Cybersecurity Monitoring/Mapping of USA Healthcare (All Hospitals) - Magnified Vulnerability due to Shared IT Infrastructure, Market Concentration, & Geographical Distribution

William Yurcik, Andreas Schick, Stephen North, Michael T. Gastner, Fabio Roberto De Miranda, Rodolfo da Silva Avelino, Andre Filipe de Moraes Batista, Gregory Pluta, Ian Brooks

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

In October 2024, there are two defining characteristics of a healthcare provider: (1) geographic location and services available at their physical structure and (2) Internet connectivity and services available via their virtual presence. For previous centuries we focused on the first defining characteristic and now we need to shift to understand and address issues that may arise from the new second defining characteristic. In this paper we address issues related to Internet connectivity and virtual presence of USA healthcare providers, especially hospitals, when ransomware cyberattacks resulting in service outages occur. We show the cybersecurity posture of a large critical national infrastructure (USA healthcare) can be measured, mapped, and quantitatively baselined. Empirical results reveal systemic issues in USA healthcare presenting "magnified vulnerabilities"in that a single exploit can have an outsized impact on an entire nationwide infrastructure. As the initial step toward addressing this issue, we document for the first time the magnified cybersecurity vulnerability of USA healthcare to shared IT infrastructure, market concentration, and the geographical distribution of hospitals.

Original languageEnglish (US)
Title of host publicationHealthSec 2024 - Proceedings of the 2024 Workshop on Cybersecurity in Healthcare, Co-Located with
Subtitle of host publicationCCS 2024
PublisherAssociation for Computing Machinery
Pages45-52
Number of pages8
ISBN (Electronic)9798400712388
DOIs
StatePublished - Nov 21 2024
Event2024 Workshop on Cybersecurity in Healthcare, HealthSec 2024 - Salt Lake City, United States
Duration: Oct 14 2024Oct 18 2024

Publication series

NameHealthSec 2024 - Proceedings of the 2024 Workshop on Cybersecurity in Healthcare, Co-Located with: CCS 2024

Conference

Conference2024 Workshop on Cybersecurity in Healthcare, HealthSec 2024
Country/TerritoryUnited States
CitySalt Lake City
Period10/14/2410/18/24

Keywords

  • cybersecurity ratings
  • hospital cybersecurity
  • ransomware

ASJC Scopus subject areas

  • Safety, Risk, Reliability and Quality
  • Computer Networks and Communications
  • General Medicine

Fingerprint

Dive into the research topics of 'Cybersecurity Monitoring/Mapping of USA Healthcare (All Hospitals) - Magnified Vulnerability due to Shared IT Infrastructure, Market Concentration, & Geographical Distribution'. Together they form a unique fingerprint.

Cite this