top of page

The Call Is Coming from Inside the Hospital: A Healthcare Cybersecurity Nightmare

Few things are more frightening than a hospital at 2:00 a.m. The lights are low. The halls are quiet. The emergency department is still moving. Somewhere, a ventilator is alarming. A nurse is trying to access a patient's chart. The lab is waiting on an order.


Then the phone rings: “IT is having an issue.”


A few minutes later, someone reports that they cannot access the EHR. Then registration stops. Pharmacy cannot access medications. Radiology cannot retrieve images. The phones begin behaving strangely.


And then someone says the words every hospital emergency manager hopes never to hear from the IT department:


“I think we've been hacked.” (Cue the horror music.)


October is National Cybersecurity Awareness Month, making it the perfect time to look at cybersecurity from a perspective that goes beyond firewalls, passwords, and IT departments. For healthcare emergency managers, a cyberattack should be viewed as what it can become: A disaster.


Cyber incidents can create the same operational consequences as a fire, flood, severe weather event, or utility failure. The difference is that the cyberattack may not begin with smoke, sirens, or visible damage. Instead, systems quietly disappear one screen at a time.


And if your organization isn't prepared, you may find yourself starring in your own healthcare horror movie.


When the threat is already inside the house


The classic horror movie scenario is simple: someone is receiving threatening phone calls and eventually discovers that the threat is coming from inside the house. Cybersecurity has its own version of this nightmare.

The attacker may not need to break through the front door. A compromised credential, phishing email, vulnerable device, misconfigured system, or compromised third-party connection may provide a pathway into the organization.


From an emergency management perspective, the important question isn't simply:


“How do we keep them out?”


It is also:


“What happens if they're already inside?”


That is where incident response, downtime procedures, and business continuity planning become critical. If the EHR suddenly becomes unavailable:


  • Can clinical staff immediately transition to downtime procedures?

  • Can the organization continue medication administration?

  • Can the emergency department continue accepting patients?

  • Can providers access critical patient information?

  • Can laboratory and radiology services continue?

  • Can the hospital communicate internally and externally?


Cybersecurity is prevention. Emergency preparedness is what happens when prevention fails.


The Final Act: Your Disaster Recovery Plan


Every good horror movie eventually reaches the moment when the characters must answer the most important question: What are we going to do now? For hospitals, the answer should already exist in the emergency operations plan, business continuity plans, IT disaster recovery plans, and downtime procedures. But having a plan isn't enough. The plan needs to be tested.


HHS guidance emphasizes that healthcare organizations should maintain contingency and disaster recovery capabilities, back up critical information, and periodically test restoration capabilities. HHS also identifies basic incident planning and preparedness as an essential cybersecurity performance goal because cyber incidents can create patient-safety, business-continuity, and operational-downtime consequences. This is where exercises become incredibly valuable. A hospital doesn't necessarily need to simulate an elaborate Hollywood-style cyberattack.


Don't Let Your Cyber Plan Become a Horror Story


Cybersecurity is often viewed as a technical issue. But in healthcare, the consequences are operational, clinical, and organizational. A ransomware attack doesn't care whether your hospital's emergency preparedness program is accredited. It doesn't care whether your EOP has been sitting untouched on a shared drive for three years. And it certainly doesn't care whether you've ever tested your downtime procedures.


The good news is that hospitals already know how to prepare for disasters. You conduct hazard vulnerability assessments. You have developed emergency operations plans. You have an established Incident Command. You conduct exercises. You have already identified critical functions and developed continuity strategies. And, lastly, you have tested recovery.


Cybersecurity belongs in that same preparedness conversation.


So, this October, while everyone else is watching Halloween, The Exorcist, The Shining, or A Nightmare on Elm Street, emergency managers might want to watch something even scarier: What happens when the EHR goes down?


Because the scariest cyberattack isn't the one that makes the news. It's the one your organization wasn't prepared to manage. Don't wait for the lights to go out to discover where the emergency plan has gaps. Test it. Exercise it. Improve it. And make sure your hospital is prepared for the next cyber nightmare—before it becomes reality

 

Author: Charles (CJ) Sabo, MPH, CHEP, EMT-B, Manager, Emergency Management

 

 
 
 

Comments


bottom of page