{"id":60269,"date":"2022-12-05T14:45:14","date_gmt":"2022-12-05T06:45:14","guid":{"rendered":"https:\/\/version-2.com\/?p=60269"},"modified":"2023-02-22T14:31:40","modified_gmt":"2023-02-22T06:31:40","slug":"why-healthcare-organizations-are-vulnerable-to-attacks","status":"publish","type":"post","link":"https:\/\/version-2.com\/en\/2022\/12\/why-healthcare-organizations-are-vulnerable-to-attacks\/","title":{"rendered":"Why Healthcare Organizations Are Vulnerable to Attacks"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"60269\" class=\"elementor elementor-60269\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-30b42a6f elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"30b42a6f\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;1cb17ff&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-4560343c\" data-id=\"4560343c\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-dc060ff elementor-widget elementor-widget-text-editor\" data-id=\"dc060ff\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\n<p align=\"center\"><img decoding=\"async\" class=\"head-img\" src=\"https:\/\/images.prismic.io\/keepit\/73006a14-aca0-4d8a-8918-9ff608d87b0f_Healthcare-Why-Vulnerable-ransomware.png\" alt=\"\" ><\/p>\n<h4>And What They Can Do to Thwart Them<\/h4><p>Statistically speaking, a ransomware attack can and will likely happen to your healthcare delivery organization (HDO), and if you don\u2019t believe it, let these stats sink in for a minute:<\/p><ul><li>66% of healthcare organizations were hit by ransomware in 2021 (Source: Sophos\u2019 State of Ransomware in Healthcare 2022).<\/li><li> 38% of attacks on healthcare\u2014where the attack type is known\u2014were ransomware (Source: IBM Security X-Force Threat Intelligence Index 2022).<\/li><li>19 days: the average length of a ransomware incident (Source: United States Department of Health and Human Services).<\/li><\/ul><p>To make matters worse, the impact is felt throughout the entire organization when a ransomware disruption happens. The 2021 HIMSS Healthcare Cybersecurity Survey reported that the most significant security incidents caused disruption to:<\/p><ul><li>Systems\/devices impacting business operations (32% of survey respondents);<\/li><li>IT Operations (26% of respondents); <\/li><li>Systems\/devices impacting clinical care (21% of respondents).<\/li><\/ul>\n<h4><b>Why are HDOs Particularly Vulnerable to Ransomware Attacks?<\/b>&nbsp;<\/h4><p>Other than the goldmine of valuable data and enormous leverage gained by shutting down critical services (and potentially lifesaving), here are five main reasons why ransomware gangs target healthcare organizations:&nbsp;<\/p><ol><li><b>Comparatively weak defenses:<\/b> HDOs are focused on providing healthcare services and rarely have the dedicated budget to build and maintain a solid cybersecurity position.&nbsp;<\/li><li><b>Lack of cybersecurity specialists:<\/b> There\u2019s a reason why the world\u2019s largest enterprises either have staff-dedicated security teams or work closely with third-party specialists. Security is a specialized field, and HDOs typically lack the same resources \u2013 or their experts are already overburdened.&nbsp;<\/li><li><b>An ever-expanding attack surface:<\/b> The IT environment within most HDOs is a complex and expanding mix of legacy systems, traditional on-premises equipment, specialized devices, and hybrid clouds, creating plenty of opportunity for attackers to find and exploit vulnerabilities to gain entry, establish persistence, and escalate their intrusions.&nbsp;<\/li><li><b>A large employee base:<\/b> Many\u2014if not most\u2014ransomware attacks begin with a successful phishing email. Phishing campaigns that target HDO employees are executed with skill, and it only takes one mistake from one employee to bypass defenses.&nbsp;<\/li><li><b>Poor detection, response, and remediation capabilities:<\/b> Security is a very specialized field, and many HDOs lack these skills in-house and haven\u2019t proactively engaged third-party providers.<\/li><\/ol><p>While backups aren\u2019t intended to prevent ransomware attacks (and can\u2019t prevent the attackers from publishing what they steal), they have been proven to mitigate the impact by minimizing service disruption, lowering costs, and ensuring business continuity and compliance. Read our <a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/www.keepit.com\/blog\/why-m365-data-backup-for-healthcare-organizations\/\">healthcare continuity and compliance article here.