Protecting Healthcare Computing Resources in the Pandemic

by May 28, 2020

Categories

Tags

Administration agent-based monitoring Agentless Monitoring alert responses alert thresholds alerting Alerts Amazon Aurora Amazon EC2 Amazon RDS Amazon RDS / Aurora Amazon RDS for SQL Server Amazon Redshift Amazon S3 Amazon Web Services (AWS) Analytics application monitoring Aqua Data Studio automation availability Azure Azure SQL Database azure sql managed instance Azure VM backup Backup and recovery backup and restore backup compression backup status Backup Strategy backups big data Blocking bug fixes business architecture business data objects business intelligence business process modeling business process models capacity planning change management cloud cloud database cloud database monitoring cloud infrastructure cloud migration cloud providers Cloud Readiness Cloud Services cloud storage cloud virtual machine cloud VM clusters code completion collaboration compliance compliance audit compliance audits compliance manager compliance reporting conference configuration connect to database cpu Cross Platform custom counters Custom Views customer survey customer testimonials Dark Theme dashboards data analysis Data Analytics data architect data architecture data breaches Data Collector data governance data lakes data lineage data management data model data modeler data modeling data models data privacy data protection data security data security measures data sources data visualization data warehouse database database administration database administrator database automation database backup database backups database capacity database changes database community database connection database design database developer database developers database development database diversity Database Engine Tuning Advisor database fragmentation database GUI database IDE database indexes database inventory management database locks database management database migration database monitoring database navigation database optimization database performance Database Permissions database platforms database profiling database queries database recovery database replication database restore database schema database security database support database synchronization database tools database transactions database tuning database-as-a-service databases DB Change Manager DB Optimizer DB PowerStudio DB2 DBA DBaaS DBArtisan dBase DBMS DDL Debugging defragmentation Demo diagnostic manager diagnostics dimensional modeling disaster recovery Download drills embedded database Encryption End-user Experience entity-relationship model ER/Studio ER/Studio Data Architect ER/Studio Enterprise Team Edition events execution plans free tools galera cluster GDPR Getting Started Git GitHub Google Cloud Hadoop Healthcare high availability HIPAA Hive hybrid clouds Hyper-V IDERA IDERA ACE Index Analyzer index optimization infrastructure as a service (IaaS) infrastructure monitoring installation Integrated Development Environment interbase Inventory Manager IT infrastructure Java JD Edwards JSON licensing load test load testing logical data model macOS macros managed cloud database managed cloud databases MariaDB memory memorystorage memoryusage metadata metric baselines metric thresholds Microsoft Azure Microsoft Azure SQL Database Microsoft PowerShell Microsoft SQL Server Microsoft Windows MongoDB monitoring Monitoring Tools Monyog multiple platforms MySQL news newsletter NoSQL Notifications odbc optimization Oracle PeopleSoft performance Performance Dashboards performance metrics performance monitoring performance schema performance tuning personally identifiable information physical data model Platform platform as a service (PaaS) PostgreSQL Precise Precise for Databases Precise for Oracle Precise for SQL Server Precise Management Database (PMDB) product updates Project Migration public clouds Query Analyzer query builder query monitor query optimization query performance Query Store query tool query tuning query-level waits Rapid SQL rdbms real time monitoring Real User Monitoring recovery regulations relational databases Releases Reporting Reports repository Restore reverse engineering Roadmap sample SAP Scalability Security Policy Security Practices server monitoring Server performance server-level waits Service Level Agreement SkySQL slow query SNMP snowflake source control SQL SQL Admin Toolset SQL CM SQL code SQL coding SQL Compliance Manager SQL Defrag Manager sql development SQL Diagnostic Manager SQL Diagnostic Manager for MySQL SQL Diagnostic Manager for SQL Server SQL Diagnostic Manager Pro SQL DM SQL Doctor SQL Enterprise Job Manager SQl IM SQL Inventory Manager SQL Management Suite SQL Monitoring SQL Performance SQL Quality SQL query SQL Query Tuner SQL Safe Backup SQL script SQL Secure SQL Security Suite SQL Server sql server alert SQL Server Migration SQL Server Performance SQL Server Recommendations SQL Server Security SQL statement history SQL tuning SQL Virtual Database sqlmemory sqlserver SQLyog Storage Storage Performance structured data Subversion Support tempdb tempdb data temporal data Tips and Tricks troubleshooting universal data models universal mapping unstructured data Uptime Infrastructure Monitor user experience user permissions Virtual Machine (VM) web services webinar What-if analysis WindowsPowerShell

The COVID-19 pandemic has forced members of society to make many changes in their daily lives. Social distancing, working remotely and wearing masks to reduce transmission of the virus are just a few of the ways we are all being asked to address this global pandemic. During these trying times, the importance of the healthcare industry cannot be overstated. The citizens of the world depend on their healthcare providers for information regarding the virus and treatment of infected individuals.

