{"id":7698,"date":"2024-01-01T20:53:12","date_gmt":"2024-01-02T01:53:12","guid":{"rendered":"https:\/\/www.appliedpolicy.com\/staging\/7403\/?p=7698"},"modified":"2024-12-05T12:57:30","modified_gmt":"2024-12-05T17:57:30","slug":"ransomware-in-healthcare","status":"publish","type":"post","link":"https:\/\/www.appliedpolicy.com\/staging\/7403\/ransomware-in-healthcare\/","title":{"rendered":"Ransomware in Healthcare"},"content":{"rendered":"<p>[vc_row full_width=&#8221;stretch_row&#8221; gap=&#8221;35&#8243;][vc_column][vc_column_text]<\/p>\n<p style=\"font-weight: 400;\">On Thanksgiving Day, 2023, Ardent Health Services, which owns and operates 30 hospitals and over 200 sites of care in six states, recognized that it was the victim of a ransomware attack. In <a href=\"https:\/\/ardenthealth.com\/cybersecurityincident\">response<\/a>, the organization \u201cproactively took its network offline, suspending all user access to its information technology applications, including corporate servers, Epic software, internet and clinical programs.\u201d<\/p>\n<p style=\"font-weight: 400;\">Essentially deprived of the technologies that have become the lifeblood of modern healthcare systems, Ardent-affiliated hospitals scrambled to cope. Emergency rooms went to divert status and some non-emergent, elective procedures were temporarily postponed. Staff at one hospital described working without access to electronic health records as \u201c<a href=\"https:\/\/www.koat.com\/article\/lovelace-hospitals-network-outage-chaos\/45965312\">chaotic<\/a>.&#8221; Not able to use\u00a0Epic\u2019s My Chart system, patients had to find <a href=\"https:\/\/www.abqjournal.com\/business\/lovelace-patients-struggle-to-refill-prescriptions-contact-staff-following-cyberattack-on-health-system\/article_e64c87f2-9095-11ee-804d-e7afb0addd2a.html\">workarounds<\/a> to obtain prescription refills.<\/p>\n<h3 style=\"font-weight: 400;\"><strong>A growing problem<\/strong><\/h3>\n<p style=\"font-weight: 400;\">The Ardent case was just one of <a href=\"https:\/\/www.chiefhealthcareexecutive.com\/view\/health-data-cyberattacks-have-affected-more-than-100-million-people-in-2023\">hundreds<\/a> of cyberattacks on healthcare reported in 2023 and the associated ransom demand\u2014the specifics of which remain unknown\u2014is emblematic of a growing problem for the healthcare sector.<\/p>\n<p style=\"font-weight: 400;\">In the decades since <a href=\"https:\/\/www.cnn.com\/2021\/05\/16\/tech\/ransomware-joseph-popp\/index.html\">the first<\/a> ransomware attack was delivered to AIDS researchers on floppy discs in 1989, cyberattacks in general and ransomware attacks in particular have grown in both sophistication and cost. The healthcare sector, which <a href=\"https:\/\/www.bea.gov\/news\/blog\/2023-09-25\/experimental-data-map-health-care-estimates-gdp-centers-medicare-medicaid\">represents<\/a> nearly a fifth of the U.S. economy and is replete with protected health information (PHI) and personally identifiable information (PII), remains a favorite target among cybercriminals. In 2022, healthcare remained the primary target for critical infrastructure attacks, suffering nearly 25% of all ransomware incidents.<\/p>\n<p style=\"font-weight: 400;\">According to the American Hospital Association (AHA), there was a \u201cdramatic <a href=\"https:\/\/www.aha.org\/guidesreports\/2018-06-15-cybersecurity-and-risk-advisory-services\">increase<\/a> in cyberattacks targeting hospitals and health systems\u201d during the COVID-19 pandemic. As cybercriminals increasingly target small and rural hospitals, which generally have weaker defense systems, the average recovery duration has become longer.<\/p>\n<p style=\"font-weight: 400;\">It isn\u2019t just hospitals. As researchers raced to develop vaccines and treatments for COVID-19 in 2020, hackers <a href=\"https:\/\/www.cnn.com\/2020\/11\/27\/asia\/north-korea-astrazeneca-suspected-cyberattack-intl\/index.html\">presumed<\/a> to be associated with North Korea attempted to breach the information systems of global pharmaceutical company AstraZeneca. Drug development and research were further threatened when eResearchTechnology (ERT), which develops software used in clinical trials, <a href=\"https:\/\/www.nytimes.com\/2020\/10\/03\/technology\/clinical-trials-ransomware-attack-drugmakers.html\">was hit<\/a> by a ransomware attack in 2021.