More than one study reveal the trouble the healthcare industry continues having when it comes to information security and taking threats seriously. A brief outline of the different findings (from three separate surveys) can help to spotlight some of the issues at hand.
The Global State of Information Security Survey 2015
6th Annual HIMSS Security Survey
5th Annual Privacy and Security of Healthcare Data Report by Ponemon Institute
In addition to the above surveys, our company has found healthcare organizations to have 2000 plus high vulnerabilities per assessment conducted. Not 11 or 100, but 2000. What all this information tells us is that the healthcare industry as a whole has yet to make security threats a priority or if they are, they continue to lack in doing enough to secure their environment and data. For example, thinking that policies and procedures are enough to prevent or quickly detect a data breach is highly erroneous. Add to this inadequate funding and resources for incident response. It’s no wonder these organizations have suffered 11 or more incidents in the past couple years.
Another focal point of the studies shows the increase in healthcare incidents. This trend indicates that threats aren’t going away, quite the contrary. One of the reasons is most likely the value behind medical records on the black market. They are worth 10 times more than credit card numbers and can be used by those who have them to buy medical equipment and drugs or to resell them and use them to file fraudulent claims with insurers.
From the studies we also see how HIPAA compliance isn’t enough to secure healthcare data; especially when organizations and business associates aren’t even meeting the requirements like performing risk assessments for security incidents. If that weren’t enough, we continue to see limited funding for security by healthcare organizations.
With an increase in threat incidents and high-profile breaches, such as the Anthem hack, what is stalling healthcare executives and CIOs in making a change on how they approach security?
These are only five of the most obvious reasons why it’s not possible for healthcare organizations to continue their lax security approach. It’s not a matter of when this becomes obvious, but a matter of when do organizations want to ensure the safety of their patients, employees and enterprise.
What security steps have you taken to secure your PHI and overall environment to avoid data loss?
Photo courtesy of Maksim Kabakou