Cyber Hygiene in the Health Sector
IN THE
HEALTH
SECTOR
PROTECT YOUR SYSTEMS & MEDICAL SERVICES CYBER HYGIENE PRACTICES
1/ PROTECT YOUR SYSTEMS & MEDICAL DEVICES Health entities across Europe are increasingly reliant on digital solutions - from electronic health records and telemedicine to connected medical devices and AI-powered diagnostics. This digital transformation also brings greater exposure to cyber threats such as ransomware, phishing and the exploitation of system
2/ PROTECT YOUR NETWORKS
vulnerabilities, which can disrupt critical services, compromise patient safety, and undermine trust.
Fortunately, many of these risks can be mitigated through relatively
3/ MIND THE SECURITY OF SMARTPHONES & E-CARE
straightforward measures, including regular system updates, secure backup management, and multi-factor authentication, which can prevent the vast majority of common cyberattacks.
4/ KEEP PATIENT RECORDS SAFE
This booklet, developed by ENISA, provides clear and targeted guidance with practical steps that health entities can take to:
5/ TAKE INCIDENTS SERIOUSLY ♦ Safeguard sensitive data
♦ Minimise exposure to common cyber threats 6/ MANAGE THE ICT SUPPLY CHAIN ♦ Strengthen overall cyber resilience.
This guidance is intended for both large hospitals and healthcare providers, as well as smaller entities, such as specialist clinics and General Practitioners, which 7/ CYBER-EDUCATE YOUR STAFF often lack the resources but remain equally vulnerable to cyber-attacks.
8/ PHYSICAL SECURITY PROTECT YOUR SYSTEMS & MEDICAL SERVICES KNOW YOUR SECURE SYSTEM ACCESS CONTROL ICT ASSETS CONFIGURATIONS
♦ Manage system and software settings. ♦ Change default passwords. ♦ Manage and monitor administrative privileges.
♦ Scan and monitor all connected systems ♦ Disable unnecessary ports and services. ♦ Apply the least privilege principle. and devices. ♦ Uninstall unnecessary software. ♦ Enforce strong passwords and consider ♦ Label and ringfence providing a password manager to employees. legacy systems. ♦ Require multi-factor authentication (MFA) especially for online accessible systems.
CYBER HYGIENE IN THE HEALTH SECTOR 3 PROTECT YOUR SYSTEMS & MEDICAL SERVICES MALWARE BACKUPS OF STAY UP-TO-DATE PROTECTION AND CONFIGURATIONS, SECURITY LOGGING SOFTWARE AND DATA
♦ Install the latest security patches ♦ Deploy malware protection solutions. ♦ At least one backup copy must be ransomware on all devices. resilient or offline. ♦ Allow only authorised apps and software. ♦ If it can’t be patched, ringfence it. ♦ Perform integrity checks. ♦ Review logs for failed login attempts, privilege ♦ Enable automatic periodic updates on any escalations, and malware alerts. ♦ Test backup restoration. system that is not critical or vendor-restricted. ♦ Be aware of data retention periods. ♦ Scan all systems and devices for unpatched vulnerabilities and outdated software.
PROTECT YOUR SYSTEMS & MEDICAL SERVICES PROTECT YOUR NETWORKS CORPORATE HARDEN YOUR FORTIFY EMAIL SECURE WI-FI NETWORKS INTERNET ACCESS PROTECTION
♦ Use secure network protocols. ♦ Enable hosted spam / phish ♦ Use latest wireless encryption ♦ Deploy next-gen firewalls.
filtering. standards. ♦ Apply network segmentation. ♦ Apply web application filters.
♦ Turn on attachment & link ♦ Isolate guest Wi-Fi from clinical ♦ Have 24/7 flow monitorig & ♦ Shield your internet facing systems scanning (sandbox / safe links). LAN. alerting. with Web-Application Firewall (WAF)
♦ Enforce secure protocols to block ♦ Hide SSIDs for sensitive internal and DDoS mitigation service.
domain spoofing. networks. ♦ Enforce the use of VPN and MFA
♦ Create strong Wi-Fi passwords. when off-site.
CYBER HYGIENE IN THE HEALTH SECTOR 5 MIND THE SECURITY OF SMARTPHONES & E-CARE MIND THE SECURITY OF ENABLE SECURE MOBILE USE PATIENT OPERATED DEVICES
♦ Design controls to ensure that no lasting harm occurs when the device is ♦ Allow the installation of approved apps only. lost, stolen, or misused. ♦ Enable remote-wipe if device is lost. ♦ Use strong individual credentials. ♦ Enforce strong passwords and encryption of sensitive data. ♦ Enforce auto-logout and wipe browser/app data in case of inactivity. ♦ Apply a 30-second automatic device lockout. ♦ Provide clear security recommendations.