<\/p>\n<p style=\"font-weight: 400;\">In 2023, several large pharmaceutical companies reported ransomware attacks. In March, Sun Pharmaceuticals of Mumbai <a href=\"https:\/\/www.bseindia.com\/xml-data\/corpfiling\/AttachHis\/91ff7cd7-b616-435c-b978-595dbd9368cf.pdf\">alerted<\/a> the National Stock Exchange of India to \u201ca breach of certain file systems and the theft of certain company data and personal data.\u201d Following this, Granules India\u00a0<a href=\"https:\/\/www.bseindia.com\/xml-data\/corpfiling\/AttachHis\/615df5e3-bf68-4cae-8116-df5cdc0116a7.pdf\">reported<\/a> an IT breach\u00a0for which the Russia-based <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-165a\">LockBIt<\/a> subsequently <a href=\"https:\/\/techcrunch.com\/2023\/06\/15\/lockbit-ransomware-granules-india\/\">claimed<\/a> responsibility. And, even as it celebrated the success of its Alzheimer\u2019s drug Leqembi last summer, Japan\u2019s Eisai <a href=\"https:\/\/www.eisai.com\/news\/2023\/news202341.html\">acknowledged<\/a> an attack on \u201csome\u201d of its servers.<\/p>\n<p style=\"font-weight: 400;\">According to IBM Security\u2019s <a href=\"https:\/\/www.ibm.com\/downloads\/cas\/E3G5JMBP\" target=\"_blank\" rel=\"noopener\" data-auth=\"NotApplicable\" data-linkindex=\"8\">report<\/a>, the average data breach in the healthcare sector costs $10.93 million\u2014one and a half times the cost of a breach in 2020.<\/p>\n<p style=\"font-weight: 400;\">But the damage isn\u2019t only monetary.<\/p>\n<p style=\"font-weight: 400;\">In Germany, a delay in care after a ransomware attack on D\u00fcsseldorf University Hospital <a href=\"https:\/\/www.healthcareitnews.com\/news\/hospital-ransomware-attack-leads-fatality-after-causing-delay-care\">resulted<\/a> in a patient\u2019s death. Additional research in the United States indicates that ransomware attacks were responsible for between 42 to 67 Medicare patients&#8217; deaths between 2016 and 2021.<\/p>\n<p style=\"font-weight: 400;\">In a cybersecurity <a href=\"https:\/\/www.aha.org\/advisory\/2023-11-15-new-ransomware-threat-rhysida-group-targets-hospitals-puts-patient-safety-risk\">advisory<\/a> issued in November, JRiggi, AHA\u2019s National Advisor for Cybersecurity and Risk stated, \u201cRansomware attacks against hospitals are not financial crimes; they are acts of cyber terrorism and threat-to-life crimes.\u201d<\/p>\n<h3 style=\"font-weight: 400;\"><strong>The process<\/strong><\/h3>\n<p style=\"font-weight: 400;\">Cyberattacks typically begin with <a href=\"https:\/\/consumer.ftc.gov\/articles\/how-recognize-remove-avoid-malware\">malware<\/a>, or malicious software. This may take one of several forms, notably Trojans or worms.<\/p>\n<p style=\"font-weight: 400;\">Trojans, named after the Greek Trojan Horse, are represented to users as benign downloads or legitimate software. Users are tricked into loading and executing the Trojan on their computers, resulting in unauthorized access to their system. Trojans do not replicate themselves, which means they require user interaction to be installed or spread to other systems. Trojans can serve as \u201cloaders\u201d for additional malware.<\/p>\n<p style=\"font-weight: 400;\">In contrast, a worm is a standalone malware program that replicates itself to spread to other computers. Unlike a Trojan, it does not need to attach itself to an existing program or rely on human action to propagate. Worms typically exploit vulnerabilities in operating systems or other software to spread across networks, causing widespread damage. While Trojans are more about deceptive entry at a single computer, worms are focused on rapid and autonomous propagation to infect as many devices as possible.<\/p>\n<p style=\"font-weight: 400;\">Ransomware is a specific type of malware that encrypts the victim&#8217;s files or locks the user out of their device and is accompanied by a ransom demand for the restoration of access. While malware\u2019s data breaches allow a hacker to immediately steal information from a system, the primary goal of ransomware is to extort money from its victims. Attackers typically demand payment in cryptocurrency in exchange for a key which will allow access to the encrypted data or locked system. A hacker may demonstrate the legitimacy of a key by unlocking a single file or process. If their demands are ignored, they may begin publishing stolen data on the internet to taunt a victim and raise the stakes.