MétaCan
Menu
Retour à la cohorte
Enregistrement W4416589253 · doi:10.1016/j.radonc.2025.111305

ESTRO framework for radiation oncology departments to mitigate against cyberattacks

2025· article· en· W4416589253 sur OpenAlexaff
Samuel Peters, Anita O’Donovan, Amanda Caissie, Mary P. Coffey, Ali Dabach, Geoff P. Delaney, Gert Frenken, Brian Liszewski, Philippe Maignon, Eric Messens, Sophie Perryck, Baoshe Zhang, P.M.J. Reijnders-Thijssen

Notice bibliographique

RevueRadiotherapy and Oncology · 2025
Typearticle
Langueen
DomaineComputer Science
ThématiqueInformation and Cyber Security
Établissements canadiensCancer Care OntarioDalhousie UniversityTrinity College
Organismes subventionnairesnon disponible
Mots-clésPreparednessRadiation oncologyHealth careProtocol (science)Data breach

Résumé

récupéré en direct d'OpenAlex

INTRODUCTION: The healthcare sector, particularly radiation oncology departments, is facing an increasing threat of cyberattacks that compromise patient data, disrupt clinical workflows and endanger patient safety. These attacks highlight a critical lack of preparedness and the need for a structured approach to cybersecurity resilience. While other industries have comprehensive mitigation measures in place, specific guidance for radiotherapy is lacking. This paper aims to present practical and comprehensive recommendations for mitigating cyberattacks and minimising their direct impact on patient care in radiation therapy. METHODOLOGY: Preparing this report involved three phases. First, the authors adapted existing international frameworks, such as the NIST CSF, to the specific needs of radiation oncology, resulting in a six-step framework: Preparation, Prevention, Detection, Response, Recovery and Debriefing and Continuous Improvement. Secondly, a systematic literature review was conducted using keywords related to cyberattacks in healthcare and radiotherapy. Third, the information extracted from the literature was aggregated and summarised into specific action measures, with final consensus being reached by the entire group based on their collective expertise. RESULTS: The literature review resulted in 133 relevant articles, which were then aggregated and formulated into 190 specific action measures in total. These were assigned to the 6 steps (43 for preparation, 28 for prevention, 14 for detection, 50 for response, 22 for recovery, 24 for debriefing and continuous improvement, and nine additional steps), enabling departments to be guided through the entire lifecycle of a cyberattack. Step 1: Preparation: This proactive phase of planning for potential cyberattacks involves thorough risk assessment and identification of all systems, tools and processes. A key component is the development of a detailed business continuity plan (BCP), which must include procedures for the offline treatment or referral of patients, communication and patient prioritisation. The plan should also define the roles and responsibilities of an interdisciplinary incident response team. Step 2 - Prevention: This step focuses on implementing proactive security measures to prevent attacks. This includes user training to raise awareness, regular system updates, and general protective measures. Step 3 - Detection: This step involves identifying suspicious activities within systems and networks. It emphasises the use of security tools for real-time monitoring and the establishment of clear communication processes to enable the prompt reporting and response to potential threats. Step 4: Respond: This is the central phase of a cyberattack, focusing on executing the BCP to ensure continuity of patient treatment as quickly as possible. This includes isolating affected systems and implementing continuity of treatment procedures, which may involve using analogue workflows or transferring patients to other hospitals. Step 5: Recovery: This step begins in parallel with step 4 and involves restoring data and systems from backups or rebuilding them from scratch. It is particularly important to carefully check the restoration and merging of data to avoid incorrect documentation or erroneous treatment. Step 6: Debriefing and continuous improvement: This post-incident step ensures that lessons learned are fed back into the preparation process. It involves a thorough analysis of what went right and wrong, leading to the adaptation of the BCP. CONCLUSION: This framework aims to help departments create their own local protocols. Implementation of the framework will vary significantly between departments and preparing for an attack should be a high priority. Preparedness is not the sole responsibility of the RO staff or of the IT department; it requires comprehensive cooperation between IT specialists, clinical staff and system providers. Since the next cyberattack is not a question of 'if' but 'when,' healthcare providers must have a protocol in place that can be quickly implemented to prioritise patient well-being and safety.

Récupéré en direct depuis OpenAlex et désinversé. Les résumés ne sont pas conservés dans cette base de données : les index inversés représentent 8,6 Go des 9,3 Go de texte de la base, et le serveur dispose de 13 Go libres.

Comment cette classification a été obtenuedéplier

Prédiction machine sur la base complète

Imitation des enseignants

Ni prévalence calibrée, ni vérité terrain. Validation humaine à venir. Le volet Gemma est une étiquette directe du modèle pour chaque travail de la base, lue sur la notice réduite au titre. Le volet Codex est un classifieur appris des 10 348 étiquettes directes de Codex et calibré sur les taux pondérés de l'échantillon; les champs sans appui suffisant ne portent aucun appel Codex. Le mode candidate est l'union des deux volets; le consensus est leur intersection. Ces sorties portent le statut machine_predicted_unvalidated et ne sont pas des étiquettes humaines.

score de la tête « metaresearch » (Codex)0,003
score de la tête « metaresearch » (Gemma)0,006
Version: metacan-v3-hybrid-931329e0061cStatut de validation: machine_predicted_unvalidated
Catégories candidatesaucune
Catégories consensuellesaucune
DomaineSignal candidat: aucune · Signal consensuel: aucune
Devis d'étudeSignal candidat: Sans objet · Signal consensuel: Sans objet
GenreSignal candidat: Méthodes · Signal consensuel: Méthodes
Score de désaccord entre enseignants0,025
Score d'incertitude au seuil0,085

Scores du classifieur distillé par catégorie (deux têtes)

CatégorieCodexGemma
Métarecherche0,0030,006
Méta-épidémiologie (sens strict)0,0010,001
Méta-épidémiologie (sens large)0,0000,001
Bibliométrie0,0010,000
Études des sciences et des technologies0,0010,001
Communication savante0,0030,003
Science ouverte0,0030,005
Intégrité de la recherche0,0010,002
Charge utile insuffisante (le modèle a refusé de juger)0,0250,010

Scores machine (provisoires)

Les deux têtes enseignantes du modèle étudiant, lues sur ce travail. Un score ordonne la base pour la relecture; il n'affirme jamais une catégorie, et le statut de validation accompagne chaque rangée tel quel.

Scores de référence d'un modèle non mature (critères de maturité non atteints, 7 itérations). Un score ordonne; il n'affirme jamais une catégorie.

Tête enseignante Opus0,012
Tête enseignante GPT0,337
Écart entre enseignants0,325 · la distance entre les deux têtes enseignantes sur ce seul travail
Statut de validationscore_only:v0-immature-baseline · tel quel depuis la passe de notation : score_only signifie que le nombre peut ordonner les travaux, et qu'aucune étiquette de catégorie n'en découle

Classification

machine, non validée

Prédiction automatique; un appel candidat d’une seule source (Gemma direct ou Codex distillé), pas un consensus.

Les modèles n’ont appliqué aucune catégorie : rien dans la taxonomie ne correspondait à ce travail.
Devis d'étudeSans objet
Domainenon disponible
GenreMéthodes

Le détail, modèle par modèle et score par score, se trouve en fin de page sous « Comment cette classification a été obtenue ».

En bref

Citations0
Publié2025
Routes d'admission1
Résumé présentnon

Explorer davantage

Même revueRadiotherapy and OncologyMême sujetInformation and Cyber SecurityTravaux en français237 207