one
quarter of healthcare organizations
have experienced a cyber attack in the
past year,
Ransomware can result in the loss
of access to patient records for weeks
or months, even when the ransom is
paid, on average,
the cost of recovering from a ransomware
attack for a health care provider is $1.4
million.
Additional impacts include lost
productivity, reputational damage
and service disruption, including
lifesaving patient care.
With some re platform and imaging systems,
applications retain the vulnerabilities
of traditional systems. Even with
encryption, clinical data storage
is organized in standard file system
hierarchy, and most ransomware
attacks achieve access through file systems.
In simplest terms, ransomware
attacks data where it sits.
If a big chunk of data sits on a single
drive, it's easy to find and
in many instances only a single
layer of defense exists
using cloud native architecture.
A hierarchical file structure is
not required. Data can be broken
up and managed through encrypted ap
eyes. That makes it far more
difficult for ransomware to gain access.
Additionally, each element of the
solution contains its own protection,
networking, software
storage services, identity
and access management and hardware
infrastructure. Third party
certification of the solution providers,
compliance with standards such
as high trust sock to and others
helps ensure the solution provider
complies with current security best
practices.
Certification also provides customers
with clear independent assessments
of the solutions, security capabilities
and practices when evaluating
certification of cloud solutions. It's
critical to confirm exactly what
has been certified. Both the cloud
infrastructure provider if hosted
on a public cloud or third party private
cloud. And the solution provider
should be separately certified by applicable
bodies.
Importantly, certification of
the security standards of an infrastructure
provider does not carry over to the
solution that sits on the infrastructure.