HCAD 670 UMGC Ransomware Attack on Universal Health Services Memorandum

HCAD 670 Assignment 8: Cyberattack on Universal Health Services, Inc., 2018

Instructions

Ransomware is a type of malware from crypto virology that threatens to publish the victim’s data or perpetually block access to it unless a ransom is paid. While some simple ransomware may lock the system so that it is not difficult for a knowledgeable person to reverse, more advanced malware uses a technique called crypto viral extortion. It encrypts the victim’s files, making them inaccessible, and demands a ransom payment to decrypt. Ransomware attacks are typically carried out using a Trojan disguised as a legitimate file that the user is tricked into downloading or opening when it arrives as an email attachment. International law enforcement authorities during the height of the pandemic warned that hospitals and healthcare facilities in multiple countries were being targeted in ransomware attacks.

Often a ransomware attack is the first phase of a multistage extortion attempt from cybercriminals. Criminals routinely demand millions of dollars to unlock the encrypted systems and then follow that up by threatening to publish stolen data on the internet if they are not paid a second time.

On September 28, 2020, until October 7, 2020, Universal Health Services, which runs more than 400 healthcare facilities in the United States and the United Kingdom, has more than 90,000 employees and cares for about 3.5 million patients each year, had its IT network hit by a ransomware attack which left a number of its hospitals in the United States without access to computer and phone systems, including facilities in California, Florida, Texas, Arizona and Washington, D.C.

The ransomware attack managed to disable multiple antivirus programs in place on the targeted systems. Once the antivirus software was disabled, the malware caused the computers to log out and shut down, and if administrators attempted to reboot these systems, they simply shut down again. With their systems shut down, clinicians were unable to access vital information, including data found in their Electronic Health Record (EHR) or picture archiving and communication system (PACS) system.

Your assignment:

In a MEMO format, in 1000-1200 words, please discuss the following about the Universal Health Services (UHS) Ransomware attack of September 2020:

What went well with the response? What were the significant challenges with the response? In which ways could the response have been improved?

During Week One, we discussed Fayol’s Five Functions of Management: (a) Planning, (b) organizing, (c) coordinating, (d) commanding, and (e) controlling.

As the Chief Operating Officer (COO) at one of the (UHS) healthcare facilities in the United States or Territories (Universal Health Services, Locations; pick one), how would you augment your healthcare facility’s preparation and response to protect and mitigate against future cyberattacks? Discuss ways in which you would use all five functions of Fayol’s Five Functions of Management, which would influence the development of your plan.

Make certain that your assignment follows the Memo Format guidelines stated in the link below and is in the APA 7th edition format with a cover page, separating your sections by the appropriate APA Level Headings. Also, make sure you include a reference page and at least eight (8) references.

Resources:

Expert Solution Preview

Introduction:
The Universal Health Services (UHS) faced a ransomware attack in September 2020 that affected its IT network and computer systems. This assignment requires a memorandum that evaluates UHS’s response to the attack. The memorandum should also discuss how a COO at one of UHS’s healthcare facilities can protect and mitigate against future cyberattacks by implementing Fayol’s Five Functions of Management.

Answer:

Universal Health Services (UHS) faced a significant challenge in responding to the ransomware attack in September 2020. However, the healthcare facility had some notable achievements in its response. First, UHS promptly reported the incident to the appropriate authorities, including the Federal Bureau of Investigation. Collaborating with the authorities helped to mitigate the potential impact of the attack. UHS also provided regular updates on the attack’s progress to help stakeholders and patients stay informed.

Despite the positive aspects of UHS’s response, the healthcare facility had significant challenges in responding to and managing the attack. One significant challenge was the severity of the attack, which caused multiple antivirus programs to shut down. As a result, clinicians could not access vital information, which created delays in delivering care to patients. Additionally, the ransomware attack disrupted the facility’s communications systems, which complicated the emergency response process. Lastly, UHS faced time constraints in coordinating its response efforts as they needed to get their systems back online without paying the ransom.

The response to the UHS attack could have been improved in several ways. First, healthcare facilities should prioritize regular cybersecurity assessments to identify vulnerabilities. UHS’s information technology systems were not prepared for the level of sophistication used during the attack. A routine cybersecurity assessment could identify vulnerabilities and enable the facility to take necessary measures to mitigate them. Additionally, healthcare facilities should invest in proactive cybersecurity tools such as intrusion detection and prevention systems and data loss prevention systems to identify and stop attacks before they can cause significant damage.

As a COO at a UHS healthcare facility, I would augment my facility’s preparation against future cyberattacks in several ways by using the five functions of Fayol’s Five Functions of Management. In the planning stage, I would assess my facility’s cybersecurity infrastructure and identify vulnerable areas and measures to mitigate them. For organizing purposes, I would collaborate with my facility’s IT team to implement proactive cybersecurity measures. In coordinating efforts, I would create a task force responsible for providing regular updates, monitoring alerts and logs, and assessing the overall response strategy.

In commanding and controlling stages, I would ensure that all staff are familiar with emergency response procedures and have access to cybersecurity training to prevent social engineering attacks such as spear phishing. Lastly, I would monitor and evaluate my facility’s cybersecurity systems’ performance and identify areas that require improvement and take necessary actions to mitigate them.

In conclusion, ransomware attacks are a growing concern for healthcare facilities worldwide. UHS’s response to the ransomware attack of September 2020 was commendable, but there is room for improvement. A COO at a UHS healthcare facility can protect and mitigate against future cyberattacks by using Fayol’s Five Functions of Management to organize and plan cybersecurity infrastructure effectively, coordinate emergency response efforts, command and control responses, and assess and evaluate systems performance regularly.

