An analytical review of cybersecurity threats for medical information systems relevant from 2007 to 2017.

This review has been marked by a letter of acknowledgment from the Ministry of Health of the Russian Federation (see the screenshot under the spoiler).

How widespread are medical information systems in Russia?
- In 2006, "Informatika Sibir" (an IT company specializing in the development of medical information systems) reported [38]: "MIT Technology Review periodically publishes a traditional list of the ten most promising information and communication technologies that will soon have the greatest impact on human society. In 2006, 6 out of 10 positions on this list were occupied by technologies related in one way or another to medical issues. The year 2007 was declared 'the year of healthcare informatization' in Russia. From 2007 to 2017, the dynamics of healthcare's dependence on information and communication technologies have been steadily increasing."
- On September 10, 2012, the information-analytical center "Open Systems" reported [41] that in 2012, 350 clinics in Moscow were connected to EMIAS (the unified medical information and analytical system). A little later, on October 24, 2012, the same source reported [42] that currently 3,800 doctors have automated workplaces, and 1.8 million citizens have already tried out the EMIAS service. On May 12, 2015, the same source reported [40] that EMIAS operates in all 660 state clinics in Moscow and contains data on more than 7 million patients.
- On June 25, 2016, the magazine "Profil'" published [43] an expert opinion from the international analytical center PwC: "Moscow is the only megacity where a unified system for managing city clinics has been fully implemented, while similar solutions in other cities around the world, including New York and London, are still in the discussion stage." "Profil'" also reported that as of July 25, 2016, 75% of Moscow residents (about 9 million people) were registered in EMIAS, more than 20,000 doctors are working in the system; since the system's launch, over 240 million appointments with doctors have been made; the system performs over 500,000 various operations daily. On February 10, 2017, "Echo of Moscow" reported [39] that currently over 97% of medical appointments in Moscow are made by prior registration through EMIAS.
- On July 19, 2016, Veronika Skvortsova, the Minister of Health of the Russian Federation, stated [11] that by the end of 2018, 95% of the country's medical centers would be connected to a unified information state healthcare system (EGISZ) through the implementation of a unified electronic medical card (EMK). The corresponding law, which obliges Russian regions to connect to the system, has undergone public discussion, been agreed upon with all interested federal bodies, and will soon be submitted to the government. Veronika Skvortsova reported that electronic appointments with doctors have been organized in 83 regions; a unified regional emergency dispatch system has been implemented in 66 subjects; and medical information systems are operating in 81 regions of the country, with 57% of doctors connected to automated workstations. [11]
Can you provide more details about the unified information state healthcare system (EGSIZ)?
- EGSIZ is the foundation of all domestic MIS (medical information systems). It consists of regional fragments—RISUZ (regional information management system for healthcare). EMIAS, which was mentioned earlier, is one example of RISUZ (the most well-known and promising one). [51] As explained by [56] the editorial of the journal "Director of Information Services", EGSIZ is a cloud-based IT infrastructure, with the creation of regional segments being handled by research centers in Kaliningrad, Kostroma, Novosibirsk, Oryol, Saratov, Tomsk, and other cities of the Russian Federation.
- The goal of EGSIZ is to eliminate the "patchwork informatization" of healthcare by integrating the MIS of various agencies, each of which, prior to the implementation of EGSIZ, used its own bespoke software without any unified centralized standards. [54] Since 2008, the unified information space of healthcare in the Russian Federation has been based on 26 industry-specific IT standards [50]. Of these, 20 are international.
- The operation of medical centers largely depends on HIS, such as OpenEMR or EMIAS. HIS provide the storage of patient information: diagnostic results, data on prescribed medications, medical history, etc. The most common components of HIS (as of March 30, 2017) are: EHR (Electronic Health Records) – a system for maintaining electronic medical records that stores patient data in a structured manner and keeps their medical history. NAS (Network Attached Storage) – a network data storage. DICOM (Digital Imaging and Communications in Medicine) – a standard for producing and exchanging digital images in medicine. PACS (Picture Archiving and Communication System) – a system for storing and exchanging images, operating in accordance with the DICOM standard. It creates, stores, and visualizes medical images and documents of examined patients. The most widely used among DICOM systems. [3] All these HIS are vulnerable to extensively developed cyber-attacks, the details of which are publicly accessible.
- In 2015, Zhilayev P.S., Goryunova T.I., and Volodin K.I., technical experts from the Penza State Technological University, stated [57] in their article dedicated to cybersecurity in the medical sector that the EMIAS includes: 1) IMEK (Integrated Medical Electronic Card); 2) a citywide patient registry; 3) a patient flow management system; 4) an integrated medical information system; 5) a consolidated managerial accounting system; 6) a personalized medical care accounting system; 7) a medical registry management system. Regarding IMEK, according to [39] Echo of Moscow radio (February 10, 2017), this subsystem is built based on the best practices of the OpenEHR standard, which represents the most progressive technology that technologically advanced countries are gradually adopting.
- The editorial office of the journal 'Computerworld Russia' also clarified [41] that in addition to integrating all these services with each other and with the automated information systems of healthcare institutions, the Unified Medical Information Analytical System (EMIAS) is also integrated with the software of the federal segment 'EGIS-Health' (EGIS - Unified State Information System) and electronic government systems, including public service portals. A little later, on July 25, 2016, the editorial office of the journal 'Profil' specified [43] that the EMIAS currently encompasses several services: a situational center, an electronic registration office, an electronic medical card (EMK), electronic prescriptions, sick leave certificates, laboratory services, and personalized accounting.
- On April 7, 2016, the editorial office of the journal 'Director of Information Services' reported [59] that the EMIAS had arrived at pharmacies. An 'automated system for managing the provision of medicines to the population' called M-Pharmacy has been launched in all Moscow pharmacies that dispense medications based on preferential prescriptions.
- On January 19, 2017, the same source reported [58] that since 2015, the implementation of a unified radiological information service (ERIS), integrated with EMIAS, began in Moscow. For doctors issuing patients referrals for diagnostics, technological maps for X-ray examinations, ultrasound, CT, and MRI have been developed, which are integrated with the EMIAS. As the project expands, it is planned to connect hospitals with their numerous equipment to the service. Many hospitals have their own automated information systems, which also need to be integrated. The editorial office of 'Profil' also notes that seeing the positive experience in the capital, regions are also becoming interested in implementing EMIAS.
