Go to:
Logótipo
Você está em: Start > Publications > View > Economic Impact of a Hospital Cyberattack in a National Health System: Descriptive Case Study
Map of Premises
Principal
Publication

Economic Impact of a Hospital Cyberattack in a National Health System: Descriptive Case Study

Title
Economic Impact of a Hospital Cyberattack in a National Health System: Descriptive Case Study
Type
Article in International Scientific Journal
Year
2023
Authors
Portela, D
(Author)
Other
The person does not belong to the institution. The person does not belong to the institution. The person does not belong to the institution. View Authenticus page Without ORCID
Nogueira Leite, D
(Author)
Other
The person does not belong to the institution. The person does not belong to the institution. The person does not belong to the institution. Without AUTHENTICUS Without ORCID
Almeida, R
(Author)
Other
The person does not belong to the institution. The person does not belong to the institution. The person does not belong to the institution. Without AUTHENTICUS Without ORCID
Ricardo Cruz Correia
(Author)
FMUP
View Personal Page You do not have permissions to view the institutional email. Search for Participant Publications View Authenticus page View ORCID page
Journal
ISSN: 2561-326X
Other information
Authenticus ID: P-00Y-QZH
Resumo (PT):
Abstract (EN): Background: Over the last decade, the frequency and size of cyberattacks in the health care industry have increased, ranging from breaches of processes or networks to encryption of files that restrict access to data. These attacks may have multiple consequences for patient safety, as they can, for example, target electronic health records, access to critical information, and support for critical systems, thereby causing delays in hospital activities. The effects of cybersecurity breaches are not only a threat to patients' lives but also have financial consequences due to causing inactivity in health care systems. However, publicly available information on these incidents quantifying their impact is scarce.Objective: We aim, while using public domain data from Portugal, to (1) identify data breaches in the public national health system since 2017 and (2) measure the economic impact using a hypothesized scenario as a case study.Methods: We retrieved data from multiple national and local media sources on cybersecurity from 2017 until 2022 and built a timeline of attacks. In the absence of public information on cyberattacks, reported drops in activity were estimated using a hypothesized scenario for affected resources and percentages and duration of inactivity. Only direct costs were considered for estimates. Data for estimates were produced based on planned activity through the hospital contract program. We use sensitivity analysis to illustrate how a midlevel ransomware attack might impact health institutions' daily costs (inferring a potential range of values based on assumptions). Given the heterogeneity of our included parameters, we also provide a tool for users to distinguish such impacts of different attacks on institutions according to different contract programs, served population size, and proportion of inactivity. Results: From 2017 to 2022, we were able to identify 6 incidents in Portuguese public hospitals using public domain data (there was 1 incident each year and 2 in 2018). Financial impacts were obtained from a cost point of view, where estimated values have a minimum-to-maximum range of euro115,882.96 to euro2,317,659.11 (a currency exchange rate of euro1=US $1.0233 is applicable). Costs of this range and magnitude were inferred assuming different percentages of affected resources and with different numbers of working days while considering the costs of external consultation, hospitalization, and use of in-and outpatient clinics and emergency rooms, for a maximum of 5 working days.Conclusions: To enhance cybersecurity capabilities at hospitals, it is important to provide robust information to support decision-making. Our study provides valuable information and preliminary insights that can help health care organizations better understand the costs and risks associated with cyber threats and improve their cybersecurity strategies. Additionally, it demonstrates the importance of adopting effective preventive and reactive strategies, such as contingency plans, as well as enhanced investment in improving cybersecurity capabilities in this critical area while aiming to achieve cyber-resilience.
Language: English
Type (Professor's evaluation): Scientific
No. of pages: 7
Documents
We could not find any documents associated to the publication.
Related Publications

Of the same journal

Usability and Utility of a Mobile App to Deliver Health-Related Content to an Older Adult Population: Pilot Noncontrolled Quasi-Experimental Study (2024)
Article in International Scientific Journal
Lemos, M; Henriques, AR; Lopes, DG; Mendonça, N; Victorino, A; Costa, A; Arriaga, M; Gregório, Maria João; de Sousa, R; Canhão, H; Rodrigues, AM
Pregnant users' perceptions of the birth plan interface in the "my prenatal care" app: Observational validation study (2019)
Article in International Scientific Journal
Carrilho, JM; Oliveira, IJR; Santos, D; Osanan, GC; Ricardo Cruz Correia; Reis, ZSN
Fast Healthcare Interoperability Resources-Based Support System for Predicting Delivery Type: Model Development and Evaluation Study (2024)
Article in International Scientific Journal
Coutinho-Almeida, J; Cardoso, A; Ricardo Cruz Correia; Pereira-Rodrigues, P
Effectiveness of Secondary Risk¿Reducing Strategies in Patients with Unilateral Breast Cancer with Pathogenic Variants of BRCA1 and BRCA2 Subjected to Breast-Conserving Surgery: Evidence-Based Simulation Study (2022)
Article in International Scientific Journal
Maksimenko, J; Pedro Pereira Rodrigues; Nakazawa Mikla¨evi¿a, M; Pinto, D; Mikla¨evi¿s, E; Trofimovi¿s, G; Gardovskis, J; Cardoso, F; Cardoso, MJ
Promoting digital proficiency and health literacy in middle-aged and older adults through mobile devices with the workshops for Online Technological Inclusion (OITO) Project: experimental Study (2023)
Article in International Scientific Journal
Anna Quialheiro; André Miranda ; Miguel Garcia Jr; Adriana Camargo de Carvalho; Patrício Costa; Margarida Correia-Neves; Nadine Correia Santos
Recommend this page Top
Copyright 1996-2025 © Faculdade de Medicina Dentária da Universidade do Porto  I Terms and Conditions  I Acessibility  I Index A-Z
Page created on: 2025-08-21 at 17:38:34 | Privacy Policy | Personal Data Protection Policy | Whistleblowing | Electronic Yellow Book