purred on by the federal government, hospitals in Maryland have moved quickly in recent years to roll out electronic medical records.

Similar documents
Cybercrime: Technology Turns into a Curse. Technology has advanced drastically over the years. Specifically, computers continue to

Today s Presenters. Pills, Providers, and Problems: How to Investigate Drug Diversion in Long-Term Care

DOING IT YOUR WAY TOGETHER S STRATEGY 2014/ /19

Grant Application for Individuals

Contents. Flu and Infectious Disease Outbreaks Business Continuity Plan

Nova Scotia s Response to H1N1. Summary Report

Cohen and the First Computer Virus. From: Wolfgang Apolinarski

Written Testimony of Serena Vinter, MHS Senior Research Associate Trust for America s Health

ASO core offerings. Self-funded groups, sized 100+

Integrating HIPAA Into Your Compliance Program

Ted Yeshion, Ph.D. Science Subcommittee Chair Professor of Forensic Science Edinboro University of Pennsylvania

Justice Committee. Alternative Dispute Resolution. Written submission from Scottish Mediation

spring 2015 You re in Charge and our online tools can support you - We protect your privacy - avoid high-risk medication - How to manage diabetes

FY17 Justice and Mental Health Collaboration Program Category 3 Orientation Webinar. Tuesday, November 21, 2017

JOB DESCRIPTION. ImROC Business Manager (Mental Health Network) and Senior. Policy Manager (NHS Clinical Commissioners)

1 Switch on to dementia. Switch on to dementia. How energy companies can help people with dementia and their carers

Comprehensive Substance Abuse Strategic Action Plan

Safeguarding Adults. Patient information

National Inspection of services that support looked after children and care leavers

STAFF REPORT City of Lancaster NB 2

France: Millions of medicines seized in largest INTERPOL operation against illicit online pharmacies

Cortex Gateway 2.0. Administrator Guide. September Document Version C

A Helping Model of Problem Solving

Business Continuity and Crisis Management. Cardinal Health s Approach

Robbers Hitting Phoenix Medical- Marijuana Dispensaries: Is Bank Reform Needed?

Standards of Conduct for Transmission Providers

Challenges for U.S. Attorneys Offices (USAO) in Opioid Cases

AMERICAN CANCER SOCIETY FUNDRAISING APP FAQS

SPECIAL DISCLAIMER FOR INTERPRETING SERVICES INVOLVING CALLS TO EMERGENCY SERVICE PROVIDERS (911/E911), OR LEGAL, MEDICAL OR MENTAL HEALTH ISSUES

Building Unity in the Community through Professionalism, Passion, Vision and Commitment. Sheriff Leon Lott

Effective Date: 9/14/06 NOTICE PRIVACY RULES FOR VALUEOPTIONS

TRUSTLINE REGISTRY The California Registry of In-Home Child Care Providers Subsidized Application

SONOMA COUNTY LAW ENFORCEMENT CHIEFS ASSOCIATION

Washington County-Johnson City Health Department Christen Minnick, MPH, Director 219 Princeton Road Johnson City, Tennessee Phone:

September 1, The Honorable Tom Price, MD Secretary Department of Health and Human Services 200 Independence Avenue SW Washington, DC 20201

Preparing For Pandemic Influenza: What the CDC and HHS Recommend You Can Do

Washington Quarterly Newsletter

Predictive analytics can spot patients not taking their medicine

The National Pancreas Foundation. Volunteering Policy & Engagement Procedure

Fraud Awareness Workshop

Noninvasive Glucose Monitors to 2022

A Preliminary Report on Trends and Impact. Mike McGrath. January Montana Attorney General

Maysville Community & Technical College Pandemic Influenza Plan November 2006

SNOW HILL POLICE DEPARTMENT

DEPARTMENT OF VETERANS AFFAIRS SUMMARY: The Department of Veterans Affairs (VA) proposes to amend its medical

ADD THE FOLLOWING TO THE END OF SECTION 8 SPECIAL PROVISIONS - AS A NEW SECTION 8.11

SPONSOR PROGRAM 2018 EXHIBITOR AND. Conference participants

Sonoma County s Family Justice Center

Transcript of virtual press conference with Dr Marie-Paule Kieny, Director, Initiative for Vaccine Research World Health Organization 19 November 2009

Up to 2,000 children may be reported missing to law enforcement in the U.S. every day.

