| | November 20198UTLOOK Healthcare Tech IN MY OPINIONHealthcare CIOs have hopefully all now heard and heeded the warnings regarding enhancing their organization's cybersecurity posture, both in terms of technological sophistication and of staffing and staff awareness. Clearly this new threat has grown exponentially over the course of the last several years, and it seems likely that it will continue to escalate further. The financial and reputational costs of a breach are very large and often last for years, as witnessed by recent multi-million dollar fines levied against organizations several years after the initial incident occurred.Yet I remain concerned that our focus has been too narrow, with the safeguarding of our patients' data as the primary issue. Of course, we obviously must ensure that this data remains well-protected and out of the hands of the "bad guys." We have certainly heard about the value of health records on the open market and how it remains enormously profitable for hackers to go after this information. And as mentioned above, there's obviously the very real concern of very large financial penalties imposed on organizations for HIPAA violations, and all the other financial losses that go along with a breach.But there's an important lesson that I learned back in 2014 when the hacktivist group Anonymous attacked us at Boston Children's Hospital, and that I have seen play out more recently at hospitals around the country that likewise have been subject to ransomware and other cyberattacks. And that's that these cyberattacks have the ability to cause major disruptions in the actual provision of care to patients, and to the general operations of a healthcare organization. During our anonymous attack experience, we withstood a number of different disruptions, each of which caused different operational challenges for us.First, we experienced a massive distributed denial of service (DDoS) attack on our network, which briefly caused an interruption in both inbound and outbound Internet access. During that interruption, any clinical function that Cybersecurity and Healthcare: It's Not Just About Protecting the DataBy Daniel Nigrin, MD, SVP & CIO, Boston Children's Hospital < Page 7 | Page 9 >