AIIMS expediting 'complete revamp' of IT infra after cyber attacks

Institute has asked NIC to develop dashboard in eHospital for real time hospital bed availability

AIIMS Delhi
As per official documents, the November 23 incident was the first time that AIIMS came under a cyber attack
Deepak Patel New Delhi
3 min read Last Updated : Jun 12 2023 | 6:19 PM IST
After facing two cyber attacks in the last eight months, All India Institute of Medical Science (AIIMS) in New Delhi is expediting "complete revamp" of its IT infrastructure with special emphasis on "improving legacy network and security operations centre", according to official documents reviewed by Business Standard.

Asked about information about this "complete revamp" the institute is planning, an AIIMS spokesperson said the "details are still under finalisation".

AIIMS has been using a dashboard, developed in-house, to show information about real-time emergency beds availability. "After the recent (November 23) cyber incident, NIC (National Informatics Centre) has been requested to develop the dashboard in eHospital," the documents noted. The eHospital portal is an online registration and hospital management system being used by 1,138 hospitals, including AIIMS in New Delhi.

The first cyber attack on AIIMS took place on November 23 last year when files on the NIC's eHospital were found to be encrypted. A message was found on the server suggesting that it was a "ransomware attack". This incident affected the hospital's operations for two weeks.

The second cyber attack on AIIMS took place just last week but the hospital's cyber security systems were able to successfully thwart this attempt. "The eHospital services remain to be fully secure and are functioning normally," AIIMS had stated on June 6.

As per official documents, the November 23 incident was the first time that AIIMS came under a cyber attack. "Such a cyber security incident happened at AIIMS, New Delhi, for the first time. The older network was unmanaged and its upgradation was already being worked upon. Old computers (were) not getting operating system updates and are now getting replaced," they mentioned.

"After taking the immediate measures, cyber security is being further strengthened in coordination with the agencies concerned. A complete revamp of the IT infrastructure, which is in the pipeline, is being expedited with emphasis on improving legacy network and security operations centre," the documents noted.

The copies of data are now protected in different servers for the continuity of business activity. "This was done by putting in place enhanced security features which could be implemented immediately like endpoint hardening, strong firewall policies and network segmentation, etc, with the help of CERT-In (Indian Computer Emergency Response Team) and other agencies," the documents stated.

When the first cyber incident took place at 7 AM on November 23, the systems were immediately disconnected and put offline to prevent further spread of the infection. "The CERT-In was informed about this cyber incident and an FIR dated November 24, 2023, was registered with the special cell of the Delhi police. Six infected physical servers were seized by the Delhi police's special cell for their investigation," the documents said.

All the data for eHospital, they noted, was retrieved from a backup server which was unaffected and restored on new servers. "Most functions of the eHospital application like patient registration, appointment, admission, registration, etc were restored after two weeks of the incident," they added. In this interim two-week period, the hospital services were provided in offline/manual mode.
FINGER ON PULSE

1. AIIMS suffered a malware attack last week. However, this attempt was thwarted.

2. The first attack took place on November 23 last year when the hospital's operations were affected for two weeks.

3. The plan regarding complete revamp of IT infra has not been finalised as yet

4. Meanwhile, NIC has been asked to create a dashboard for real time emergency bed availability

One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Topics :AIIMSCyber AttacksDelhi

Next Story