LUNG CANCER SCREENING & CONTINUUM OF CARE Furthering the Accuracy and Universality of Screening Services

LANDMARK THEATRES RESUME FOR Business Plan Requirements Establishments with Beverage Alcohol

We get your personal data from the following sources (examples detailed below are not exhaustive):

Methamphetamine Human and Environmental Risks

Pandemic Flu: Preplanning for an Outbreak

Subject COMMUNICATING WITH INDIVIDUALS WHO ARE DEAF AND HARD OF HEARING. 1 July By Order of the Police Commissioner

Norwich and Pandemic Influenza Planning

Copies Of A Virus Located

Student Drug Policy Approved GE March 2011 Updated May 2012 and approved GE November 2012 Next Review November 2018 Page 1

Risk Classification Modeling to Combat Opioid Abuse

Proposed Amendment of 10A NCAC 26E.0603 Requirements for Transmission of Data

Content Part 2 Users manual... 4

What can you do as a parent?

NAPAC Trustees. Candidate Recruitment Pack

EHR Developer Code of Conduct Frequently Asked Questions

Barbara Brohl Executive Director & State Licensing Authority Colorado Department of Revenue

Cyber-Analytics: Creating Security Profiles using Predictive Analytics

Mental health pilot program saves taxpayers $9.2 million in 12 months

LSS Tariff Review Phase 2 Report

Passive Smoking from a Human Rights Perspectives

National Relay Service: The Deaf Perspective DISCUSSION PAPER

A Common-Sense Framework for Assessing Information-Based Counterterrorist Programs

CONFERENCE ROOM AND FACILITIES POLICY

How Palm Beach County Created a Victim Centered Response

Conversations With. The Honorable Dick Thornburgh The Honorable Rudolph W. Giuliani. The Issue: Prescription Drug Abuse

Pandemic Influenza Communications Exercise

Recommendations from the Report of the Government Inquiry into:

County of Los Angeles Department of Health Services Public Health

A Guide for Effective Communication in Healthcare Patients

The MetroHealth System. Creating the HIT Organizational Culture at MetroHealth. Creating the HIT Organizational Culture

American Diabetes Association 2017 Advocacy Priorities LaShawn McIver, MD, MPH Friday, February 17, :30 p.m. 5:15 p.m.

Interviewing vs. Interrogation

We, at Innovatech Group, have designed xtrack, an easy-to-use workout application that tracks the fitness progress of the user, asking the user to

COUNTY CRIME LAB: HIGH QUALITY TEST RESULTS, CHRONICALLY DELAYED

Services. Related Personal Outcome Measure: Date(s) Released: 21 / 11 / / 06 /2012

Lia Hotchkiss: I'm Lia Hotchkiss and I'm with the Agency for Healthcare. Research and Quality. We are one of the 12 agencies part of the Department of

A helping hand when you need it most

Transparent Communication Strategy for Infection Prevention and Control

ASSEMBLY COMMITTEE ON HUMAN SERVICES Blanca Rubio, Chair AB 2702 (McCarty) As Amended April 2, 2018

REGULATIONS OF THE PLYMOUTH BOARD OF HEALTH FOR TOBACCO SALES IN CERTAIN PLACES & SALE OF TOBACCO PRODUCTS TO MINORS

Moms for Peace. None of us is safe until all of us are safe.

Cardinal Health s Commitment to Opioid Anti-Diversion, Education and Misuse Prevention

Workplace Violence and Crime Through Environmental Design (CPTED) Sergeant Robert J. Greenlee III DEFINITIONS

CSSIW Participation Plan. Working Together to Improve Social Care Services

KING COUNTY SUPERIOR COURT, WASHINGTON STATE CAUSE NO SEA

Motivational Strategies for Challenging Situations

Foster Dennin Page 1 AP Lang 3/1/17 Research Paper Recreational Marijuana: Yes or No?

