Healthcare Attacks Can be Life Threatening
Two recent healthcare attacks brings home the dangers of cyberattacks.
One firm is Boston Scientific; the other is McKesson and we are beginning to get some details of these attacks. One attack disrupted global operations and the other resulted in stolen patient data.
Boston Scientific makes pacemakers and other implanted heart devices.
Devices implanted after the breach cannot provide remote monitoring and data transmission.
New remote monitoring cannot be activated at all so those patients will not get the benefit of why the device was installed. I assume that doctors at this point will stop implanting that brand of device and use a different brand. Possibly that becomes a permanent change if the doctors become comfortable with the new devices.
No monitoring means that if the patient has a cardiac episode their doctors won’t find out about it.
The devices will still record data and when the systems resume operations, the data will be uploaded. While that is nice, it is probably less than useful as real time data reporting is critical in the case of a heart device.
However, the company does not know when all of their systems will be operational again – again, not good if you are a patient that needs real time monitoring. The good news is that THIS particular attack did not affect their cloud based systems.
The second attack, against McKesson, allowed hackers to steal patient data – hundreds of millions of records (according to the hackers, about 300 million records). Here is what the company is saying about the attack:
“Based on our investigation thus far, including assessments by leading cybersecurity industry experts supporting our response, we’ve confirmed that the unauthorized access to certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units,” Francisco Fraga, McKesson executive VP, chief information officer and chief technology officer, said in a Saturday statement.
Do you have any idea what this means? I don’t. Of course they are worried about the future lawsuits, but this statement is not very helpful.
Neither company answered questions from the media.
According to the crooks, the stolen McKesson data includes:
“patients’ full names, home and email addresses, phone numbers, dates of birth, Social Security numbers, appointment dates and notes, and sensitive illness details including cancer locations on people’s bodies. The group also claims to have swiped emails containing private information from doctors to patients.”
The company says they are still shipping products. That is important; after all, what is important is their revenue. That will allow them to pay the lawyers who will defend then in the future lawsuits over the breach.
More interestingly, the company says that they have REASONABLE ASSURANCE that the intruders have been kicked out.
Credit: The Register and The Record
