🤖 AI Summary
This study addresses the challenge of assessing the true impact of ransomware attacks on healthcare institutions, which frequently conceal incidents due to legal and financial concerns. We systematically validate, for the first time, the feasibility of leveraging social media as an alternative data source. By applying natural language processing techniques to match 1,628 posts with 212 attack events, and integrating quantitative statistics with qualitative analysis, we construct a public-data-driven framework for evaluating the impact of healthcare ransomware attacks. This work overcomes traditional information disclosure barriers by effectively quantifying the latent disruptions to clinical operations and patient care. Our findings demonstrate that social media data can substantially supplement missing official reports, thereby establishing a novel paradigm for healthcare cybersecurity research.
📝 Abstract
In the modern era, ransomware attacks on critical healthcare organizations---like hospitals and insurers---are frequent, with impacts ranging from leaked private health information all the way to serious disruptions of urgent, time-sensitive clinical operations. Unfortunately, legal and economic incentives make it uncommon for hospitals to share basic information about these attacks, their scope, and the downstream impacts to patient care. In this paper, we explore the use of public social media posts---authored both by hospitals and by individuals---to garner more detailed insights about these attacks and their effects. We collect 1,628 Facebook and Reddit posts from 2018--2024, design and evaluate techniques to match post data to 212 ground-truth ransomware attacks, and conduct quantitative and qualitative analyses that explore the impacts such attacks have on critical hospital infrastructure, patient care, and providers. We conclude by discussing the promise and limitations of leveraging social data to study the impact of ransomware attacks and highlight areas of future research.