Can you provide more details about the technical features of domestic medical information systems?
- The information for this paragraph is taken from the analytical review [49] 'Informatics of Siberia'. About 70% of medical information systems are built on relational databases. In 1999, 47% of medical information systems used local (desktop) databases, with dBase tables being the overwhelming majority. This approach is characteristic of the initial development period of software for medicine and the creation of niche products.
- Every year, the number of domestic systems based on desktop databases decreases. In 2003, this figure was already just 4%. Nowadays, almost no developers use dBase tables. Some software products use their own database format; they are often found in electronic pharmacological reference books. Currently, there is a medical information system in the domestic market built on its own client-server database architecture: e-Hospital. It is hard to imagine objective reasons for such decisions.
- The following database management systems are primarily used in the development of domestic medical information systems: Microsoft SQL Server (52.18%), Cache (17.4%), Oracle (13%), Borland Interbase Server (13%), Lotus Notes/Domino (13%). In comparison, when analyzing all medical software that uses a client-server architecture, the share of Microsoft SQL Server DBMS will amount to 64%. Many developers (17.4%) allow the use of multiple DBMS, most often a combination of Microsoft SQL Server and Oracle. Two systems (IS Kondopoga [44] and Paracels-A [45]) use several DBMS simultaneously. All used DBMS are divided into two fundamentally different types: relational and post-relational (object-oriented). To date, 70% of domestic medical information systems are built on relational DBMS, while 30% are on post-relational.
- A wide variety of programming tools are used in the development of medical information systems. For example, DOKA+ [47] is written in PHP and JavaScript. "E-Hospital" [48] was developed in the Microsoft Visual C++ environment. Amulet was developed in the Microsoft Visual.NET environment. "Infomed" [46], which runs on Windows (98/Me/NT/2000/XP), has a two-tier client-server architecture; the client side is implemented in the Delphi programming language, while the server side operates under Oracle DBMS.
- About 40% of developers use tools integrated into DBMS. As a report editor, 42% rely on their own developments; 23% utilize tools embedded in the DBMS. For automating the design and testing of software code, 50% of developers use Visual Source Safe. As documentation software, 85% of developers use Microsoft products – Word or, as in the case of the creators of e-Hospital, Microsoft Help Workshop.
- In 2015, Ageenko T.Y. and Andrianov A.V., technical experts from the Moscow Institute of Technology, published an article [55] detailing the technical aspects of the hospital automated information system (HAIS), including the typical network infrastructure of a medical institution and pressing issues regarding its cybersecurity. HAIS is a secure network through which the EMIAS operates, the most promising of the Russian MIS.
- "Informatics of Siberia" claims [53] that the two most authoritative research centers involved in the development of MIS are the Institute of Software Systems of the Russian Academy of Sciences (located in the ancient Russian city of Pereslavl-Zalessky) and the non-profit organization "Foundation for the Development and Provision of Specialized Medical Assistance Medsanчасть-168" (located in the Academgorodok of Novosibirsk). "Informatics of Siberia," which can also be included in this list, is based in the city of Omsk.
What is the situation with cybersecurity in the domestic EMIAS system?
- On February 10, 2017, Vladimir Makarov, the curator of the EMIAS project, shared his thoughts [39] in an interview with Echo of Moscow radio regarding the fact that absolute cybersecurity does not exist: "There is always a risk of data leakage. We must get used to the idea that the consequence of using any modern technologies is that everything about you may become known. Even the email accounts of top state officials are hacked." In this regard, a recent incident can be mentioned in which the email of about 90 members of the British Parliament was compromised.
- On May 12, 2015, the Department of Information Technology of Moscow reported [40] on four key aspects of the Comprehensive Information Security System (CIBS) for the Unified Medical Information and Analytical System (UMIAS): 1) physical protection – data is stored on modern servers located in underground facilities, access to which is strictly regulated; 2) software protection – data is transmitted in encrypted form over secure communication channels; moreover, information can be accessed simultaneously only for one patient; 3) authorized access to data – doctors are identified using a personal smart card; for patients, there is a two-factor authentication system involving the health insurance policy number and date of birth.
- 4) Medical and personal data are stored separately in two different databases, which further enhances their security; the UMIAS servers accumulate medical information in anonymized form: doctor visits, prescriptions, sick leave certificates, referrals, and other details; personal data, such as health insurance policy number, last name, first name, patronymic, gender, and date of birth, are contained within the databases of the Moscow City Mandatory Medical Insurance Fund; information from both databases is visually merged only on the doctor's monitor after their identification.
- However, despite the seemingly impregnable nature of the UMIAS protection, modern cyberattack technologies – the details of which are publicly available – can compromise even such defenses. For example, see the description of the attack on the new Microsoft Edge browser – in conditions where there are no software vulnerabilities and all available protections are active. [62] Additionally, the absence of errors in the program's code is itself a utopia. More details on this can be found in the presentation "Dirty Little Secrets of Cyber Defenders." [63]
- On June 27, 2017, the clinic "Invitro" suspended the collection of biological material and the issuance of test results in Russia, Belarus, and Kazakhstan due to a large-scale cyberattack. [64]
- On May 12, 2017, Kaspersky Lab recorded [60] 45,000 successful cyber-attacks from the WannaCry ransomware in 74 countries; notably, most of these attacks occurred in Russia. Three days later (May 15, 2017), antivirus company Avast reported [61] that there were already 200,000 cyber-attacks from the WannaCry ransomware and stated that more than half of these attacks took place in Russia. The BBC News Agency reported (on May 13, 2017) that in Russia, among others, the Ministry of Health, the Ministry of Internal Affairs, the Central Bank, and the Investigative Committee fell victim to the virus. [61]
- However, the press offices of these and other Russian agencies unanimously assert that the cyber-attacks from the WannaCry virus, although they did occur, were not successful. Most Russian-language publications regarding the unfortunate incidents with WannaCry hastily add something like, "But according to official data, no damage was caused." On the other hand, the Western press is confident that the consequences of the WannaCry cyber-attack are more significant than presented in the Russian-language media. The Western press is so sure of this that it even lifted suspicions of Russia's involvement in this cyber-attack. Whom to trust more – Western or domestic media – is a personal matter for everyone. It is worth noting that both sides have their motives for exaggerating and downplaying factual information.
What is the situation with cybersecurity in medical information systems – in numbers?
