By Jody Jepson, Vice President Growth Strategy and Marketing, Keystone Technologies
A typical morning starts with coffee, catching up on the news, more coffee, and scrolling through LinkedIn. I cherish these calm moments to learn about what’s happening around the world before the day picks up speed. I can’t imagine beginning the day with a locked-down computer due to a ransomware attack. Sadly, it’s becoming more common to hear about healthcare or financial institutions experiencing cyberattacks that cripple their ability to provide care or services. Many of us have faced the dreaded black screen of death, but I truly fear the day an attack compromises my personal information sending me in a tailspin. I wouldn’t know the first place to start. While I have safety nets in place, the reality is that it’s not a matter of “if”, but “when.”
Cyberattacks targeting healthcare organizations are becoming increasingly common, with incidents now occurring almost weekly. Attackers employ evolving tactics to breach networks1, leading to catastrophic disruptions. In 2022 alone, over 200 major U.S. organizations were compromised, including 24 healthcare providers overseeing 289 hospitals. These disruptions not only jeopardize patient care and data security but also impose significant financial burdens, costing as much as $8,662 per minute2.
Recently, our Chief Information Officer (CIO), Jeff Bell, discussed the prolonged recovery times following healthcare cyberattacks, which often stretch from weeks to months and can sometimes exceed a year. His insights shed light on this critical issue that healthcare leaders are closely monitoring.
“In the early days of internet-connected security, the focus was on perimeter defense,” Jeff Bell, CIO of Keystone Technologies, explained. “We aimed to keep threats out while maintaining an open internal network to simplify and enhance reliability. However, as the need for more perimeter holes became evident, we realized this ‘moat strategy’ was insufficient, we needed a more layered approach.”
“Today, we operate under the assumption that threats are omnipresent and can cause not only immediate disruption but also extend for months at a time. This realization led us to develop security measures that protect sensitive data at rest and in transit, avoid sending authentication responses in clear text, implement advanced malware protection on every PC and endpoint, and segment infrastructure into separate VLANs for general users and sensitive workloads, with controlled access between them.”
Jeff highlighted that robust security measures have now moved to the cloud. “Every interaction should be treated as potentially hostile, making security more intuitive and effective. Balancing this with usability is crucial, as any network-connected system is vulnerable. The constant evolution of threats demands that we stay ahead with robust backups with Recovery Time Objectives (RTOs), and Recovery Point Objectives (RPOs) that are vetted and appropriate for the business. With bad actors laying in wait for more extended periods of time, backup retention becomes a more important topic as well.”
Effectively addressing cyberattacks involves a multifaceted approach, including removing hackers from the system and addressing the vulnerabilities that led to the breach. Consequently, IT disruptions can endure for extended periods. For instance, UnitedHealth Group’s Change Healthcare experienced a disruption that temporarily halted its payer and pharmacy applications. Similarly, Lurie Children’s Hospital of Chicago is still grappling with the aftermath of a hack on January 31st, with its MyChart patient portal offline. HSHS, a large midwest IDN suffered a multi-week outage in the early fall of 2023. And Ascension is just now coming out of a devastating attack that has lasted over 4 weeks and affected 140 hospitals in 19 states. These organizations are well run, and their DR/BC plans are solid, thank goodness. But an organization’s ultimate DR/BC goal should be to never have to execute the plans.
Is there an effective solution to this pervasive issue?
The answer lies in adopting cloud-based architectures that employ logical separation between backups and production systems, making them more resilient compared to traditional backup systems. In traditional setups, hackers can infiltrate the system and remain undetected for extended periods, moving stealthily from one system to another until they are ready to encrypt and render data unusable, including backups. Notably, systems like Veeam backups are vulnerable to such attacks, as they operate on similar principles and can be compromised via login credentials.
Understanding the complex terrain of healthcare cybersecurity attack recovery
- Complexity of Attacks
Cyberattacks targeting healthcare organizations are often sophisticated and multi-faceted, involving multiple layers of intrusion and exploitation. Attackers may use tactics such as ransomware, data exfiltration, and network infiltration to compromise critical systems and disrupt operations. The complexity of these attacks makes it challenging for organizations to identify and remediate all affected systems promptly.
- Detection and Response Time
Detection and response time play a crucial role in determining the duration of the recovery process. In many cases, healthcare organizations may not detect a cyberattack until it has already caused significant damage. Once detected, responding to the attack and containing its impact can be time-consuming, particularly if the organization lacks robust incident response capabilities and tools.
- Regulatory Compliance and Reporting Requirements
Healthcare organizations are subject to stringent regulatory requirements and reporting obligations concerning data breaches and cybersecurity incidents. Compliance with these regulations often entails extensive documentation, investigation, and remediation efforts, which can prolong the recovery process. Failure to comply with regulatory requirements can result in severe penalties and reputational damage for organizations.
