Cancer Care in the Wake of a Cyberattack: How to Prepare and What to Expect

JCO Oncol Pract. 2022 Jan;18(1):23-34. doi: 10.1200/OP.21.00116. Epub 2021 Aug 2.

Abstract

Purpose: Cyberattacks targeting health care organizations are becoming more frequent and affect all aspects of care delivery. Cancer care is particularly susceptible to major disruptions because of the potential of immediate and long-term consequences for patients who often rely on timely diagnostic testing and regular administration of systemic therapy in addition to other local treatment modalities to cure or control their diseases. On October 28, 2020, a cyberattack was launched on the University of Vermont Health Network with wide-ranging consequences for oncology, including loss of access to all network intranet servers, e-mail communications, and the electronic medical record (EMR).

Methods: This review details the immediate challenges faced by hematology and oncology during the cyberattack. The impact and response on inpatient, outpatient, and special patient populations are described. Steps that other academic- and community-based oncology practices can take to lessen the brunt of such an assault are suggested.

Results: The two areas of immediate impact after the cyberattack were communications and lack of EMR access. The oncology-specific impact included loss of the individualized EMR chemotherapy plan templates and electronic safeguards built into multistep treatment preparation and delivery. With loss of access to schedules, basic patient information, encrypted communications platforms and radiology, and laboratory and pharmacy services, clinical outpatient care delivery was reduced by 40%. The infusion visit volume dropped by 52% in the first week and new patients could not access necessary services for timely diagnostic evaluation, requiring the creation of command centers to oversee ethical and transparent triage and allocation of systemic therapies and address new patient referrals. This included appropriate transfer of patients to alternate sites to minimize delays. Inpatient care including transitions of care was particularly challenging and addressing patient populations whose survival might be affected by delays in care.

Conclusion: Oncology health care leaders and providers should be aware of the potential impact of a cyberattack on cancer care delivery and preventively develop processes to mitigate the impact.

Publication types

  • Review

MeSH terms

  • Ambulatory Care
  • Hematology*
  • Humans
  • Medical Oncology
  • Neoplasms* / therapy
  • Referral and Consultation