- On June 1, 2017, Rebecca Waintrub (Chief Medical Officer at Brigham and Women's Hospital with a doctoral degree) and Joram Borenstein (cybersecurity engineer) stated in their joint article published in Harvard Business Review [18] that the digital age has greatly simplified the collection of medical data and the exchange of patient medical records between different medical centers: today, patient medical records have become mobile and portable. However, for such digital conveniences, medical centers have to pay a serious price in terms of cybersecurity risks.
- On March 3, 2017, the news agency "SmartBrief" reported [24] that in the first two months of 2017, there were approximately 250 cybersecurity incidents, resulting in the theft of over a million confidential records. 50% of these incidents affected small and medium-sized businesses (excluding the healthcare sector). About 30% were related to the healthcare sector. Shortly after, on March 16, the same agency reported [22] that the leading sector for cybersecurity incidents to date in 2017 is the medical sector.
- On January 17, 2013, Michael Gregg, head of the consulting firm "Thoughtful Solutions" specializing in cybersecurity, reported [21] that in 2012, 94% of medical centers fell victim to confidential information leaks. This is a 65% increase compared to 2010-2011. Worse still, 45% of medical centers reported that the scale of confidential information leaks is becoming increasingly serious over time; they admitted that they experienced more than five such serious leaks during 2012-2013. However, less than half of the medical centers are confident that such leaks can be prevented or at least detected when they occur.
- Michael Gregg also reported [21] that between 2010 and 2012, within just three years, over 20 million patients became victims of EMR thefts, which contain sensitive confidential information: diagnoses, treatment procedures, payment information, insurance details, social security numbers, and much more. A cybercriminal who steals EMRs can exploit the information obtained in various ways (see the section "How are social security number thefts connected to the document forgery criminal industry?"). However, despite all this, the protection of EMRs in medical centers is often much weaker than the protection of personal email.
- On September 2, 2014, Mike Orkut, a technical expert at MIT, stated [10] that ransomware infections are increasing every year. In 2014, there were 600% more incidents than in 2013. Additionally, the FBI reported [26] that in 2016, there were more than 4,000 cases of digital extortion occurring daily—four times more than in 2015. The alarming aspect is not just the trend of increasing ransomware incidents, but also the gradual rise in targeted attacks. The most common targets of such attacks are financial institutions, retail, and medical centers.
- On May 19, 2017, the BBC reported [23] on Verizon's 2017 report, which stated that 72% of ransomware incidents target the healthcare sector. Furthermore, the number of such incidents has increased by 50% over the past 12 months.
- On June 1, 2017, the Harvard Business Review published [18] a report provided by the U.S. Department of Health and Human Services, indicating that over 113 million patient records were stolen in 2015. In 2016, over 16 million were stolen. Despite a sharp decline in incidents compared to 2016, the overall trend shows a growing concern. At the beginning of 2017, the analytic center Experian stated [27] that healthcare is currently the most sought-after target for cybercriminals.
- Data breaches involving patient information in healthcare systems are gradually becoming [37] one of the most pressing issues in the healthcare sector. According to InfoWatch, in the past two years (2005-2006), every second healthcare organization experienced a data leak. Notably, 60% of data breaches occur not through communication channels but through individuals who carry confidential information outside the organization. Only 40% of information leaks occur for technical reasons. The weakest link [36] in the cybersecurity of medical information systems is the people. A significant amount can be invested in creating security systems, yet an underpaid employee may sell information for a fraction of that cost.
Can computer viruses infect medical equipment?
- On October 17, 2012, David Talbot, a technical expert at MIT, reported [1] that medical equipment used within medical centers is becoming increasingly computerized, 'smarter,' and more flexible for reprogramming; it is also more frequently equipped with networking capabilities. As a result, medical equipment is becoming increasingly vulnerable to cyberattacks and virus infections. The problem is exacerbated by the fact that manufacturers typically do not allow modifications to their equipment—even to ensure its cybersecurity.
- For example, in 2009, the Conficker worm infiltrated the 'Beth Israel' medical center and infected some of its medical equipment, including an obstetric workstation (from Philips) and a fluoroscopy workstation (from General Electric). To prevent similar incidents in the future, John Halamka, the IT director of this medical center—and also a professor at Harvard Medical School with a doctorate—decided to disable networking capabilities on this equipment. However, he faced issues as the equipment 'cannot be updated due to regulatory constraints.' He had to make considerable efforts to negotiate with manufacturers to disable the networking features. However, disconnection from the network is far from an ideal solution, especially in the context of increasing integration and interdependence of medical equipment. [1]
- This refers to 'smart' equipment used within medical centers. But there are also wearable medical devices, which include insulin pumps and implanted pacemakers. They are increasingly susceptible to cyberattacks and computer virus infections. [1] It's also worth noting that on May 12, 2017 (the day the WannaCry ransomware virus triumphed), one of the cardiothoracic surgeons reported [28] that in the midst of a heart operation he was conducting, several computers experienced a severe failure—however, fortunately, he was able to successfully complete the procedure.
How dangerous are ransomware viruses to the medical sector?
- On October 3, 2016, Mohammed Ali, CEO of Carbonite, a company specializing in cybersecurity solutions, explained [19] in the Harvard Business Review that ransomware is a type of computer virus that blocks user access to their system until a ransom is paid. The ransomware encrypts the hard drive, thereby preventing the user from accessing information on their computer, and demands a ransom for the decryption key. To avoid detection by law enforcement, criminals use anonymous payment methods such as Bitcoin. [19]
- Mohammed Ali also stated [19] that ransomware distributors have determined that the optimal ransom price when attacking ordinary citizens and small business owners is between $300 and $500. This is an amount that many are willing to part with when faced with the prospect of losing all their digital assets. [19]
- On February 16, 2016, the Guardian reported [13] that as a result of a ransomware infection, the medical staff of Hollywood Presbyterian Medical Center lost access to their computer systems. Consequently, doctors were forced to communicate via fax, nurses had to record medical histories on old-fashioned paper charts, and patients had to visit the hospital in person to receive their test results.
- On February 17, 2016, the management of Hollywood Presbyterian Medical Center released [30] the following statement: "On the evening of February 5, our staff lost access to the hospital network. Malware locked our computers and encrypted all our files. Law enforcement was immediately notified. Cybersecurity experts assisted us in regaining access to our computers. The ransom demanded was 40 bitcoins (approximately $17,000). The quickest and most effective way to restore our systems and administrative functions was to pay the ransom and thereby obtain the decryption key. In order to restore the functionality of the hospital systems, we were forced to do this."
