Healthcare Suffers From A Lack Of Security Awareness

Healthcare organisations have suffered 22 major data breaches in the past year, resulting in the exposure of millions of patient information, a new study shows.

The 2016 Healthcare Industry Cybersecurity Report from SecurityScorecard illustrates the ills in healthcare's cybersecurity posture. SecurtiyScorecard conducted an analysis of 700 healthcare organizations including medical treatment facilities, health insurance agencies, and healthcare manufacturing businesses. The study covers the period of August 2015 through August 2016.

Network security, IP reputation, and patching cadence are among healthcare's biggest struggles, the study found. Seventy percent of health insurance providers are not adequately protecting patient information, and 63% of the 27 largest US hospitals received a C or lower in Patching Cadence, as they don't fix bugs in their software. More than 75% of the industry suffered malware infections.

"The greatest security threat comes in the form of malware that will take data and provide access to database resources," says Alex Heid, chief research officer at SecurityScorecard.

Healthcare also suffers from a security awareness problem among users.

"We found a significant correlation between malware infections, and security awareness and social engineering of employees within enterprises," says Heid. Combined with high amounts of vulnerable endpoints, including web browsers and operating systems, this leads to a spike in malware from healthcare organizations.

Healthcare is a target for exploitation because its businesses are sitting on the same data financial companies collect, Heid explains. This includes full names, dates of birth, social security numbers, and other information that can be used for identity theft.

However, healthcare providers don't have the same protection as financial institutions, he continues. The purpose of banks is to transfer and protect finances, as well as the technology to support them.

Healthcare companies are focused on human health and healing, and ensuring their services are operational to provide medical care. They weren't thinking about security difficulties because they hadn't happened yet, he continues. "Now, they have to learn by getting scratched."

"There's a need to balance security and functionality that has been difficult for the healthcare industry," he says. "The security aspect has always taken a backseat because it was never considered to be as large of a target as it has become."

How Healthcare Orgs Get Hit

A common way for malware to enter organisations is through employees who engage with suspicious websites from work, using their corporate email addresses. These may include adult online dating sites or webpages promising opportunities to make money from home.

While this trend spans all industries, Heid notes in healthcare there is a correlation between malware and high numbers of employees entering information on these websites from work computers. This is a sign of poor security awareness; workers who interact with these sites are also likely to open potentially malicious email attachments.

The study also sheds light on the growing risk of network-connected devices, aka IoT: wireless medical devices and tablets, for example. New hardware has enabled medical advancements and benefited hospitals and patients, but quick deployment has resulted in weak security.

Further, more modern IoT medical devices are being used to collect sensitive health data and require tougher network security. "It's very important hospitals understand the full capabilities of advanced medical devices they're implementing before potentially fatal accidents occur," says Heid.

Another security challenge for healthcare organisations is updating legacy Web applications. Many insurance companies and healthcare providers have merged or been acquired, and their old networks and infrastructure have been grandfathered in.

This heightens security risk, says Heid, as many companies are still using legacy Web apps that are over ten years old, and have been fixed with band-aids over the years. Now, they need a full overhaul.

Heid says healthcare organisations must patch their systems, run up-to-date endpoint software, and conduct continuous monitoring and vulnerability assessments to understand where the weak points are.

Going forward, the healthcare industry will continue to experience myriad security problems: new hacked databases from third-party providers will circulate; new medical devices will enter the market.

However, healthcare organisations are becoming more security-savvy, he says. "Healthcare businesses and their leadership are definitely starting to pay attention," he says. "Nobody wants to be the next headline."

Dark Reading:                       Healthcare Industry Lacks Basic Security Knowhow

« Find The Hacker With Action Security Intelligence
Cost of Data Breaches Will Keep On Getting Higher »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Continuity Shop

Continuity Shop

Continuity Shop provides training and consultancy in Business Continuity and Information Security to some of the world's biggest organisations.

Datto

Datto

Datto delivers a single toolbox of easy to use products and services designed specifically for managed service providers and the businesses they serve.

AllegisCyber Capital

AllegisCyber Capital

AllegisCyber is an investment company with a focus on seed and early stage investing in cybersecurity and its applications in emerging technology markets.

Miratech

Miratech

Miratech is a global IT services and consulting organization offering a full range of IT infrastructure solutions and services including cyber security.

Synectics Solutions

Synectics Solutions

Synectics deliver solutions for reducing risk, combating financial crime, and enabling organisations to meet their compliance and regulatory commitments.

Rule4

Rule4

Rule4 is a global professional services firm that provides practical, real-world knowledge and solutions in areas including cybersecurity, AI, Machine Learning and industrial control systems.

Shift5

Shift5

Shift5 focus on securing operational technology (OT) by building best-in-class, dual-use products serving military and commercial entities.

DDOS-Guard

DDOS-Guard

DDoS-GUARD is one of the leading service providers on the global DDoS protection and content delivery markets.

Critical Start

Critical Start

Critical Start provides Managed Detection and Response services, endpoint security, threat intelligence, penetration testing, risk assessments, and incident response.

N8 Identity

N8 Identity

N8 Identity helps organizations realize the vision of Autonomous Identity Governance™ with AI-driven Identity solutions.

Netpoleon Group

Netpoleon Group

Netpoleon is a leading provider of integrated security, networking solutions and value added services.

VinCSS

VinCSS

VinCSS Internet Security Services JSC is a leading organization working in the field of researching, developing, producing products as well as providing cyber security services.

Acora

Acora

Acora provide a range of best-in-class managed services, Microsoft-centric business software, and cloud solutions designed to help mid-market organisations succeed in the digital economy.

SafeBase

SafeBase

Safebase provide the infrastructure for Trust Communication. Our Trust Center enables Security and Sales teams to share and automate access to security, compliance, and privacy information.

Miggo Security

Miggo Security

Miggo is the first Application Detection and Response (ADR) platform on a mission to stop application breaches.

Affinity Technology Partners

Affinity Technology Partners

Affinity Technology Partners has been fueling the growth of Nashville, Tennessee businesses and nonprofits with reliable IT services since 2002.