<\/a>&nbsp;<\/p><p><b>The bottom line:<\/b> The native backup features built into SaaS applications are woefully inadequate to support a disaster recovery process like the one needed after a ransomware detonation.<\/p>\n<p><b>The bottom line:<\/b><\/p><p>Native backup features built into SaaS applications are woefully inadequate to support a disaster recovery process like the one needed after a ransomware detonation.<\/p>\n<h4><b>SaaS Data Protection Is Your Responsibility. Period.<\/b>&nbsp;<\/h4><p>Backing up cloud SaaS data is the responsibility of the SaaS customer, not the vendor. This applies to all of your SaaS applications, including OneDrive, Teams, SharePoint, Exchange, Azure AD, Salesforce, Google Workspace, and practically any other service from any other vendor.&nbsp;<\/p><p>In its own cloud documentation, Microsoft\u2019s \u201cDivision of Responsibility\u201d states that all information and data fall under \u201cresponsibility always retained by the customer.\u201d If you\u2019re not convinced data loss could happen to you,<b> ESG Research found that 81% of Microsoft 365 users had to recover data, and only 15% could recover 100% of their data.<\/b><\/p>\n\n<p align=\"center\"><img decoding=\"async\" src=\"https:\/\/images.prismic.io\/keepit\/f959688e-7727-4536-ae1f-dc0fba621cf7_what-is-shared-responsibility.png\" alt=\"\" ><\/p>\n<p>While SaaS apps like M365 may provide recycle bins, your data is still at risk because these bins have limited storage durations and can be emptied or bypassed with hard deletes, rendering data unrecoverable. Some companies also attempt to replace backup with workarounds, such as litigation hold, but <a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/www.keepit.com\/blog\/litigation-hold-cloud-backup\/\">our blog post <\/a>elaborates on why legal hold is not a reasonable replacement for backup.<\/p><p>Putting items on retention or legal hold can preserve data longer, but an e-discovery search to find missing or deleted data won\u2019t allow you to do a direct restore. Additionally, the data you export may or may not be in a usable, restorable format.&nbsp;<\/p><p>In fact, in the <a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/www.microsoft.com\/en-us\/servicesagreement\">Microsoft services agreement<\/a>, Microsoft explicitly instructs customers to back up their data, which is directly in line with the shared responsibility model mentioned above:<\/p>\n<q>We strive to keep the Services up and running; however, all online services suffer occasional disruptions and outages, and Microsoft is not liable for any disruption or loss you may suffer as a result. In the event of an outage, you may not be able to retrieve Your Content or Data that you\u2019ve stored. We recommend you regularly backup Your Content and Data that you store on the Services or store using Third-Party Apps and Services.<\/q><p class=\"small\">Microsoft services agreement<\/p>\n<h4><b>Ransomware Gangs Are Well Organized and Now Targeting Backups<\/b> <\/h4><p>Ransomware gangs aren\u2019t dumb and don\u2019t lack resources. While the perception may be that ransomware groups are a small team of backroom hackers, they actually operate like Fortune 500 enterprises. Their operations are funded by the proceeds of their crimes, and often supported by a shockingly well-developed ecosystem of specialized services, with some even enjoying the protection of nation states. <\/p><p>Because the potential financial rewards are so high, ransomware teams constantly evolve their tactics, techniques, and procedures (TTPs) to find new ways to get into IT environments, inflict maximum damage, and gain maximum leverage. <\/p><p>It was only a matter of time before ransomware operators began targeting backups, leading Microsoft to warn in its 2021 Digital Defense Report that \u201cinformation disruptors and attackers aggressively search for backup facilities.\u201d <\/p><p>For example, the Conti ransomware deletes Windows Volume Shadow Copies before encryption and disables 146 Windows services related to backup, security, and database capabilities. <\/p><p>The Conti gang and their affiliates also routinely employ multi-week dwell times as part of the strategy to maximize discovery and find and corrupt backups. <\/p><p>Not yet convinced? These TTPs are just part of why their ransom message confidently states: \u201cAs you know (if you don\u2019t \u2013 just Google it), all the data that our software has encrypted cannot be recovered by any means without contacting our team directly.