- Job title
- Accounting clerk
- Sector
- Media and publishing
- Organization type
- two-branch business
- Joined
- Dec 2024
- Message
- 113
We operate a private nursing home and elderly care facility with a 45-bed capacity in eastern France. We have a team of 22 healthcare and support staff. Our systems process highly sensitive data, including residents' chronic illnesses, daily medication dosage schedules, physician reports, legal guardian contact details, and social security records. Our IT infrastructure consists simply of a local file server, a patient care tracking system, and 8 office PCs. We pay an external technician 800 EUR a month for part-time maintenance support.
Over the past few months, we've been horrified by news reports about the surge in ransomware (rançongiciel) attacks on hospitals and care facilities across France. When I brought this up with our technician, he brushed it off, saying, "All the PCs have antivirus installed and up to date, nothing's going to happen to us." That answer didn't reassure me at all, though.
In a potential ransomware attack, beyond locked computers, what are we realistically risking with regulatory authorities (CNIL, ARS, etc.)? How do official breach notification procedures work, and what practical measures should a care home with a limited budget like ours implement immediately?