Current:Home > reviewsCyberattacks on hospitals thwart India's push to digitize health care -ProfitSphere Academy
Cyberattacks on hospitals thwart India's push to digitize health care
PredictIQ Quantitative Think Tank Center View
Date:2025-04-06 09:35:22
In late November, as a thick layer of smog settled on the All India Institute of Medical Sciences in New Delhi, patients began to experience extended wait times. Long lines snaked along the vast building and backed up for several yards.
Computers at the hospital had stopped working, so medical reports could not be generated. Though patients were still being treated, paper bills were being handed out. After a few days, people who feared that traveling back home would be too expensive began to sleep under a nearby overpass to wait it out.
A massive cyberattack had compromised the health data of millions of patients, from those who live in extreme poverty to high-profile politicians, bureaucrats and judges.
The Delhi Police had a bigger problem at hand. They were in possession of an email that read, "What happened? Your files are encrypted? What is the price to repair? The price depends on how fast you can pay to us," reported news sources.
The Delhi police initially denied reports of a ransom demand. But they later confirmed that the servers at AIIMS were attacked and data was being held for ransom. Police sources were quoted as saying the attack originated from China and Hong Kong.
Two weeks later, servers at AIIMS are just now limping back to normal.
A digital health ID for every Indian
Cybersecurity experts express larger concerns.
Because India does not have robust cybersecurity systems or strong data protection laws, the breach has made observers uneasy about Prime Minister Narendra Modi's ambitious plan to digitize the health records of all Indians.
In 2020, most people around the world were just hearing about COVID-19. Indians were forced into a sudden lockdown, and no one knew when vaccines or a semblance of normal life would return.
Against that backdrop, Modi announced that every Indian would get a health ID under the National Digital Health Mission: "Your every test, every illness, what doctors prescribed and when, your reports will be on a single health ID."
These health records can be accessed by health-care professionals only after the informed consent of the ID holder, Modi clarified.
Cybersecurity experts are doubtful about getting informed consent as that concept is relatively new in the country. "Citizens being forced to get a health ID and digitize their health records without the right safeguards is making them vulnerable," says Srinivas Kodali, a technology expert and researcher with Free Software Movement of India. "With plans for ubiquitous sharing of health records across hospitals, doctors, insurance agencies and health tech firms, Indians' health data is expected to be more prone to leaks, data breaches and exploitation," he adds.
More than 170,000 hospitals across the country have signed up for the National Digital Health Mission already. Registration is mandatory for government-run hospitals.
Right across from AIIMS is another massive government-run hospital, where thousands of people line up for treatment. Around the same time that AIIMS reported the ransomware attack, Safdarjung Hospital also reported a cyberattack that incapacitated its servers for a day. Data was not breached and the servers were restored quickly.
Currently, the safety of a patient's data will depend on how safe the hospital servers are. Under the National Digital Health Mission, all hospitals will be responsible for storing and protecting the patient data they collect. Patients at Safdarjung were merely lucky that their data was not breached.
Kodali says if there is a plan to have one unique national health ID, then the cybersecurity of the such massive amounts of data should be the responsibility of the government. "To expect hospitals to deal with their own cybersecurity is like asking an IT professional to medically operate on himself," he says.
In a 2022 white paper, the artificial intelligence company CloudSEK said that cyberattacks on the global health care industry rose by more than 95% compared to last year. Attacks mostly occurred on systems in the U.S., followed by India.
Cyberthreats loom
Observers warn against large-scale digitization before necessary checks are in place. "In large systems, digitalization can bring in efficiencies, but it also creates the possibility of disruption to information flows with cascading impacts for society," says Anita Gurumurthy, director of the non-profit IT for Change, which works on tech policy and human rights.
Indian authorities agree that the country is facing increasing cyberthreats. The Indian Computer Emergency Response Team (CERT-IN), the national cybersecurity watchdog, noted a 51% increase in the number of ransomware attacks, including on critical infrastructure, from the year before.
In the absence of a personal data protection bill, as well as a law governing the digital health ecosystem, Gurumurthy says, the regulatory system is not conducive to maintaining large data sets.
In addition, users' lack of awareness about cyber risks and the use of old, legacy technologies contribute to vulnerability, according to Rajeswari Pillai Rajagopalan, director of the Centre for Security, Strategy and Technology (CSST) at the think tank Observer Research Foundation. "India also needs to study the evolving tactics, techniques and procedures [TTPs] of hackers and criminals to be able to prevent these attacks. India will pay a serious price if it is seen as an easy target."
veryGood! (8774)
Related
- Rolling Loud 2024: Lineup, how to stream the world's largest hip hop music festival
- Saoirse Ronan secretly married her 'Mary Queen of Scots' co-star Jack Lowden in Scotland
- Secret Service and FBI officials are set to testify about Trump assassination attempt in latest hearing
- The 25 Most Popular Amazon Items E! Readers Bought This Month: Viral Beauty Products & More
- Which apps offer encrypted messaging? How to switch and what to know after feds’ warning
- 83-year-old Alabama former legislator sentenced to 13 months in federal prison for kickback scheme
- How Stephen Nedoroscik delivered on pommel horse to seal US gymnastics' Olympic bronze
- Selena Gomez hits back at criticism of facial changes: 'I have Botox. That's it.'
- The city of Chicago is ordered to pay nearly $80M for a police chase that killed a 10
- Watch as rescuers save Georgia man who fell down 50-foot well while looking for phone
Ranking
- Toyota to invest $922 million to build a new paint facility at its Kentucky complex
- Steals from Lululemon’s We Made Too Much: $29 Shirts, $59 Sweaters, $69 Leggings & More Unmissable Scores
- Madden 25 ratings reveal: Tyreek Hill joins 99 club, receiver and safety rankings
- Boar's Head faces first suit in fatal listeria outbreak after 88-year-old fell 'deathly ill'
- US appeals court rejects Nasdaq’s diversity rules for company boards
- Olympic medals today: What is the medal count at 2024 Paris Games on Tuesday?
- Olympic men's triathlon event postponed due to pollution levels in Seine river
- 2024 Olympics: Colin Jost Shares Photo of Injured Foot After Surfing Event in Tahiti
Recommendation
Macy's says employee who allegedly hid $150 million in expenses had no major 'impact'
Dad dies near Arizona trailhead after hiking in over 100-degree temperatures
2024 Olympics: Egyptian Fencer Nada Hafez Shares She Competed in Paris Games While 7 Months Pregnant
Utility cuts natural gas service to landslide-stricken Southern California neighborhood
Average rate on 30
Erica Ash, 'Mad TV' and 'Survivor's Remorse' star, dies at 46: Reports
‘TikTok, do your thing’: Why are young people scared to make first move?
Senate set to pass bill designed to protect kids from dangerous online content