{"id":4782,"date":"2024-08-09T20:59:25","date_gmt":"2024-08-10T01:59:25","guid":{"rendered":"https:\/\/www.darkreading.com\/endpoint-security\/healthcare-providers-must-plan-for-ransomware-attacks-on-third-party-suppliers"},"modified":"2024-08-09T20:59:25","modified_gmt":"2024-08-10T01:59:25","slug":"healthcare-providers-must-plan-for-ransomware-attacks-on-third-party-suppliers","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/09\/healthcare-providers-must-plan-for-ransomware-attacks-on-third-party-suppliers\/","title":{"rendered":"Healthcare Providers Must Plan for Ransomware Attacks on Third-Party Suppliers"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltc56d3c2aac619e2c\/663e454c18e60a2a0e68c51d\/healthcar_cyber_JJ_Gouin_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/healthcare-providers-must-plan-for-ransomware-attacks-on-third-party-suppliers.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/healthcare-providers-must-plan-for-ransomware-attacks-on-third-party-suppliers.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The American Hospital Association and the Health-ISAC issued a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.aha.org\/advisory\/2024-08-01-american-hospital-association-and-health-isac-joint-threat-bulletin-tlp-white\" rel=\"noopener\">joint threat bulletin<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> after a series of ransomware attacks by Russian cybercrime ransomware gangs created blood shortages and disrupted patient care in the U.S. and U.K.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The organizations urged healthcare delivery organizations (HDOs), hospitals and health systems to prepare for physical supply chain disruptions caused by cyberattacks on third-party vendors that could create significant problems to patient care delivery. The bulletin highlighted three recent ransomware attacks against blood suppliers.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In July, Florida-based blood supplier OneBlood was the target of a ransomware attack that created major shipping delays of blood products in the region as the company was forced to manually label blood samples. The result was a blood shortage that impacted area hospitals and patient care. In June, pathology provider Synnovis was attacked by a ransomware gang, creating delays in care and planned surgeries across multiple London hospitals, and which left thousands of units of blood unable to be used because patient blood types couldn\u2019t be looked up without access to the health record system. And in April, blood plasma provider Octapharma was attacked through a vulnerable VMWare system, closing blood plasma donations in 35 states. Those cybercriminals were able to steal donor information and donor-protected health information, in addition to disrupting patient care in the U.S. and E.U.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Healthcare IT teams to consider how supply-chain outages will impact business operations and patient care, and identify single points of failure. The attacks highlight the need to incorporate mission-critical suppliers into enterprise risk management and emergency management plans.&nbsp;Organizations also need to develop multi-disciplinary Third-Party Risk Management (TRPM) governance committees and programs to identify mission-, business-, and life-critical parties in their supply chain, and develop procedures on how they would handle the loss of any of these services.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Health-ISAC and AHA bulletin also recommends considering whether third party vendors are: essential to the healthcare mission, could result in catastrophic consequences for the organization if the vendor fails, and whether there are suitable alternatives.&nbsp;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/endpoint-security\/healthcare-providers-must-plan-for-ransomware-attacks-on-third-party-suppliers\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The American Hospital Association and the Health-ISAC issued a joint<\/p>\n","protected":false},"author":12,"featured_media":4783,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4782","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/healthcare-providers-must-plan-for-ransomware-attacks-on-third-party-suppliers-scaled.jpg?fit=2560%2C1707&ssl=1",2560,1707,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/healthcare-providers-must-plan-for-ransomware-attacks-on-third-party-suppliers-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/healthcare-providers-must-plan-for-ransomware-attacks-on-third-party-suppliers-scaled.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/healthcare-providers-must-plan-for-ransomware-attacks-on-third-party-suppliers-scaled.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/healthcare-providers-must-plan-for-ransomware-attacks-on-third-party-suppliers-scaled.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/healthcare-providers-must-plan-for-ransomware-attacks-on-third-party-suppliers-scaled.jpg?fit=1536%2C1024&ssl=1",1536,1024,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/healthcare-providers-must-plan-for-ransomware-attacks-on-third-party-suppliers-scaled.jpg?fit=2048%2C1365&ssl=1",2048,1365,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/healthcare-providers-must-plan-for-ransomware-attacks-on-third-party-suppliers-scaled.jpg?fit=1024%2C683&ssl=1",1024,683,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/healthcare-providers-must-plan-for-ransomware-attacks-on-third-party-suppliers-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/healthcare-providers-must-plan-for-ransomware-attacks-on-third-party-suppliers-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/healthcare-providers-must-plan-for-ransomware-attacks-on-third-party-suppliers-scaled.jpg?fit=2560%2C1707&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4782","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4782"}],"version-history":[{"count":1,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4782\/revisions"}],"predecessor-version":[{"id":4810,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4782\/revisions\/4810"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4783"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4782"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4782"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4782"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}