- On May 12, 2017, the news agency 'New York Times' reported [28] that as a result of the WannaCry incident, some hospitals became so paralyzed that they couldn't even print name tags for newborns. Patients were told, 'We cannot serve you because our computers are down.' It's quite unusual to hear this in such large cities as London.
If cyber incidents are so dangerous, why do manufacturers of medical equipment computerize their devices?
- On July 9, 2008, Christina Grifantini, a technical expert at MIT, noted in her article 'Medical Centers: The Age of Plug and Play' [2]: The alarming variety of new 'smart' medical devices in hospitals promises better patient care. However, the problem is that these devices are often incompatible with each other, even if produced by the same manufacturer. Therefore, doctors face a pressing need to integrate all medical equipment into a single computerized network.
- On July 9, 2009, Douglas Rosindale, an IT specialist at the Veterans Health Administration and a professor at Harvard Medical School with a PhD, stated [2] the urgent need for computerized integration of medical equipment with the following words: 'Today, a multitude of proprietary systems with closed architecture from different vendors are available, but the problem is that they cannot interact with each other. And this creates challenges in patient care.'
- When medical devices make independent measurements and do not share them with each other, they cannot comprehensively assess the patient's condition, and therefore, they trigger alarms at the slightest deviation from normal indicators, whether justified or not. This creates significant difficulties for nurses, especially in the intensive care unit, where there are many such independent devices. Without network integration and support, there will be chaos in the intensive care unit. Integration and local network support allow for coordinating the work of medical devices and medical information systems (especially the interaction of these devices with patient electronic medical records), leading to a significant reduction in false alarm signals. [2]
- Hospitals have a lot of outdated, expensive equipment that does not support network integration. Facing a pressing need for integration, hospitals either gradually replace this equipment with new models or retrofit it to enable connectivity within the overall network. Even with new equipment designed with integration in mind, this problem is not entirely resolved. Each manufacturer of medical equipment, driven by perpetual competition, seeks to ensure that their devices can only integrate with one another. However, many emergency departments require such a specific set of various devices that no single manufacturer can provide alone. Therefore, choosing one manufacturer will not solve the compatibility problem. This presents another hurdle to comprehensive integration, and hospitals are investing significant resources to address it. Otherwise, incompatible equipment will turn the hospital into a chaotic place with its false alarm signals. [2]
- On June 13, 2017, Peter Pronovost, a physician with a doctorate and the Deputy Director for Patient Safety at the major medical center 'Johns Hopkins Medicine,' shared [17] his thoughts in the 'Harvard Business Review' about the need for the computerization of medical equipment: 'Take, for example, a ventilator. The optimal ventilation mode for a patient’s lungs directly depends on the patient’s height. The height of the patient is stored in the EMR. Typically, the ventilator does not interact with the EMR, which means doctors have to obtain this information manually, perform some calculations on paper, and manually set the parameters of the ventilator. If the ventilator and EMR were linked via a computerized network, this operation could be automated. Similar routines for maintaining medical equipment also exist among dozens of other medical devices. Therefore, doctors have to perform hundreds of routine operations daily, which are accompanied by errors—albeit rare, they are inevitable.'
- New computerized hospital beds are equipped with a set of high-tech sensors that can monitor a variety of parameters of the patient lying on them. For instance, these beds can determine, by tracking the patient's movement dynamics, whether they are at risk for pressure sores. These high-tech sensors account for 30% of the total cost of the bed. However, without computerized integration, this 'smart bed' is of little use—since it cannot communicate with other medical devices. A similar situation is observed with 'smart wireless monitors' that measure heart rate, respiratory rate, blood pressure, etc. Without the integration of all this equipment into a single computerized network—and primarily ensuring direct interaction with the patients' EMR—its utility is minimal. [17]
Why have cybercriminals shifted their focus from the financial sector and retail stores to medical centers?
- On February 16, 2016, Julia Cherry, a special correspondent for the Guardian, shared her observations about how medical centers are particularly appealing to cybercriminals because their information systems — due to a nationwide push for medical centers to digitize medical records — contain a wealth of diverse information. This includes credit card numbers, personal information about patients, and confidential medical data. [13]
- On April 23, 2014, Jim Finkel, a cybersecurity analyst from the Reuters news agency, explained [12] that cybercriminals tend to take the path of least resistance. The cybersecurity systems of medical centers are much weaker compared to other sectors that have already recognized this issue and implemented effective countermeasures. This is why cybercriminals are attracted to them.
- On February 18, 2016, Mike Orkut, a technical expert at MIT, reported that the interest of cybercriminals in the medical sector is driven by five key reasons: 1) Most medical centers have already transitioned all their documents and records to digital formats; the rest are in the process of doing so. The data in these records contains personal information that is highly valued on the dark web black market. 2) Cybersecurity in medical centers is not a priority; they often use outdated systems and do not maintain them properly. 3) The need for quick access to data in emergency situations often outweighs the need for security, causing hospitals to neglect cybersecurity, even while being aware of the possible consequences. 4) Hospitals are increasingly connecting more devices to their networks, giving bad actors more options to infiltrate the hospital network. 5) The trend towards more personalized medicine — particularly the demand for patients to have comprehensive access to their electronic medical records — makes health information systems even more accessible targets. [14]
- Retail and the financial sector have long been popular targets for cybercriminals. As the stolen information from these institutions floods the black market of the Dark Web, it becomes cheaper, making it less profitable for bad actors to steal and sell it. Therefore, these criminals are now venturing into a new, more lucrative sector. [12]
- On the black market of the Dark Web, medical cards are much more expensive than credit card numbers. This is mainly because they can be used to access bank accounts and obtain prescriptions for controlled medications. Additionally, the fact that a medical card has been stolen and the fact of its illegal use are much harder to detect, and the time from abuse to detection is significantly longer than in the case of credit card misuse. [12]
- According to Dell experts, some particularly enterprising cybercriminals are combining health information extracted from stolen medical cards with other sensitive data to create a package of fake documents. These packages are referred to as “fullz” and “kitz” in Dark Web jargon. The price of each such package exceeds $1000. [12]
- On April 1, 2016, Tom Simonite, a technical expert from MIT, stated [4] that a significant difference in cyber threats within the medical sector lies in the severity of the consequences they promise. For instance, if you lose access to your work email, you will naturally feel upset; however, losing access to medical cards containing vital information for patient treatment is an entirely different matter.
