Impact of and Response to Cyberattacks in Radiation Oncology.
Cyberattacks on health care facilities are increasing and significantly affecting health care delivery throughout the world. The recent cyberattack on our hospital-based radiation facility exposed vulnerabilities of radiation oncology systems and highlighted the dependence of radiation treatment on integrated and complex radiation planning, delivery and verification systems. After the cyberattack on our health care facility, radiation oncology staff reconstructed patient information, schedules, and radiation plans from existing paper records and physicians developed a system to triage patients requiring immediate transfer of radiation treatment to nearby facilities. Medical physics and hospital information technology collaborated to restore services without access to the system backup or network connectivity. Ultimately, radiation treatments resumed incrementally as systems were restored and rebuilt. The experiences and lessons learned from this response were reviewed. The successes and shortcomings were incorporated into recommendations to provide guidance to other radiation facilities in preparation for a possible cyberattack. Our response and recommendations are intended to serve as a starting point to assist other facilities in cybersecurity preparedness planning. Because there is no one-size-fits-all response, each department should determine its specific vulnerabilities, risks, and available resources to create an individualized plan.