On October 29, 2020, the Office of Civil Rights (“OCR”) of the Department of Health and Human Services (“HHS”) announced that pursuant to credible information by HHS, the FBI, and the Cybersecurity and Infrastructure Security Agency (CISA), hospitals and healthcare providers are at an imminent risk of a cybersecurity attack. As a response to this looming threat, law enforcement is advising healthcare entities to implement best practices to avoid a cyberattack.
Specifically, CISA, HHA, and the FBI are predicting ransomware attacks. Ransomware is a type of malicious software that denies users access to targeted data. Hackers encrypt the data and hold it hostage until a random is paid. If the ransom is not paid, the hackers will permanently destroy all the data. Unfortunately for healthcare providers, the Department of Treasury recently announced that any entity that pays a ransom to get their data returned will be in violation of the International Emergency Economic Powers Act and will thus be subject to paying steep civil monetary penalties, not to exceed $250,000.
This puts providers in a precarious position, so CISA, the FBI, and HHS have come out with various references and guides to help prevent healthcare providers’ systems from being susceptible to a ransomware attack in the first place. Some of these preventive measures include: regularly backing up data, keeping data backups offline from the network, regularly changing passwords and avoid using the same password for different accounts, using two-step verification where available, regularly updating operating systems as soon as updates are available, and always having antivirus and anti-malware programs regularly scanning and updating.