Cybersecurity
Published on
09.04.2021

Cybersecurity: how can hospitals defend themselves?

Peter Knight

Quick reply

Dax, Villefranche-sur-Saône, AP-HP: why hospitals became prime targets, and what outsourced hosting changes for their patient data.

In this article

In February 2021, the ordeal suffered by several French hospitals was on everyone's lips: following a cyberattack, their entire management system was frozen. Experts and newspapers picked the story apart from every angle and tried to make sense of it. The victims, for their part, were understandably thrown. Within a matter of days, the hospitals in Dax and Villefranche-sur-Saône were held hostage remotely. The hospitals of the Dordogne came within hours of the same fate. The situation put every other hospital in the country on alert.

Cyberattacks are a growing scourge, made worse by how fast new technology is evolving. They now appear to have taken aim at hospitals, left vulnerable by the health crisis. It is therefore urgent that hospitals put cybersecurity tools in place to protect themselves.

healthcare ebook

Cyberattacks on hospitals in France

During the night of Monday 8 to Tuesday 9 February 2021, Dax hospital fell victim to a cyberattack that paralysed its servers. The attackers used ransomware to infiltrate the hospital's network and block its operations. Ransomware is malicious software that does not destroy files but blocks or encrypts them, making them unusable. That is exactly what happened to hundreds of patient files at Dax hospital.

Having done so, the attackers demanded a ransom in exchange for decrypting the files. The direct consequence was that staff could not reach patient records. Some operations under way had to be suspended and postponed, while the most important were simply handed to another facility. Patients could not receive prescriptions or take their medication, because access to their records was simply barred.

The day after that major attack, an intrusion attempt was thwarted at a hospital group in the Dordogne. The same method was used, but this time the IT provider detected the encryption software in time, before it could attack the files, which were therefore kept safe. Villefranche-sur-Saône was not so lucky. On Monday 15 February 2021, its hospital, along with the sites at Tarare and Trévoux, met the same fate as Dax. The RYUK crypto-virus caused all the damage that followed. Staff went back to pen and paper and procedures were postponed.

These attacks are the most recent, but they are far from the only ones. On Sunday 22 March 2020, the Paris public hospital system (AP-HP) was also attacked and paralysed. The attackers generated a large number of connections simultaneously, overloading the servers for around an hour. According to many experts, a manoeuvre like that is a sign of attacks to come. And well before AP-HP, in 2019, Rouen university hospital had also been targeted. There is no denying that cyberattacks against hospitals and healthcare facilities are going strong, and nothing suggests they are about to stop.

How hospitals can defend themselves against cyberattacks

Why are French hospitals being targeted?

Attackers looking to profit think about their targets in two ways. First, they look for targets that can be hacked easily, either because the system is weak or because the people using it are poorly informed. Second, they assess whether the target is able to pay the ransom. Targets have to have the means to pay, and no other option but to pay.

Since the health crisis arrived, French hospitals have been more vulnerable than ever. To begin with, the security measures they have are not sufficient. Digital tools are generally not maintained, and staff trained in medicine rather than IT do not always have the right instincts. The Covid-19 crisis made an already poor situation worse. Since 1 November 2020, a 45% rise in cyberattacks against hospitals has been recorded in Europe, against 22% in other sectors.

During the crisis, hospitals became more vulnerable than usual. Staff under pressure, because of the influx of infected patients, had little time to worry about cybersecurity. The attackers' first condition for choosing a target was therefore met. Beyond that, hospitals cannot afford to be shut down at a time when hundreds of people need care. They are therefore likely to give in easily to the attackers' demands and pay the ransom in order to reach the records of the patients they are treating (knowing full well that nothing guarantees the attackers will restore access to the data). Second condition met. French hospitals therefore make a prime target in a pandemic.

Hospitals can protect themselves from these attacks with NetExplorer

Hospitals have to find a secure way of using digital tools at such a delicate time, without fearing for the sensitive data passing through them. Outsourced hosting is the best answer. It guarantees the integrity, the sovereignty and the security of the data. If local servers are hacked, the attackers can neither seize the data nor block it, because it is not there.

NetExplorer offers a secure solution that lets every healthcare facility protect its files from any misuse. It centralises the facility's files on a single platform so they can be kept more secure. NetExplorer is HDS certified (Health Data Hosting). On that basis, we are authorised to store and process all personal health data. We carry out every task incumbent on a host to a high standard, and we use data centres that are all based in France and secured.

The NetExplorer solution also lets the various healthcare departments share patient records, or any other file belonging to the hospital or facility, in complete confidence, without worrying about their format or their size. Most importantly, access is secured, which keeps intruders out.

Try NetExplorer free for 7 days and see how to protect your health data

No items found.
No items found.

Definition

No items found.

FAQ

No questions found.

Best practices / Common pitfalls

No items found.

Key figures

No items found.

Key takeaways

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

You could keep all your documents on a floppy disk.
Vintage office chair with a pile of folders and a beige corded telephone, handset off the hook on red carpet.

But let's be honest, our cloud-based file storage and sharing solution is much easier.