Welcome and Key Contacts

Virtual Mentor Ethics Journal of the American Medical Association September 2005, Volume 7, Number 9

University Policy TOBACCO-FREE POLICY

Transcription:

1 of 5 4/5/2016 7:22 AM Health Hackers crippled computer systems at hospital chain MedStar Health Inc. on Monday, forcing records systems offline for thousands of patients and doctors. The hack is one of several high-profile breaches that have riddled the health care sector. (Molly Riley / AP) By Ian Duncan and Andrea K. McDaniels Contact Reporters The Baltimore Sun APRIL 2, 2016, 3:18 PM purred on by the federal government, hospitals in Maryland have moved quickly in recent years to roll out electronic medical records. The benefits are many. Electronic medical records can help patients avoid unnecessary tests. They help doctors tailor treatment even for patients they are meeting for the first time. With more information on hand, everyone can make better decisions. But as the attack last week on computer networks at MedStar Health hospitals in Maryland and the District of Columbia demonstrated, the new systems can leave hospitals vulnerable. After unidentified hackers encrypted hospital data, staff members, patients and family members reported delays in service and confusion in treatment. Some cancer patients were unable to get radiation treatment

2 of 5 4/5/2016 7:22 AM for several days. For all the enthusiasm about adopting electronic medical records, security remains a concern. The primary worry has been that hackers could steal patients' information to enable identity theft. But recent attacks have demonstrated the threat of ransomware, in which hackers deny access to data rather than stealing it. In the MedStar attack, as has been the case with other health care providers, the hackers demanded payment in the difficult-to-trace digital currency bitcoin in exchange for the digital keys to unlock the encrypted data, according to copies of the ransom note obtained by The Baltimore Sun. MedStar declined to make anyone available for an interview about the attack or its response, but issued a page-long statement in response to detailed questions faxed by The Sun. "With only a few exceptions, handled on a case-by-case basis, care continued throughout this situation and has been provided to thousands of patients during the past five days," the nonprofit health care system said. "MedStar's priority throughout this attack remains focused on providing high quality, safe care for patients and continuing to meet the care needs of the community." Hospitals in California and Kentucky also have fallen prey to recent ransomware attacks. Despite widespread media coverage of those incidents, analyst Ted Harrington said, many health care organizations still have only a vague understanding of the range of threats they face. Harrington's Baltimore-based Independent Security Evaluators recently completed a two-year study of the digital threats to hospitals. "Most health care organizations have not up to this point been adequately considering denial of service," he said, using the phrase for attacks that focus on shutting down a target's systems. It is also not clear that the laws that require businesses to notify their customers and the public when hackers steal data apply when files are locked up but not stolen. Federal and Maryland laws describe a breach as when information is taken out of a computer system. Jeffrey L. Karberg, who handles identity theft at the Office of the Maryland Attorney General, said the question revolves around the use of the word "acquire" in the laws. "If I've just taken your house key and am willing to sell it back, have I acquired your house?" he asked. The attack on MedStar, which operates 10 hospitals in the region, including Union Memorial, Harbor, Franklin Square and Good Samaritan, brought the computer systems of one of the region's largest health care providers to a halt at the beginning of the workweek.

