Mitigating the Effects of Ransomware Attacks on Healthcare Systems

Sreejith Gopinath,Aspen Olmsted
DOI: https://doi.org/10.48550/arXiv.2202.06108
2022-02-12
Cryptography and Security
Abstract:Healthcare information systems deal with a large amount of Personally Identifiable Information related to patients like dates of birth and social security numbers, patients health information and history, and financial information like credit card details and bank accounts. Most healthcare institutions purchase information systems from commercial vendors and have minimal inhouse expertise required to maintain these systems. Most institutions lack the expertise required to research evolving threats and maintain a tough security posture. We propose a risk transference based system architecture that moves sensitive data outside the system boundary, into data stores that are managed with stringent and efficient security protocols.
What problem does this paper attempt to address?