\u201d <\/p><p>As a result of these ever-evolving tactics, the CISA Alert DarkSide Ransomware: Best Practices for Preventing Business Disruption from Ransomware Attacks recommends \u201censuring that backups are implemented, regularly tested, and isolated from network connections.\u201d What is true backup? <a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/www.keepit.com\/blog\/what-is-true-backup\/\">Learn more about it from our blogpost here<\/a>.<\/p>\n<h4><b>5-Factor Business Case for a Dedicated SaaS Backup and Recovery Solution<\/b><\/h4><p><b>1. Fulfilling Regulatory Obligations<\/b><\/p><p>Third-party backup and recovery services help you:<\/p><ul><li>Stay compliant by ensuring your data remains immutable and tamperproof;<\/li><li>Secure data and metadata;<\/li><li>Document and recover not just all data but all data processing;<\/li><li>Ensure auditors have full visibility of everything that has impacted the data.<\/li><\/ul><p><b>2. Protecting Organizational Continuity <\/b><\/p><p>Keeping services operational is essential for maintaining the revenue that keeps an organization running\u2014and having reliable backups that can be quickly restored is vital for returning to partial or complete service. <\/p><p>Sophos reported that 25% of healthcare organizations disrupted by ransomware took up to a month to restore operations.<\/p><p><b>3. When Disaster Strikes<\/b>&nbsp;<\/p><p>Data outages in the real world are a matter of when, not if, making your ability to quickly recover essential data an important part of business continuity planning. Learn more in our <a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/lp.keepit.com\/disaster-recovery-guide\">disaster recovery guide<\/a>.&nbsp;<\/p><p><b>4. Avoiding Ransom Payments <\/b><\/p><p>If you fear having to face ransom payment demands, consider these stats from Sophos:<\/p><ul><li>61% of healthcare organizations disrupted by ransomware in 2021 paid the ransom. This statistic suggests that no matter how often the board or the finance team says, \u201cWe won\u2019t pay the ransom,\u201d there\u2019s a better-than-even chance that when faced with a brutal reality of business disruption, they will pay.<\/li><li>It turns out that paying the ransom isn\u2019t even a guarantee that services will be fully restored. Even ignoring buggy ransomware decryptors (unfortunately a real thing), Sophos\u2019 investigations revealed, \u201cOn average, in 2021, healthcare organizations that paid the ransom got back only 65% of their data.\u201d <\/li><li>And if you\u2019re feeling lucky, the Sophos report noted, \u201cOnly 2% of those that paid the ransom in 2021 got ALL their data back.\u201d <\/li><\/ul><p>That\u2019s a poor return for ransoms that typically range from USD 1M to $25M USD. <\/p><p>Those high ransom amounts also mean that even if the business case is made entirely on ransom avoidance, it\u2019s a good bet that a dedicated SaaS backup solution will pay for itself in costs alone the very first data loss incident\u2014not to mention the guaranteed access to and quality of data returned alongside the ease-of-use third-party backup software solutions offer. <\/p><p>Furthermore, as the United States government focuses more on ransomware and its criminal enterprises, paying a ransom may even violate federal laws.<\/p><p><b>5. Filling Cyber Insurance Gaps and Meeting Coverage Requirements <\/b><\/p><p>If you have cyber insurance, you may be wondering if you\u2019re protected from having to pay ransom payments. The reality is that you probably aren\u2019t.<\/p><ul><li>A 2021 research report by MDR provider eSentire found that only 60% of security professionals whose organizations have cyber insurance indicated that their insurer covers the cost of lost business.<\/li><li>In \u201cThe Long Road Ahead to Ransomware Preparedness,\u201d ESG Research reported that only 66% of organizations with cyber insurance were covered for ransoms. <\/li><\/ul><p>Cyber insurance is\u2014at best\u2014a poor solution and having dedicated backups can help lower premiums and protect against areas not covered by insurance policies. We are already seeing a trend where coverage mandates backup.