Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
30
2
3
4
5
6
7
9
12
13
14
15
17
19
22
25
27
12:00 AM - HLTH 2019
28
29
30
31
1
2
3
01 Oct
2019-10-01 - 2019-10-02    
All Day
The UK’s leading health technology and smart health event, bringing together a specialist audience of over 4,000 health and care professionals covering IT and clinical [...]
08 Oct
2019-10-08 - 2019-10-09    
12:00 am
Looking to maximize the efficiency of your current Revenue Cycle solution? Join us as we present strategies for analyzing your MEDITECH Revenue Cycle, and learn from other [...]
2019 Southwest Dental Conference
2019-10-10 - 2019-10-11    
All Day
ABOUT 2019 SOUTHWEST DENTAL CONFERENCE For 91 years, the Southwest Dental Conference has been the meeting of choice for quality professional development and innovative educational [...]
Annual Conference & Exhibition Lyotalk USA 2019
2019-10-10 - 2019-10-11    
All Day
ABOUT ANNUAL CONFERENCE & EXHIBITION LYOTALK USA 2019 Lyotalk is USA’s largest annual conference on Lyophilization/Freeze Drying. Lyotalk attracts gathering from of 150+ experts from [...]
Lab Indonesia 2019
2019-10-10 - 2019-10-12    
All Day
ABOUT LAB INDONESIA 2019 LabAsia is Southeast Asia’s leading laboratory exhibition, serving as the region’s trade platform for laboratory equipment & services suppliers to engage [...]
30th International Conference on Clinical and Experimental Ophthalmology
2019-10-11 - 2019-10-12    
All Day
ABOUT 30TH INTERNATIONAL CONFERENCE ON CLINICAL AND EXPERIMENTAL OPHTHALMOLOGY The 30th International Conference on Clinical and Experimental Ophthalmology is going to be held during October [...]
7th International Conference on Cosmetology & Beauty 2019
Cosmetology and Beauty 2019 passionately welcomes each one of you to attend a global conference in the field of cosmetology which is held on October [...]
16 Oct
2019-10-16 - 2019-10-17    
All Day
ABOUT 17TH INTERNATIONAL CONFERENCE ON CANCER RESEARCH AND THERAPY Cancer Research Conference 2019 coordinates addressing the principal themes and in addition inevitable methodologies of oncology. [...]
Global Cardio Diabetes Conclave 2019
2019-10-18 - 2019-10-20    
All Day
ABOUT GLOBAL CARDIO DIABETES CONCLAVE 2019 A strong correlation between cardiovascular diseases and diabetes is now well established. The American Heart Association considers that individuals [...]
2019 Rehabilitation Medicine Society of Australia and New Zealand
2019-10-20 - 2019-10-23    
All Day
ABOUT 2019 REHABILITATION MEDICINE SOCIETY OF AUSTRALIA AND NEW ZEALAND On behalf of Rehabilitation Medicine Society of Australia and New Zealand (RMSANZ) and the organising [...]
21 Oct
2019-10-21 - 2019-10-23    
All Day
ABOUT GLOBAL CONFERENCE ON SURGERY AND ANESTHESIA (GCSA 2019) Global Conference on Surgery and Anesthesia (GCSA 2019) scheduled on October 21-23 2019 in Dubai, UAE [...]
21 Oct
2019-10-21 - 2019-10-22    
All Day
ABOUT 10TH INTERNATIONAL CONFERENCE ON MASS SPECTROMETRY AND CHROMATOGRAPHY ME Conferences is excited to announce the “10th International Conference on Mass Spectrometry and Chromatography” that [...]
MEDICAL JAPAN 2019 TOKYO
2019-10-23 - 2019-10-25    
All Day
ABOUT MEDICAL JAPAN 2019 TOKYO B to B Trade Show Covering All the Products/Services/Technologies in the Healthcare Industry! MEDICAL JAPAN TOKYO, a sister show of [...]
15th ACAM Laser and Cosmetic Medicine Conference 2019
2019-10-23 - 2019-10-25    
All Day
ABOUT 15TH ACAM LASER AND COSMETIC MEDICINE CONFERENCE 2019 As the new president of ACAM, I am delighted to welcome you all to the 15th [...]
23rd European Nephrology Conference
2019-10-24 - 2019-10-25    
All Day
ABOUT 23RD EUROPEAN NEPHROLOGY CONFERENCE Theme: The Imminent of Nephrology: Current & Advance Approaches to treat Kidney Diseases 23rd European Nephrology Conference is the world’s [...]
FNCE 2019 Food & Nutrition Conference & Expo
2019-10-26 - 2019-10-29    
All Day
ABOUT FNCE 2019 – FOOD & NUTRITION CONFERENCE & EXPO Experience dynamic educational opportunities not available elsewhere. Gain access to new trends, perspectives from expert [...]
HLTH 2019
2019-10-27 - 2019-10-30    
All Day
ABOUT HLTH 2019 HLTH is the largest and most important conference for health innovation. It’s an unprecedented, large-scale forum for collaboration across senior leaders from [...]
Events on 2019-10-01
01 Oct
Events on 2019-10-08
08 Oct
8 Oct 19
Massachusetts
Events on 2019-10-10
Events on 2019-10-18
Global Cardio Diabetes Conclave 2019
18 Oct 19
Bidhannagar
Events on 2019-10-23
Events on 2019-10-24
Events on 2019-10-26
Events on 2019-10-27
HLTH 2019
27 Oct 19
Las Vegas
Articles