<\/p>\n<p style=\"font-weight: 400;\">The risk of ransomware attacks on healthcare organizations has been elevated by ransomware-as-a-service (<a href=\"https:\/\/www.ibm.com\/topics\/ransomware-as-a-service\">RaaS<\/a>), a model in which the creators or operators of ransomware make their malicious software available for use or purchase by other criminals, typically on the so-called dark web.<\/p>\n<p style=\"font-weight: 400;\">RaaS makes ransomware readily available to a wider pool of attackers, including those with limited technological skills. Providers of RaaS such as <a href=\"https:\/\/www.ic3.gov\/Media\/News\/2022\/220420.pdf\">BlackCat\/ALPHV<\/a>, a group which has long played a game of <a href=\"https:\/\/www.wired.com\/story\/alphv-blackcat-ransomware-doj-takedown\/\">cat-and-mouse<\/a> with the Federal Bureau of Investigation (FBI), offer a range of services beyond the ransomware itself. These may include support, payment processing, and even \u201ccustomer service\u201d to assist those using their products.<\/p>\n<h3 style=\"font-weight: 400;\"><strong>The perpetrators<\/strong><\/h3>\n<p style=\"font-weight: 400;\">While early cyberattacks followed a &#8220;spray and pray&#8221; model in which perpetrators rapidly and randomly distributed malicious code to numerous targets without specific selection criteria, today\u2019s cybercriminals are more precise in both their intentions and their targets. And, despite Hollywood stereotypes, they are generally not hobbyist hackers working from their parents\u2019 basements.<\/p>\n<p style=\"font-weight: 400;\">Modern cybercriminals are often nation-state actors or members of organized crime syndicates. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has <a href=\"https:\/\/www.cisa.gov\/topics\/cyber-threats-and-advisories\/advanced-persistent-threats-and-nation-state-actors\">identified<\/a> China, Russia, Iran, and North Korea as state sponsors of cybercrime.<\/p>\n<p style=\"font-weight: 400;\">As cyberattacks have become more sophisticated, their perpetrators have become more difficult to locate. One federal <a href=\"https:\/\/www.justice.gov\/media\/1313271\/dl?inline\">indictment<\/a> illustrates the challenge law enforcement faces in pinpointing cybercriminals\u2019 locations with its reference to its subjects\u2019 positions \u201cin or around Russia, Belarus, Ukraine, and elsewhere.\u201d<\/p>\n<p style=\"font-weight: 400;\">The indictment\u2019s reference to three countries once affiliated with the Soviet Union is neither unusual nor incidental. The Carnegie Endowment for International Peace has <a href=\"https:\/\/carnegieendowment.org\/2018\/02\/02\/why-russian-government-turns-blind-eye-to-cybercriminals-pub-75499\">observed<\/a> that the blind eye turned by some former Soviet states has allowed cybercriminals to operate within their borders with relative impunity.<\/p>\n<p style=\"font-weight: 400;\">This geographical concentration of cybercriminals in Eastern Europe means that sociopolitical developments in the region can impact cybercrime activity. For example, the Russian invasion of Ukraine prompted a Ukrainian researcher to <a href=\"https:\/\/www.wired.com\/story\/conti-leaks-ransomware-work-life\/\">leak<\/a> information related to the Russian based <a href=\"https:\/\/globalinitiative.net\/analysis\/conti-ransomware-group-cybercrime\/\">Conti gang<\/a>. And some cybersecurity experts have <a href=\"https:\/\/www.wired.com\/story\/ransomware-attacks-rise-2023\/\">attributed<\/a> a brief dip in ransomware crimes in 2022 to the conflict in Ukraine.