<\/p><p>Ultimately, as mentioned above, paying the ransom does not guarantee your organization will be able to recover data and metadata with great enough fidelity to put you back into operation.<\/p>\n<h4><b>How to Mitigate the Impact \u2013 Cloud SaaS Data Backup  <\/b><\/h4><p>When it comes to a data backup solution to circumvent ransom payments, you simply cannot afford not to protect yourself. <\/p><p>There is no shortage of cases where companies pay the ransom and get \u201cdata\u201d back, but these companies paying the ransom don\u2019t ever know what condition that data will be in. The way to ensure that your data is safeguarded is to back it up with third-party backup.  <\/p><p>SaaS applications and cloud technology have made everyone\u2019s lives easier, however, assuming data in the cloud is safe by default is a cautionary tale in the making and is an assumption that you are likely to regret.<\/p>\n<h4><b>What to do about ransomware:<\/b> Test Your SaaS Data Risk and Protection Readiness <\/h4><p>Completing the following short assessment will help you better understand your SaaS data risk and protection readiness. Simply note a &#8216;yes&#8217; or &#8216;no&#8217; in response to the following statements.<\/p><p><b>Data Risk Assessment:<\/b><\/p><ol><li>We have strong IT defenses in place, including endpoint, cloud, and network protection and robust logging. <\/li><li>We have a Security Operations (SecOps) team, Managed Detection and Response (MDR) service, or a similar real-time security function to contain threats that bypass our defenses. <\/li><li>We understand our threat surface, including legacy systems and hybrid IT environments. <\/li><li>We have a robust vulnerability discovery and management program. <\/li><li>All our employees undergo regular, healthcare domain-specific Phishing and Security Awareness Training (PSAT). <\/li><\/ol><p><b>SaaS Data Protection Readiness: <\/b><\/p><ol><li>We have a backup and recovery solution in place for our M365 application data beyond the limited functionality included within M365. <\/li><li>We can access our data 24\/7, even if primary systems are unavailable. <\/li><li>We have a retention policy in place and regularly verify that the procedure is followed. <\/li><li>We comply with HIPAA and other regulatory requirements that apply to our region. <\/li><li>We have tested our M365 restoration processes and are confident that we can fully restore any of our M365 data if it were to be lost. <\/li><li>We are satisfied with the time it takes to restore data, whether we need to restore a specific file or perform a full disaster recovery. <\/li><li>We are satisfied with the time it takes to offboard employees. <\/li><li>We stopped paying SaaS licensing for departed employees. <\/li><li>We can remotely monitor the status of our SaaS applications\u2019 backups. <\/li><li>We can easily get an overview of the total body of data backed up from our SaaS applications. <\/li><li>We are satisfied with the number of resources we apply to backup and related IT tasks. <\/li><li>We understand that cybercrime operators target healthcare delivery organizations and their TTPs target backups.<\/li><\/ol><p>For both risk and protection readiness, add up the number of times you answered \u201cNo.\u201d<\/p><ul><li>If you scored 2 out of 5 or higher on the Data Risk Assessment, your SaaS data is at high risk.&nbsp;<\/li><li>If you scored 3 out of 12 or higher on the SaaS Data Protection Readiness, then it is likely you will encounter serious problems recovering data in the event of a disruption.<\/li><\/ul><p>To learn more about healthcare organizations and how to secure data in the cloud, access the comprehensive (and complimentary) <a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/lp.keepit.com\/healthcare-compliance-and-continuity-ebook\">Keepit healthcare eBook here.<\/a><\/p><p>If you&#8217;re interested in learning more about Keepit&#8217;s backup and recovery solution for protecting and managing cloud SaaS data, continue to <a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/www.keepit.com\/services\/\">Keepit services page<\/a>.