The Economics of Cybercrime and Security
Case Study: The AIIMS Cyber Attack
How a 2022 ransomware attack shut down systems at India's premier hospital, what it cost, and lessons for public institutions.
In November 2022, a ransomware attack hit the All India Institute of Medical Sciences (AIIMS) in New Delhi.
What happened
- Hospital servers were encrypted, taking down digital systems.
- Services like registration, billing and lab reports had to run manually for about two weeks.
- Reports suggested large amounts of patient data were affected.
Impact
- Long queues and delays for patients.
- Staff reverted to paper.
- Costs of restoring systems.
- Trust concerns over patient data.
Why hospitals are targets
- Critical services create pressure to pay.
- Legacy IT systems.
- Valuable health data.
Response
- Government agencies investigated.
- Systems were restored from backups over weeks.
- It prompted reviews of cybersecurity in public institutions.
Lessons
- Backups kept offline.
- Network segmentation to limit spread.
- Staff training.
- Incident response plans.
The paper hospital
During the attack, AIIMS doctors wrote prescriptions by hand and patients waited hours for manual registration, showing how dependent hospitals had become on computers.
Thinking only businesses face cyber attacks
Public hospitals and services are major targets.
Key takeaways
- AIIMS Delhi was hit by ransomware in November 2022.
- Services ran manually for about two weeks.
- Hospitals are targeted for critical services and data.
- Backups, segmentation and training are key lessons.
No recording for this one yet - EconReader can read it aloud for you.