<\/p>\n<h3 style=\"font-weight: 400;\"><strong>Advising law enforcement and paying ransom<\/strong><\/h3>\n<p style=\"font-weight: 400;\">The Department of Health and Human Services (HHS) advises any healthcare organization hit with a ransomware attack to contact its local FBI or United States Secret Service field office. While language in the ransomware might threaten consequences for contacting the police, IBM Security has <a href=\"https:\/\/www.ibm.com\/downloads\/cas\/E3G5JMBP\">found<\/a> that excluding law enforcement from resolution of a ransomware attack is likely to result in higher costs as well as longer breach lifecycles. Attackers may represent themselves as being the only path for decryption of files, but the FBI and other law enforcement agencies are often able to offer decryption <a href=\"https:\/\/www.justice.gov\/opa\/pr\/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant\">keys<\/a>.<\/p>\n<p style=\"font-weight: 400;\">Managing ransom demands can be fraught with pitfalls. While paying ransom is not illegal, federal agencies, including the FBI, CISA, and HHS, recommend against complying with ransom demands. Importantly, although paying ransom may not be a crime, engaging in financial transactions with any individual or entity\u00a0 on the U.S. Department of the Treasury\u2019s Office of Foreign Assets Control\u2019s (\u201cOFAC\u201d) <a href=\"https:\/\/ofac.treasury.gov\/ofac-sanctions-lists\">sanction lists<\/a> is.<\/p>\n<p style=\"font-weight: 400;\">And cybersecurity experts say that paying ransom doesn\u2019t guarantee protection from future attacks. One <a href=\"https:\/\/www.cbsnews.com\/news\/ransomware-victims-suffer-repeat-attacks-new-report\/\">study<\/a> found that 80% of organizations paying ransom were victims of subsequent attacks.<\/p>\n<h3 style=\"font-weight: 400;\"><strong>\u00a0<\/strong><strong>Insurance considerations<\/strong><\/h3>\n<p style=\"font-weight: 400;\">The increasing frequency of and growing costs associated with cyberattacks have made purchasing <a href=\"https:\/\/www.ftc.gov\/business-guidance\/small-businesses\/cybersecurity\/cyber-insurance\">cyber insurance<\/a> a requisite part of doing business. They have also made insurance companies more circumspect drafting policy language and extending coverage.<\/p>\n<div>\n<p>Some of the world&#8217;s best known insurance firms settled a multimillion-dollar dispute last week with biopharmaceutical giant Merck, which exemplifies the complications of cybercrimes.<\/p>\n<\/div>\n<p style=\"font-weight: 400;\">In 2017, Merck was one of dozens of companies impacted by the NotPetya malware attack. Launched by the Russian Main Intelligence Directorate (GRU) in <a href=\"https:\/\/www.washingtonpost.com\/world\/national-security\/russian-military-was-behind-notpetya-cyberattack-in-ukraine-cia-concludes\/2018\/01\/12\/048d8506-f7ca-11e7-b34a-b85626af34ef_story.html\">an effort<\/a> to disrupt Ukraine\u2019s financial system and cripple the country\u2019s infrastructure, NotPetya incorporated <a href=\"https:\/\/nordvpn.com\/blog\/what-is-eternalblue\/\">leaked code<\/a> from the U.S. National Security Administration.<\/p>\n<p style=\"font-weight: 400;\">Although NotPetya alerted victims that a decrypting key was available in exchange for a nominal bitcoin payment, the site associated with payment was easily <a href=\"https:\/\/www.theguardian.com\/technology\/2017\/jun\/28\/notpetya-ransomware-attack-ukraine-russia\">taken down<\/a>. In a world that depends upon misrepresentation, NotPetya was not even the ransomware it purported to be. It was pure malware. And it was alarmingly effective, eventually causing $10 billion damage worldwide.<\/p>\n<p style=\"font-weight: 400;\">Merck saw at least 40,000 computers in its global network infected by NotPetya. An astonishing <a href=\"https:\/\/www.njcourts.gov\/system\/files\/court-opinions\/2023\/a1879-21a1882-21.pdf\">one-quarter<\/a> of these were impacted within the first 90 seconds of exposure. The massive disruption to the company\u2019s manufacturing, research and development, and sales operations ultimately resulted in an estimated $1.4 billion in damages.<\/p>\n<p style=\"font-weight: 400;\">When Merck filed insurance claims under several \u201call risk\u201d property policies, its insurance companies denied payment citing \u201cHostile\/Warlike Action\u201d exclusions in their policies. Merck sued the insurers for payment. In December 2021, a court ruled in Merck\u2019s favor. A New Jersey appellate court also <a href=\"https:\/\/www.njcourts.gov\/system\/files\/court-opinions\/2023\/a1879-21a1882-21.pdf\">ruled<\/a> in Merck\u2019s favor in May 2023, noting that \u201cexclusion of damages caused by hostile or warlike action by a government or sovereign power in times of war or peace requires the involvement of military action.