Article (Scientific journals)
Hospital cybersecurity: Emergency planning response and preparedness to mitigate the effects of a potential cyberattack on French hospitals in Paris, France.
GHANCHI, Ali; Barthe, Charles; Perret, Didier
2025In Journal of Emergency Management, 23 (1), p. 45 - 53
Peer reviewed
 

Files


Full Text
JEM_23-1-04-Ghanchi (2).pdf
Author postprint (85.42 MB)
Request a copy

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Humans; Paris; Hospitals; Disaster Planning/organization & administration; Disaster Planning/methods; Computer Security
Abstract :
[en] Over the last few years, numerous hospitals in France have been subject to increasingly frequent and severe cyberattacks that have disrupted healthcare provision to varying degrees. To mitigate this threat, especially in light of the forthcoming 2024 Olympic Games, Assistance Publique-Hôpitaux de Paris in Paris has been developing contingency plans that have been tested in simulated exercises called CRYPTolocker EXercice since May 2021. The latest simulated ransomware cyberattack that involved more than 200 participants took place on July 5, 2023, and lasted for 24 hours. Although cybersecurity contingency plans are confidential for obvious reasons, this article presents the multidisciplinary organization of the simulated attack based on previous experiences from other hospitals and general findings that are in the public domain. It was found that the procedures in place worked well overall, and countermeasures were quickly implemented to limit the severity of this simulated cyberattack. However, failings were observed in intra- and extra-hospital communication, and conflicting priorities between different categories of personnel (administrative, managerial, and clinical) hampered the information technology team in resolving various issues. Furthermore, it was found that mental fatigue, task saturation, and information overload may have overwhelmed senior managers at sporadic intervals. This often resulted in an action-reaction approach being used to find temporary solutions to immediate problems. Consequently, senior managers who participated in this simulated cyberattack were unable to think strategically and anticipate demands for middle- and long-term issues. This unprecedented exercise was an important learning experience for all participants, and the lessons learned will help further improve contingency planning and cyber resilience. It advised that all hospitals worldwide adopt and develop a similar multidisciplinary approach (taking into account their local contexts) to limit the deleterious effects of a potential cyberattack that undoubtedly will become more prevalent in the future.
Disciplines :
Human health sciences: Multidisciplinary, general & others
Author, co-author :
GHANCHI, Ali  ;  University of Luxembourg ; APHP Hôpital Necker-Enfants Malades, GHU Paris Centre, Service d'Obstétrique - Maternité, Chirurgie Médecine et Imagerie Fœtales, Paris, France. ORCID: https://orcid.org/0000-0002-6082-2140
Barthe, Charles;  Direction des Services Numériques, Département Sécurité du Système d'Information, Campus Picpus, Paris, France
Perret, Didier;  Direction des Services Numériques, Département Sécurité du Système d'Information, Campus Picpus, Paris, France
External co-authors :
yes
Language :
English
Title :
Hospital cybersecurity: Emergency planning response and preparedness to mitigate the effects of a potential cyberattack on French hospitals in Paris, France.
Publication date :
2025
Journal title :
Journal of Emergency Management
ISSN :
1543-5865
Publisher :
Weston Medical Publishing, United States
Volume :
23
Issue :
1
Pages :
45 - 53
Peer reviewed :
Peer reviewed
Available on ORBilu :
since 28 March 2025

Statistics


Number of views
61 (1 by Unilu)
Number of downloads
2 (1 by Unilu)

Scopus citations®
 
0
Scopus citations®
without self-citations
0
OpenCitations
 
0
OpenAlex citations
 
1

Bibliography


Similar publications



Contact ORBilu