I'm Mary Ann Colbessette-McGee, executive editor at Information Security Media Group. Today I'm speaking with healthcare attorney David Hoffman, an assistant professor of bioethics at Columbia University's School of Professional Studies. David is also general counsel, where he also oversees compliance for Claxton Hepburn Medical Center in New York. Hi, David.
Hello. So, David, as you know, we're seeing cybercriminals hitting many, many hospitals as well as other healthcare entities with ransomware encryption, data exfiltration, and other types of attacks. These criminals try to extort payments from the hospitals for decryptor keys, the supposed return or deletion of stolen patient information, and other promises. And in some cases, we're even seeing cybercriminals directly shaking down patients for ransoms in order to remove their sensitive data from the dark web.
Lately, there have also been some reports of hackers trying to extort patients directly, threatening them with swatting. So, you know, with all of this said, what do you make of these evolving and ongoing cybercrime developments, both from the standpoint of being a healthcare attorney but also a bioethicist? It's terrible is the short answer. This is a demonstration of the rule that no good deed goes unpunished.
We have created a healthcare delivery system that utilizes and maximizes the benefit of electronic commerce and interaction, the electronic medical record, patient portals, many other modalities that have substantially enhanced patient care, but at the cost of just insurmountable set of responsibilities for keeping all of that data safe while there are threat actors, bad guys, probably bad gals too, who are looking to exploit this openness in order to profit in a decidedly criminal manner. So it is really our desire to use all of these electronic tools to benefit healthcare that is being used against us. And it's a very, very serious problem, especially for smaller organizations that can't afford the elaborate and sophisticated either internal IT infrastructure to protect data or external consultant organizations, of which there are many, but which are very expensive. So, David, I understand that you're concerned about cryptocurrency being the new Swiss bank accounts for cybercriminals.
What do you mean by that? And what do you think should be done to stop these sorts of cybercriminal activities that are being supported and fueled through cryptocurrency? I've been concerned about the anonymous nature of our cryptocurrency global infrastructure for a very long time, both from an operational legal perspective and from an ethical perspective. But having now been through, and I'm happy to report survived, a ransomware cyber attack, I'm frankly enraged that as a society, as a global society, we have endorsed and in fact promoted the availability of anonymity in cyber currency transactions.
For generations, Swiss bank accounts, numbered anonymous Swiss bank accounts, were the pre-electronic revolution means of engaging in financial transactions where the parties could remain anonymous. And over the course of recent decades, even Switzerland recognized that that was an untenable business model for the Swiss banking system. And they eliminated anonymous numbered Swiss bank accounts. And then what did we turn around and do?
We recreated that same problem on steroids in a way that it has facilitated these ransomware attacks and lots of other criminal activities. You can now hire someone to commit murder using cyber currency to pay for the service. And it is difficult and impossible in some cases to trace where the payment came from. That's a conscious decision that we made as a global community and one which I think in light of the recent attacks on a whole range of infrastructure, both ransomware attacks and outright malicious destructive attacks, we need to rethink whether this serves a sufficiently beneficial purpose, this notion of anonymous cyber currency transactions that we ought to tolerate.
It would be impossible for these criminal organizations, most if not all of which are located outside of the U.S. jurisdiction, such that U.S. law enforcement has a very hard time trying to track them down and bring them to justice. We have to think about whether we ought to tolerate the anonymous component of cyber currency transactions.
Because for the longest time, the cybercriminals were fairly sophisticated and took a slightly longer view about who they would attack and how they would attack. Hospitals, for example, ransomware organizations like LockBit had an explicit publicly disclosed policy that they would not attack healthcare organizations, hospitals. And they did that not for altruistic reasons. Let's not lose sight of the fact that these people are criminals.
They did it because they didn't want to draw unnecessary attention to themselves and enforcement activities. Likewise, ransom demands were typically titrated in order to be just enough that the organization could afford the ransom, but not so much that it would motivate an enormous investment of time and money to build cyber defenses. That has changed in large measure because of the ubiquity of cybersecurity, Bitcoin and the like, so that cybercriminals, I guess because they perceive that hospitals are good targets, have taken the position that hospitals are as at risk as any other organization from a business perspective, if you think of these criminals as being business people, for good reason. Most businesses, most operations, can shut down for a period of time to flesh out a cyber attack and reboot their systems and build new defenses when an attack occurs.
