Economic Impact of a Hospital Cyberattack in a National Health System: Descriptive Case Study

被引:4
|
作者
Portela, Diana [1 ,2 ,5 ]
Nogueira-Leite, Diogo [1 ,2 ,3 ,4 ]
Almeida, Rafael [1 ,4 ]
Cruz-Correia, Ricardo [1 ,2 ,4 ]
机构
[1] Univ Porto, Fac Med, Dept Community Med Informat & Hlth Decis Sci MEDCI, Porto, Portugal
[2] Univ Porto, Fac Med, Doctoral Programme Hlth Data Sci HEADS, Porto, Portugal
[3] Univ Nova Lisboa, Hlth Econ Management Knowledge Ctr, Nova Sch Business & Econ, Lisbon, Portugal
[4] eMAIS Movimento Assoc Sistemas Informacao Saude, Porto, Portugal
[5] Univ Porto, Dept Community Med Informat & Hlth Decis Sci MEDCI, Fac Med, Rua Dr Placido da Costa, P-4200450 Porto, Portugal
关键词
cybersecurity; medical informatics; economic impact; economic; cost; security; privacy; cyberattack; data breach; health system;
D O I
10.2196/41738
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
Background: Over the last decade, the frequency and size of cyberattacks in the health care industry have increased, ranging from breaches of processes or networks to encryption of files that restrict access to data. These attacks may have multiple consequences for patient safety, as they can, for example, target electronic health records, access to critical information, and support for critical systems, thereby causing delays in hospital activities. The effects of cybersecurity breaches are not only a threat to patients' lives but also have financial consequences due to causing inactivity in health care systems. However, publicly available information on these incidents quantifying their impact is scarce.Objective: We aim, while using public domain data from Portugal, to (1) identify data breaches in the public national health system since 2017 and (2) measure the economic impact using a hypothesized scenario as a case study.Methods: We retrieved data from multiple national and local media sources on cybersecurity from 2017 until 2022 and built a timeline of attacks. In the absence of public information on cyberattacks, reported drops in activity were estimated using a hypothesized scenario for affected resources and percentages and duration of inactivity. Only direct costs were considered for estimates. Data for estimates were produced based on planned activity through the hospital contract program. We use sensitivity analysis to illustrate how a midlevel ransomware attack might impact health institutions' daily costs (inferring a potential range of values based on assumptions). Given the heterogeneity of our included parameters, we also provide a tool for users to distinguish such impacts of different attacks on institutions according to different contract programs, served population size, and proportion of inactivity. Results: From 2017 to 2022, we were able to identify 6 incidents in Portuguese public hospitals using public domain data (there was 1 incident each year and 2 in 2018). Financial impacts were obtained from a cost point of view, where estimated values have a minimum-to-maximum range of euro115,882.96 to euro2,317,659.11 (a currency exchange rate of euro1=US $1.0233 is applicable). Costs of this range and magnitude were inferred assuming different percentages of affected resources and with different numbers of working days while considering the costs of external consultation, hospitalization, and use of in-and outpatient clinics and emergency rooms, for a maximum of 5 working days.Conclusions: To enhance cybersecurity capabilities at hospitals, it is important to provide robust information to support decision-making. Our study provides valuable information and preliminary insights that can help health care organizations better understand the costs and risks associated with cyber threats and improve their cybersecurity strategies. Additionally, it demonstrates the importance of adopting effective preventive and reactive strategies, such as contingency plans, as well as enhanced investment in improving cybersecurity capabilities in this critical area while aiming to achieve cyber-resilience.
引用
收藏
页数:7
相关论文
共 50 条
  • [1] The Greek economic crisis and its impact on the national health system
    Karamanis, Kostas
    Kolias, Georgios
    Triarchi, Eirini
    Malescou, Christina
    MANAGEMENT & MARKETING, 2024, 19 (01) : 73 - 92
  • [2] National hospital mortality surveillance system: a descriptive analysis
    Cecil, Elizabeth
    Wilkinson, Samantha
    Bottle, Alex
    Esmail, Aneez
    Vincent, Charles
    Aylin, Paul P.
    BMJ QUALITY & SAFETY, 2018, 27 (12) : 974 - 981
  • [3] Postpartum hemorrhage in Suriname: A national descriptive study of hospital births and an audit of case management
    Kodan, Lachmi R.
    Verschueren, Kim J. C.
    Prust, Zita D.
    Zuithoff, Nicolaas P. A.
    Rijken, Marcus J.
    Browne, Joyce L.
    Klipstein-Grobusch, Kerstin
    Bloemenkamp, Kitty W. M.
    Grunberg, Antoon W.
    PLOS ONE, 2020, 15 (12):
  • [4] Descriptive analysis of hospital activity indicators published by the Autonomous Regional Governments in the Spanish National Health System
    Garcia-Vicente, Sergio
    de Ramon-Frias, Rosa
    Angel Manez-Ortiz, Miguel
    REVISTA ESPANOLA DE SALUD PUBLICA, 2022, 96
  • [5] Economic crisis and national health system
    Martin Martin, Jose Jesus
    CUADERNOS DE RELACIONES LABORALES, 2016, 34 (02) : 315 - 334
  • [6] Economic impact of clinical pharmacy unit in a pediatric hospital in the public health system
    Barraza, Marlon F.
    Garcia, Patricio
    Morales, Jorge
    Azocar, Manuel
    Lobos, Carolina
    Teresa Droguett, Maria
    Jesus Henriquez, Maria
    INTERNATIONAL JOURNAL OF CLINICAL PHARMACY, 2017, 39 (01) : 271 - 271
  • [7] The Economic Impact of Hurricane Evacuations on a Coastal Georgia Hospital: A Case Study
    Desai, Samir P.
    Gordon, Jimmy
    Harris, Curtis Andrew
    FRONTIERS IN PUBLIC HEALTH, 2019, 7
  • [8] Clinical usefulness and economic implications of continuation/maintenance electroconvulsive therapy in a Spanish National Health System public hospital: A case series
    Rodriguez-Jimenez, Roberto
    Bagney, Alexandra
    Torio, Iosune
    Caballero, Montserrat
    Ruiz, Pedro
    Jose Rivas, Francisco de Paula
    Angel Jimenez-Arriero, Miguel
    REVISTA DE PSIQUIATRIA Y SALUD MENTAL, 2015, 8 (02): : 75 - 82
  • [9] The evolution of the national licensing system of health care professionals: a qualitative descriptive case study in Lao People’s Democratic Republic
    Miwa Sonoda
    Bounkong Syhavong
    Chanphomma Vongsamphanh
    Phisith Phoutsavath
    Phengdy Inthapanith
    Arie Rotem
    Noriko Fujita
    Human Resources for Health, 15
  • [10] The evolution of the national licensing system of health care professionals: a qualitative descriptive case study in Lao People's Democratic Republic
    Sonoda, Miwa
    Syhavong, Bounkong
    Vongsamphanh, Chanphomma
    Phoutsavath, Phisith
    Inthapanith, Phengdy
    Rotem, Arie
    Fujita, Noriko
    HUMAN RESOURCES FOR HEALTH, 2017, 15