\u201d<\/p>\n<p style=\"font-weight: 400;\">The case was slated for review by the New Jersey Supreme Court last week when the parties announced a confidential settlement on January 3.<\/p>\n<p style=\"font-weight: 400;\">For insurers, the Merck case has been a cautionary tale highlighting how extraordinarily expensive cyberattacks can be. Many, including <a href=\"https:\/\/assets.lloyds.com\/media\/35926dc8-c885-497b-aed8-6d2f87c1415d\/Y5381%20Market%20Bulletin%20-%20Cyber-attack%20exclusions.pdf\">Lloyds of London<\/a>, have updated their policy language regarding cybercrime executed by state actors.<\/p>\n<p style=\"font-weight: 400;\">They have also increased their rates. Testifying before the Senate Homeland Security and Governmental Affairs Committee, Kate Pierce, the Senior Virtual Information Security Officer of Fortified Security, <a href=\"https:\/\/www.c-span.org\/video\/?526750-1\/hearing-cybersecurity-risks-health-care\">said<\/a> that \u201cskyrocketing premiums, lower limits, and increasing requirements\u201d were putting cyber insurance coverage out of the reach of many organizations, especially rural hospitals.<\/p>\n<h3 style=\"font-weight: 400;\"><strong>HIPAA concerns<\/strong><\/h3>\n<p style=\"font-weight: 400;\">The Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH) established standards for preventing and protocols for managing healthcare entities\u2019 breaches of PHI. But some <a href=\"https:\/\/jamanetwork.com\/journals\/jama-health-forum\/fullarticle\/2784981\">argue<\/a> that \u201cHIPAA\u2019s dual focus on privacy and security, which can create a misalignment of incentives\u201d in a changing digital landscape.<\/p>\n<p style=\"font-weight: 400;\">HHS <a href=\"https:\/\/www.hhs.gov\/sites\/default\/files\/RansomwareFactSheet.pdf\">specifies<\/a> that ransomware and malware attacks qualify as security incidents under HIPAA\u2019s Security Rule. If PHI is compromised as the result of a cyberattack, the incident may meet the threshold of a\u00a0 <a href=\"https:\/\/www.govinfo.gov\/content\/pkg\/CFR-2010-title45-vol1\/pdf\/CFR-2010-title45-vol1-sec164-402.pdf\">breach<\/a>, and healthcare organizations must comply with HIPAA\u2019s Breach Notification Rule. This would include notifying both HHS and impacted individuals, as well the media in cases affecting over 500 people.<\/p>\n<p style=\"font-weight: 400;\">Under the <a href=\"https:\/\/www.congress.gov\/bill\/116th-congress\/house-bill\/7898\/text\">HITECH Amendment<\/a>, which was signed into law in 2021, HHS \u201cmay reduce fines and penalties for violations of certain federal privacy standards for health information if an entity subject to those standards has adopted particular cybersecurity practices.\u201d<\/p>\n<p style=\"font-weight: 400;\">Section 405(d) of the Cybersecurity Information Sharing Act (CISA) of 2015 tasks HHS with the enhancing cybersecurity in the healthcare industry. This includes leading a public-private partnership to develop and regularly update practical, consensus-based cybersecurity guidelines and best practices. HHS\u2019s <a href=\"https:\/\/405d.hhs.gov\/\">405(d) Program<\/a> seeks to align the healthcare sector&#8217;s security strategies with the federal government&#8217;s broader cybersecurity approach, with <a href=\"https:\/\/www.dhs.gov\/\">input<\/a> from the Department of Homeland Security and threat hunting <a href=\"https:\/\/www.aha.org\/system\/files\/media\/file\/2022\/12\/nsa-apt5-citrix-adc-tlp-whitethreat-hunting-guidance-december-2022.pdf\">guidance<\/a> from the National Security Administration. This collaboration has produced the &#8220;Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients&#8221; (<a href=\"https:\/\/405d.hhs.gov\/Documents\/HICP-Main-508.pdf\">HICP)<\/a> publication, which offers a comprehensive framework for healthcare organizations to mitigate cyber threats.