Cyberattacks on care homes and healthcare facilities
Quick reply
Ransomware, phishing, drive-by downloads: the attacks aimed at hospitals and care homes, what they cost, and the defences to put in place.

In France as elsewhere, protecting data in healthcare facilities has become a major concern. Cyberattacks carried out by malicious actors keep increasing day after day. Between information systems paralysed, connected medical devices shut down and personal data stolen, the harm these attacks cause is widespread and severe. NetExplorer explains the essentials of what you need to know about the phenomenon, and offers an effective way to keep your healthcare facility safe from attack.

The rise of cyberattacks in healthcare facilities
In France, four healthcare facilities are reportedly hit by cyberattacks every day. Most of those attacks are rudimentary, but the ones considered more "elaborate" are said to happen once a week. According to a recent study, attacks against hospitals and health centres rose by more than 45%, against 22% in other sectors. In 2019, for instance, healthcare facilities in Montpellier, Saint-Denis and Condrieu faced serious attacks (ransomware, laboratory results blocked, banking malware and so on).
The rise in attacks across health and hospital settings can be explained by the particular circumstances of Covid-19. The pandemic left hospitals and health centres very vulnerable. The constant flow of Covid-19 patients, on top of the usual load, brought stress and fatigue to healthcare staff, which led to less vigilance around IT security and so made malicious intrusions easier. Those behind the attacks also reckon that during a health crisis, hospitals will be more inclined to pay a ransom in order to keep working.
Finally, the budgets care homes, hospitals and health centres devote to cybersecurity are small. Attackers therefore take advantage of the weaknesses in their data storage systems to carry out various kinds of attack.
The attacks aimed at health centres
There are many kinds of cyberattack directed at care homes, hospitals and healthcare facilities. Each follows its own particular method.
Ransomware
Ransomware is malicious software that holds a healthcare facility's data hostage until a ransom is paid. Using it, attackers block access to your data and then threaten to delete it or make it public.
Ransomware encrypts your content in whole or in part, making it unusable without the decryption key. Attackers using this technique generally demand that the ransom be paid in cryptocurrency (bitcoin, for instance).
Phishing
This attack combines technical skill with social engineering. It involves sending emails that look as though they come from trustworthy sources, in order to collect personal data. Phishing attacks can be concealed inside an email attachment.
Attackers can also persuade you to follow a link pointing to an illegitimate website, which usually holds malicious software that can be used to steal the personal and confidential data of your hospital's patients.
Man-in-the-middle attacks
This method involves intercepting encrypted exchanges between two people or two computers in order to decode what they contain. The attacker receives the messages from both parties and replies to each of them while posing as the other.
Drive-by downloads
Also known as drive-by download, this is a common technique for spreading malware. Attackers hack unsecured websites by inserting a script into the HTTP or PHP code of one of the pages. The aim is to install viruses directly onto the computer of someone visiting the site, through a download they never asked for.
There are other kinds of cyberattack too, such as:
- password cracking,
- SQL (Structured Query Language) injection,
- cross-site scripting,
- eavesdropping,
- attacks on medical devices and records.
Whatever method is used, a cyberattack can have serious and damaging consequences for the healthcare facilities that fall victim to one. That is why it matters to have an effective solution such as the one NetExplorer offers to protect your facility's data.

The consequences of cyberattacks on care homes and healthcare facilities
The consequences of attacks aimed at hospitals and health centres take several forms.
Significant financial damage
Cyberattacks can cause healthcare facilities to lose income. Some attacks also carry a risk of inflated telephone charges. Attackers may equally demand a substantial sum as a ransom before restoring your IT systems.
Hospital operations paralysed
An attack can have a heavy impact on your information system and serious repercussions for your patients. In September 2020, for instance, a cyberattack on the university clinic in Düsseldorf, Germany, led to tragedy: the attack compromised the functioning of the hospital's connected devices. A patient who needed emergency surgery had to be transferred to another facility, and died during the journey.
In the same way, on 9 February 2021, around 70 patients being treated by the radiotherapy department at Dax hospital had to be redirected to other health centres, because a cyberattack had made treatment impossible. Since the hospital's equipment sterilisation and catering procedures are heavily computerised, those were disrupted too.
Cyberattacks on health systems can also cause appointment booking systems to fail.
Damage to healthcare facilities' reputation
Attackers quite often publish patients' medical, banking or financial data on the dark web. That reflects badly on the hospital and harms its reputation. Your patients or residents could also lose confidence in you and turn to other healthcare facilities.
The NetExplorer solution for avoiding cyberattacks
Even though cyberattacks against care homes and healthcare facilities are becoming routine, it is possible to avoid them by investing in protecting your data. To that end, we recommend the NetExplorer solution. This secure French cloud lets you store any kind of file, whatever its size or its format.
With this solution, all of your data is stored online on a single platform that is simple to use. You get several security guarantees, such as two-factor authentication, which makes your healthcare facility's data harder still to breach.
NetExplorer also holds ISO 27001, PCI DSS and HDS (Health Data Hosting) certification and complies with the GDPR. It therefore guarantees maximum protection for your patients' data, along with watertight confidentiality and the integrity of the information stored and shared.
With NetExplorer, all of your data is finally encrypted in full and scanned by our premium anti-virus. Your database is therefore protected against ransomware, malware and every other kind of attack.
Other articles you might like
Strengthening your resilience against cyberattacks
Ransomware and human error: the technical and organisational levers that build resilience and let you react quickly after an incident.


But let's be honest, our cloud-based file storage and sharing solution is much easier.


