The Healthcare Industry: 2014

The Healthcare Industry: 2014's Biggest Data Breach Victim

For many, 2014 has been the year of the data breach. While media attention was largely focused on breaches at major retailers, it was actually the healthcare industry that suffered the most substantial blow this year. According to the Identity Theft Resource Center, the medical industry accounted for 43 percent of all data breaches for the calendar year. And, the Ponemon Institute reported an estimated 1.84 million Americans were victims of medical identity theft last year. It looks like there’s no slowing for healthcare industry breaches, as we can expect an equally active year looking forward.

Starting on January 1, 2015, under provisions set by the 2009 American Recovery and Reinvestment Act, healthcare organizations will be required to show they have implemented digital medical records in order to continue to receive funding from Medicaid and Medicare. With this push to get more and more medical records online, it is essential that we understand why healthcare organizations have been under attack in the past and, more importantly, what these organizations can do to protect themselves from cyber criminals in 2015.

Why are healthcare organizations being targeted?

One of the key reasons healthcare organizations are being targeted with alarming frequency is the financial appeal of a medical identity to cyber criminals. According to the World Privacy Forum, a medical identity, which includes private information like Social Security numbers and health plan ID numbers, is worth about $50 on the online black market. By comparison, a cyber criminal can fetch around $1 for a Social Security number and $3 for an active credit card. The high value of a medical identity makes it incredibly desirable to high-tech criminals looking to make a quick buck.

Another reason for the growth of medical identity theft is the rapidly approaching January 1 deadline for healthcare facilities to show “meaningful use” of electronic health records (EHRs). This deadline is causing many healthcare facilities to scramble to transition existing paper records online in order to avoid penalties. In the process, these facilities are sometimes failing to ensure security best practices. This is especially evident for smaller healthcare facilities. These facilities don’t have the staff or resources that larger organizations have which can put a strain on resources and leads to oversights in security efforts.

What steps are being taken to ensure security now?

This October, CSID, in partnership with Research Now, conducted a survey to gain insight into what measures healthcare facilities are currently taking to protect themselves ahead of the inevitable shift to digital records.

While an overwhelming majority of respondents (85 percent) felt that their systems adequately limit the risk of a breach, only 17 percent of organizations are worried about losing patient data in the case of a breach. Even more worrisome, 41 percent of the surveyed healthcare organizations spend 10 percent or less of their IT budget on protecting patient data against a breach.

The survey also found that roughly half of employees at healthcare organizations that have access to EHRs also have access to their personal email at work – making it easy for patient data to leave a controlled environment undetected.

While most healthcare organizations showed they are implementing basic security measures like firewalls, anti-virus software and strict password enforcement, only 32 percent said they use multi-factor authentication and only 27 percent said they actively vet third-party vendors.

The results of the survey demonstrate that there is plenty of room for healthcare organizations to improve upon their security. With the move to digital records, it’s clear that data breaches will continue to threaten the healthcare industry. So, as we look to 2015:

What can healthcare organizations do to protect themselves?

Make security education for employees a priority: According to CSID’s survey, nearly half of healthcare organizations do not currently have programs in place to educate employees on how medical identity theft happens. Increasing employee education will arm individual employees with the tools they need to protect patient data.

Audit third-party vendors: Not enough healthcare organizations are auditing third party vendors, which is essential for increasing security. Any outside vendor that has access to patient information should be thoroughly vetted.

Track, encrypt and password-protect mobile devices hosting patient information: Organizations should create a BYOD policy that puts strict limits on how patient data can be viewed and transmitted on devices.

Collaborate with other healthcare organizations: In a closed environment, share resources with other organizations and exchange ideas for improving security measures.

Have a response plan: In the event of a data breach crisis, executives and employees should be able to reference an up-to-date plan for guidelines on policies and procedures.

Data breaches will not go away in 2015. Cyber criminals will continue their attempts to steal medical identities, especially as so much of our physical world makes the transition to digital. However, with increased education, a more substantial vetting process for third party vendors, the tracking of mobile devices, increased collaboration among healthcare organizations, and a solid response plan, healthcare organizations can better defend themselves against these cyber threats.

About the Author

Joe Ross is the president and co-founder of CSID.

Featured

  • The Future of Access Control: Cloud-Based Solutions for Safer Workplaces

    Access controls have revolutionized the way we protect our people, assets and operations. Gone are the days of cumbersome keychains and the security liabilities they introduced, but it’s a mistake to think that their evolution has reached its peak. Read Now

  • A Look at AI

    Large language models (LLMs) have taken the world by storm. Within months of OpenAI launching its AI chatbot, ChatGPT, it amassed more than 100 million users, making it the fastest-growing consumer application in history. Read Now

  • First, Do No Harm: Responsibly Applying Artificial Intelligence

    It was 2022 when early LLMs (Large Language Models) brought the term “AI” into mainstream public consciousness and since then, we’ve seen security corporations and integrators attempt to develop their solutions and sales pitches around the biggest tech boom of the 21st century. However, not all “artificial intelligence” is equally suitable for security applications, and it’s essential for end users to remain vigilant in understanding how their solutions are utilizing AI. Read Now

  • Improve Incident Response With Intelligent Cloud Video Surveillance

    Video surveillance is a vital part of business security, helping institutions protect against everyday threats for increased employee, customer, and student safety. However, many outdated surveillance solutions lack the ability to offer immediate insights into critical incidents. This slows down investigations and limits how effectively teams can respond to situations, creating greater risks for the organization. Read Now

  • Security Today Announces 2025 CyberSecured Award Winners

    Security Today is pleased to announce the 2025 CyberSecured Awards winners. Sixteen companies are being recognized this year for their network products and other cybersecurity initiatives that secure our world today. Read Now

New Products

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.