The AIIMS ransomware attack was among the most significant cyber attack events in respect to the healthcare sector Recently in India.
The event underscored the vulnerability of healthcare systems to ransomware attacks with impacting essential medical operations, digital infrastructure and posing operational challenges in large healthcare organizations.
It all started in November 2022 when the digital systems of the All India Institute of Medical Sciences (AIIMS), New Delhi, were compromised after a presumed ransomware attack. Affected online services included registration of patients appointments billing, lab reports, and others.
During this time the hospital staff had to make use of manual processes to keep some services available.
It took many hours to repair the effected systems after the attack had been investigated and the details established. Police and security experts worked on restoring any digital systems after the cyber attack.
Operational impact: The AiMs was devastating since health systems rely so much on, inter-connected digital systems. The attack disrupted workflow and made access to some digital services impossible. The incident also showed how damaging attacks on service systems could be with consequences rather than costs.
Availability of systems in healthcare in particular can have significant repercussions with patient care, staff productivity, communication and access to information. The attack highlighted a growing focus on possible cybersecurity threats to hospitals and other critical services.
A critical lesson learnt from the AIIMS ransomware attack is the necessity to have well established backup and recovery processes in place. Ensuring that there are regular copies of data maintained offline or away from infected systems can assist in recovering from a malware attack. Network segmentation is another key security practice.
Dividing sensitive information or systems ensures that an attacker has a harder time moving within the network after the initial penetration.
Others include implementing robust access controls, multi-factor authentication, conducting periodic audits and scans of systems, and raising the level of employee cybersecurity knowledge through training and awareness campaigns.
The AIIMS attack exemplified how a cybersecurity breach impacts a large and complex healthcare system. It highlighted the importance of planning for cybersecurity proactively, continuous threat monitoring, solid backups, establishing procedures for handling security breaches and coordinated recovery efforts.
Healthcare organizations can learn from such cases to build toward greater cyber resilience.