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-cbd5f21 elementor-widget elementor-widget-shortcode\" data-id=\"cbd5f21\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\t\t<div data-elementor-type=\"page\" data-elementor-id=\"18103\" class=\"elementor elementor-18103\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-748947f elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"748947f\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;c4f773e&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7995c19\" data-id=\"7995c19\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a437045 elementor-widget elementor-widget-image-box\" data-id=\"a437045\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><div class=\"elementor-image-box-content\"><h3 class=\"elementor-image-box-title\">About Version 2 Digital<\/h3><p class=\"elementor-image-box-description\">Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.\n<br><br>\nThrough an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t\n\t\t<div data-elementor-type=\"page\" data-elementor-id=\"50842\" class=\"elementor elementor-50842\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c1043a3 elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"c1043a3\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;_id&quot;:&quot;c4f773e&quot;,&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c911d7d\" data-id=\"c911d7d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-026fa41 elementor-widget elementor-widget-text-editor\" data-id=\"026fa41\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>About Keepit<\/strong><br \/>At Keepit, we believe in a digital future where all software is delivered as a service. Keepit\u2019s mission is to protect data in the cloud Keepit is a software company specializing in Cloud-to-Cloud data backup and recovery. Deriving from +20 year experience in building best-in-class data protection and hosting services, Keepit is pioneering the way to secure and protect cloud data at scale.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>And What They Can Do to Thwart Them Statistically speak [&hellip;]<\/p>\n","protected":false},"author":143524195,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_wpcom_ai_launchpad_first_post":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[488,853,61],"tags":[489,854],"class_list":["post-60269","post","type-post","status-publish","format-standard","hentry","category-488","category-keepit","category-press-release","tag-489","tag-keepit"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Why Healthcare Organizations Are Vulnerable to Attacks - Version 2<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.keepit.com\/blog\/why-healthcare-organizations-ransomware\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Why Healthcare Organizations Are Vulnerable to Attacks - Version 2\" \/>\n<meta property=\"og:description\" content=\"And What They Can Do to Thwart Them Statistically speak [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.keepit.com\/blog\/why-healthcare-organizations-ransomware\/\" \/>\n<meta property=\"og:site_name\" content=\"Version 2\" \/>\n<meta property=\"article:published_time\" content=\"2022-12-05T06:45:14+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-02-22T06:31:40+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/images.prismic.io\/keepit\/73006a14-aca0-4d8a-8918-9ff608d87b0f_Healthcare-Why-Vulnerable-ransomware.png\" \/>\n<meta name=\"author\" content=\"version2hk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"version2hk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.keepit.com\\\/blog\\\/why-healthcare-organizations-ransomware\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/2022\\\/12\\\/why-healthcare-organizations-are-vulnerable-to-attacks\\\/\"},\"author\":{\"name\":\"version2hk\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/person\\\/d14d2d3cd77ffdb618b9f1330fe084db\"},\"headline\":\"Why Healthcare Organizations Are Vulnerable to Attacks\",\"datePublished\":\"2022-12-05T06:45:14+00:00\",\"dateModified\":\"2023-02-22T06:31:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/2022\\\/12\\\/why-healthcare-organizations-are-vulnerable-to-attacks\\\/\"},\"wordCount\":2151,\"publisher\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.keepit.com\\\/blog\\\/why-healthcare-organizations-ransomware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/images.prismic.io\\\/keepit\\\/73006a14-aca0-4d8a-8918-9ff608d87b0f_Healthcare-Why-Vulnerable-ransomware.png\",\"keywords\":[\"2022\",\"Keepit\"],\"articleSection\":[\"2022\",\"Keepit\",\"Press Release\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/version-2.com\\\/2022\\\/12\\\/why-healthcare-organizations-are-vulnerable-to-attacks\\\/\",\"url\":\"https:\\\/\\\/www.keepit.com\\\/blog\\\/why-healthcare-organizations-ransomware\\\/\",\"name\":\"Why