- This topic has 3 replies, 4 voices, and was last updated 3 years, 5 months ago by Ameen.
2019-10-18 at 10:50 am #14924SaranathKeymaster
Please read your friend’s report and provide comments on “Are there any other preventive measures to avoid the attack?”.
Case study 4 : Ransomware attack on fetal diagnostic lab breaches 40,800 patient records
1.Provide a brief description of the story.
June 2018, Fetal Diagnostic Institute of the Pacific was hit by Ransomware attack on personal information some patient records of fetal diagnostic lab breaches but Officials took immediate action to contain the incident and enlisted a cybersecurity firm. They were able to successfully and installed further protections to better prevent future incidents. Backup data server is very important from the situation because of they maintained for contingency and were able to restore the impacted data.
2.What is/are the impact of this data breach? Consequences of the data breach.
Personal information destroy, cannot work and leakage. Consequences of the data breach is cannot process some patient information in patient system. It will be damage to the server or some data loss.
3.How did the data breach occur?
The situation talked about the weak point of security and privacy as often employees are the weakest links to accessed something or open some email or used other software but it have many way to attack server such as low security and privacy the gab of network system, rack of update operation and software.
4.What should be the main cause of the data breach? Provide a brief explanation of the cause of data breach, such as phishing, ransomware, HIPAA violation, database misconfiguration, human error, third-party vendor error)?
I think main cause of the data breach in situation is weak point of employees because of Ransomware attack Will come as an credible email attachment and advertisement. Ransomware not designed to steal user information in any way. But will encode or lock files such as documents, images, videos, users will not be able to open any files if they are encrypted which means that encryption is required to use the unlock key to recover the data or call Ransom.
5.How could you prevent this data breach attack?
- Risk analysis to identify threats and vulnerabilities on electronic protected health information.
- Design and develop methods to protect the system from various types of malware, including ransomware.
- Train employees to detect malware and report detection results to relevant parties
- Restrict access Only for people or software that is needed
- Prepare emergency plans such as Disaster Recovery and have regular backup plans and create incident action plan (IAP) of system.
2019-10-23 at 3:49 am #15049tullaya.sitaParticipant
– increase awareness of employee about cyber security including the phishing email
– scan the mobile storage devices with the up to date virus database program regularly before connect to the computer in the systems
2019-10-23 at 11:23 am #15054Pyae Phyo AungParticipant
Regular awareness raising of employees about the cyber safety and security.
Notice the preventive methods of cyber attack and ransomeware attack such as phishing alert, regular update anti virus software, window update, do not visit pirate sites and/or download & install pirated software.
2019-10-23 at 6:31 pm #15068AmeenParticipant
Ransomeware targets server store data are financially worth hacking such as credit card numbers, identifiable information. To make the dataset less juicy, the data should be collected only need-to-know data and should be stored with de-identifiable form.
You must be logged in to reply to this topic. Login here