- Therefore, for cybercriminals who understand that this information is incredibly valuable to healthcare providers, the medical sector is a highly attractive target. So appealing that they continually invest significant resources to make their ransomware even more sophisticated, striving to stay one step ahead in their perpetual battle against antivirus systems. The impressive sums they reap from ransomware enable them to make these investments without hesitation, and these costs pay off handsomely. [4]
Why have ransomware infection cases increased in the medical sector and continue to rise?
- On June 1, 2017, Rebecca Weintrob (Chief Executive of Brigham and Women’s Hospital, PhD) and Joram Borenstein (cybersecurity engineer) published [18] in the Harvard Business Review the results of their joint study on cybersecurity in the medical sector. The key points of their research are presented below.
- No organization is immune to hacking. This is the reality we live in, and this reality became especially evident when the notorious WannaCry ransomware spread in mid-May 2017, infecting medical centers and other organizations worldwide. [18]
- In 2016, administrators at the major clinic "Hollywood Presbyterian Medical Center" unexpectedly found that they had lost access to information on their computers. Doctors could not access their patients' medical records or even their own reports. All the information on their computers was encrypted by ransomware. While the clinic's data was held hostage by criminals, doctors had to redirect patients to other hospitals. For two weeks, they wrote everything on paper until they decided to pay the ransom demanded by the criminals – $17,000 (40 bitcoins). Tracking the payment was impossible as the ransom was paid through an anonymous bitcoin payment system. A couple of years ago, if cybersecurity specialists had heard that decision-makers would be grappling with converting money into cryptocurrency to pay a ransom to a virus developer, they would not have believed it. However, this is exactly what happened today. Ordinary people, small business owners, and large corporations are all under threat from ransomware. [19]
- As for social engineering, phishing emails that contain malicious links and attachments are no longer sent in the name of overseas relatives wishing to bequeath you part of their wealth in exchange for confidential information. Today’s phishing emails are well-crafted communications, free of typos; often disguised as official documents with logos and signatures. Some of them are indistinguishable from regular business correspondence or legitimate application update notifications. Sometimes, decision-makers engaged in hiring receive emails from a promising candidate - with a resume attached that contains ransomware. [19]
- However, advanced social engineering is just one part of the problem. Even more alarming is the fact that a ransomware virus can be launched without any direct user involvement. Ransomware can spread through security vulnerabilities or through unprotected outdated applications. At least one fundamentally new type of ransomware appears each week, and the number of ways ransomware can penetrate computer systems is constantly increasing. [19]
- For instance, regarding the WannaCry ransomware... Initially (on May 15, 2017), security experts concluded [25] that the main reason for the infection of the UK’s National Health Service was that hospitals were using an outdated version of the Windows operating system – XP (hospitals use this system because much expensive medical equipment is incompatible with newer versions of Windows). However, shortly after (on May 22, 2017), it became clear [29] that attempts to run WannaCry on Windows XP often led to computer crashes without infection, and the majority of infected machines were running on Windows 7. Additionally, it was initially believed that the WannaCry virus spread through phishing, but later it was found that this virus spread independently, like a network worm, without user assistance.
- Moreover, there are specialized search engines that do not look for websites on the internet but instead search for physical equipment. They can indicate in which location and which hospital specific equipment is connected to the network. [3]
- Another significant factor in the prevalence of ransomware is access to cryptocurrency, particularly Bitcoin. The ease of anonymously collecting payments from around the world contributes to the rise of cybercrime. Additionally, by paying ransom to the attackers, you are effectively encouraging further extortion attempts against you. [19]
- At the same time, cybercriminals have learned to compromise even the systems that have the most modern protection and the latest software updates; the detection and decryption tools that protection systems rely on do not always work, especially if the attack is targeted and unique. [19]
- Nevertheless, there is an effective countermeasure against ransomware: making backups of critical data. This way, in the event of trouble, the data can be easily restored. [19]
Doctors, nurses, and patients affected by WannaCry – what were the repercussions for them?
- On May 13, 2017, Sarah Marsh, a journalist for the Guardian, surveyed several individuals who became victims of the WannaCry ransomware to understand what this incident means for the affected (names changed for privacy reasons):
- Sergey Petrovich, doctor: I could not provide proper care to my patients. No matter how much the management tried to assure the public that cyber incidents do not affect the safety of end patients – it is not true. We couldn’t even take X-rays when our computerized systems went down. And no medical procedure can proceed without these images. For instance, that unfortunate evening, I had a patient to see, and I needed to send him for an X-ray, but because our computerized systems were paralyzed, I couldn’t do this. [5]
- Vera Mikhailovna, breast cancer patient: After undergoing a chemotherapy session, I was halfway home from the hospital when the cyberattack occurred. And although my session was already complete, I had to spend several more hours in the hospital – waiting for them to finally give me my medications. The delay was because the medical staff checks them against the prescriptions in computerized systems before dispensing. Patients waiting behind me were already in the ward for their chemotherapy session; their medications had also been delivered. But since it was impossible to verify their compliance with the prescriptions, the procedure was postponed. The treatments for other patients were postponed until the next day. [5]
- Tatyana Ivanovna, nurse: On Monday, we were unable to view patients' electronic medical records and the list of appointments scheduled for today. I was on duty over the weekend, so on Monday, when our hospital fell victim to a cyberattack, I had to recall who was supposed to come in for an appointment. Our hospital's information systems were locked. We could not access medical histories, view prescriptions; we could not look up addresses and contact details of patients; fill out documents; or check test results. [5]
- Evgeny Sergeyevich, System Administrator: Usually, Fridays after lunch are our busiest times. This Friday was no different. The hospital was packed with people, and five staff members were on duty taking calls, with their phones ringing incessantly. All our computer systems were functioning smoothly, but around 3:00 PM, all the computer screens went black. Our doctors and nurses lost access to patients' electronic medical records, and the staff handling incoming calls were unable to enter requests into the system. [5]
How can cybercriminals harm a plastic surgery clinic?
