News | Cybersecurity | October 31, 2016

Healthcare Industry Lacking in Basic Cybersecurity Awareness Among Staff

New healthcare cybersecurity report exposes risk of attacks through social engineering, highlights vulnerability of industry

cybersecurity, healthcare industry, SecurityScorecard report, social engineering, cyberattacks

October 31, 2016 — SecurityScorecard, a security rating and continuous risk monitoring platform, released its 2016 Healthcare Industry Cybersecurity Report in October. The report is a comprehensive analysis exposing alarming cybersecurity vulnerabilities across 700 healthcare organizations including medical treatment facilities, health insurance agencies and healthcare manufacturing companies. Security breaches in this industry pose devastating consequences, according to the company, because they can render an entire system or network inoperable, creating a life or death situation that needs immediate attention.

Among all industries, healthcare ranks 15th out of 18 in Social Engineering, suggesting a security awareness problem among healthcare professionals, putting millions of patients at risk.  The Verizon Data Breach Report ranks Social Engineering as the third most common cause for breaches, a number that is rising at the same rate as Hacking and Malware.

"The low Social Engineering scores among a multitude of healthcare organizations show that security awareness and employee training are likely not sufficient," said Alex Heid, chief research officer at SecurityScorecard. "Security is only as strong as the weakest link, and employees are often the lowest-hanging fruit when it comes to phishing, spear phishing and other social engineering attacks. For a hacker, it only takes one piece of information such as learning the email structure of an organization to exploit an employee into divulging sensitive information or providing an access point into that organization's network."

Another risk is the array of devices with wireless capabilities such as Internet of Things (IoT) devices, wireless medical devices and tablets, which have paved the way for medical advances benefiting hospitals and patients. However, their speedy delivery and implementation has resulted in subpar security setups.

"As long as these IoT devices are manufactured with poor security standards, the vulnerability doesn't only lie within the devices themselves, but they also pose a risk to any hospital, treatment center or individual using the device. If a connected device is hacked into, the device can be forced to malfunction or it can be used as a pathway to reach an organization's primary network," continued Heid.

Among the report's key findings are:

  • Over 75 percent of the entire healthcare industry has been infected with malware over the last year;
  • Ninety-six percent of all ransomware targeted medical treatment centers;
  • Healthcare manufacturing nearly reaches a 90 percent malware infection rate;
  • Sixty-three percent of the 27 biggest U.S. hospitals have a C or lower in Patching Cadence, which measures an organization's ability to implement security software patches in a timely fashion;
  • Healthcare has the fifth highest count of ransomware among all industries;
  • Over 50 percent of the healthcare industry has a Network Security score of a C or lower; and
  • Past-breached healthcare companies still have 242 percent as many low scores in Social Engineering compared to non-breached companies

Ransomware and breaches are affecting the healthcare industry at an increasingly alarming rate, according to the report, with 22 major public breaches occurring since August 2015. Earlier this year, Hollywood Presbyterian Medical Center paid $17,000 as a result of ransomware after losing access to patient records for 10 days. In March 2016, 21st Century Oncology struggling with DNS Health, Network Security and Patching Cadence suffered a data breach that led to a loss of 2.2M patient records and a $57M class-action lawsuit. Overall, breached healthcare companies still struggle with security post-breach, according to the report.

 

Related Healthcare Cybersecurity Content:

Raising the Bar for Medical Device Cyber Security

Market Report Calls Into Question St. Jude Medical EP Device Safety, Cybersecurity

FDA Harshly Criticizes Abbott, St. Jude For Failure to Address EP Device Safety

Healthcare 2015 Data Breaches - Why the Cloud Is Not Responsible

HIMSS: Two-Thirds of Healthcare Organizations Experienced a Recent, Significant Security Incident

How You Should – and Should Not – Be Sharing Medical Information With Patients

How Can Doctors Practice Better Security?

 

For more information: www.securityscorecard.com

Related Content

Scranton Gillette Communications Names Diagnostic and Interventional Cardiology Group Publisher and Integrated Media Consultant

Diane Vojcanin (left) was named vice president, group publisher, healthcare group, overseeing Imaging Technology News (ITN) and Diagnostic and Interventional Cardiology (DAIC). Andreja Slapsys (right) was named a healthcare group integrated media consultant.

News | Cardiovascular Business | September 06, 2019
Business-to-business communications company Scranton Gillette Communications has named Diane Vojcanin as vice president...
FDA Opens Proposal Solicitation Period for 2020 Experiential Learning Program
News | Cardiovascular Business | July 17, 2019
The U.S. Food and Drug Administration (FDA) Center for Devices and Radiological Health (CDRH) announced the 2020...
The Current Direction of Healthcare Reform Explained by CMS Administrator Seema Verma
News | Cardiovascular Business | June 11, 2019
Centers for Medicare and Medicaid Services (CMS) Administrator Seema Verma addressed the American Medical Association (...
DAIC Earns Azbee National Bronze Award for Social Media Presence
News | Cardiovascular Business | May 10, 2019
May 10, 2019 — Diagnostic and Interventional Cardiology (DAIC) earned a Bronze Award at the 2019 Na
Cath lab staff working as a team to prepare for a procedure at Presbyterian Medical Center Cardiac Cath Lab, Charlotte N.C. Pictured are Barry Horsey RCIS, Emily Luna RN, RCIS, Adam Martin RCIS, Caleadia Jessup RN.

Cath lab staff working as a team to prepare for a procedure at Presbyterian Medical Center Cardiac Cath Lab, Charlotte N.C. Pictured are Barry Horsey RCIS, Emily Luna, RN, RCIS, Adam Martin, RCIS, Caleadia Jessup, RN.

Feature | Cardiovascular Business | May 03, 2019 | Ruben Filimonczuk, RCES, AS-PMD
One of the most promising areas for innovation in healthcare is to be found in the workforce – both in hiring and ret
Fail-safe Program for New Medical Technology Focuses on Patient Safety
News | Cardiovascular Business | April 29, 2019
New medical technology offers the promise of improving patient care, as well as the potential for harm if caregivers...
Medicare Trustees Report Hospital Insurance Trust Fund Will Deplete in Seven Years
News | Cardiovascular Business | April 22, 2019
The Medicare Hospital Insurance (HI) Trust Fund, which funds Medicare Part A, will only be able to pay full benefits...
Videos | Cardiovascular Business | April 16, 2019
A discussion with Ruth Fisher, MBA, vice president of the...
Foreign-trained doctors now make up one-third of cardiologists in the United States and help make up for the U.S. overall shortage of physicians. Pictured here is co-author of this article Mandeep R. Mehra, MBBS, MSc, FRCP, who is an example of the contribution international physicians have made in the U.S. He is medical director of the Brigham and Women’s Hospital Heart and Vascular Center.

Foreign-trained doctors now make up one-third of cardiologists in the United States and help make up for the overall shortage of physicians. Pictured here is co-author of this article Mandeep R. Mehra, MBBS, MSc, FRCP, who is an example of the contribution international physicians have made in the U.S. He is medical director of the Brigham and Women’s Hospital Heart and Vascular Center, The William Harvey Distinguished Chair in Advanced Cardiovascular Medicine, and a professor of medicine at Harvard Medical School. He is past-president of both the Heart Failure Society of America and the International Society of Heart and Lung Transplantation. 

Feature | Cardiovascular Business | April 15, 2019 | William W. Pinsky, M.D., FAAP, FACC, and Mandeep R. Mehra, MBBS, MSc , FRCP
As we strive to process today’s successive news cycles involving negative reports about immigration, it is easy for m
Overlay Init