The healthcare sector has become an easy target for professional hacker groups utilizing artificial intelligence (AI) technology to launch large-scale cyberattacks. In a seminar hosted by Viettel Cyber Security, experts emphasized that data breach incidents in medical facilities do not merely trigger financial losses, but pose fatal risks to patient safety and the overall integrity of healthcare services.
In response to these threats, relevant authorities have begun enforcing stricter regulations, including classifying medical records and genetic information as sensitive personal data. Medical facilities are now required to comply with strict rules such as patient consent notices and mandatory reporting of data processing impact assessments. Violations of these rules carry severe sanctions, ranging from administrative fines to proportional fines based on annual revenue.
However, legal compliance alone is not enough. Many hospitals are still constrained by legacy operational systems and a lack of information security experts. Experts suggest a phased approach, starting from network separation (segmentation) to isolate legacy systems, to implementing regular data backups to ensure the continuity of medical services during system disruptions.
In addition to infrastructure upgrades, raising human resource awareness remains the front line of defense. Healthcare facilities are advised not to act alone in maintaining data security. Building partnerships with 24/7 Security Operations Center (SOC) monitoring service providers can be an effective and efficient solution for detecting threats early before they cause widespread system damage.