Cybersecurity and the blood supply: The vulnerabilities of the technological revolution
Bibliographic record
Abstract
Blood and its components are critical for a myriad of medical conditions, and a safe and sufficient blood supply is fundamental to modern healthcare systems.1 Blood products are considered “Essential Medicines” by the World Health Organization, and a lack of safe blood directly and indirectly contributes to morbidity and mortality.2, 3 While periodic blood shortages do occur in high-income countries, particularly since the onset of the COVID-19 pandemic in 2020,4-6 blood operators in the United States, United Kingdom, and Canada have continued to provide a relatively consistent blood supply. This resilience is attributable to unrelenting efforts to recruit donors, dynamic allocation and transportation of blood products for shifting local needs, and contingency planning for operational threats such as pandemics, natural disasters, mass-casualty events, and large-scale failures of infrastructure.7 Importantly, providing a safe and sufficient blood supply relies on robust electronic health management information systems (HMIS), Blood Donor Collection Software, general information technology (IT) infrastructure, and software interfaces and digital integration among blood establishments, distribution centers, and healthcare institutions. These technological capabilities introduce unique vulnerabilities to incidental—or malicious—disruptions. Ransomware, a type of malicious software that denies access to devices, system, and files in exchange for ransom, has been responsible for two recent disruptions in the blood supply, highlighting a serious vulnerability. A ransomware cyberattack in June 2024 on Synnovis (London, UK), a laboratory company that provides testing services, resulted in an unprecedented blood shortage across multiple large National Health Service hospitals in London that is ongoing at the time of writing.8 UK officials have imposed limits on blood use and are appealing for increased blood donations; however, thousands of blood donation appointments were canceled due to the disruption in computer systems from the cyberattack and a concurrent global IT outage that impacted EMIS (Leeds, UK), an external organization that provides electronic patient record systems and software used in primary care, acute care, and community pharmacy in the United Kingdom.9 Similarly, in July 2024, a ransomware cyberattack on OneBlood (Orlando, FL), a blood establishment supporting hundreds of hospitals in the Southeastern United States, impaired their ability to label and distribute blood products to hospitals in their catchment area.10 As in the United Kingdom, OneBlood was able to remain operational by implementing manual processes, albeit at significantly reduced capacity. More than 250 hospitals were alerted to activate critical blood shortage protocols. The Florida Hospital Association worked closely with the US Food and Drug Administration (FDA), the Association for the Advancement of Blood and Biotherapies (AABB), and community blood centers to obtain units to meet hospital transfusion needs. Emergency protocols to extend product outdates and allow blood product movement between hospitals were allowed by the FDA to ensure blood availability. Despite these procedures, group O red blood cell (RBC) and platelet inventory levels were severely impacted for several days, resulting in postponed and canceled appointments and procedures. In response to this attack, AABB activated its Interorganizational Task Force on Domestic Disasters and Acts of Terrorism to secure and transport blood products from other blood centers to affected areas.11 Diversion of critical blood products raised the concern of impacting blood inventory in hospitals outside of the OneBlood network. These high-profile ransomware attacks on a fragile blood supply chain endanger patients and public health and underscore the need for contingency planning to maintain a stable blood supply during times of crisis. Key efforts include ensuring best transfusion practices are in place to encourage ordering that minimizes blood transfusion exposure; maintaining regular multidirectional communication of blood availability and utilization among stakeholders; outlining contingency plans when significant changes to blood product demand and/or supply occur; and promoting awareness of blood donation to meet the needs of the public. Further, restriction of type O RBCs and platelets for essential medical cases may be necessary during crisis management; this may include adjusting transfusion thresholds for patients and/or postponing elective medical and surgical procedures that may require transfusion. Physicians should also consider the importance of ensuring that patients undergoing urgent/emergent procedures are made aware of the limited blood supply and the implications.12 While the blood supply is managed at a national level in the United Kingdom, Canada, and other countries, with centralized blood collection and distribution, the US blood supply consists of multiple entities responsible for collection and distribution. In the United States, mergers and consolidation of blood collection establishments over the past two decades have resulted in several large nonprofit organizations supplying the majority of blood products. These entities operate in parallel with a number of large regional blood centers and many smaller local, and sometimes hospital-based, blood collection agencies. Infectious disease testing of blood products has also consolidated, with a single laboratory organization testing 70% of the blood supply across its eight locations.13 There are both disadvantages and advantages to this structure. For example, a single cyberattack could potentially cripple large aspects of the blood system. At the regional level, locations such as South Florida have only a single major local organization that collects most of the blood products. Although there is a program to request blood at the national level for patients with special transfusion needs such as multiple alloantibodies or IgA-deficiency, there is no real-time central data repository of blood collection for the United States as a whole. This results in challenges in determining the location of blood products during a crisis, complicating distribution efforts across the country. Thus, when the blood supply is threatened in these regions, there must be considerations for hospitals to source blood products