Radiation Oncology Ransomware Attack Response Risk Analysis Using Failure Modes and Effects Analysis

被引:0
|
作者
Vinogradskiy, Yevgeniy [1 ]
Schubert, Leah [2 ]
Taylor, Amy [1 ]
Rudoler, Shari [1 ]
Lamb, James [3 ]
机构
[1] Thomas Jefferson Univ, Dept Radiat Oncol, Philadelphia, PA 19144 USA
[2] Univ Colorado, Dept Radiat Oncol, Sch Med, Aurora, CO USA
[3] Univ Calif Los Angeles, Dept Radiat Oncol, Los Angeles, CA USA
关键词
RADIOTHERAPY; DELAY; FMEA;
D O I
10.1016/j.prro.2024.03.001
中图分类号
R73 [肿瘤学];
学科分类号
100214 ;
摘要
Purpose: There have been numerous significant ransomware attacks impacting Radiation Oncology in the past 5 years. Research into ransomware attack response in Radiation Oncology has consisted of case reports and descriptive articles and has lacked quantitative studies. The purpose of this work was to identify the significant safety risks to patients being treated with radiation therapy during a ransomware attack scenario, using Failure Modes and Effects Analysis. Methods and Materials: A multi-institutional and multidisciplinary team conducted a Failure Modes and Effects Analysis by developing process maps and using Risk Priority Number (RPN) scores to quantify the increased likelihood of incidents in a ransomware attack scenario. The situation that was simulated was a ransomware attack that had removed the capability to access the Record and Verify (R&V) system. Five situations were considered: 1) a standard treatment of a patient with and without an R&V, 2) a standard treatment of a patient for the first fraction right after the R&V capabilities are disabled, and 3) 3 situations in which a plan modification was required. RPN scores were compared with and without R&V functionality. Results: The data indicate that RPN scores increased by 71% (range, 38%-96%) when R&V functionality is disabled compared with a nonransomware attack state where R&V functionality is available. The failure modes with the highest RPN in the simulated ransomware attack state included incorrectly identifying patients on treatment, incorrectly identifying where a patient is in their course of treatment, treating the incorrect patient, and incorrectly tracking delivered fractions. Conclusions: The presented study quantifies the increased risk of incidents when treating in a ransomware attack state, identifies key failure modes that should be prioritized when preparing for a ransomware attack, and provides data that can be used to guide future (c) 2024 American Society for Radiation Oncology. Published by Elsevier Inc. All rights reserved.
引用
收藏
页码:e407 / e415
页数:9
相关论文
共 50 条
  • [1] Collision Risks in a Modern Radiation Oncology Department: An Efficient Approach to Failure Modes and Effects Analysis
    Schubert, L.
    Westerly, D.
    Vinogradskiy, Y.
    Aldridge, J.
    Fisher, C.
    Liu, A.
    [J]. MEDICAL PHYSICS, 2016, 43 (06) : 3519 - 3519
  • [2] Risk Assessment of Clinical Radiation Processes using Failure Modes and Effect Analysis
    Angers, C.
    Studinski, R.
    La Russa, D.
    Bahm, J.
    Renaud, J.
    Clark, B. G.
    [J]. MEDICAL PHYSICS, 2012, 39 (07) : 4628 - 4628
  • [3] Risk Analysis Using Failure Modes, Effects, and Criticality Analysis for Transmission Network Assets
    Suwanasri, Cattareeya
    Saribut, Surapol
    Suwanasri, Thanapong
    Phadungthin, Rattanakorn
    [J]. ENERGIES, 2021, 14 (04)
  • [4] Risk analysis for the supplier selection problem using failure modes and effects analysis (FMEA)
    Li, Simon
    Zeng, Wei
    [J]. JOURNAL OF INTELLIGENT MANUFACTURING, 2016, 27 (06) : 1309 - 1321
  • [5] Risk analysis for the supplier selection problem using failure modes and effects analysis (FMEA)
    Simon Li
    Wei Zeng
    [J]. Journal of Intelligent Manufacturing, 2016, 27 : 1309 - 1321
  • [6] Prospective risk assessment for gentamicin using failure modes and effects analysis
    Collignon, U.
    McRobbie, D.
    [J]. PHARMACY WORLD & SCIENCE, 2008, 30 (06): : 1028 - 1029
  • [7] Implementing a new scale for failure mode and effects analysis (FMEA) for risk analysis in a radiation oncology department
    Baehr, Andrea
    Oertel, Michael
    Kroeger, Kai
    Eich, Hans Theodor
    Haverkamp, Uwe
    [J]. STRAHLENTHERAPIE UND ONKOLOGIE, 2020, 196 (12) : 1128 - 1134
  • [8] Implementing a new scale for failure mode and effects analysis (FMEA) for risk analysis in a radiation oncology department
    Andrea Baehr
    Michael Oertel
    Kai Kröger
    Hans Theodor Eich
    Uwe Haverkamp
    [J]. Strahlentherapie und Onkologie, 2020, 196 : 1128 - 1134
  • [9] EVALUATION OF SAFETY IN A RADIATION ONCOLOGY SETTING USING FAILURE MODE AND EFFECTS ANALYSIS
    Ford, Eric C.
    Gaudette, Ray
    Myers, Lee
    Vanderver, Bruce
    Engineer, Lilly
    Zellars, Richard
    Song, Danny Y.
    Wong, John
    DeWeese, Theodore L.
    [J]. INTERNATIONAL JOURNAL OF RADIATION ONCOLOGY BIOLOGY PHYSICS, 2009, 74 (03): : 852 - 858
  • [10] Risk analysis of geothermal power plants using Failure Modes and Effects Analysis (FMEA) technique
    Feili, Hamid Reza
    Akar, Navid
    Lotfizadeh, Hossein
    Bairampour, Mohammad
    Nasiri, Sina
    [J]. ENERGY CONVERSION AND MANAGEMENT, 2013, 72 : 69 - 76