Hospitals can't do that. And the criminals know that. So they know that when they successfully launch a ransomware attack, the hospital has both a legal, ethical, and practical obligation to pursue restoring the ability to provide services as quickly as possible with no downtime in the flow of patients to the front door. That, frankly, makes us really kind of excellent targets.
And that's a problem. So now, David, as I mentioned in the intro, you're general counsel for Claxton Hepburn Medical Center in upstate New York, which along with its sister hospital, Carthage Area Hospital, and the affiliated North Country Orthopedic Group, which are collectively members of North Star Health Alliance, those entities were hit last summer with a ransomware attack by LockBit threat actors. And then the hospitals recently filed a lawsuit against unnamed LockBit threat actors as a means to get a cloud-based storage vendor to return the patient data that was stolen in that attack back to the hospitals so that the hospitals could proceed with analysis of the effective data and breach notifications, so on and so forth. What's the latest with that?
Why did these hospitals file the lawsuit? And what's been happening with that? Can you give us an update? Absolutely.
We filed a lawsuit against John Doe and Jane Doe, fictitious individuals representing the human beings who run the LockBit criminal syndicate, in order to have a vehicle for issuing a judicial subpoena, a legal request to the cloud-based service provider to, in effect, give us back the information that the bad guys, the LockBit criminals, were able to exfiltrate, to actually remove from our IT infrastructure and deposit on the cloud-based storage servers so that we would have a clear and certain understanding of what information left our organization's IT infrastructure and what of that information then left the cloud-based provider's platform so that it was potentially in the possession of the bad guys. And that was successful. We were able to work with the legal staff of the cloud-based provider in order to get copies of that information back. We are currently in the process of analyzing that information to determine which of our patients were affected and what information left our control so that we can take appropriate steps to protect the privacy interests of our patients.
So this is both a risk management concern, obviously, but it's also an ethical concern from the perspective of our obligation to our communities to do everything we can to, on the one hand, give them easy access to their information through patient portals, but on the other hand, protect their privacy from threat actors like LockBit. So we're in that process now. And without having retrieved that information from the cloud storage provider, we would not with certainty be able to know what exactly left our control and what exactly went from the cloud-based servers to the threat actors. Based on the data that you've seen so far that was impacted, any sense of how many people were involved, what sort of data, and what sort of advice do you have for other entities that are going through similar situations where they know their data was exfiltrated and perhaps they know or they don't know where that data is?
How do they find out where that data is and what should they do? Should they take similar actions? Well, we are currently in the process of analyzing the data, so we don't yet know how many people's information was impacted, but we're working through that right now, again, both for legal compliance reasons, right? HIPAA requires notification to individuals whose information was subject to a breach.
And also because it is part of our ethical obligation to our community to protect them from the negative impact of these criminal actions by the LockBit syndicate. You know, the decisions that have to be made once you learn that you have been subject to a ransomware attack are overwhelming if you are not well prepared for the event. We were fortunate in that we had backup systems. We had all of our data backup and were able to successfully restore from the backup nearly all of the information in our systems.
And that's important because if you can't restore your systems from backup, it makes the calculation whether you ought, normatively, to pay the ransom or not much more difficult, much more gut-wrenching because hospitals, especially ones that serve rural areas, can be shut down for weeks and months where patients have nowhere else to turn. So that's the problem. So clearly, you know, the issue is preparation and then you just have to hope that your systems hold, that they're effective, and that the technology involved in both storing the data and then restoring the data to the IT infrastructure comes off without a hitch. There are lots of handoffs that are invisible that you expect and plan for them to work, but they don't always work.
And that's one of the other considerations that every organization has to contemplate from an organizational ethics perspective to plan out ahead of time what will we do if everything in our response to the cyber event goes as planned and what are we going the resource you have available to fulfill your mission, in the case of hospitals, providing patient care. And that's tricky, and it requires a team that can come together quickly, that knows what is going to happen on day 1, day 2, and farther down the line, so that you're acting in a responsible and coordinated fashion. So how soon after you filed the lawsuit did the cloud-based vendor return the data for you to then begin to assess? And do you think you would have gotten that if you hadn't filed the lawsuit?