<\/p>\n<h3 style=\"font-weight: 400;\"><strong>Going forward<\/strong><\/h3>\n<p style=\"font-weight: 400;\">To succeed, enhancing cybersecurity in healthcare must be a shared responsibility involving government agencies, industry organizations, and individual companies and providers. Every member of the sector can benefit from standardized cybersecurity measures, financial support, and collaborative efforts.<\/p>\n<p style=\"font-weight: 400;\">Stirling Martin, the Chief Security and Privacy Officer and Vice President of <a href=\"https:\/\/www.epic.com\/\">Epic<\/a>, whose products include the patient portal <a href=\"https:\/\/mychart.org\/\">My Chart<\/a>, told the Senate Homeland Security and Governmental Affairs Committee that he <a href=\"https:\/\/www.c-span.org\/video\/?526750-1\/hearing-cybersecurity-risks-health-care\">believes<\/a> that the federal government should establish a minimum threshold for security best practices in healthcare. He also called for establishing a legal safe harbor for organizations that meet a defined benchmark of security.<\/p>\n<p style=\"font-weight: 400;\">Meeting minimum standards could be costly and would present an additional burden, especially for critical access and rural hospitals. Achieving a consistent standard of security in U.S. healthcare may require federal subsidies and rethinking\u00a0incentives \u2014 which could well be justified, given the stakes.<\/p>\n<p style=\"font-weight: 400;\">Ultimately, as HHS <a href=\"https:\/\/405d.hhs.gov\/post\/detail\/0472a552-daa8-42da-8aaa-b899495daece\">observes<\/a>, \u201ccyber safety is patient safety.\u201d<\/p>\n<p>[\/vc_column_text][\/vc_column][\/vc_row]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[vc_row full_width=&#8221;stretch_row&#8221; gap=&#8221;35&#8243;][vc_column][vc_column_text] On Thanksgiving Day, 2023, Ardent Health Services, which owns and operates 30 hospitals and over 200 sites of care in six states, recognized that it was the victim of a ransomware attack. In response, the organization \u201cproactively took its network offline, suspending all user access to its information technology applications, including corporate [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":7005,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"nf_dc_page":"","ap4_related_services":"","footnotes":""},"categories":[628],"tags":[],"class_list":["post-7698","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-medical-devices-and-technology"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Ransomware in Healthcare - Applied Policy<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.appliedpolicy.com\/ransomware-in-healthcare\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Ransomware in Healthcare - Applied Policy\" \/>\n<meta property=\"og:description\" content=\"[vc_row full_width=&#8221;stretch_row&#8221; gap=&#8221;35&#8243;][vc_column][vc_column_text] On Thanksgiving Day, 2023, Ardent Health Services, which owns and operates 30 hospitals and over 200 sites of care in six states, recognized that it was the victim of a ransomware attack. In response, the organization \u201cproactively took its network offline, suspending all user access to its information technology applications, including corporate [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.appliedpolicy.com\/ransomware-in-healthcare\/\" \/>\n<meta property=\"og:site_name\" content=\"Applied Policy\" \/>\n<meta property=\"article:published_time\" content=\"2024-01-02T01:53:12+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-12-05T17:57:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.appliedpolicy.com\/wp-content\/uploads\/iStock-1372095539.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1365\" \/>\n\t<meta property=\"og:image:height\" content=\"768\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Applied Policy\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Applied Policy\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.appliedpolicy.com\\\/ransomware-in-healthcare\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.appliedpolicy.com\\\/ransomware-in-healthcare\\\/\"},\"author\":{\"name\":\"Applied Policy\",\"@id\":\"https:\\\/\\\/appliedpolicy.com\\\/#\\\/schema\\\/person\\\/326364c9511f087d2d72266f52773a49\"},\"headline\":\"Ransomware in