Archive for April 20, 2024

French Hospital Reduced To Pen And Paper After Getting Pwned In A Cyberattack

Posted in Commentary with tags on April 20, 2024 by itnerd

The 869 Bed Hospital Simone Veil in Cannes, France (CHC-SV) suffered a severe cyberattack this week forcing the hospital staff to revert to using pen and paper for documenting medical activities. The hospital, which employs 2,100 staff including 230 doctors, provides extensive healthcare services, including 150,000 outpatient visits and 50,000 emergency room visits annually, along with performing 9,000 surgeries and assisting in 1,500 births.

The hospital announced (English translation here) that due to the cyberattack, all computer systems were shut down, leaving only the telephone systems operational for external communications, adding that “so far, there has been no demand for ransom nor any data theft identified. Investigations are ongoing.” This disruption led to the cancellation of about 30% of all non-urgent surgical procedures and the rescheduling of many non-urgent consultations. However, consultations that do not require computer access continue as scheduled.

The hospital administration noted, “CHC-SV had never before been the victim of a cyberattack of this kind,” highlighting that recent cyber-exercises played a key role in effectively managing and containing the damage from the attack. As of the latest updates, no ransomware or extortion groups have claimed responsibility for the incident at CHC-SV.

Though forced back to using paper and pencils, the hospital’s website appears to be functioning normally and they have been posting updates on the attack.

BullWall Executive, Carol Volk had this comment:

   “The cyberattack on the Hospital Simone Veil in Cannes is a stark reminder of the vulnerabilities in our healthcare systems. This incident left the hospital reliant on manual documentation and points to a serious need for enhanced cybersecurity measures. Despite the success of recent cyber security exercises, the attack’s impact was still significant, disrupting many non-urgent medical services and forcing a reliance on less efficient processes.

   “By ensuring robust defenses are in place and equally important, good protective measures such as ransomware containment, hospitals can limit the damage of attacks and better protect patient care and data. As healthcare continues to depend heavily on digital technologies, the sector must prioritize these investments to prevent future disruptions and safeguard patient health.”

This attack underscores the fact that healthcare are “soft target” for threat actors. And that needs to change. Because if it doesn’t change, something really tragic is going to happen. As in someone dying because a cyberattack deprived them of the care that they needed.