HSE cyberattack and patient data
Deputy Tóibín condemns the cyberattacks on the HSE and Department of Health as crimes that endangered patients and disrupted care. The Taoiseach calls for a united stance against the attackers, says cybersecurity funding has been increased, and urges that stolen material not be amplified.
-----as Deputy McDonald is well aware. I appeal to Deputies, please, to adhere to the time limit. They are well aware of what the time limit is and, when they are asked to desist, please, would they desist?
Comment on this
The recent cyberattacks on the HSE and the Department of Health are monstrous crimes. They are attacks on the most vulnerable in Irish society. Patients are already struggling with never-ending waiting lists that have been worsened by Covid and ongoing restrictions but shockingly, on top of this, key life and death treatment is again put on hold due to this odious crime. The Government has a duty of care with regard to safeguarding and protecting the health of citizens and their personal data. This responsibility is particularly important in Ireland as we are a data island. Some 30% of the data that exist in the EU are located here. If one is going to mine data, the place to go is Ireland.
What is the record of the Government with regard to protection from cyberattack and safeguarding personal data? According to a reply I received this week to a parliamentary question, Tusla, for example, had 362 breaches in the past year, which is practically a breach for every day of the year. Incredibly, the National Cyber Security Centre, NCSC, has been rudderless for the past year, with no director put in place.
The NCSC is also homeless. It does not even have a permanent residence from which to operate. The Government sees the role of the director of the NCSC to be so important that it has set the wage for that individual lower than a backbench Opposition Member.
The former chief executive officer of the HSE, Tony O'Brien, stated this week that the HSE's expenditure on IT security is approximately a quarter of what would be expected compared to other health systems. That is a phenomenally difficult thing for any Government to have to deal with. The person who was head of the HSE in recent times is saying that the Government is spending a quarter of what it should be spending on cybersecurity. The NCSC has been given a budget of just €5 million. Let us think about that. Last year, the Department of the Taoiseach spent €16.5 million on PR alone. The NCSC has a staff of 25, with no dedicated premises or director and a budget amounting to one third of the Department of the Taoiseach's budget on PR. How can the Government claim to be fulfilling its duty of care with regard to Ireland against cyberattack? After the British NHS suffered a similar attack in 2017, it cost that government £92 million directly to deal with the cost of the attack. It also cost the British Government £210 million to strengthen its cybersecurity in the three subsequent years.
When will patient treatment return? How much will this cost in terms of citizens' lives and health, and taxpayer funds?
Comment on this
I thank the Deputy for raising what is a very serious issue indeed. The first point I will make is that this is an attack on our health service by criminals. There should be no truck or any quarter given to criminals of this kind who undermine patient safety, and seek, by their actions-----
Comment on this
The lack of security is undermining patient safety.
Comment on this
Let us give these people no truck. There should be a collective national effort to articulate one single simple message. What you are doing is outrageous and wrong. It is morally wrong-----
Comment on this
The lack of security is outrageous too.
Comment on this
That is the Government's position on this and I would hope the Opposition's position also. I am responding to Deputy Tóibín's point. I would appreciate the opportunity to respond.
Comment on this
You are taking your time about it.
Comment on this
He does not want to answer the question. Bluffer.
Comment on this
All of the right people are in the right place in responding to these criminals. Cybersecurity is not something new. Every state, system and private sector operator is facing cybersecurity threats and attacks on an ongoing basis. That is my first point.
My second point is that in the last budget alone we trebled funding for the NCSC. We trebled funding for it. More than that, it has not been rudderless as Deputy Tóibín stated. That is a wrong phrase to use. It has not been. There is a vacancy that is being filled. The person could not take it in February, having been vacant since November. It is not without a home. We need less of that sort of melodramatic presentation. That is grist to the mill to those who are attacking the system. We have very good capacity within our system in terms of the quality of the personnel available to deal with this issue. It has been dealt with in the correct manner: contain the problem, remedy, restore and protect. That is what we are about with both the NCSC, and the HSE in terms of restoring services. The chief executive officer of the HSE has long experience in this field from different employment he was in. Our overriding objective is to get service up as quickly as we possibly can for patients. We must do it methodically and properly in a way that is robust against further attack. That is why, unfortunately, it will take time to get services fully restored, but we are prioritising key areas, as Deputy Tóibín knows.
Comment on this
I prefaced my statement by saying where the responsibility lies for this attack. It lies with the criminals who were involved but the Government has a duty of care and responsibility to the patients of this country for the delivery of healthcare and protection of their data. Its duty of care is far more to this country, given that this is an island of data. Right now we have hospitals where operations are being cancelled, people are running around with paper documents and staff are acting as runners between hospitals and GPs.
I raised this issue first in 2013 with the then Minister for Communications, Energy and Natural Resources, Pat Rabbitte. Since then, many people have raised the issue. It is hard to get around the contradictions. Cybercriminals are operating a generation ahead of an island nation that hosts 50 international cybersecurity companies and 6,000 of the world's best cybersecurity experts. Yet there is no permanent home for the National Cyber Security Centre, NCSC, there is no director at the moment and the investment is paltry with regard to the responsibilities the centre holds. When will the Government invest properly in this?
Comment on this
I said even during the last budget debate and, since I became Taoiseach, I have been very focused on the international cybersecurity threat. We have significantly increased funding for the NCSC and, within the HSE, both capital and current funding have gone up dramatically in recent years. Current expenditure has gone from €45 million to €83 million of ICT spend within health; capital expenditure has gone from €85 million to €120 million in 2021, which is an illustration-----
Comment on this
That is not cybersecurity funding; it is ICT.
Comment on this
The overall point is we are consistently increasing funding. This is an ongoing battle, as the Deputy knows. Cybersecurity will not go away any time soon. We will constantly review increasing resources and capacity over coming years to deal with these criminals, who are fundamentally responsible for this attack on patients and our health service. It is important that all those with responsibilities on social media or public media more generally do not facilitate these criminals in the publication of any material they have illegally secured. Our fundamental objective is to restore services as quickly as we can.