The Most Common Healthcare Security Problem Could Be Right Under Your Nose

The Most Common Healthcare Security Problem Could Be Right Under Your Nose

The question is this: How can healthcare organizations protect themselves against threats when most originate from within their own walls?

Verizon’s "2018 Data Breach Investigation Report" did not paint a pretty picture for the state of healthcare data security. Not only is the healthcare industry the most vulnerable to cyberattacks, but it’s also the only industry in which more data breaches are caused by internal actors (56 percent) than external ones (43 percent).

This disparity stems from a combination of factors — not the least of which is the complex communication that’s involved in delivering patient care. In other industries, such as banking, limiting access to sensitive information is usually simple and role-based. By comparison, healthcare professionals must share protected health information (PHI) not only with one another, but also with third-party entities and individuals, such as specialists and insurance providers.

With so many outside parties having such unrestricted access to patient information, it is no wonder the risk of a data breach is so high. The question is this: How can healthcare organizations protect themselves against threats when most originate from within their own walls?

The Threats Within Your Organization

The U.S. Computer Emergency Readiness Team (US-CERT) classifies an insider threat as an “employee, contractor, or other business partner who has or had authorized access to an organization's network, system, or data and intentionally misused that access to negatively affect the confidentiality, integrity, or availability of the organization's information or information systems.”

Often, people bucket insider threats into two categories — “malicious” or “accidental” — but there is also a third category: “non-malicious.” It might seem like semantics, but it is important to know how to best protect your organization against each type:

1. Take Measures Against Vengeful Employees

A malicious insider threat is one that deliberately aims to harm your organization, whether that involves stealing patient and financial information, sabotaging your IT infrastructure, committing wide-scale fraud, or quietly spying on your organization. After analyzing more than 800 malicious attacks, US-CERT could not discern a standard profile for malicious insider threats.

Unlike a remote hacker, who uses technical means to infiltrate your system, a malicious insider will adopt more insidious means, such as social engineering and exploiting business processes to gain access. Because malicious insiders all operate differently and cannot be profiled, preventing their attacks can prove very difficult.

That said, you can mitigate your organization’s risk by remedying weaknesses in security policies and holding awareness training. Watch for red flags that could warn you of an employee’s malicious intent, such as downloading abnormal data and bragging about hacking abilities. Also, teach employees how to spot these signs, and create a confidential model for reporting them so employees feel more confident doing so.

For even stricter security precautions, use advanced data tracking and analytics to keep an eye on data anomalies and monitor any suspicious activity on the network. When used correctly, technology and comprehensive security policies will be your strongest tools against a malicious attack.

2. Combat User Error

Employees who are an accidental insider threat have no intent to break policy or harm your organization but instead fall victim to the pitfalls of simple human error.

Even with high-end spam filters and redundancies in place, healthcare employees continue to frequently make mistakes that leave them vulnerable to phishing attacks. An overconfidence in their ability to spot scams coupled with sophisticated techniques like display name spoofing leads employees to trust emails that come from seemingly legitimate sources.

Combat accidental threats by reminding employees that it only takes a single click for hackers to gain access to the system. Regular training programs will keep employees vigilant, and routine policy reviews will make sure they fully understand the rules. You can never overstate the risk involved with growing complacent.

Also, boost employee awareness by providing them with security tools that block suspicious websites from loading and prevent them from unwittingly downloading suspicious email files. If employees’ devices ask permission before completing such actions, they will be forced to think deliberately about the risks.

3. Prioritize Policy Over Politeness

Non-malicious insider threats exploit certain policies and practices, too, but not with the intent to harm the organization. In many cases, this type of threat occurs when an employee breaks a policy to help a fellow employee — for instance, sharing a password. While the employee had good intentions, he or she has now created an entry point for a potential malicious actor.

For example, when Edward Snowden stole data from the National Security Agency with the intent to compromise it, he gained much of his access by fooling co-workers into sharing their login credentials. As non-malicious threats, the co-workers wittingly broke policy to help a colleague in need and unwittingly paved the way for extensive data theft. These same co-workers could have been the NSA’s frontline defense against Snowden — if they had reported his request to violate a policy.

To avoid similar situations, make sure employees are aware of updated security policies through routine awareness training. Also, stress the importance of policy over politeness, and encourage them to report any violations they witness. Snowden’s co-workers might have questioned whether it was a good idea to give him access to their accounts but did so anyway to avoid seeming impolite. When everyone agrees policy is the most important factor, politeness is no longer a hindrance to security.

As hackers discover more sophisticated ways to compromise organizations’ data security, the rate of ransomware, data theft, and other cyberattacks will continue to increase. As the most frequently targeted industry, healthcare organizations would do well to pay special attention to the telltale signs of security threats — from both outside and inside their walls.

Featured

  • TSA Intercepts 6,678 Firearms at Airport Security Checkpoints in 2024

    During 2024, the Transportation Security Administration (TSA) intercepted a total of 6,678 firearms at airport security checkpoints, preventing them from getting into the secure areas of the airport and onboard aircraft. Approximately 94% of these firearms were loaded. This total is a minor decrease from the 6,737 firearms stopped in 2023. Throughout 2024, TSA managed its “Prepare, Pack, Declare” public awareness campaign to explain the steps for safely traveling with a firearm. Read Now

  • 2024 Gun Violence Report: Fewer Overall Incidents, but School Deaths and Injuries Are on the Rise

    Omnilert, provider of gun detection technology, today released its compilation of Gun Violence Statistics for 2024 summarizing gun violence tragedies and their adverse effects on Americans and the economy. While research showed a decrease in overall deaths and injuries, the rising number of school shootings and fatalities and high number of mass shootings underscored the need to keep more people safe in schools as well as places of worship, healthcare, government, retail and commerce, finance and banking, hospitality and other public places. Read Now

  • Survey: Only 7 Percent of Business Leaders Using AI in Physical Security

    A new survey from Pro-Vigil looks at video surveillance trends, how AI is impacting physical security, and more. Read Now

  • MetLife Stadium Uses Custom Surveillance Solution from Axis Communications

    Axis Communications, provider of video surveillance and network devices, today announced the implementation of a custom surveillance solution developed in collaboration with the MetLife Stadium security team. This new, tailored solution will help the venue augment its security capabilities, providing high-quality video at unprecedented distances and allowing the security team to identify details from anywhere in the venue. Read Now

Featured Cybersecurity

Webinars

New Products

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions. 3

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame. 3

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.” 3