- As reported by the 'Guardian' [6], on May 30, 2017, the criminal group 'Tsarskaya Gvardiya' published confidential data of 25,000 patients from the Lithuanian plastic surgery clinic 'Grozio Chirurgija'. This included private intimate photos taken before, during, and after surgeries (which are kept due to the specific nature of the clinic's work); as well as scans of passports and social security numbers. The clinic has a good reputation and offers competitive prices, attracting clients from 60 countries, including worldwide celebrities [7]. All of them became victims of this cyber incident.
- A few months earlier, after hacking the clinic's servers and stealing data, the 'guards' demanded a ransom of 300 bitcoins (approximately $800,000). The clinic's management refused to cooperate with the 'guards' and remained adamant even when the ransom was reduced to 50 bitcoins (around $120,000). [6]
- Losing hope of receiving a ransom from the clinic, the "guards" decided to shift their focus to its clients. In March, they published photos of 150 patients from the clinic [8] in the Dark Web, to scare others and force them to pay up. The "guards" demanded ransoms ranging from 50 to 2000 euros, payable in bitcoin, depending on the victim's notoriety and the intimacy of the stolen information. The exact number of patients who were blackmailed is unknown, but several dozen victims have approached the police. Now, three months later, the "guards" have published confidential data of another 25,000 clients. [6]
A cybercriminal stole a medical record – what does this mean for its rightful owner?
- On October 19, 2016, Adam Levin, a cybersecurity expert and head of the research center "CyberScout," noted [9] that we live in a time when medical records are starting to contain an alarming amount of overly intimate information: about diseases, diagnoses, treatments, and health issues. In the wrong hands, this information can be exploited for profit in the Dark Web's black market, which is why cybercriminals often target medical centers.
- On September 2, 2014, Mike Orkutt, a technical expert from MIT, stated [10]: "While stolen credit card numbers and Social Security numbers are experiencing decreasing demand in the Dark Web's black market, medical records, which contain a wealth of personal information, are in high demand. This is partly because they allow uninsured individuals to access medical care that they otherwise could not afford."
- A stolen medical card can be used to obtain medical assistance in the name of its rightful owner. As a result, the medical records of the rightful owner and those of the thief will get mixed up. Additionally, if the thief sells stolen medical cards to third parties, the card may become even more compromised. Therefore, when the rightful owner visits the hospital, they risk receiving medical assistance based on someone else's blood type, medical history, list of allergies, etc. [9]
- Moreover, the thief may exhaust the insurance limit of the rightful owner of the medical card, depriving them of the ability to receive necessary medical assistance when it is needed the most. Many insurance plans have annual caps on certain types of procedures and treatments. Certainly, no insurance company will pay for two appendectomy surgeries. [9]
- By using a stolen medical card, a thief can abuse prescriptions for medications, thereby denying the rightful owner access to necessary medication when they need it. Prescription medications are generally limited. [9]
- Mitigating massive cyberattacks on credit and debit cards is not that problematic. Protecting against targeted phishing attacks is somewhat more challenging. However, when it comes to the theft of electronic medical cards and their misuse, the crime can be nearly invisible. If the crime is discovered, it is usually only in an emergency situation when the consequences can be literally life-threatening. [9]
Why is there such an increasing demand for the theft of medical cards?
- In March 2017, the Identity Theft Resource Center reported that over 25% of data breaches occur in medical centers. These breaches cost medical centers an annual loss of $5.6 billion. Below are several reasons why the theft of medical cards is in such increasing demand. [18]
- Medical cards are the most sought-after product on the black market of the Darknet. They are sold there for $50 each. In comparison, credit card numbers are available for $1 each on the Darknet, which is 50 times cheaper than medical cards. The demand for medical cards is also driven by the fact that they are a consumable component in complex criminal services involving document forgery. [18]
- If a buyer for medical cards cannot be found, the perpetrator can use the medical card themselves to carry out traditional theft: medical cards contain enough information to open a credit card, establish a bank account, or take out a loan in the victim's name. [18]
- With a stolen medical card in hand, a cybercriminal can conduct a sophisticated targeted phishing attack (metaphorically sharpening the phishing spear), posing as a bank: “Good day, we know you are about to have surgery. Don’t forget to pay for the accompanying services by clicking on this link.” And then you think, “Well, since they know I have surgery tomorrow, this must be a legitimate message from the bank.” If the criminal fails to capitalize on the stolen medical cards here as well, they might use ransomware to extort money from the medical center for restoring access to blocked systems and data. [18]
- Medical centers are very slow to implement cybersecurity measures that have already been established in other industries, which is quite ironic, given that medical centers are responsible for ensuring medical confidentiality. Additionally, medical centers generally have significantly smaller budgets for cybersecurity and far less qualified cybersecurity specialists compared to, for example, financial organizations. [18]
- Medical IT systems are closely tied to financial services. For instance, medical centers may have flexible savings plans for unforeseen expenses, with their own payment cards or savings accounts that hold six-figure sums. [18]
- Many organizations work with medical centers and provide their employees with an individual wellness system. This gives an attacker the opportunity, through hacking medical centers, to access the confidential information of the corporate clients of the medical center. Not to mention that the employer themselves could act as the attacker, quietly selling the medical data of their employees to third parties. [18]
- Medical centers have extensive supply chains and large lists of suppliers with whom they have established digital connections. By hacking the IT systems of a medical center, an attacker can also compromise the systems of suppliers. Moreover, suppliers connected to the medical center through digital communication are already an enticing entry point for attackers into the IT systems of the medical center. [18]
- In other areas, protection has become very sophisticated, and therefore attackers have had to adapt to a new sector, where transactions are conducted through vulnerable hardware and software. [18]
How are social security number thefts linked to the document forgery criminal industry?
- On January 30, 2015, the news agency "Tom's Guide" explained [31] the difference between simple document forgery and combined forgery. In the simplest case, document forgery involves a fraudster simply posing as another individual, using their name, Social Security Number (SSN), and other personal information. This type of fraud is relatively quick and easy to detect. In the combined approach, bad actors create an entirely new identity. By forging a document, they take a real SSN and add fragments of personal information from several different individuals. This Frankenstein monster, stitched together from the personal information of various people, is much harder to detect than simple document forgery. Since the fraudster uses only bits of information from each victim, their fraudulent activities won't be linked to the legitimate owners of those fragments. For instance, when the legitimate owner checks their SSN activity, they will find nothing suspicious.