Healthcare Organizations Are Vulnerable to Attacks - Version 2\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.keepit.com\\\/blog\\\/why-healthcare-organizations-ransomware\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.keepit.com\\\/blog\\\/why-healthcare-organizations-ransomware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/images.prismic.io\\\/keepit\\\/73006a14-aca0-4d8a-8918-9ff608d87b0f_Healthcare-Why-Vulnerable-ransomware.png\",\"datePublished\":\"2022-12-05T06:45:14+00:00\",\"dateModified\":\"2023-02-22T06:31:40+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.keepit.com\\\/blog\\\/why-healthcare-organizations-ransomware\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.keepit.com\\\/blog\\\/why-healthcare-organizations-ransomware\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.keepit.com\\\/blog\\\/why-healthcare-organizations-ransomware\\\/#primaryimage\",\"url\":\"https:\\\/\\\/images.prismic.io\\\/keepit\\\/73006a14-aca0-4d8a-8918-9ff608d87b0f_Healthcare-Why-Vulnerable-ransomware.png\",\"contentUrl\":\"https:\\\/\\\/images.prismic.io\\\/keepit\\\/73006a14-aca0-4d8a-8918-9ff608d87b0f_Healthcare-Why-Vulnerable-ransomware.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.keepit.com\\\/blog\\\/why-healthcare-organizations-ransomware\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9801\",\"item\":\"https:\\\/\\\/version-2.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Why Healthcare Organizations Are Vulnerable to Attacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#website\",\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/\",\"name\":\"Version 2\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/version-2.com\\\/zh\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\",\"name\":\"Version 2\",\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/version-2.com\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/version-2.com\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1\",\"width\":1795,\"height\":335,\"caption\":\"Version 2\"},\"image\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/person\\\/d14d2d3cd77ffdb618b9f1330fe084db\",\"name\":\"version2hk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d280627252b42d7489de74dd88aa04043a495f25e258575000dc767e287bf94c?s=96&d=identicon&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d280627252b42d7489de74dd88aa04043a495f25e258575000dc767e287bf94c?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d280627252b42d7489de74dd88aa04043a495f25e258575000dc767e287bf94c?s=96&d=identicon&r=g\",\"caption\":\"version2hk\"},\"sameAs\":[\"http:\\\/\\\/version2xfortcom.wordpress.com\"],\"url\":\"https:\\\/\\\/version-2.com\\\/en\\\/author\\\/version2hk\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Why Healthcare Organizations Are Vulnerable to Attacks - Version 2","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.keepit.com\/blog\/why-healthcare-organizations-ransomware\/","og_locale":"en_US","og_type":"article","og_title":"Why Healthcare Organizations Are Vulnerable to Attacks - Version 2","og_description":"And What They Can Do to Thwart Them Statistically speak [&hellip;]","og_url":"https:\/\/www.keepit.com\/blog\/why-healthcare-organizations-ransomware\/","og_site_name":"Version 2","article_published_time":"2022-12-05T06:45:14+00:00","article_modified_time":"2023-02-22T06:31:40+00:00","og_image":[{"url":"https:\/\/images.prismic.io\/keepit\/73006a14-aca0-4d8a-8918-9ff608d87b0f_Healthcare-Why-Vulnerable-ransomware.png","type":"","width":"","height":""}],"author":"version2hk","twitter_card":"summary_large_image","twitter_misc":{"Written by":"version2hk","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.keepit.com\/blog\/why-healthcare-organizations-ransomware\/#article","isPartOf":{"@id":"https:\/\/version-2.com\/2022\/12\/why-healthcare-organizations-are-vulnerable-to-attacks\/"},"author":{"name":"version2hk","@id":"https:\/\/version-2.com\/zh\/#\/schema\/person\/d14d2d3cd77ffdb618b9f1330fe084db"},"headline":"Why Healthcare Organizations Are Vulnerable to