Well, so we asked the cloud vendor directly, and they said that they couldn't release the data without some court order, without some court-based subpoena, because they have their own business and ethical concerns that they have to be mindful of. For one thing, they need to know for sure what it is we're asking for, and with a sufficient level of legal clarity that they are giving us everything that we believe we're entitled to and nothing more. There is always the issue of the information not being immediately readily identifiable as belonging to one organization versus another. I'm fond of telling my students that the difference between a bicycle and a computer is that you can look at a bicycle and see all of the parts and understand how they're supposed to work, and from that, figure out what's not working.
Computer is just the opposite, right? It is literally a black metal box, mostly black, that performs all of its functions in a manner that is invisible to the human eye. So in the case of our request to have our data returned to us, we needed to be able to supply the cloud service provider with sufficient information that they could identify all of our information and none of anyone else's information, because they have their own obligations, both business, legal, and ethical to their customers to maintain privacy and confidentiality of that data. And because it's all just computer files, right, zeros and ones, actually ascertaining what is appropriate and responsive to a subpoena and what is not is its own tricky task.
And to that, the fact that we needed this information in a hurry so that we could give notification to our patients, our customers, as it were, as quickly as possible. So I can't remember off the top of my head how long it was from the filing of the lawsuit until we actually received the data back, because there are lots of interactions at the technical level, the hospital's IT staff and the cloud service provider's legal and forensic staff. But they responded as quickly as they could, and we were very happy with how they handled our request. I don't fault them for a moment, by the way, for insisting that there be some legal process by which they were handing over the information, because that gives them assurance that they're doing everything that they ought to be doing and nothing more.
And David, originally the lawsuit, the reason for the lawsuit was to have that legal means for the cloud-based server company to return the data, but the lawsuit itself was against the unnamed lockbit actors. What's going to happen from there? Do you think you'll have any luck in hearing back from anybody representing lockbit? Do you withdraw the lawsuit?
What happens with that? I have no expectation that lockbit will ever respond to the lawsuit. I'm not sure that they even know that it occurred, and I suspect that they just don't care. What will happen is once we are sure in working with the cloud-based service provider that we have everything that we need, the lawsuit will be discontinued because there's no purpose in keeping it clogging up the court system's calendar unless we learn something that suggests that we might be able to identify one or more individuals.
One of the decisions that we made that is so controversial is that we immediately notified law enforcement, the FBI, the New York State Department of Health, the New York State Office of Homeland Security, to let them know that we had been attacked and to ask for their assistance in identifying where, if anywhere, any of our data has gone. Those cooperative efforts continue to this day, and we may at some point through other channels that law enforcement has available to it that I'm not aware of be able to identify some of the actual human beings behind the lockbit syndicate. But as I said, I'm not expecting that, and I'm not expecting it anytime soon if it happens at all. And finally, David, what other cyber issues facing the healthcare sector in 2024 are you most concerned about and why?
From a clinical ethics perspective, what I'm most concerned about because of both the frequency and the severity of the events is intentional misuse of data which an individual, whether it is a healthcare provider or a service provider to a healthcare company, misuse of their approved and appropriate access to data where patients don't know where their information is going. It is an interesting conceptual question. It's a conceptual question, again, in philosophical terms, both in terms of epistemology, how we know what we know to be true, and metaphysics, the notion of what is the physical object that is the electronic medical record. It's an interesting question, who owns a patient's electronic medical record.
Before the advent of electronic commerce in healthcare, it was pretty clear. The medical record as a physical object, the paper that was in the folder that was kept in the office of a clinician, doctor, therapist, other healthcare professionals or an organization, that paper was owned by the organization, but the knowledge, the data contained within that record, were owned or were subject to the control of the patient. Well, that entire construct has been turned on its head by the electronic medical record where you can transfer one patient's medical information or 10 million patients' medical information every bit as easily. And so the notion of who should have control over the mechanism of distribution of a patient's medical information is the new and important question that we as a healthcare delivery system and as a society need to be confronting.
Well, thank you so much, David. I've been speaking to attorney David Hoffman. I'm Marianne Kolbasak-McGee of Information Security Media Group. Thanks for joining us.