quickly from noncontracted or secondary blood centers while maintaining all standards of blood product distribution—an issue that does not occur in countries with a national blood system. As such there are unique issues that arise from the variation in reach and scope of some entities, with potential cybersecurity issues arising for both larger and smaller suppliers and laboratories. However, there are strengths of the US blood system being less centralized as well, given the breadth of different providers. Despite the recent mergers and consolidation, multiple systems remain, which beget more redundancy/separation; thus, failures may be less likely to propagate as quickly, and could be contained to a single blood collection establishment. Additionally, a number of US hospitals maintain blood donor centers, which are essentially absent in countries with national blood systems and may provide a buffer against these threats. These specific differences could help prevent a nationwide blood crisis due to a cyberattack. The cyberattacks on Synnovis and OneBlood also highlight susceptibilities inherent to/introduced by modern-day technology; the acute effects of disruptions to these processes are no more evident than in healthcare. Interruptions that prevent transfusion of patients in need (e.g., cardiovascular surgery, trauma, obstetrics, hematopoietic stem cell and solid organ transplant, etc.) can have devastating consequences. Fittingly, on July 17, 2024, a panel of experts from the Task Force Preparation of Labs for Emergencies (TF-PLE) of the European Federation of Clinical Chemistry and Laboratory Medicine (EFLM) published recommendations for reinforcing cybersecurity and managing cyberattacks in medical laboratories.14 While this guidance focused primarily on hospitals and laboratories, many recommendations apply to blood collection establishments and blood banks. For example, regularly updated antivirus software programs and firewalls to prevent outside infiltration are critical. Cloud-based information system servers are favored over physical servers, although vulnerabilities may still exist. “Downtime procedures,” such as those required by AABB standards, should be clearly outlined and expanded.15 Specific recommendations by the expert panel guidance include education on methods used by “cyber-terrorists,” and training simulations during cyberattacks.16 Additionally, the expert panel suggested that establishments prepare a detailed “incident response plan” in the event of a cyberattack, including responsibilities and methods to continue working, in conjunction with the development of an “incident response team” that includes laboratory professionals to assist in minimizing workflow issues. Notwithstanding these recommendations and other expert guidance for mitigating and managing a cyberattack in the medical laboratory, there are unique considerations in the blood collection and blood transfusion domains. Customers use technology to order blood and laboratory testing. Blood establishments rely on technology not only to recruit and schedule donors, but also use Blood Establishment Computer Systems (BECS) to assist in blood manufacturing. BECS are essentially specially licensed laboratory information systems with specialized hardware, software, and interfaces that have received clearance from the FDA in the United States.17 The use of BECS is critical to gain efficiencies, maximize safety, and document every step of the manufacturing process, from donor selection to collection, processing, infectious disease testing, typing, labeling, storage, and distribution of blood components. Technology has become so interwoven into current Good Manufacturing Practice (cGMP) processes that the sudden loss of access to computer systems may necessitate reliance on manual or telephone-based processes, potentially crippling their capacity to collect, manufacture, and distribute blood and to receive orders or electronic communications from hospitals. In addition, sudden conversion to a manual process on a large scale could have safety implications, as manual processes are more error-prone, especially when rarely practiced. As BECS falls under FDA regulations for medical devices, recommendations on cybersecurity device design, labeling, and documentation for premarket submission have been evolving over the past 10 years. More recently, the Department of Homeland Security's (DHS) Cybersecurity and Infrastructure Security Agency (CISA) proposed a rule on cyber incident reporting that included blood centers.18 This rule requires blood centers and other covered critical infrastructure organizations to report covered cyber incidents to the federal government within 72 h and ransom payments within 24 h, in addition to other provisions. The goal is to improve available information to allow for countermeasures and to identify and mitigate vulnerabilities. While the reports will not be made public, anonymized information from the reports may be released to warn against similar attacks. This information will be valuable in protecting against future attacks. In addition, it may be beneficial for blood collection centers to produce novel plans such as blood donor networks, which could be mobilized in the event of a cyberattack or agreements with other blood suppliers in the event of a disruption to their critical systems. Ultimately, we believe that the development of recommendations for how to both prevent and mitigate the effects of cyberattacks that account for the unique considerations in the blood collection and transfusion medicine community should be prioritized to ensure an adequate blood supply and protect patient health. The authors declare no conflicts of interest. Data availability not applicable as no new data were created.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame distilled prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.
Codex and Gemma teacher scores by category
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.002 | 0.003 |
| Meta-epidemiology (narrow) | 0.000 | 0.000 |
| Meta-epidemiology (broad) | 0.001 | 0.000 |
| Bibliometrics | 0.000 | 0.000 |
| Science and technology studies | 0.000 | 0.003 |
| Scholarly communication | 0.000 | 0.000 |
| Open science | 0.001 | 0.000 |
| Research integrity | 0.000 | 0.002 |
| Insufficient payload (model declined to judge) | 0.000 | 0.000 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one teacher head, not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".