Main Session
Sep 29
SS 44 - Using AI and Other Software to Elevate Patient Safety and Quality

338 - Development and Validation of a Vendor-Neutral Backup and Recovery Software for Cyberattack Resiliency

02:45pm - 02:55pm ET
Room 256

Presenter(s)

Danfu Liang, PhD - Thomas Jefferson University, Philadelphia, PA

D. Liang1, J. Pijanowski2, Y. Chen3, A. Safakish1, M. Marquess1, J. Sanchez1, J. M. Lamb2, and Y. Vinogradskiy3; 1Department of Radiation Oncology, Sidney Kimmel Medical College at Thomas Jefferson University, Philadelphia, PA, 2UCLA, Department of Radiation Oncology, Los Angeles, CA, 3Dept. of Radiation Oncology, Sidney Kimmel Medical College and Comprehensive Cancer Center, Thomas Jefferson University, Philadelphia, PA

Purpose/Objective(s): Cyberattacks may result in loss of access to record and verify (R&V) systems in radiation oncology, creating major challenges for timely and safe continuation of patient treatments. There is a lack of tools and methods that enable reliable, independent access to critical radiotherapy information to support safe and timely continuation of care during R&V downtime. The purpose of this work was to develop and evaluate through cyber resiliency exercises, a novel Radiotherapy Backup and Recovery Dashboard Tool (RBRDT).

Materials/Methods: The RBRDT was developed to back up the latest radiotherapy records to a local server and intuitively display patient information, including delivered fractions, setup notes, last treatment date, and other relevant data in a human-readable web-based dashboard. The RBRDT works with either an electronic patient information management system or a patient information system and can directly generate treatment cards to facilitate on-treatment record keeping in the event of R&V downtime. The RBRDT was successfully deployed at two institutions and was evaluated through cyber resiliency exercise at each institution where either either an electronic patient information management system (Institution 1) or a patient information system (Institution 2) were assumed to be unavailable. The cyber resiliency exercises included selecting current on-treat patients and multi-disciplinary teams were instructed to 1) determine which fraction each patient is on and 2) prepare a treatment card for each patient. On treat patients were divided into 2 equal cohorts. For cohort 1, participants used available systems, excluding the R&V and RBRDT, to retrieve treatment information and generate treatment cards. For cohort 2, participants were able to use the RBRDT. Task completion time and failure modes were compared between cohort 1 and 2.

Results: 95 patients were evaluated for the cyberattack resiliency exercises across both institutions. Manual recovery required an average of 69 minutes (Institution 1 = 66 minutes, Institution 2 = 72 minutes), compared with 25 minutes using the RBRDT (Institution 1 = 29 minutes, Institution 2 = 21 minutes). Without the RBRDT, failure modes included incorrect treatment card generation and inaccurately identifying on-treatment fractionation due to sub-optimal record keeping, confusion regarding re-simulation plans, and uncertainty for multi-site treatments. With the RBRDT, minor issues were observed including missing information for patients not yet on treatment and timing-related delays when the backup occurred after treatment.

Conclusion: In a simulated cyberattack-related R&V downtime scenario, the use of the developed RBRDT software reduced time to recovery of treatment information and improved workflow compared with manual recovery methods. Overall, these findings demonstrate that RBRDT can enhance cyber resiliency and support timely and accurate resumption of radiotherapy treatments during R&V system downtime.