Healthcare\",\"datePublished\":\"2024-01-02T01:53:12+00:00\",\"dateModified\":\"2024-12-05T17:57:30+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.appliedpolicy.com\\\/ransomware-in-healthcare\\\/\"},\"wordCount\":2203,\"image\":{\"@id\":\"https:\\\/\\\/www.appliedpolicy.com\\\/ransomware-in-healthcare\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.appliedpolicy.com\\\/staging\\\/7403\\\/wp-content\\\/uploads\\\/iStock-1372095539.jpg\",\"articleSection\":[\"Medical Devices and Technology\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.appliedpolicy.com\\\/ransomware-in-healthcare\\\/\",\"url\":\"https:\\\/\\\/www.appliedpolicy.com\\\/ransomware-in-healthcare\\\/\",\"name\":\"Ransomware in Healthcare - Applied Policy\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/appliedpolicy.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.appliedpolicy.com\\\/ransomware-in-healthcare\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.appliedpolicy.com\\\/ransomware-in-healthcare\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.appliedpolicy.com\\\/staging\\\/7403\\\/wp-content\\\/uploads\\\/iStock-1372095539.jpg\",\"datePublished\":\"2024-01-02T01:53:12+00:00\",\"dateModified\":\"2024-12-05T17:57:30+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/appliedpolicy.com\\\/#\\\/schema\\\/person\\\/326364c9511f087d2d72266f52773a49\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.appliedpolicy.com\\\/ransomware-in-healthcare\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.appliedpolicy.com\\\/ransomware-in-healthcare\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.appliedpolicy.com\\\/ransomware-in-healthcare\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.appliedpolicy.com\\\/staging\\\/7403\\\/wp-content\\\/uploads\\\/iStock-1372095539.jpg\",\"contentUrl\":\"https:\\\/\\\/www.appliedpolicy.com\\\/staging\\\/7403\\\/wp-content\\\/uploads\\\/iStock-1372095539.jpg\",\"width\":1365,\"height\":768},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.appliedpolicy.com\\\/ransomware-in-healthcare\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/appliedpolicy.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Ransomware in Healthcare\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/appliedpolicy.com\\\/#website\",\"url\":\"https:\\\/\\\/appliedpolicy.com\\\/\",\"name\":\"Applied Policy\",\"description\":\"Health policy and reimbursement consulting\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/appliedpolicy.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/appliedpolicy.com\\\/#\\\/schema\\\/person\\\/326364c9511f087d2d72266f52773a49\",\"name\":\"Applied Policy\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.appliedpolicy.com\\\/staging\\\/7403\\\/wp-content\\\/uploads\\\/AP_Logo_icon_HiRes_rgb-1-300x300.jpg\",\"url\":\"https:\\\/\\\/www.appliedpolicy.com\\\/staging\\\/7403\\\/wp-content\\\/uploads\\\/AP_Logo_icon_HiRes_rgb-1-300x300.jpg\",\"contentUrl\":\"https:\\\/\\\/www.appliedpolicy.com\\\/staging\\\/7403\\\/wp-content\\\/uploads\\\/AP_Logo_icon_HiRes_rgb-1-300x300.jpg\",\"caption\":\"Applied Policy\"},\"url\":\"https:\\\/\\\/www.appliedpolicy.com\\\/staging\\\/7403\\\/author\\\/applied-policy-insight\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Ransomware in Healthcare - Applied Policy","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.appliedpolicy.com\/ransomware-in-healthcare\/","og_locale":"en_US","og_type":"article","og_title":"Ransomware in Healthcare - Applied Policy","og_description":"[vc_row full_width=&#8221;stretch_row&#8221; gap=&#8221;35&#8243;][vc_column][vc_column_text] On Thanksgiving Day, 2023, Ardent Health Services, which owns and operates 30 hospitals and over 200 sites of care in six states, recognized that it was the victim of a ransomware attack. In response, the organization \u201cproactively took its network offline, suspending all user access to its information technology applications, including corporate [&hellip;]","og_url":"https:\/\/www.appliedpolicy.com\/ransomware-in-healthcare\/","og_site_name":"Applied Policy","article_published_time":"2024-01-02T01:53:12+00:00","article_modified_time":"2024-12-05T17:57:30+00:00","og_image":[{"width":1365,"height":768,"url":"https:\/\/www.appliedpolicy.com\/wp-content\/uploads\/iStock-1372095539.jpg","type":"image\/jpeg"}],"author":"Applied