient can help you secure your practice, with comprehensive network solutions designed to defend you and your patients against cyber-attacks. We specialize in healthcare security, and understand the importance of protecting ePHI – which is why we tailor our solutions to your unique needs. Explore our network security services today and learn how we can protect your practice.
