Last year, the Department of Health & Human Services has issued a strong warning to U.S. hospitals, highlighting the growing cyber threats to healthcare. The Federal agency’s report on hospital cyber resiliency noted that the widespread adoption of health information technology, driven by the Health Information Technology for Economic and Clinical Health (HITECH) Act, the Affordable Care Act, and the 21st Century Cures Act, has expanded the healthcare industry’s vulnerability to cyberattacks.
“Directly targeted ransomware attacks aimed to disrupt clinical operations are an outsized and growing cyber threat to hospitals,” HHS emphasized. “Ransomware is currently the largest threat to this sector and deserves immediate attention—especially considering the impact the nonavailability of services can have on patient care and safety.”
Os ataques de ransomware são frequentemente combinados com o roubo de dados confidenciais de pacientes. De acordo com oPrograma de Cibersegurança do HHS, electronic health records (EHRs) are prime targets for cyberattacks because they contain valuable protected health information (PHI) such as names, social security numbers, geographic data, and biometrics. This data is highly profitable for cybercriminals and difficult to secure once exposed.
Regulamentos de segurança relativos a EMR/EHR de acordo com a HIPAA
O alerta do HHS destaca vulnerabilidades significativas nos sistemas de informação da área da saúde que expõem as organizações a ataques de ransomware, violações de dados e outras ameaças cibernéticas. Os prestadores de serviços de saúde devemreconhecer esses alertas como chamadas urgentes à ação, e não como avisos de rotina. As implicações vão além das questões técnicas: a segurança inadequada dos prontuários eletrônicos (EHR) gera responsabilidade legal, compromete o atendimento ao paciente e prejudica a reputação da instituição.
As ameaças comuns à segurança dos EHR incluem:
- Insider threats: Staff members who accidentally or intentionally misuse their access to patient records.
- Third-party risks: Vendors and business associates with access to systems but potentially inadequate security practices.
- Legacy systems: Outdated software and hardware that no longer receive security updates.
- Mobile device vulnerabilities: Unsecured smartphones and tablets used to access patient information.
- Cloud security gaps: Inadequate protection for data stored in cloud environments.
- Phishing attacks: Targeted campaigns designed to steal credentials from healthcare workers.
- Inadequate backup protocols: Insufficient or untested backup systems that fail during recovery scenarios.
These threats directly connect to HIPAA non-compliance when organizations fail to implement required safeguards. For example, a ransomware attack exploiting unpatched software represents a violation of the HIPAA Security Rule’s system protection requirements.
The financial consequences of these attacks can be severe. According to IBM’s 2024 Cost of a Data Breach Report, healthcare breaches cost organizations an average of $9.77 million. One example is therecent ransomware settlement involving Heritage Valley Health System, where the Office for Civil Rights imposed a $950,000 fine and required a corrective action plan. Incidents like this underscore the importance of robust cybersecurity measures to prevent breaches and reduce risks.
As normas de segurança relativas a EMR/EHR de acordo com a HIPAA incluem a implementação de medidas de segurança administrativas, físicas e técnicas razoáveis e adequadas para proteger as ePHI. ANorma de Segurança HIPAAestabelece mandatos específicos para a proteção dos EHR. Exige que as entidades reguladas tenham:
- Administrative safeguards: Risk analysis, security management processes, workforce training, and contingency planning.
- Physical safeguards: Facility access controls, workstation security, and device/media controls.
- Technical safeguards: Access controls, audit controls, integrity controls, and transmission security.
- Organizational requirements: Business associate contracts and documentation requirements.
- Policies and procedures: Implementation of reasonable and appropriate security measures.
As organizações de saúde devem realizar uma avaliação abrangente dos riscos de segurança para identificar vulnerabilidades. Em seguida, devem desenvolver um plano de correção que priorize as lacunas críticas, atualizando políticas e procedimentos de segurança, implementando salvaguardas técnicas e oferecendo treinamento aos funcionários sobre protocolos de segurança. Auditorias de segurança regulares ajudam a manter a conformidade contínua e a se adaptar às ameaças emergentes.
Medidas de segurança e importância dos EHR
Como os EHRs são alvos privilegiados, a segurança é cada vez mais importante. A segurança dos EHRs abrange medidas de proteção especializadas, projetadas para proteger as ePHI (informações de saúde protegidas eletrónicas) nos sistemas de informação de saúde.A segurança dos EHRs deve abordar tanto as vulnerabilidades técnicasdos sistemas digitais quanto os requisitos exclusivos de privacidade exigidos pelas regulamentações de saúde.
A base da segurança eficaz do HIPAA EHR assenta em três princípios fundamentais:
- Confidentiality protects against unauthorized access to sensitive patient data.
- Integrity maintains the accuracy and consistency of health records throughout their lifecycle.
- Availability makes certain that authorized users can access critical information when needed for patient care.
Medidas essenciais de segurança para prontuários eletrônicos
Essas medidas de segurança de EHR podem ajudar as organizações de saúde a proteger os dados dos pacientes e, ao mesmo tempo, atender aos requisitos da HIPAA:
- Access controls: Role-based permissions that limit data access to authorized personnel based on job function and need-to-know basis.
- Authentication systems: Multi-factor authentication requiring multiple verification methods before granting system access.
- Encryption: Data encryption both at rest and in transit to protect information even if systems are breached.
- Audit trails: Comprehensive logging of all system activities to track who accessed records and what changes were made.
- Regular EHR security risk analysis: Systematic evaluation of security vulnerabilities and implementation of mitigation strategies.
- Backup and recovery: Regular data backups with tested recovery procedures to maintain availability during incidents.
- Physical safeguards: Restricted physical access to servers and workstations containing ePHI.