Attacks","datePublished":"2022-12-05T06:45:14+00:00","dateModified":"2023-02-22T06:31:40+00:00","mainEntityOfPage":{"@id":"https:\/\/version-2.com\/2022\/12\/why-healthcare-organizations-are-vulnerable-to-attacks\/"},"wordCount":2151,"publisher":{"@id":"https:\/\/version-2.com\/zh\/#organization"},"image":{"@id":"https:\/\/www.keepit.com\/blog\/why-healthcare-organizations-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/images.prismic.io\/keepit\/73006a14-aca0-4d8a-8918-9ff608d87b0f_Healthcare-Why-Vulnerable-ransomware.png","keywords":["2022","Keepit"],"articleSection":["2022","Keepit","Press Release"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/version-2.com\/2022\/12\/why-healthcare-organizations-are-vulnerable-to-attacks\/","url":"https:\/\/www.keepit.com\/blog\/why-healthcare-organizations-ransomware\/","name":"Why Healthcare Organizations Are Vulnerable to Attacks - Version 2","isPartOf":{"@id":"https:\/\/version-2.com\/zh\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.keepit.com\/blog\/why-healthcare-organizations-ransomware\/#primaryimage"},"image":{"@id":"https:\/\/www.keepit.com\/blog\/why-healthcare-organizations-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/images.prismic.io\/keepit\/73006a14-aca0-4d8a-8918-9ff608d87b0f_Healthcare-Why-Vulnerable-ransomware.png","datePublished":"2022-12-05T06:45:14+00:00","dateModified":"2023-02-22T06:31:40+00:00","breadcrumb":{"@id":"https:\/\/www.keepit.com\/blog\/why-healthcare-organizations-ransomware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.keepit.com\/blog\/why-healthcare-organizations-ransomware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.keepit.com\/blog\/why-healthcare-organizations-ransomware\/#primaryimage","url":"https:\/\/images.prismic.io\/keepit\/73006a14-aca0-4d8a-8918-9ff608d87b0f_Healthcare-Why-Vulnerable-ransomware.png","contentUrl":"https:\/\/images.prismic.io\/keepit\/73006a14-aca0-4d8a-8918-9ff608d87b0f_Healthcare-Why-Vulnerable-ransomware.png"},{"@type":"BreadcrumbList","@id":"https:\/\/www.keepit.com\/blog\/why-healthcare-organizations-ransomware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9801","item":"https:\/\/version-2.com\/"},{"@type":"ListItem","position":2,"name":"Why Healthcare Organizations Are Vulnerable to Attacks"}]},{"@type":"WebSite","@id":"https:\/\/version-2.com\/zh\/#website","url":"https:\/\/version-2.com\/zh\/","name":"Version 2","description":"","publisher":{"@id":"https:\/\/version-2.com\/zh\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/version-2.com\/zh\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/version-2.com\/zh\/#organization","name":"Version 2","url":"https:\/\/version-2.com\/zh\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/version-2.com\/zh\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/version-2.com\/wp-content\/uploads\/2020\/08\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1","contentUrl":"https:\/\/i0.wp.com\/version-2.com\/wp-content\/uploads\/2020\/08\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1","width":1795,"height":335,"caption":"Version 2"},"image":{"@id":"https:\/\/version-2.com\/zh\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/version-2.com\/zh\/#\/schema\/person\/d14d2d3cd77ffdb618b9f1330fe084db","name":"version2hk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d280627252b42d7489de74dd88aa04043a495f25e258575000dc767e287bf94c?s=96&d=identicon&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d280627252b42d7489de74dd88aa04043a495f25e258575000dc767e287bf94c?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d280627252b42d7489de74dd88aa04043a495f25e258575000dc767e287bf94c?s=96&d=identicon&r=g","caption":"version2hk"},"sameAs":["http:\/\/version2xfortcom.wordpress.com"],"url":"https:\/\/version-2.com\/en\/author\/version2hk\/"}]}},"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pbQRKm-fG5","jetpack_featured_media_url":"","post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/posts\/60269","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/users\/143524195"}],"replies":[{"embeddable":true,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/comments?post=60269"}],"version-history":[{"count":19,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/posts\/60269\/revisions"}],"predecessor-version":[{"id":60751,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/posts\/60269\/revisions\/60751"}],"wp:attachment":[{"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/media?parent=60269"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/categories?post=60269"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/tags?post=60269"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}