As shown in a previous post to this newsletter (Link), cyberattacks on hospitals and radiation oncology departments are on the rise and pose a huge risk of disrupting critical workflows and directly endangering patient safety. The critical issue here is that many hospital staff lack awareness of this risk, or view it as a simple IT problem, and many hospitals are completely unprepared. It is therefore worth reminding ourselves what happens in the event of a cyberattack that involves ransomware: all of the clinic’s data is encrypted and therefore unusable. This means there is no access to electronic patient records, no details of scheduled appointments and no way of contacting patients (due to a lack of contact details), no radiotherapy plans and, consequently, no way of treating patients.

As there is a very high probability that we will at some point fall victim to such an attack, it is essential to be prepared. The primary aim here is to maintain patient care under emergency conditions without compromising safety during the critical phase when electronic data and systems are not available as usual. To achieve this, there are essentially four points to bear in mind:

  1. You need a comprehensive understanding and awareness of what cyberattacks are, how they occur and what risks they pose to patient care.
  2. To be able to respond to an attack, the hospital needs people who can manage the situation and lead the required processes during a crisis. These people together are known as an incident response team (IRT), which comprises hospital staff and staff from central IT, hospital management or other departments, who guide the hospital as necessary through the crisis.
  3. To survive the period from system failure until full recovery, a business continuity plan (BCP) is required. This is a guideline that provides step-by-step instructions on how clinical processes are to be carried out without access to normally available systems and data.
  4. In order to have any patient information available during a system failure (which can last from several days to several weeks) and to be able to continue treatment, a fail-safe and fully functional fallback procedure or backup system must be in place.

A few working groups and committees have focused on these four key points and published relevant guidelines [1, 2]. However, this article is focused on the framework that has been developed by the working group set up for this purpose by the ESTRO Radiation Oncology Safety and Quality Committee (ROSQC) [3]. This framework guides clinics through all phases of a cyberattack: the pre-incident phase, when everything is functioning as intended and the hospital should be making preparations; the incident phase, during which the contingency procedures take place; and the post-incident phase, in which procedures to return processes to normal are addressed. The whole process is split into six steps, with several subtopics and corresponding action measures. The six steps are listed below.

1 Preparation

  • Identify systems, tools, processes and stakeholders that will be affected by a cyberattack
  • Define a BCP and ensure that it is in place and known by the organisation. It should include:
    • availability of patient data (at least patient demographics, treatment schedules, treatment regimes, copies of radiotherapy plans);
    • process for contingency treatments (onsite or referring to neighbouring hospitals);
    • collaboration agreement with neighbouring hospitals;
    • triaging of patients;
    • detailed phases of the continuity procedures;
    • documentation process on paper (which data, quality assurance processes); and
    • communication processes.
  • Define personnel with specific roles and responsibilities, including the incident response teams (IRT, including medical physics experts, physicians, radiation therapists, admin and IT staff, medical technologists).
  • Define what data has to be stored as backup/fallback on paper/offline and how to access it once the network is down.
  • Plan procedures for regular testing of the emergency processes.

 

2 Prevention

  • Ensure user awareness and training in cyber security at all levels of the organisation
  • Put technical measures in place to reduce the risk of an attack and its consequences. These are:
    • regular system patching;
    • appropriate endpoint protection and anti-virus policies;
    • safeguarding of network architecture (e.g., firewalls, micro-segmentation);
    • stringent user management (incl. password policy, multi-factor identification); and
    • data protection (encryption, storage/archiving).
  • Conduct regular penetration testing.

 

3 Detection

  • Ensure that real-time detection tools (monitoring and logging for malicious code and unauthorised access) are in place
  • Once an incident happens:
    • Have communication systems and automatic alerts to inform the IRT (through the pre-defined crisis communication plan); and
    • Identify the impact (which systems and which data are affected).

4 Response

  • Activate BCP as defined in Step 1 and IRT meetings
  • Isolate infected systems/data/network ranges or segments
  • Remediate the vulnerabilities that have been exploited
  • Implement procedures regarding cyberattack handling:
    • follow the different response phases (according to the BCP);
    • meet regularly with and pass information to all stakeholders (employees, providers, patients…) ‑ information is key;
    • continue patient treatment in the contingency mode:
      • decide whether treatment should be onsite or offsite according to BCP; and
      • carefully document on paper all treatment steps.
  • Document all activities and decisions of the IRT.

It is important at this stage that enough time is spent before starting patient treatment to make sure that all necessary safety measures are in place as they would be under normal circumstances.

 

5 Recovery

  • Specify when the recovery plan should be activated and which recovery method should be used
  • Check the recovered data for completeness and correctness:
    • Compare new data (from contingency process) with old. Are there any gaps?
    • Merge the data.
  • Set and communicate the end of the recovery and resume normal business activities
  • Adapt ongoing treatment regimens for treatment gap compensation where needed.

 

6 Debriefing and continuous improvement

  • Gather a multidisciplinary debriefing committee
  • Review past events and check whether the BCP has worked effectively or whether changes are required
  • Adapt and test the BCP in line with lessons learned
  • Disseminate learning internally and externally.

 

The whole framework comprises 190 action measures. It may not be possible to work through all these points in a short space of time. However, step 1 (preparation) is a good way to start. The first move should be to define the IRT, which bears responsibility for the whole BCP. Next, departments should focus on “identification of systems, tools, processes and stakeholders and their weaknesses” to have an overview of how the clinic works, what dependencies exist and which systems and processes are critical. Based on that assessment, one should start building the BCP. This should include the following: create a valid backup solution by defining what data is stored where and how it is accessible; establish an offline treatment procedure that can be enacted when no network is available; and set up collaborations and agreements with neighbouring hospitals.

By following the steps set out in the ESTRO ROSQC framework and the points summarised here, a hospital may be well prepared for an emergency. This means that patients can be treated safely even under very difficult circumstances. I will describe what the process of an emergency response phase looks like in a future newsletter.

Picture1.png

 

Samuel Peters
Head of radiation oncology informatics

HOCH Health Ostschweiz

Kantonsspital St. Gallen, Switzerland

 

References

[1] Siochi, R. A., et al. (2025). "AAPM working group on cybersecurity report 438: A white paper on cybersecurity management for business continuity in radiology and radiation therapy." J Appl Clin Med Phys 26(12): e70358.

[2] Canadian Association of Provincial Cancer Agencies (2026). Pan-Canadian Emergency Preparedness Framework for Radiotherapy Downtime; https://capca.ca/document/pan-canadian-emergency-preparedness-framework-for-radiotherapy-downtime/

[3] Peters, S., et al. (2025). "ESTRO framework for radiation oncology departments to mitigate against cyberattacks." Radiother Oncol: 111305.