Economic Impact of a Hospital Cyberattack in a National Health System: Descriptive Case Study

被引:4
|
作者
Portela, Diana [1 ,2 ,5 ]
Nogueira-Leite, Diogo [1 ,2 ,3 ,4 ]
Almeida, Rafael [1 ,4 ]
Cruz-Correia, Ricardo [1 ,2 ,4 ]
机构
[1] Univ Porto, Fac Med, Dept Community Med Informat & Hlth Decis Sci MEDCI, Porto, Portugal
[2] Univ Porto, Fac Med, Doctoral Programme Hlth Data Sci HEADS, Porto, Portugal
[3] Univ Nova Lisboa, Hlth Econ Management Knowledge Ctr, Nova Sch Business & Econ, Lisbon, Portugal
[4] eMAIS Movimento Assoc Sistemas Informacao Saude, Porto, Portugal
[5] Univ Porto, Dept Community Med Informat & Hlth Decis Sci MEDCI, Fac Med, Rua Dr Placido da Costa, P-4200450 Porto, Portugal
关键词
cybersecurity; medical informatics; economic impact; economic; cost; security; privacy; cyberattack; data breach; health system;
D O I
10.2196/41738
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
Background: Over the last decade, the frequency and size of cyberattacks in the health care industry have increased, ranging from breaches of processes or networks to encryption of files that restrict access to data. These attacks may have multiple consequences for patient safety, as they can, for example, target electronic health records, access to critical information, and support for critical systems, thereby causing delays in hospital activities. The effects of cybersecurity breaches are not only a threat to patients' lives but also have financial consequences due to causing inactivity in health care systems. However, publicly available information on these incidents quantifying their impact is scarce.Objective: We aim, while using public domain data from Portugal, to (1) identify data breaches in the public national health system since 2017 and (2) measure the economic impact using a hypothesized scenario as a case study.Methods: We retrieved data from multiple national and local media sources on cybersecurity from 2017 until 2022 and built a timeline of attacks. In the absence of public information on cyberattacks, reported drops in activity were estimated using a hypothesized scenario for affected resources and percentages and duration of inactivity. Only direct costs were considered for estimates. Data for estimates were produced based on planned activity through the hospital contract program. We use sensitivity analysis to illustrate how a midlevel ransomware attack might impact health institutions' daily costs (inferring a potential range of values based on assumptions). Given the heterogeneity of our included parameters, we also provide a tool for users to distinguish such impacts of different attacks on institutions according to different contract programs, served population size, and proportion of inactivity. Results: From 2017 to 2022, we were able to identify 6 incidents in Portuguese public hospitals using public domain data (there was 1 incident each year and 2 in 2018). Financial impacts were obtained from a cost point of view, where estimated values have a minimum-to-maximum range of euro115,882.96 to euro2,317,659.11 (a currency exchange rate of euro1=US $1.0233 is applicable). Costs of this range and magnitude were inferred assuming different percentages of affected resources and with different numbers of working days while considering the costs of external consultation, hospitalization, and use of in-and outpatient clinics and emergency rooms, for a maximum of 5 working days.Conclusions: To enhance cybersecurity capabilities at hospitals, it is important to provide robust information to support decision-making. Our study provides valuable information and preliminary insights that can help health care organizations better understand the costs and risks associated with cyber threats and improve their cybersecurity strategies. Additionally, it demonstrates the importance of adopting effective preventive and reactive strategies, such as contingency plans, as well as enhanced investment in improving cybersecurity capabilities in this critical area while aiming to achieve cyber-resilience.
引用
收藏
页数:7
相关论文
共 50 条
  • [41] IMPACT OF BACTERAEMIA ON HAEMODIALYSIS PATIENTS: A DESCRIPTIVE STUDY IN PENINSULA HEALTH
    Rao, N.
    Lau, W.
    Wong, K.
    Venkataraman, V.
    NEPHROLOGY, 2020, 25 : 71 - 72
  • [42] Stroke Lotto: Socio-economic and health system factors that impact on stroke rehabilitation and recovery in Australia -a case study
    Davey, Julie
    INTERNATIONAL JOURNAL OF STROKE, 2019, 14 : 19 - 19
  • [43] Modelling National Economic System: A Case of the Croatian Economy
    Sovilj, Sinisa
    Tkalec, Marina
    Pripuzic, Dominik
    Kostanjcar, Zvonko
    SOUTH EAST EUROPEAN JOURNAL OF ECONOMICS AND BUSINESS, 2023, 18 (01) : 115 - 144
  • [44] Hospital discharge statistics from public hospital of the National Health System, 2003
    不详
    SALUD PUBLICA DE MEXICO, 2004, 46 (05): : 464 - 487
  • [45] The Impacts of the Hierarchical Medical System on National Health Insurance on the Resident's Health Seeking Behavior in Taiwan: A Case Study on the Policy to Reduce Hospital Visits
    Yan, Yu-Hua
    Kung, Chih-Ming
    Yeh, Horng-Ming
    INTERNATIONAL JOURNAL OF ENVIRONMENTAL RESEARCH AND PUBLIC HEALTH, 2019, 16 (17)
  • [46] Hospital discharge statistics from public hospital of the National Health System, 2000
    不详
    SALUD PUBLICA DE MEXICO, 2002, 44 (02): : 158 - 187
  • [47] Resource elements of the national blue economic system and their development mechanisms: a case study of China
    Qi, Xiaofei
    FRONTIERS IN MARINE SCIENCE, 2025, 12
  • [48] Association between cognitive health and masticatory conditions: a descriptive study of the national database of the universal healthcare system in Japan
    Da Silva, John D.
    Ni, Shy Chwen
    Lee, Cliff
    Elani, Hawazin
    Ho, Kailing
    Thomas, Carlos
    Kuwajima, Yukinori
    Ishida, Yoshiki
    Kobayashi, Takuya
    Ishikawa-Nagai, Shigemi
    AGING-US, 2021, 13 (06): : 7943 - 7952
  • [49] Bariatric surgeries performed by the Brazilian National Health System in the period 2010-2016: a descriptive study of hospitalizations
    Carvalho, Adriane da Silva
    Rosa, Roger dos Santos
    EPIDEMIOLOGIA E SERVICOS DE SAUDE, 2019, 28 (01): : e2018260
  • [50] Impacts of economic sanctions on population health and health system: a study at national and sub-national levels from 2000 to 2020 in Iran
    Mohamadi, Efat
    Kraemer, Alexander
    Majdzadeh, Reza
    Mohamadzade, Morteza
    Mohammadshahi, Marita
    Kiani, Mohammad Mehdi
    Ebrahimi, Fatemeh
    Mostafavi, Hakimeh
    Olyaeemanesh, Alireza
    Takian, Amirhossein
    GLOBALIZATION AND HEALTH, 2024, 20 (01)