3 of 5 4/5/2016 7:22 AM MedStar opened command centers to deal with the crisis, it said in its statement. Information technology teams worked to identify the malware and moved to block it. The health system said it would not discuss the malware details, the attack or the attackers, but did say it had not paid any ransom. "Additional media coverage featuring criminal acts offenses against the public that are punishable perpetuates the infamy of malicious attacks for airtime and publicity," MedStar said. By Friday, MedStar said, 90 percent of its systems were back up and running. It said a close-to-normal number of patients had passed through the doors of its facilities during the outages. Health care executives and regulators say their increasing reliance on computer networks and electronic patient data have brought new challenges. Sharon Boston, a spokeswoman for LifeBridge Health, said the corporation takes information security seriously and works to adapt to new threats as they arise. LifeBridge operates Sinai, Northwest and Carroll hospitals in the Baltimore region. "The use of the electronic medical record across the health care industry is broader and deeper than it has ever been, and will continue to grow," Boston said. "With the evolving nature of these electronic threats, LifeBridge Health continually monitors the safety and potential vulnerability of our information systems and takes appropriate action." Ben Steffen, executive director of the Maryland Health Care Commission, said electronic medical records are still new and have vulnerabilities, but they benefit patient care. "Certainly, we are still in the midst of introducing and spreading electronic medical records," Steffen said. "We're still at version one in this cycle, and making the systems more secure is one of the more important challenges moving ahead." Nationally, about 80 percent of doctors now report using electronic records, up from less than 20 percent in 2001. While those figures do not tell the whole story many practices mix paper and electronic records, and some electronic records are merely scans of papers they are now considered mainstream. Hospitals use a variety of measures to prevent hacks and keep patient information safe, said David Sharp, the director of the state's Center for Health Information Technology and Innovative Care Delivery, part of the Maryland Health Care Commission. Hospitals conduct manual cybersecurity tests, Sharp said, and scan continuously for new viruses. Chief information officers meet regularly with state officials. After the MedStar hack, Sharp said, the commission plans to hold those meetings more often. "Hospitals are doing what they should do," he said. "It is unfortunate cyberattacks occur, but no industry is

4 of 5 4/5/2016 7:22 AM immune." That's true every industry faces computer security challenges, and businesses in almost every sector have been targeted by hackers but analysts say health care organizations face particular difficulties. Tenable Network Security, which conducted a survey of several industries last year, ranked health care companies' computer security as below average. "Health care in general has not had a very good track record with information security overall," said Cris Thomas, a strategist at the Columbia-based firm. Many medical devices are now connected to the Internet, creating another vulnerability in hospital networks. In some cases, security fixes to the devices can be applied only by their vendors' technicians. There are signs that MedStar could have done more to withstand or even ward off an attack, some analysts say. Many forms of ransomware require tricking a user into opening a file to begin an infection. The best defense is training employees but even then, there is no guarantee that a craftily worded email from a hacker won't con a staff member. The tool used to attack MedStar, according to details of the ransom note and a website to which the hackers directed MedStar, was Samsam, a different kind that preys on weaknesses in a particular piece of software. It is dangerous because it can be slipped into a network at any time of day or night and spreads quickly. But the defense against it is easier: Install updates that fix the weaknesses. "From a resolution standpoint, this is a really easy-to-solve problem," said Craig Williams, an analyst at Cisco's Talos who has been tracking the use of Samsam. The tool is new it first appeared in December but private security companies and the FBI have been warning about it, and the weaknesses it exploits are widely known. By Monday morning, when MedStar discovered what it called a virus in its systems, it was too late to take those steps. Instead, the company's response was to pull everything offline. MedStar called the decision "courageous and mission-critical." The health system said law enforcement and cybersecurity experts praised the move as "a critical component in the resulting recovery time." But security analysts who spoke to The Sun have questioned the move, which they called an extreme measure that harked back to the responses of the 1990s. "It sounds to me sort of like a panic mode," Thomas said. "Disconnecting and unplugging sort of works, but

5 of 5 4/5/2016 7:22 AM it's not a viable solution these days." The outage left doctors and nurses relying on older techniques to move information. Paper records stacked up on desks, and fax machines were pressed into service. One doctor said a little beeping device that is practically an antique in the wider world but still common in hospitals proved invaluable. It's called a pager. iduncan@baltsun.com amcdaniels@baltsun.com twitter.com/iduncan twitter.com/ankwalker Copyright 2016, The Baltimore Sun This article is related to: Hospitals and Clinics, Healthcare Providers, Medical Procedures, Cyber Crime, Theft, LifeBridge Health, Bitcoin