Policy","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Applied Policy","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.appliedpolicy.com\/ransomware-in-healthcare\/#article","isPartOf":{"@id":"https:\/\/www.appliedpolicy.com\/ransomware-in-healthcare\/"},"author":{"name":"Applied Policy","@id":"https:\/\/appliedpolicy.com\/#\/schema\/person\/326364c9511f087d2d72266f52773a49"},"headline":"Ransomware in Healthcare","datePublished":"2024-01-02T01:53:12+00:00","dateModified":"2024-12-05T17:57:30+00:00","mainEntityOfPage":{"@id":"https:\/\/www.appliedpolicy.com\/ransomware-in-healthcare\/"},"wordCount":2203,"image":{"@id":"https:\/\/www.appliedpolicy.com\/ransomware-in-healthcare\/#primaryimage"},"thumbnailUrl":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-content\/uploads\/iStock-1372095539.jpg","articleSection":["Medical Devices and Technology"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.appliedpolicy.com\/ransomware-in-healthcare\/","url":"https:\/\/www.appliedpolicy.com\/ransomware-in-healthcare\/","name":"Ransomware in Healthcare - Applied Policy","isPartOf":{"@id":"https:\/\/appliedpolicy.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.appliedpolicy.com\/ransomware-in-healthcare\/#primaryimage"},"image":{"@id":"https:\/\/www.appliedpolicy.com\/ransomware-in-healthcare\/#primaryimage"},"thumbnailUrl":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-content\/uploads\/iStock-1372095539.jpg","datePublished":"2024-01-02T01:53:12+00:00","dateModified":"2024-12-05T17:57:30+00:00","author":{"@id":"https:\/\/appliedpolicy.com\/#\/schema\/person\/326364c9511f087d2d72266f52773a49"},"breadcrumb":{"@id":"https:\/\/www.appliedpolicy.com\/ransomware-in-healthcare\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.appliedpolicy.com\/ransomware-in-healthcare\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.appliedpolicy.com\/ransomware-in-healthcare\/#primaryimage","url":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-content\/uploads\/iStock-1372095539.jpg","contentUrl":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-content\/uploads\/iStock-1372095539.jpg","width":1365,"height":768},{"@type":"BreadcrumbList","@id":"https:\/\/www.appliedpolicy.com\/ransomware-in-healthcare\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/appliedpolicy.com\/"},{"@type":"ListItem","position":2,"name":"Ransomware in Healthcare"}]},{"@type":"WebSite","@id":"https:\/\/appliedpolicy.com\/#website","url":"https:\/\/appliedpolicy.com\/","name":"Applied Policy","description":"Health policy and reimbursement consulting","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/appliedpolicy.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/appliedpolicy.com\/#\/schema\/person\/326364c9511f087d2d72266f52773a49","name":"Applied Policy","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-content\/uploads\/AP_Logo_icon_HiRes_rgb-1-300x300.jpg","url":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-content\/uploads\/AP_Logo_icon_HiRes_rgb-1-300x300.jpg","contentUrl":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-content\/uploads\/AP_Logo_icon_HiRes_rgb-1-300x300.jpg","caption":"Applied Policy"},"url":"https:\/\/www.appliedpolicy.com\/staging\/7403\/author\/applied-policy-insight\/"}]}},"_links":{"self":[{"href":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-json\/wp\/v2\/posts\/7698","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-json\/wp\/v2\/comments?post=7698"}],"version-history":[{"count":7,"href":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-json\/wp\/v2\/posts\/7698\/revisions"}],"predecessor-version":[{"id":7712,"href":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-json\/wp\/v2\/posts\/7698\/revisions\/7712"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-json\/wp\/v2\/media\/7005"}],"wp:attachment":[{"href":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-json\/wp\/v2\/media?parent=7698"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-json\/wp\/v2\/categories?post=7698"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.appliedpolicy.com\/staging\/7403\/wp-json\/wp\/v2\/tags?post=7698"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}