Many diverse sectors of society have come together in an attempt to minimize the impact of the coronavirus. In many cases, people have responded in admirable ways to help their fellow human beings. Unfortunately, there are always entities that attempt to take advantage of the misfortune of others to further their ends. This is especially malicious in the face of the COVID-19 virus.

Price-gouging has been reported regarding the procurement of essential supplies for both individuals and organizations like hospitals. These activities have spurred the U.S. Department of Justice to take action against the perpetrators.

Cybercriminals Take Aim at the Healthcare Industry

Sadly, cybercriminals are also taking advantage of the confusion caused by COVID-19 to launch attacks on individuals and organizations. The healthcare industry is a prime target for their malicious code and the risk of infection with malware hangs in the air like the coronavirus itself. Specifically, ransomware can cripple a healthcare provider by encrypting data resources and rendering them useless until the criminals are paid off.

Due to the critical nature of healthcare data assets during the pandemic, hackers had initially made unsubstantiated claims that they would leave hospitals and medical organizations alone. These assurances soon proved to be untrue as the ransomware variant Maze began making an unwelcome appearance in IT environments.

Maze takes ransomware attacks to a new level by downloading sensitive information that cybercriminals use as leverage to get their financial demands met by affected organizations. Criminals threaten to post patient information on the web in addition to encrypting critical healthcare systems. This creates a powerful incentive for infected hospitals or health institutions to pay the ransom.

Many ransomware attacks are carried out by automated bots that search for generic system weaknesses that can be exploited to facilitate infection. These weaknesses are often human-related, with phishing emails being a preferred method of delivering ransomware. With proper training and user vigilance, the success of these types of attacks can be mitigated.

A new and troubling trend is the emergence of human-operated ransomware attacks that make use of extensive system administration and network security knowledge to infiltrate systems. They then discover security weaknesses and attempt to attain elevated privileges to allow them to spread their malware. The ransomware can lay dormant for weeks or months before being deployed to attack infected systems.

Small hospitals and health centers have become prime targets for ransomware attacks. This practice began before the COVID-19 pandemic but has become a larger problem with the increased focus on healthcare IT environments. Small institutions are targeted because they are more likely to pay the criminals to avoid any lapse in patient care. They are also often challenged to provide the level of IT security required to keep intruders away from their systems.

Even in the best of times, hospitals cannot afford for mission-critical systems to be unavailable. The loss of patient-centric systems can have severe repercussions on care that cannot be tolerated. In the midst of the pandemic, these issues take on even greater importance. Lives can be in the balance as the result of compromised systems and databases.

Backups are the Best Protection Against Ransomware

The critical nature of healthcare data assets makes it imperative that the responsible IT teams take all possible precautions to protect them. This protection demands a two-pronged approach consisting of measures to limit the possibility of infection and procedures to recover if an attack proves to be successful. Teams also need the ability to use backups to restore critical systems quickly while avoiding conceding to the ransom demands.

IDERA’s SQL Safe Backup protects your SQL Server environment from ransomware attacks by providing the backups required to recover the affected systems. The comprehensive backup application uses advanced backup compression, disk-writing, and multi-threading techniques to increase backup speed. This can be an important factor when backups need to fit into an aggressive time window.

Backups are secured with 128-bit and 256-bit AES encryption for additional data protection. You can also mirror backups to multiple locations during a backup operation. Advanced restore capabilities give your team flexibility when recovering from an emergency. Databases can be immediately restored to minimize downtime and you can choose to recover to any point-in-time.

The SQL Server platform is popular for databases in many industries including healthcare. It provides well-needed protection for the valuable data stored in your SQL Servers and should be added to the set of tools your database team has at its disposal. These days, you need to protect your data and yourself from the effects of COVID-19 and those who use it for unscrupulous purposes.