The Healthcare Industry: 2014

The Healthcare Industry: 2014's Biggest Data Breach Victim

For many, 2014 has been the year of the data breach. While media attention was largely focused on breaches at major retailers, it was actually the healthcare industry that suffered the most substantial blow this year. According to the Identity Theft Resource Center, the medical industry accounted for 43 percent of all data breaches for the calendar year. And, the Ponemon Institute reported an estimated 1.84 million Americans were victims of medical identity theft last year. It looks like there’s no slowing for healthcare industry breaches, as we can expect an equally active year looking forward.

Starting on January 1, 2015, under provisions set by the 2009 American Recovery and Reinvestment Act, healthcare organizations will be required to show they have implemented digital medical records in order to continue to receive funding from Medicaid and Medicare. With this push to get more and more medical records online, it is essential that we understand why healthcare organizations have been under attack in the past and, more importantly, what these organizations can do to protect themselves from cyber criminals in 2015.

Why are healthcare organizations being targeted?

One of the key reasons healthcare organizations are being targeted with alarming frequency is the financial appeal of a medical identity to cyber criminals. According to the World Privacy Forum, a medical identity, which includes private information like Social Security numbers and health plan ID numbers, is worth about $50 on the online black market. By comparison, a cyber criminal can fetch around $1 for a Social Security number and $3 for an active credit card. The high value of a medical identity makes it incredibly desirable to high-tech criminals looking to make a quick buck.

Another reason for the growth of medical identity theft is the rapidly approaching January 1 deadline for healthcare facilities to show “meaningful use” of electronic health records (EHRs). This deadline is causing many healthcare facilities to scramble to transition existing paper records online in order to avoid penalties. In the process, these facilities are sometimes failing to ensure security best practices. This is especially evident for smaller healthcare facilities. These facilities don’t have the staff or resources that larger organizations have which can put a strain on resources and leads to oversights in security efforts.

What steps are being taken to ensure security now?

This October, CSID, in partnership with Research Now, conducted a survey to gain insight into what measures healthcare facilities are currently taking to protect themselves ahead of the inevitable shift to digital records.

While an overwhelming majority of respondents (85 percent) felt that their systems adequately limit the risk of a breach, only 17 percent of organizations are worried about losing patient data in the case of a breach. Even more worrisome, 41 percent of the surveyed healthcare organizations spend 10 percent or less of their IT budget on protecting patient data against a breach.

The survey also found that roughly half of employees at healthcare organizations that have access to EHRs also have access to their personal email at work – making it easy for patient data to leave a controlled environment undetected.

While most healthcare organizations showed they are implementing basic security measures like firewalls, anti-virus software and strict password enforcement, only 32 percent said they use multi-factor authentication and only 27 percent said they actively vet third-party vendors.

The results of the survey demonstrate that there is plenty of room for healthcare organizations to improve upon their security. With the move to digital records, it’s clear that data breaches will continue to threaten the healthcare industry. So, as we look to 2015:

What can healthcare organizations do to protect themselves?

Make security education for employees a priority: According to CSID’s survey, nearly half of healthcare organizations do not currently have programs in place to educate employees on how medical identity theft happens. Increasing employee education will arm individual employees with the tools they need to protect patient data.

Audit third-party vendors: Not enough healthcare organizations are auditing third party vendors, which is essential for increasing security. Any outside vendor that has access to patient information should be thoroughly vetted.

Track, encrypt and password-protect mobile devices hosting patient information: Organizations should create a BYOD policy that puts strict limits on how patient data can be viewed and transmitted on devices.

Collaborate with other healthcare organizations: In a closed environment, share resources with other organizations and exchange ideas for improving security measures.

Have a response plan: In the event of a data breach crisis, executives and employees should be able to reference an up-to-date plan for guidelines on policies and procedures.

Data breaches will not go away in 2015. Cyber criminals will continue their attempts to steal medical identities, especially as so much of our physical world makes the transition to digital. However, with increased education, a more substantial vetting process for third party vendors, the tracking of mobile devices, increased collaboration among healthcare organizations, and a solid response plan, healthcare organizations can better defend themselves against these cyber threats.

About the Author

Joe Ross is the president and co-founder of CSID.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

  • OpenAI's GPT-4 Is Capable of Autonomously Exploiting Zero-Day Vulnerabilities

    According to a new study from four computer scientists at the University of Illinois Urbana-Champaign, OpenAI’s paid chatbot, GPT-4, is capable of autonomously exploiting zero-day vulnerabilities without any human assistance. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles. 3

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises. 3