Agora on cybersecurity in healthcare facilities

By Charles Cardine
Published on 24/10/2023
Agora on cybersecurity in healthcare facilities

They are the worst nightmare of healthcare facilities. Cyberattacks are multiplying and hitting healthcare organizations hard, as their data is so lucrative. To combat them, teams are mobilizing, security measures are being deployed, and organizations and mindsets are changing. They were at the heart of the forum held at Healthcare Week Luxembourg on September 21st. This event was organized by SIH Solutions magazine. Here are some of the topics discussed by our guests.

An End-to-End Chain

In April 2022, the Grand Est region was severely impacted by a cyberattack. Taking advantage of a vulnerability in one of the firewalls, a hacker infiltrated the Information System connecting the eight facilities of the Coeur Grand Est Hospital Group. Administrative data was then leaked on the dark web. In response, internet access was cut off to stop the attack. The result: a degraded emergency service, impacted payroll, messaging, and treasury systems, and out-of-service monitoring probes… “Nearly 18 months later, we are still in the remediation phase,” notes a dismayed Nadia Foubet, CIO of the GHT (Groupement Hospitalier de Territoire – Territorial Hospital Group). This illustrates the scale of the incident. It should be noted that “the vital importance of our data makes healthcare facilities very attractive to hackers,” emphasizes Stéphane Barcik, CISO of Pulsy, the GRADeS (Groupement de Recherche et d’Action de Sécurité – Regional Group for Research and Development in Healthcare) of the Grand Est region. “Fraud, identity theft, information for the insurance or banking sectors, and even for research… Data can have multiple uses,” underlines Jérôme Gauthier, CISO at the Luxembourg eHealth Agency. And yet, in Luxembourg, no major attacks have been reported in healthcare facilities. While various factors are involved, the dedication of the teams seems to partly explain this situation. “Each of our facilities has a dedicated Information Security Officer (ISSO) team and a Security Operations (SOC) team,” explains Jérôme Gauthier. “Their members come from the world of penetration testing and therefore have extensive experience with attacks. Their involvement is very strong and permeates all levels of the facility. Management, healthcare professionals, technicians… Everyone is fully engaged.” Stéphane Barcik agrees. “Cybersecurity is everyone’s business. It’s a real chain. It risks breaking where there’s a weak link.” That’s why it’s essential that information flows freely and that training is adequate.

Training, Recovery, and Remediation

For manufacturers, security is obviously a top priority. All filters and barriers are deployed to combat attacks. But if attacks do occur, knowing how to react is just as crucial. “A hospital is there to save lives,” insists Emmanuel Canes, Healthcare Field Director EMEA at Dell Technologies. “In the event of an attack, professionals must be able to quickly access a restored and healthy workstation.” The issue of data restoration is therefore just as much a part of the problem and must receive the same level of planning as protection. This is essential for maintaining hospital operations. And it is also during this phase that certain questions must be addressed. According to Nadia Foubet, “During an attack, it’s worth considering whether to rebuild an information system that is 10 or 15 years old exactly as it was, or to immediately allocate resources to opt for a more recent, more resilient, and more convergent structure.” Budgets must therefore be allocated. This is an area where Emmanuel Canes finds a weakness in France. “Budgets are too low, averaging around 1.6%.” Luxembourg, on the other hand, has a higher level of digital maturity, with budgets representing more than 2% of healthcare facilities’ budgets. Jérôme Gauthier drives the point home: “In Luxembourg, money isn’t an issue when it comes to cybersecurity. When a project is identified as necessary to protect our systems, the resources are allocated for its implementation.” It’s crucial to understand that major institutional projects cannot be undertaken without defining the security framework that will support them and the associated costs. This is the opinion of Philippe Mayer, CEO of the GIP (Groupement d’Intérêt Général) Okantis, which assists healthcare facilities in improving their information systems. “Facilities cannot embark on major projects involving patient records, convergence, or community-hospital communication without determining how they will achieve their security goals. It’s like installing a masterpiece painting in your home without having a door.” It is essential to conduct a thorough assessment of your cybersecurity before anything else. And this requires a significant budget that should not be overlooked. “The second area of focus for us revolves around the detection of and response to attacks,” notes Nadia Foubet. “This involves implementing monitoring tools, but also addressing the issue of human resources and available time.” And this is indeed the crux of the matter. In the healthcare sector, recruitment often proves challenging. A shortage of expert profiles, salary demands that are too high for public institutions… They often struggle to expand their teams. Beyond recruitment, training is also a key area that everyone emphasizes. Many cyberattacks are linked to misuse and can easily be thwarted by reinforcing best practices. This vigilance can be achieved through a quality approach to training. This is all the more important because, without prevention and in the face of urgent care, inappropriate actions are possible. As we can see, while the identified courses of action are shared by all, the realities are quite diverse. This variety greatly enriched the debate of September 21st.

Marion BOIS

[pdf-embedder url=“https://www.sih-solutions.fr/wp-content/uploads/2023/10/014SIHMAG_v02.pdf” title=“SIH Solutions Magazine”]