- System Remediation and Restoration
After a cyberattack, healthcare organizations must remediate compromised systems and restore normal operations. This process involves identifying and patching security vulnerabilities, restoring data from backups, and rebuilding infrastructure as necessary. Depending on the extent of the damage and the complexity of the organization’s IT environment, system remediation and restoration efforts can take weeks or even months to complete.
- Resource Constraints
Healthcare organizations may face resource constraints, including limited IT staff, budgetary constraints, and competing priorities, which can impede the recovery process. Lack of sufficient resources can lead to delays in implementing security measures, conducting forensic investigations, and restoring services, prolonging the overall recovery timeline.
4 security pillars to maintain continuity of care
Security is ever-evolving, as Jeff Bell’s account of the measures taken by his team demonstrates. So, how do you get started? A cookie-cutter approach won’t suffice since every healthcare system has unique needs, such as patient data management, regulatory compliance, and varying levels of existing infrastructure. Leveraging cloud technology and industry best practices is crucial. This means implementing secure cloud-based backup solutions to protect against cybersecurity threats and data loss events. Jeff’s team has identified four key pillars that executives should consider to stay ahead of potential disruptions.
1. Multi-Factor Authentication (MFA) is crucial to protect email and other critical attack vectors from compromise. This includes paying attention to non-human accounts such scanner, fax, shared conference room accounts and others. These non-human accounts are often the weakest link and the bad guys know this and will exploit this fact.
2. Advanced Endpoint Detection and Response (EDR) software is crucial to a layered defense which protects from within as well as the perimeter.
3. Security Information and Event Management (SIEM) aggregates event logs and other information in one place allowing faster and more accurate triangulation on the vectors that back actors are using to breach an environment. SIEM can often provide predictive alerts highlighting the actions of bad actors before they become a problem.
4. Ongoing security awareness training may be the most important pillar of all since a human with any level of privilege on the systems can unknowingly defeat much of the above technical controls. Regular training along with period tests (e.g. random fake phishing email attacks) are key to a strong and healthy defense.
By adopting these practices, healthcare organizations can build a resilient defense against the ever-present risk of cyberattacks.
Secure patient data for ease of accessibility
Keystone Technologies places a high priority on advanced data security solutions, ensuring that our clients’ data is thoroughly protected in the ever-evolving healthcare environment. Our comprehensive security measures are meticulously designed to meet all HIPAA regulatory requirements, providing healthcare organizations with the peace of mind that their sensitive data is safeguarded against potential threats and vulnerabilities.Our EHR hosting solutions including Legacy Data Archival and EHR Cloud Read-Only backups in AWS are stored as inviolable snapshots, residing separately from any accessible servers, mitigating the risk of infiltration by hackers.
Moreover, our conversion team has the capability to transfer these snapshots to a distinct AWS account, further enhancing security by creating an additional layer of separation. In essence, the inherent attributes of cloud-based solutions provide IT tools that are unparalleled in traditional IT architectures.

Figure 1. EHR Cloud Solutions
Taking a proactive step towards data protection, the adoption of robust cloud-based backup solutions is crucial in safeguarding healthcare organizations against the evolving threat landscape posed by cyberattacks. Legacy systems that were not adequately backed up or may have been compromised during the breach could face permanent data loss. Therefore, the adoption of robust cloud-based backup solutions is crucial in safeguarding healthcare organizations against the evolving threat landscape posed by cyberattacks.
Investing in robust cybersecurity measures, including threat detection and response capabilities, incident response planning, and secure backup and recovery solutions such as Legacy Data Archival, can help organizations mitigate the impact of cyberattacks and minimize downtime. Additionally, fostering collaboration with industry partners, regulatory agencies, and cybersecurity experts can provide valuable support and resources during the recovery process.
Ultimately, the extended recovery period in healthcare cybersecurity highlights the critical need for proactive cybersecurity initiatives, readiness for incidents, and the integration of a continuity of care plan bolstered by cloud-based EHR Hosting. By addressing the underlying factors contributing to prolonged recovery times, healthcare organizations can enhance their resilience to cyber threats and ensure the continuity of patient care and data security.
Security assessment
If you are curious about your healthcare system’s security, please reach out to schedule a security assessment. Our top priority is patient care and that begins with a secure system. Let us work on spotting any vulnerabilities so you can focus on what you do best, care for your patients. Contact Us for a free security consultation.
Plus, if you are headed to the AWS DC Summit June 25 through 27, our executive team will be onsite at booth #124. Let’s Meet Up for coffee or set up for a time to chat with them. See you in our nation’s capital.
Resource 1. https://www.govtech.com/security/floridas-cyber-journey-puts-state-and-local-hand-in-hand
Resource 2. https://www.comparitech.com/blog/information-security/ransomware-attacks-hospitals-data/