Healthcare Infrastructure
Hospital networks, AIIMS ransomware, pharmaceutical IP, and healthcare data breaches
01 Breach Incident & Attribution Data
Healthcare Breach Incident Table
| Incident | Date | Records | Attribution | Confidence | Attack Vector |
|---|---|---|---|---|---|
| AIIMS Delhi | Nov 2022 | 40M | UNC4540 (Chinese) | HIGH | Phishing + VPN Exploit |
| CoWIN | Jun 2023 | 1300M | Unknown/Criminal | CONFIRMED | API Enumeration |
| Star Health | Oct 2024 | 31M | Insider + External | CONFIRMED | Data Export Abuse |
| Dr. Reddy's | Oct 2020 | 5M | Lazarus Group (North Korea) | HIGH | Ransomware |
| Tamil Nadu Hospitals | Dec 2022 | 0M | Unknown/Criminal | CONFIRMED | Ransomware |
| Lupin | Sep 2021 | 2M | Unknown Ransomware | CONFIRMED | Credential Compromise |
| Apollo (cumulative) | 2020-2023 | 10M | Multiple | CONFIRMED | Various |
| PM-JAY | 2023-2024 | 500M | N/A | RISK | Distributed Attack Surface |
Threat Actor Attribution Matrix
UNC4540/Worn in Paris
AIIMS, Pharma R&D
Phishing, VPN Exploit, Custom Backdoors
No CISO, No Segmentation
Lazarus Group
Dr. Reddy's, Vaccines
Ransomware, Data Exfiltration
Perimeter Vulnerabilities
Transparent Tribe
PM-JAY, Hospitals
Healthcare-themed Phishing
Small Hospital Security
APT41
Pharma Formulation IP
Spear-phishing, Supply Chain
CRO Security
Criminal RaaS
All Hospitals
LockBit, Ransomware commoditization
Zero Security Controls
Insider Threats
Star Health Type
Database Access, Data Sale
No Insider Threat Program
Dark Web Data Pricing Sheet
| Data Type | Price Range (INR) | Volume | Risk Level |
|---|---|---|---|
| Basic Demographics | ₹100-₹300 | High | Medium |
| Insurance Policy Data | ₹300-₹800 | Medium | High |
| Lab Results + Diagnostics | ₹500-₹1,500 | Medium | High |
| Full Medical History | ₹1,500-₹5,000 | Low | Critical |
| HIV Status + Linked Data | ₹3,000-₹8,000 | Low | Critical |
| Mental Health Records | ₹2,000-₹6,000 | Low | Critical |
Medical Device Risk Matrix
MRI/CT Scanners
CRITICALGE Signa, Philips, Siemens
53%+ Unsupported
High
Infusion Pumps
CRITICALMedtronic, BD Alaris
Legacy OS Common
Critical
Pacemaker Programmers
CRITICALMedtronic
Unpatchable
Life-threatening
Patient Monitors
HIGHPhilips IntelliVue, GE CARESCAPE
Varying
High
Anesthesia Machines
HIGHGE Aespire, Drager
2023 FDA Recall
Confirmed
PACS Systems
HIGHMedical Imaging Storage
Win Server 2008/2012
High
02 Records Compromised & Incident Timeline
PM-JAY Integration Points
Empaneled Hospitals
HIGHAttack surface for lateral movement
32,403State Servers
CRITICALInferior security feeding national platform
28Integration APIs
HIGHNever subjected to security assessment
24,000Data Centers
MEDIUMCentralized NHA architecture
5Field Workers
HIGHEndpoint attack surface
50,000Hospital Security Maturity Comparison
03 Vulnerability & Activity Heatmaps
04 Architecture & Flow Diagrams
05 Threat Actor Targeting Map
Breach Records by Sector (Millions)
Breach Cause Distribution
Security Maturity by Tier
Missing Controls Assessment
| Category | Control | Status | Evidence |
|---|---|---|---|
| Prevention | Dedicated CISO | ABSENT | AIIMS had none |
| Prevention | Network Segmentation | ABSENT | Flat network at AIIMS |
| Prevention | Vulnerability Management | ABSENT | Unpatched Fortinet VPN |
| Prevention | Backup Isolation | ABSENT | Destroyed during dwell |
| Prevention | MFA / PAM | ABSENT | Lupin credential compromise |
| Prevention | Security Awareness | ABSENT | Phishing in all state-sponsored |
| Prevention | OT/IT Separation | ABSENT | Legacy devices on general network |
| Prevention | Insider Threat Program | ABSENT | Star Health executive sold data |
| Detection | Security Monitoring/SOC | ABSENT | No detection during 14-day dwell |
| Detection | Threat Hunting | ABSENT | Active intrusion undetected |
| Detection | Access Analytics/DLP | ABSENT | 31M Star Health exported unnoticed |
| Response | Incident Response Plan | ABSENT | Ad hoc AIIMS response |
| Response | Forensic Capability | ABSENT | 14-day restoration reflects paralysis |
| Regulatory | Mandatory Breach Notification | ABSENT | No requirement |
| Regulatory | Min Security Standards | ABSENT | None defined for healthcare |
Regulatory Status Comparison
| Regulatory Element | DISHA (Proposed) | DPDP Act 2023 | Healthcare-Specific |
|---|---|---|---|
| Health Data Protection | Proposed | General Framework | Lacking |
| Consent Requirements | Proposed | General Consent | Not Specified |
| Breach Notification | Proposed | Limited | Not Defined |
| Patient Rights | Proposed | General | Not Detailed |
| Min Security Standards | Proposed | None | Not Defined |
| Enforcement Penalties | Proposed | Civil Remedies | Not Sector-Specific |
| Mandatory Testing | N/A | N/A | NOT REQUIRED |
| Device Inventory | N/A | N/A | Not Mandated |
AIIMS Attack - System Availability
Healthcare Ransomware Trend
Healthcare Data Breach Impact
Healthcare Security Score
Threat Assessment
Pharmaceutical Targeting
Case Studies
AIIMS Delhi Ransomware Attack
Chinese state-sponsored group UNC4540 conducted ransomware attack on AIIMS Delhi servers. Attack disrupted hospital operations for 14 days affecting patient care, lab systems, and administrative functions.
Star Health Data Breach
Star Health insurance suffered data breach exposing 31 million customer records including medical histories, insurance claims, and personal identification data. Data sold by insiders.
Dr. Reddy's Ransomware
Dr. Reddy's Laboratories suffered ransomware attack forcing shutdown of data centers across multiple locations during COVID-19 vaccine development phase.
PM-JAY Data Security
Pradhan Mantri Jan Arogya Yojana health insurance scheme covering 500+ million individuals has IT infrastructure with multiple intermediaries creating distributed data exposure.
Key Findings
Hospital OT Network Convergence
Hospital OT networks controlling HVAC, building automation, medical gas systems, and elevators connect to IT networks without adequate segmentation. AIIMS attack demonstrated pathway to safety-critical systems.
Aadhaar Biometric Irreversibility
ABHA (Ayushman Bharat Health Account) links biometric credentials to health records. Compromised biometrics cannot be revoked - creates permanent identity theft risk.
Healthcare Insider Market
Hospital employees sell patient records at ₹500-500,000 per record depending on completeness. Star Health breach demonstrated insider involvement in data sales.
Pharmaceutical IP Targeting
Indian pharma companies targeted by APT41 and other state actors for R&D data, clinical trial results, and generic drug formulations. Premium value in state-sponsored markets.
Medical Device IoMT Security
Internet of Medical Things (IoMT) devices including infusion pumps, pacemakers, and diagnostic equipment have documented vulnerabilities and limited patching capability.