Share This Post

Email
WhatsApp
Facebook
Twitter
LinkedIn
Pinterest
Reddit

Order a Similar Paper and get 15% Discount on your First Order

Related Questions

EHHA 501 Patient Journey Flow Chart

Develop an existing patient journey that crosses the three sectors of care in your organization (the organization is military hospital) Hwo could this be improved ? As a chart flow  You are a medical professor in charge of creating college assignments and answers for medical college students. You design and

MDC Gabapentin in the Context of Bipolar Disorder

A new patient presents to your office for treatment of bipolar disorder. In his medical history, he reports that he takes gabapentin prescribed by his primary care provider, but he is not sure what he takes it for. He states he is almost out of his gabapentin and is asking

KEMUL Health & Medical Using Technology to Prevent Patient

Using Technology To Prevent Patient Falls Review the concepts of technology application as presented in the Resources. Reflect on how emerging technologies such as artificial intelligence may help fortify nursing informatics as a specialty by leading to increased impact on patient outcomes or patient care efficiencies. In a project proposal

KEMUL Organizational Conflict and Effectiveness

1. Conflict  2.Relationship Between Organizational Conflict and Effectiveness  3.Common Sources of Organizational Conflict 4.Managerial Response to Conflict 5.Categories of Conflict 6.Stages of Conflict 7.Conflict Resolution Outcomes 8.Common Conflict Resolution Strategies. 9.Compromising 10.Competing 11.Cooperating/Accommodating 12.Common Causes of Organizational Conflict 13.Helpful Tips in Conflict Resolution. 14.Negotiation 15.Types of Alternative Dispute Resolution (ADR)

HSA 405 SU?Healthcare Quality Case Study

Overview In order to complete this case study, refer to this week’s readings for policy information required to analyze and make recommendations on this case. As a healthcare quality fraud analyst, you are responsible for identification of root causes and providing recommendations in an action plan to ensure compliance with

Needs to be 3 paragraphs You are the sole psychologist on

Needs to be 3 paragraphs  You are the sole psychologist on what is considered a small-sized base, with a population of approximately 6,000 people, including civilians, dependents, reservists, and active duty personnel. You have an appointment scheduled today with a patient whom you know works within the MTF (Military Treatment

Homework Content ScenarioThe administrator’s presentation,

Homework Content Scenario The administrator’s presentation, based on your briefing, was so well received by the board members that they asked to see a proposal for a hospital-based outpatient facility. In fact, the board suggested that the administrator ask you to take the lead in the project. Your administrator is

The CEO of a health care system has asked you, the system’s

The CEO of a health care system has asked you, the system’s strategic planner, to explain the factors they must consider when deciding the resources that should be devoted to a new facility project. List and describe the factors that determine the location, physical size, projected staffing, and effective décor

AMU HIMA 410 Hospital Data Modeling and Entity Relationship

A data model provides a view of how the data is structured throughout an organization. You’ve been provided with a set of data points from a local hospital. Instructions: Using the data points provided, create a model. Your data model should structure the data to support the business practices of

HIMA 360 AMU Encoder Selection for HIM Director Report

Case Scenario: Part 1: You are the HIM Director at Community General Hospital. As the director, you are in charge of purchasing an encoder for your 20 coders. You have identified the criteria that you will use to make the determination and put it in the grid below. Vendor 1

NUR 3846 BCC Deep Vein Thrombosis Questions

Using the video from Episode 2 on Samantha, answer the following prompts: Prompt 1: Explain in detail the pathogenesis of a DVT (Deep Vein Thrombosis) and how it can lead to a PE (Pulmonary Embolism). Prompt 2: Research and list all the possible treatment options for a DVT. Please correlate

MDC Key Elements of Psychiatric Assessment Discussion Reply

response to post: Discuss the Key elements of Psychiatric assessment and Interviewing of children. Assessing children and adolescents is challenging.  A psychiatric assessment can determine if a child is experiencing a disorder or if there are other factors that may be causing their difficulties. Establishing rapport is the first and

MDC Conducting Psychiatric Assessments Discussion Reply

Respond to Ste: Discuss the Key Elements of Psychiatric Assessment and Interviewing of Children When conducting psychiatric assessments and interviewing of children, there are several important elements to consider. According to Sharma et al. (2019), creating a rapport is crucial to building a relationship of trust with children while encouraging

MDC Assessing Childrens Mental Health Discussion Reply

post response Mari: Assessing children and adolescents is challenging. Generally, the child/adolescent in question would not have initiated the consultation or may not be in agreement with the need for a consultation. The consultation may or may not even be sought for the most impairing problem at hand. While children

MU African American Counselors in Training Project

Task summary: You are to do Exploring clinical supervision with African American counselors in Training editing Full description: please write Exploring clinical supervision with African American counselors in Training   You are a medical professor in charge of creating college assignments and answers for medical college students. You design and

Few people have not heard about the Food and Drug

Few people have not heard about the Food and Drug Administration (FDA). The COVID pandemic has placed a renewed focus on its role in assuring safety of drug approval. It is not nearly as well known that the FDA is tasked with regulating multiple categories of products. One cannot work in healthcare

MHA 543 UP Health & Medical Generational Work Trait

Work traits vary considerably between various generations. Each individual has a unique manner for interacting with others and solving problems or addressing issues that arise. In this assignment, you will address work trait differences and how these differences might impact the organizational culture and succession planning.  Part I: Individual Work

Health & Medical Health Screening Tests Issues and Concerns

Describe what you already know about the module’s topics (if anything) With your limited understanding, how you would answer the module’s guiding question: “Do you think most people undergoing a screening test understand how to assess the benefits and risks of the test?” What other questions does the guiding question