TY - JOUR
T1 - Cybersecurity Challenges and the Academic Health Center
T2 - An Interactive Tabletop Simulation for Executives
AU - Maggio, Lauren A.
AU - Dameff, Christian
AU - Kanter, Steven L.
AU - Woods, Beau
AU - Tully, Jeffrey
N1 - Publisher Copyright:
© 2021 Lippincott Williams and Wilkins. All rights reserved.
PY - 2021/6/1
Y1 - 2021/6/1
N2 - Problem Academic health centers (AHCs) face cybersecurity vulnerabilities that have potential costs to an institution's finances, reputation, and ability to deliver care. Yet many AHC executives may not have sufficient knowledge of the potential impact of cyberattacks on institutional missions such as clinical care, research, and education. Improved cybersecurity awareness and education are areas of opportunity for many AHCs. Approach The authors developed and facilitated a tabletop cybersecurity simulation at an international conference for AHC leaders in September 2019 to raise awareness of cybersecurity issues and threats and to provide a forum for discussions of concerns specific to CEOs and C-suite-level executives. The 3.5-hour interactive simulation used an evolving, 3-phase case study describing a hypothetical cyberattack on an AHC with a ransomware demand. The approximately 70 participants, from AHCs spanning 25 states and 11 countries, worked in teams and discussed how they would react if they held roles similar to their real-life positions. The authors provide the full scenario as a resource. Outcomes The exercise was well received by the participants. In the postsession debrief, many participants noted that cybersecurity preparedness had not received the level of institutional attention given to threats such as epidemics or natural disasters. Significant variance in teams' courses of action during the simulation highlighted a lack of consensus with regard to foundational decisions. Participants identified this as an area that could be remedied by the development of guidelines or protocols. Next Steps As health care cybersecurity challenges persist or grow in magnitude, AHCs will have increased opportunities to lead in the development of best practices for preparedness and response. AHCs are well positioned to work with clinicians, security professionals, regulators, law enforcement, and other stakeholders to develop tools and protocols to improve health care cybersecurity and better protect patients.
AB - Problem Academic health centers (AHCs) face cybersecurity vulnerabilities that have potential costs to an institution's finances, reputation, and ability to deliver care. Yet many AHC executives may not have sufficient knowledge of the potential impact of cyberattacks on institutional missions such as clinical care, research, and education. Improved cybersecurity awareness and education are areas of opportunity for many AHCs. Approach The authors developed and facilitated a tabletop cybersecurity simulation at an international conference for AHC leaders in September 2019 to raise awareness of cybersecurity issues and threats and to provide a forum for discussions of concerns specific to CEOs and C-suite-level executives. The 3.5-hour interactive simulation used an evolving, 3-phase case study describing a hypothetical cyberattack on an AHC with a ransomware demand. The approximately 70 participants, from AHCs spanning 25 states and 11 countries, worked in teams and discussed how they would react if they held roles similar to their real-life positions. The authors provide the full scenario as a resource. Outcomes The exercise was well received by the participants. In the postsession debrief, many participants noted that cybersecurity preparedness had not received the level of institutional attention given to threats such as epidemics or natural disasters. Significant variance in teams' courses of action during the simulation highlighted a lack of consensus with regard to foundational decisions. Participants identified this as an area that could be remedied by the development of guidelines or protocols. Next Steps As health care cybersecurity challenges persist or grow in magnitude, AHCs will have increased opportunities to lead in the development of best practices for preparedness and response. AHCs are well positioned to work with clinicians, security professionals, regulators, law enforcement, and other stakeholders to develop tools and protocols to improve health care cybersecurity and better protect patients.
UR - http://www.scopus.com/inward/record.url?scp=85106969033&partnerID=8YFLogxK
U2 - 10.1097/ACM.0000000000003859
DO - 10.1097/ACM.0000000000003859
M3 - Article
C2 - 33239532
AN - SCOPUS:85106969033
SN - 1040-2446
VL - 96
SP - 850
EP - 853
JO - Academic Medicine
JF - Academic Medicine
IS - 6
ER -