MIND THE SECURITY OF SMARTPHONES & E-CARE KEEP PATIENT RECORDS SAFE CLASSIFY & PROTECT LOG AND MONITOR SAFEGUARD DEVICES & DATA
♦ Identify sensitive data. ♦ Log and monitor all access to health records. ♦ Never leave devices unattended. ♦ Tag data based on sensitivity levels. ♦ Check systems for unauthorised access or ♦ Enforce a clean-desk/ clear-screen policy. data leaks. ♦ Encrypt data at rest and in transit. ♦ Secure printing of data. ♦ Alert on unusual activity. ♦ Implement metadata cleaning processes. ♦ Secure asset lifecycle (disposal or reuse). ♦ Verify vendor SLAs for cloud EHR & hosted apps. ♦ Ensure patient data access in an emergency.
CYBER HYGIENE IN THE HEALTH SECTOR 7 TAKE INCIDENTS SERIOUSLY OPERATIONAL BE PREPARED DISASTER RECOVERY COLLABORATION
♦ Establish an incident response process. ♦ Establish collaboration with suppliers, ♦ Unplug equipment safely if there’s smoke,
Managed Security Service Provider, other water, or power issues. ♦ Create a team and assign roles and responsibilities. hospitals and peers. ♦ Use critical devices with an uninterruptible ♦ Know and communicate who to contact in case ♦ Contact your national CSIRT or supervising power source. of a cyber incident. authority in case of a relevant incident and ♦ Test UPS/generator fail-over. ♦ Plan for the worst-case scenario. follow their instructions.
♦ Include floods, fires or power outages in your ♦ Perform vulnerability scans and penetration tests. Data Center Recovery Plan.
TAKE INCIDENTS SERIOUSLY MANAGE THE ICT SUPPLY CHAIN PROCURE SECURELY SUPPLIER RELATIONSHIP
♦ Involve IT department. ♦ Restrict access to minimum necessary and secure dedicated remote connections. ♦ Include security requirements at the earliest stage. ♦ Define incident reporting and establish procedures for incident response. ♦ Verify supplier compliance with standards. ♦ Know who to contact for security issues relating to suppliers. ♦ Ensure the security of onboarding and offboarding procedures of suppliers through the SLA agreement.
CYBER HYGIENE IN THE HEALTH SECTOR 9 CYBER EDUCATE YOUR STAFF AWARENESS ACTIVITIES TRAINING ACTIVITIES STRATEGY
♦ Train by role. ♦ Phishing simulations. ♦ Ransomware simulation. ♦ Adapt content to audience. ♦ Intranet pages, staff newsletters. ♦ Gamified quiz about cybersecurity. ♦ Use peer-to-peer learning. ♦ Learning sessions. ♦ Cybersecurity exercises. ♦ Train the trainers. ♦ Awards. ♦ Case studies. ♦ Make it practical. ♦ Escape room. ♦ Document training courses.
CYBER EDUCATE YOUR STAFF PHYSICAL SECURITY SECURE WORKSPACES & FACILITIES PERIMETER
♦ Make sure staff and contractors always wear a badge. ♦ Physically secure devices, cables & USB sticks. ♦ Maintain intrusion alarms. ♦ Use fire suppression. ♦ Log every entry and exit. ♦ Check heating, ventilation and air conditioning (HVAC). ♦ Encourage approaching persons that do not seem authorised to physically ♦ Know where the emergency exits and fire alarms are. access an area. ♦ Audit camera coverage and store 30 days of footage.
CYBER HYGIENE IN THE HEALTH SECTOR 11 ABOUT ENISA
The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certification schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost resilience of the Union’s infrastructure, and, ultimately, to keep Europe’s society and citizens digitally secure. More information about ENISA and its work can be found here: www.enisa.europa.eu.
Catalogue number: TP-01-25-024-EN-N ISBN: 978-92-9204-720-7 DOI: 10.2824/3818935
ENISA
European Union Agency for Cybersecurity
Athens Office
Agamemnonos 14 Chalandri 15231, Attiki, Greece
Heraklion Office
95 Nikolaou Plastira 700 13 Vassilika Vouton, Heraklion, Greece
Brussels Office
Rue de la Loi 107 1049 Brussels, Belgium