Taipei: The Ministry of Digital Affairs (MODA) has announced new initiatives designed to bolster cybersecurity in Taiwan's medical sector, following cyberattacks on several hospitals earlier this year attributed to a Chinese hacker. The measures aim to prevent potential paralysis of hospital operations and protect sensitive personal data from being compromised.
According to Focus Taiwan, MODA Deputy Minister Lin Yi-jing expressed concerns at a news conference in Taipei about hospitals being vulnerable to ransomware attacks, which could critically impact Taiwan's healthcare infrastructure. To combat these threats, MODA is collaborating with the Ministry of Health and Welfare (MOHW) to enhance cybersecurity protections for hospitals, which are deemed critical infrastructure.
MODA's strategy includes implementing four key measures: conducting cyber defense drills, developing cybersecurity talent, providing institutional guidance, and intensifying inspections. Tsai Fu-longe, director-general of MODA's Administration for Cyber Security, highlighted an exercise planned for late 2025 that will engage domestic and international white-hat hackers to identify vulnerabilities within the medical sector.
The drills will involve eleven hospitals working together to fend off simulated cyberattacks, thereby improving their capacity to implement protective measures and report incidents. Tsai emphasized the importance of these drills in fostering cooperation among hospitals and improving their technical defenses.
Following attacks by a hacker known as "CrazyHunter" earlier this year, Lee Chien-chang, head of MOHW's Department of Information Management, noted improvements in the resilience of Taiwan's medical sector. The ransomware attacks had disrupted the computer systems of Taipei's MacKay Memorial Hospital in February and Changhua Christian Hospital in March. While no data breach occurred at Changhua, patient information was stolen from MacKay and later offered for sale when the hospital declined to pay the ransom.
In response to these incidents, the MOHW issued guidelines in March to help hospitals respond effectively to ransomware attacks. Lee stated that these guidelines, which outline actions to take within specific time frames post-attack, are unique to Taiwan.
All medical centers in Taiwan have since installed Endpoint Detection and Response (EDR) systems, a cybersecurity tool that was largely absent before the attacks but proved effective in protecting some systems during the February incident. In April, the Criminal Investigation Bureau identified "CrazyHunter" as a 20-year-old employee of a cybersecurity firm in Zhejiang Province, China. This revelation raised questions about potential Chinese government involvement, though Lee refrained from speculating on the matter.
In addressing the readiness of Taiwan's medical sector for future attacks, Lee emphasized the government's focus on resilience, ensuring that, if breached, hospital operations can be swiftly restored. "This is what we are working on now," Lee concluded.