South Korea moves to deploy offensive cybersecurity after hospital data leaks | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Cases are mounting of patient examination videos circulating on illegal overseas websites and hospitals halting care after their computer networks are hit by ransomware. At the National Assembly audit, lawmakers said medical institutions that handle health care information—once leaked, hard to retrieve—are failing to keep up with the pace of attacks.

Jung Eun-kyeong, Minister of Health and Welfare, agreed with criticism that security levels at medical institutions are lacking during the Health and Welfare Committee’s audit on the 7th, saying, “There is clearly a limit in that we cannot keep up with the speed of the attackers.” The ministry said it will draw up a joint public-private response, including introducing “offensive cyber security” to proactively identify security vulnerabilities at medical institutions.

Minister Jung Eun-kyeong answers lawmakers’ questions during the National Assembly Health and Welfare Committee’s audit of the Ministry of Health and Welfare in Yeouido, Seoul, on the 7th./Courtesy of News1

That day’s audit presented a series of facts about cyberattacks targeting medical institutions, from leaks of medical information to suspensions of hospital care.

Heo Jong-sik of the Democratic Party of Korea said examination videos filmed at obstetrics and gynecology clinics and plastic surgery clinics are being distributed on illegal overseas websites. Heo said his office alone confirmed 80 cases that were referred to police for investigation, and the number of victims reached about 100.

Reports said some leaked videos exposed not only patients’ faces and the examined area but even hospital names. Heo said, “I don’t know who could feel safe going to a hospital,” noting that from a patient’s standpoint, it could become a lifelong trauma.

IP cameras connected to the internet are being cited as the cause of the video leaks. The Minister said, “We are verifying the leak route through a police investigation,” adding, “For now, IP cameras have been identified as the problem and need reinforcement.”

However, she explained that operating room video recordings are relatively better secured. The currently mandated recordings inside operating rooms are stored as closed-circuit television (CCTV) using a closed network, not internet-connected IP cameras.

Ransomware attacks targeting hospital networks are also increasing. According to Heo’s office, ransomware attacks on medical institutions rose from eight last year to 14 this year. At Kangwon National University Hospital, care was halted for 4 hours and 50 minutes due to a ransomware attack, and at Hwasun Chonnam National University Hospital, 298 cases of personal information were found to have been leaked.

Three disruptions also occurred this year on the National Emergency Treatment Information Network, which links emergency medical institutions nationwide. At the National Medical Center (NMC), recovery took up to 32 hours. There are concerns that if the emergency medical information network itself stops, beyond a single hospital’s system failure, it could affect patient care and emergency response.

Criticism also continued that medical institutions’ defense systems are not sufficient.

Han Ji-a of the People Power Party pointed to a 2021 case in which a North Korean hacking group infiltrated Seoul National University Hospital and leaked the health care information of about 830,000 people, saying the cyber security response of agencies under the ministry remains vulnerable.

According to Han, 16.7% of 263 general hospitals, including tertiary general hospitals, had no information security budget at all. The average number of information security personnel per medical institution was just 0.9.

Han especially took issue with national university hospitals, which were transferred to the ministry this year, being excluded from regular security audits. She noted that despite the ministry’s security support, information leaks and business paralysis due to ransomware occurred at Chonnam National University Hospital and Kangwon National University Hospital, respectively.

What Han proposed is “offensive cyber security.” The approach uses security experts or artificial intelligence (AI) to identify system vulnerabilities in the same manner as real-world attacks and fix them in advance.

Han said, “You can at least change a resident registration number, but genomic and human body information are irreversible once leaked,” and called for prioritizing the introduction of offensive cyber security at national university hospitals, the National Health Insurance Service, and the Health Insurance Review & Assessment Service (HIRA).

The Minister also said she would review ways to secure security personnel and budgets for medical institutions. After asking the Korean Medical Association Organization and the Korean Hospital Association to conduct and strengthen their own security checks at private medical institutions, she said the ministry will prepare measures to bolster security, including offensive cyber security.

The Minister said, “I fully agree with the assessment that the security of sensitive health care information is severely lacking,” adding, “We will prepare and report an effective security reinforcement plan, including ways to secure specialized personnel and budgets.”

※ This article has been translated by AI. Share your feedback here.

——————————————————–


Click Here For The Original Source.

.........................