- Security awareness training: Ongoing education for all staff on security protocols and threat recognition.
Preocupações com a privacidade e a segurança dos registos médicos eletrónicos
A integridade e a privacidade dos dados representam aspectos distintos, mas interligados, das preocupações com a privacidade e a segurança dos EHR. A integridade dos dados concentra-se em manter a precisão e a integridade dos registros de saúde ao longo de seu ciclo de vida: impedindo alterações não autorizadas, detectando dados corrompidos e preservando a confiabilidade das informações médicas.
A privacidade centra-se no controle de quem pode acessar as informações dos pacientes e em que circunstâncias. Ambos os elementos exigem medidas de proteção específicas para manter a conformidade com a HIPAA.
Embora a criptografia forneça uma camada crítica de proteção para os dados do EHR, ela não pode servir como uma solução de segurança abrangente para violações de segurança do EHR. Os dados criptografados permanecem vulneráveis se os controles de acesso forem fracos, os sistemas de autenticação forem comprometidos ou se os funcionários internos fizerem uso indevido de seus privilégios de acesso legítimos. As organizações de saúde devem implementar umaabordagem de segurança em várias camadasque aborde todo o espectro de vulnerabilidades potenciais para lidar com as questões de privacidade e segurança do EHR.
Controles de acesso, registros de auditoria e avaliações regulares de risco atuam em conjunto para preservar tanto a integridade quanto a privacidade dos prontuários eletrônicos. Os controles de acesso limitam a exposição dos dados com base na função e na necessidade. Os registros de auditoria garantem a prestação de contas ao rastrear todas as interações com informações de saúde protegidas. As avaliações de risco identificam vulnerabilidades emergentes antes que elas possam ser exploradas.
“The shift to the cloud has gained momentum because it reduces technical debt and improves security,” says Jaimie Fox, Senior Technology Strategist at Microsoft. “Cloud providers offer far greater security than individual hospitals, allowing healthcare providers and EHR vendors to securely move infrastructure while focusing on innovation and efficiency.”
Many healthcare providers are increasingly recognizing the necessity to take advantage of the cloud’s advantages over traditional infrastructure. However, this shift raises a critical question: How can healthcare organizations protect mission-critical systems from cyber threats while ensuring they remain operational for patient care?
Aprimorando a segurança do EHR Cloud
With growing cyber threats to EHR systems, healthcare organizations must adopt proven strategies for cyber resilience. Key methods include leveraging cloud-based security infrastructure, comprehensive risk mitigation, and integrating AI into security workflows to enhance readiness against attacks.
Compessoal de segurança cibernética limitado, as organizações de saúde têm a oportunidade de usar a cloud reforçar sua postura de segurança cibernética, bem como lidar com a dívida técnica queaflige a maioria dos hospitais dos Estados Unidos. While complying with federal, state, and local regulations is crucial, mitigating cybersecurity risks goes beyond just meeting compliance standards.
“In cyber resilience, protecting data availability is as critical as ensuring its confidentiality and integrity,” says David Houlding, Microsoft’s Director of Global Healthcare Security and Compliance Strategy. “Healthcare organizations must also defend against breaches, insider threats, and third-party risks, which can cause severe disruptions, including system shutdowns.”
The cloud’s flexibility and scalability enable the rapid integration of advanced, data-intensive technologies that help healthcare cybersecurity professionals strengthen security and empower clinicians to apply cutting-edge tools to patient care.
“AI capabilities, which enhance productivity and reduce costs in EHR systems, are only achievable in a cloud environment,” notes Fox. “Traditional on-premises systems cannot support these advanced AI functions, limiting innovation and cutting-edge solutions in clinical care.”
AI can also revolutionize healthcare cybersecurity by quickly identifying and responding to potential threats to data, systems, and applications.
“With AI, security analysts can detect and respond to sophisticated attacks, such as phishing and spear phishing, which are now becoming more widespread and cheaper to execute due to attackers also using AI-driven automation,” says Houlding. “Additionally, AI can provide real-time guidance, helping security teams improve their skills on the job, making them better equipped to handle the rapidly evolving threat landscape.”
As healthcare organizations transition to the cloud, balancing innovation with security is essential.
Choosing the Right Cyber Resilience Partner
Ao aproveitar a segurança cloud e as proteções impulsionadas por IA,os prestadores de serviços de saúde podem proteger sistemas críticos while driving clinical innovations in patient care.
“Commvault is a trusted Microsoft partner and a key partner for healthcare organizations seeking true cloud cyber resilience on Azure. They have an unmatched track record, and as you’ve heard from our colleagues, their value proposition is unique and industry-leading, says Karen Cox, Global Healthcare Partner Strategy Leader at Microsoft.
“Commvault is a leader and early participant in the Microsoft Copilot for Security Partner Program, using the latest technology to protect enterprises,” she continues. “Their solutions are fully integrated with Microsoft security, co-engineered with Microsoft, and adhere to Azure Protection Services standards. This makes Commvault an ideal partner for safeguarding healthcare applications and data, whether in the cloud or a hybrid environment.”
Healthcare organizations can strengthen their recovery strategies against EHR attacks by leveraging Commvault Cleanroom Recovery, the only solution validated by the Enterprise Strategy Group for ensuring recovery into a guaranteed clean environment. With ransomware posing a top threat, a secure and auditable recovery plan is essential for resuming operations quickly and safely.
By using Commvault’s advanced cyber resilience platform, healthcare organizations can recover quickly and safely without the risk of reinfection, protecting patient data and ensuring long-term operational security. Download our guia completopara preparar sua organização de saúde com etapas práticas e melhores práticas para recuperação cibernética.