How can you protect your pharmacy from cyber crime?

4 min read

In January, England’s biggest NHS trust had a major problem. But the crisis facing bosses at Barts Health NHS Trust in London had nothing to do with winter pressures, overstretched A&E services or chronic underfunding.

Instead, staff arrived at work to find their entire IT system had been crippled by a cyber attack – an online assault by criminal hackers using a computer virus to try and copy, steal or block access to confidential data.

The trust was forced to shut down large sections of its system for four days, while support specialists tried to iron out the glitches. The offending virus was identified as ‘Trojan malware’ – a type of cyber weapon that tricks the user into installing the malicious software, which crooks can then use to copy or even alter sensitive data.

IT experts at the trust said they had never come across the virus in question. But they insisted no confidential medical records had been accessed.

Nevertheless, it was a chilling reminder that no one is safe in the battle against cyber crime, and that online criminals are just as likely to attack NHS organisations as corporate giants. Last October, Northern Lincolnshire and Goole NHS FoundationTrust had to cancel nearly 3,000 appointments and shut down its systems for several days after an attack involving ‘ransomware’ – where attackers ‘freeze’ data until the victim pays a ransom, usually via the digital currency Bitcoin.

But what do these stories have to do with community pharmacy? Many pharmacies are small, local businesses employing a handful of people and with relatively limited amounts of data to steal. Cyber criminals are unlikely to be interested in them as targets, right?

Wrong. A survey by professional services company Accenture UK, published on April 25, found that one in eight consumers in England have had their personal medical information stolen – with pharmacies most at risk.

This isn’t a new problem. A 2014 report by the Pharmacy Board of Australia found that at least 10 pharmacists across the country had been targeted by hackers in the space of just 18 months, in a mini-epidemic of what officials described as ‘financial terrorism’. Criminals had used ransomware to plant viruses on pharmacy IT systems, which then encrypted all the data so that it became completely inaccessible.

All victims were ordered to pay large ransoms in order to regain access to their systems. Some refused and restored data using old back-ups, but it’s not clear how many actually paid up. There was a similar spate of ransomware attacks on German pharmacies last year, as hackers attempted to cash in on the move towards digital records.

Jonathan Lee, healthcare sector manager for digital security provider Sophos UK, says it would be a huge mistake for any pharmacy to think they are safe. “Organisations of all sizes are suffering from cyber attacks, so community pharmacies are just as at risk as any other organisation,” he warns.

“We receive and analyse 400,000 previously unseen [types of cyber menace] each day, so the threat is significant. And [pharmacists] should understand that confidential patient data is potentially at risk if best practice is not followed and adequate protection is not put in place.“

Take ransomware, for example. “The producers of ransomware aren’t just idly waiting for their bit of malware to hit its target,” says Mr Lee. “They work in professional teams, constantly updating and enhancing new variants of ransomware – and if you’re caught, the consequences can be severe.”

Mr Lee says crooks have had great success with ransomware, as it hijacks files and ‘locks them up’ using unbreakable encryption. “So if you don’t have preventative measures in place and get hit with ransomware, one way or another you will end up paying the price.

“This will either be through loss of data, or loss of being able to function properly whilst you restore [data] from back-ups.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at chemistanddruggist.co.uk →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.