- Bad actors can use their Frankenstein monster to obtain employment or take out loans [31], as well as to open shell companies [32]; for making purchases, acquiring driver's licenses, and passports [34]. Even in the case of taking a loan, tracking the act of document forgery is very difficult, and therefore if bankers begin to investigate, the legitimate holder of the personal information fragment will likely be held accountable, rather than the creator of the Frankenstein monster.
- Unscrupulous entrepreneurs can use document forgery to deceive creditors by creating a so-called business sandwich. The essence of the business sandwich is that unscrupulous entrepreneurs can create several fake identities and present them as clients of their business, thus creating the illusion of business success. This makes them more attractive to creditors and allows them to take advantage of more favorable lending conditions. [33]
- The theft and misuse of personal information often goes unnoticed by its rightful owner for a long time but can cause significant inconvenience at the most inopportune time. For example, a legitimate owner of an SSN may apply for social services and get denied due to excessive income generated from a fabricated business scheme utilizing their SSN. [33]
- Since 2007 and up to the present day, the multi-billion-dollar criminal business of document forgery based on SSNs has been gaining increasing popularity [34]. Fraudsters prefer SSNs that are not actively used by their legitimate owners, including the SSNs of children and deceased individuals. According to the CBS news agency, in 2014, monthly incidents were counted in the thousands, whereas in 2009, there were no more than 100 per month. The exponential growth of this type of fraud—especially its impact on children's personal data—will have dire consequences for young people in the future. [34]
- Children's SSNs are used in this fraudulent scheme 50 times more frequently than adults' SSNs. This interest in children's SSNs is due to the fact that they are generally inactive until the age of 18. Thus, if the parents of minor children do not keep track of their SSNs, their child may be denied a driver's license or a student loan in the future. It can also complicate employment if information about dubious SSN activity becomes accessible to a potential employer. [34]
Today, there is much discussion about the prospects and security of artificial intelligence systems. How does this play out in the medical sector?
- In the June 2017 issue of MIT Technology Review, the editor-in-chief of this publication, specializing in artificial intelligence technologies, published his article "The Dark Side of Artificial Intelligence," which addressed this question in detail. Key points from his article [35]:
- Modern artificial intelligence (AI) systems are so complex that even the engineers who design them cannot explain how AI makes certain decisions. As of today, and in the foreseeable future, it seems impossible to develop an AI system that can always explain its actions. The technology of deep learning has proven to be very effective in addressing pressing problems of recent years: image and voice recognition, language translation, and medical applications. [35]
- AI carries significant hopes for diagnosing deadly diseases and making complex economic decisions; it is also expected that AI will become a central element in many other industries. However, this will not happen—or at least should not happen—until we find a way to create a deep learning system that can explain the decisions it makes. Otherwise, we will not be able to predict when this system will fail—and it will inevitably fail sooner or later. [35]
- This problem has become urgent already, and in the future, it will only worsen. Whether it concerns economic, military, or medical decisions. The computers running these AI systems have programmed themselves in such a way that we have no way of understanding 'what is on their minds.' What can we say about end-users, when even the engineers designing these systems cannot comprehend and explain their behavior? As AI systems continue to evolve, we may soon cross a line—if we haven't already—where, relying on AI, we will need to make a 'leap of faith.' Of course, as humans, we ourselves cannot always explain our reasoning and often rely on intuition. But can we allow machines to think in the same way—unpredictable and inexplicable? [35]
- In 2015, Mount Sinai, a medical center in New York, was inspired to apply the concept of deep learning to its extensive database of patient histories. The data structure used to train the AI system included hundreds of parameters based on lab results, diagnostics, tests, and medical records. The program that processed these records was named 'Deep Patient.' It was trained using records from 700,000 patients. When tested with new records, it proved to be very useful for predicting diseases. Without any interaction with an expert, 'Deep Patient' identified symptoms hidden in the medical histories, which the AI believed indicated that the patient was on the verge of serious complications, including liver cancer. We had previously experimented with various predictive methods that used the medical histories of many patients as input data, but the results of 'Deep Patient' are incomparable. Moreover, there are completely unexpected achievements: 'Deep Patient' predicts the onset of mental disorders, such as schizophrenia, very well. However, since modern medicine lacks tools to predict it, the question arises of how the AI managed to do this. Yet, 'Deep Patient' cannot explain how it does it. [35]
- Ideally, such tools should explain to doctors how they reached certain conclusions — to justify the use of a particular medication, for example. However, modern artificial intelligence systems unfortunately cannot do this. We can create such programs, but we do not understand how they work. Deep learning has led AI systems to explosive success. Currently, such AI systems are used to make critical decisions in industries like medicine, finance, manufacturing, and others. Perhaps this reflects the nature of intelligence itself — that only part of it can be rationally explained, while for the most part it makes spontaneous decisions. But what will this lead to when we allow such systems to diagnose cancer and conduct military maneuvers? [35]
Has the medical sector learned lessons from the WannaCry incident?
- On May 25, 2017, the news agency BBC reported [16] that one of the significant reasons for neglecting cybersecurity in wearable medical devices is their low computing power, dictated by strict size requirements. Two other equally significant reasons are the lack of knowledge on how to write secure code and the pressing deadlines for product release.
- In the same report, BBC noted [16] that as a result of examining the source code of one of the pacemakers, over 8,000 vulnerabilities were discovered; and that despite widespread attention on cybersecurity issues raised by the WannaCry incident, only 17% of medical device manufacturers took specific actions to ensure the cybersecurity of their devices. As for healthcare centers that managed to avoid falling victim to WannaCry, only 5% of them took measures to assess the cybersecurity of their equipment. These reports emerged shortly after more than 60 healthcare organizations in the UK were targeted by a cyberattack.
- On June 13, 2017, a month after the WannaCry incident, Peter Pronovost, a physician with a doctorate and the chief safety officer of the major medical center Johns Hopkins Medicine, discussed [17] in Harvard Business Review the pressing challenges of computerized integration in medical equipment—he did not mention cybersecurity.
- On June 15, 2017, a month after the WannaCry incident, Robert Pearl, a physician with a doctorate and the leader of two medical centers, while discussing [15] in Harvard Business Review the modern challenges faced by developers and users of EMR systems, said not a word about cybersecurity.
- On June 20, 2017, a month after the WannaCry incident, a group of PhD scientists from Harvard Medical School, who also lead key departments at Brigham and Women’s Hospital, published [20] in the pages of Harvard Business Review the results of a roundtable discussion focused on the need to modernize medical equipment to improve patient care. The roundtable addressed the potential for reducing the burden on doctors and cutting costs through the optimization of technological processes and comprehensive automation. Representatives from 34 leading medical centers in the United States participated in the discussion. In discussing the modernization of medical equipment, the participants placed high hopes on predictive tools and smart devices. Cybersecurity was not mentioned at all.
How can medical centers ensure cybersecurity?
- In 2006, the head of the Department of Information Systems of Special Communications of the Federal Protective Service of Russia, Lieutenant General Nikolai Ilyin, stated [52]: “The issue of information security is more relevant today than ever. The number of devices in use is rapidly increasing. Unfortunately, cybersecurity considerations are not always taken into account at the design stage. It is clear that the cost of solving this problem ranges from 10 to 20 percent of the system's total cost, and customers are often reluctant to pay extra money. However, it must be understood that reliable information protection can only be achieved through a comprehensive approach that combines organizational measures with the implementation of technical protection means.”
- On October 3, 2016, Mohammed Ali, a former key employee of IBM and Hewlett Packard and now the head of Carbonite, a company specializing in cybersecurity solutions, shared [19] in the Harvard Business Review his observations regarding the cybersecurity situation in the medical sector: "Given how widespread ransomware is and the potential for costly damage, I am always surprised when in conversations with CEOs I find that they do not take this issue seriously. At best, CEOs delegate cybersecurity concerns to the IT department. However, that is not enough to ensure effective protection. Therefore, I always urge CEOs to: 1) include ransomware prevention measures in their organizational development priorities; 2) review their cybersecurity strategy at least once a year; 3) involve their entire organization in relevant education."
- Established solutions from the financial sector can be borrowed. The main conclusion [18] drawn by the financial sector from the chaos of cybersecurity is: "The most effective element of cybersecurity is staff training. Because, to date, the primary cause of cybersecurity incidents is the human factor, particularly individuals' susceptibility to phishing attacks. While strong encryption, cyber risk insurance, multi-factor authentication, tokenization, card chip technology, blockchain, and biometrics are useful, they are largely secondary."
- On May 19, 2017, the BBC reported [23] that in the UK, after the WannaCry incident, sales of security software increased by 25%. However, according to Verizon experts, panic buying of security software is not what is needed for ensuring cybersecurity; to secure it, one must follow proactive protection rather than reactive.
P.S. Did you like the article? If so, please give it a like. If I see that readers on Habr show interest in this topic by reaching a total of 70 likes, I will prepare a follow-up shortly, reviewing even more recent threats to medical information systems.
Bibliography
- David Talbot. // MIT Technology Review (Digital). 2012.
- Kristina Grifantini. // MIT Technology Review (Digital). 2008.
- Dens Makrushin. // SecureList. 2017.
- Tom Simonite. // MIT Technology Review (Digital). 2016..
- Sarah Marsh. // The Guardian. 2017.
- Alex Hern. // The Guardian. 2017.
- Sarunas Cerniauskas. // OCCRP: Organized Crime and Corruption Reporting Progect. 2017.
- Ray Walsh. // BestVPN. 2017.
- Adam Levin. // HuffPost. 2016.
- Mike Orcutt. // MIT Technology Review (Digital). 2014.
- Pyotr Sapozhnikov. // АМИ: Российское агентство медико-социальной информации. 2016.
- Jim Finkle. // Reuters. 2014.
- Julia Carrie Wong. // The Guardian. 2016.
- Mike Orcutt. // MIT Technology Review (Digital). 2016.
- Robert M. Pearl, MD (Harvard). // Harvard Business Review (Digital). 2017.
- // BBC. 2017.
- Peter Pronovost, MD. // Harvard Business Review (Digital). 2017.
- Rebecca Weintraub, MD (Harvard), Joram Borenstein. // Harvard Business Review (Digital). 2017.
- Mohamad Ali. // Harvard Business Review (Digital). 2016.
- Meetali Kakad, MD, David Westfall Bates, MD. // Harvard Business Review (Digital). 2017.
- Michael Gregg. // HuffPost. 2013.
- // SmartBrief. 2017.
- Matthew Wall, Mark Ward. // BBC. 2017.
- // BBC. 2017.
- Alex Hern. // The Guardian. 2017.
- // FBI. 2017.
- // Rxperian. 2017.
- Steven Erlanger, Dan Bilefsky, Sewell Chan. // The New York Times. 2017.
- // BBC. 2017.
- Allen Stefanek. .
- Linda Rosencrance. // Tom’s Guide. 2015.
- .
- .
- Steven D’Alfonso. // Security Intelligence. 2014.
- Will Knight. The Dark Secret at the Heart of AI // MIT Technology Review. 120(3), 2017.
- Kuznetsov G.G. // «Информатика Сибири».
- // «Информатика Сибири».
- // «Информатика Сибири».
- Vladimir Makarov. // Радио «Эхо Москвы».
- // Открытые системы. 2015.
- Irina Sheyan. // Computerworld Россия. 2012.
- Irina Sheyan. // Computerworld Россия. 2012.
- Olga Smirnova. // Профиль. 2016.
- A Anastasia Tseplyova. // 2012.
- .
- Kuznetsov G.G. // «Информатика Сибири».
- .
- .
- // «Информатика Сибири».
- // «Информатика Сибири».
- // «Информатика Сибири».
- // «Информатика Сибири».
- // «Информатика Сибири».
- Ageenko T.Yu., Andrianov A.V. // IT-Стандарт. 3(4). 2015.
- 2013.
- Zhilyaev P.S., Goryunova T.I., Volodin K.I. // Международный студенческий научный вестник. 2015.
- Irina Sheyan. // Директор информационной службы. 2017.
- Irina Sheyan. // Директор информационной службы. 2016.
- // 2017.
- Andrei Makonin. // БиБиСи. 2017.
- Erik Bosman, Kaveh Razavi. Dedup Est Machina: Memory Deduplication as an Advanced Exploitation Vector // Proceedings of the IEEE Symposium on Security and Privacy. 2016. pp. 987-1004.
- Bruce Potter. Dirty Little Secrets of Information Security // DEFCON 15. 2007.
- Ekaterina Kostina. .
Source: habr.com