Cybercrime 2018: Most Hospitals’ IT Security Is Still Not Enough

cybercrime 2018
BIRMINGHAM, UNITED KINGDOM - JUNE 14: A doctor at The Queen Elizabeth Hospital Birmingham does his rounds on the wards on June 14, 2006 in Birmingham, England. Senior managers of the NHS have said that the organisation needs to become more open in the future. (Photo by Christopher Furlong/Getty Images)

Have you noticed? We haven’t read shocking news of record-breaking security breaches, in fact not since 2015-2016. Remember Bon Secours Health System where the information of 655,000 patients was compromised via the internet? Or the breach at 21st Century Oncology Holdings that hit more than two million patients across 181 cancer treatment centers? A cyber attack on Banner Health affected 3.6 million people, and NewKirk Products, a business associate, was hacked to the tune of 3.5 million affected individuals. According to HHS’ Wall of Shame, over 113 million people were hit in 2015 by breaches of their personal data, and in 2016 more than 27 million patient records were impacted. But, in the whole of 2017 “only” about 4.7 million people were victimized, a four year low.  This may seem like good news, but before we get too comfortable with our seemingly safer data security today, here’s the story behind the story —  and it isn’t pretty.

Many big healthcare cybersecurity news stories have focused on ransomware, the frightening new weapon used by hackers to stop healthcare computing operations cold in order to extort bitcoin payoffs. Though ransomware attacks received a lot of press, it is clear that patient identity theft remains the most dangerous threat facing the healthcare industry. Even back  In 2016 the HIMSS Cybersecurity Survey reported that identity theft had become cyber criminals’ strategy of choice because of patient data’s sheer marketplace value.

This year’s HIMSS 2018 Cybersecurity Survey of 239  information security professionals from various healthcare organizations reported a similar predominant trend of identity theft. The number of individuals impacted by security incidents decreased, but the number of incidents has not slowed down. Over 75% reported that their organizations had experienced a significant security incident in the last year. “If anything…significant security incidents will continue to grow in number, complexity, and impact,” according to the report.

Externally based incidents have gotten the most press. HIMSS reports that the three greatest perpetrators of recent significant security incidents are online scam artists (phishing exploiters), negligent hospital insiders, and criminal hackers. These are  followed by malicious insiders and social engineers — hackers who play fraudulent tricks on insiders using tools like phone calls and social media.

If we look a little deeper at the numbers below it becomes clear that our hospital insiders — physicians, nurses, IT and other staff — are complicit, mostly inadvertently (a few, deliberately), in at least 70 percent of security incidents.These would include staff or business associates that are taken in by online scam artists and criminal social engineers, in addition to negligent insiders. Take a look at this screenshot from HIMSS’ 2018 report:

We must squarely look at the unfortunate role of our well-meaning hospital insiders in the dangerous state of healthcare cybersecurity today and step up protections:

  • Phishing and social engineering by bad actors only work if we mere mortals don’t catch these threats before damage occurs. Such incidents accounted for 37.6 percent of security breaches last year.
  • Negligent insiders accounted for 21 percent of incidents.
  • Social engineering (almost five percent of last year’s incidents) succeeds only if our staff doesn’t recognize and catch it.
  • Over five percent of insiders were deliberately bad actors.

It’s clear that healthcare organizations must do more to reduce these internal vulnerabilities, as well as prevent external hacking in its many ever changing forms.

The somewhat good news: About 85% of respondents say that their organizations have increased the resources needed to manage cybersecurity concerns. The following graph shows the percentage of IT budgets allocated to cybersecurity in 2018.

We can all agree that any increased expenditures and efforts to protect our hospitals’ data are important actions, but we all should be concerned that the overall hospital industry’s response to the abundance of security risks has not been greater or more clearly defined as priorities in IT budgets.

Specific efforts focusing on internal vulnerabilities should be especially high priority. Potential issues like the following must be hit hard:

  • How thorough and frequent is staff training? Is it absolutely required of all staff?
  • Are stringent rules in place that clearly include severe consequences?
  • Is the IT department and security staff in control — or instead, overwhelmed or not effectively engaged?  For example, does IT follow and enforce best practices in secure network management, device management, and the simplest of protections, frequent password changes designed for difficulty? Is IT conducting frequent systems penetration testing? Is IT on top of the most dangerous, current potential cyberthreats?
  • Does the IT department include highly trained security staff, either employees or external contractors?
  • Are thorough security risk analyses conducted at least once a year — ideally, more frequently?
  • Is the C-suite committed to data security and privacy, and is this communicated enterprise wide?
  • Are necessary security and privacy protections adequately funded?

Most predictions indicate healthcare is headed into a period of increased cybersecurity risks in 2019 and beyond.  Hospitals, other providers and business associates should complete a security risk analysis soon, if they haven’t yet conducted one this year.  As always, well-qualified internal IT security professionals or an objective third part security professional must lead the process. Then they should calibrate your organization’s unique risks against potential costs — including the privacy costs of patients — to plan ahead for technical and social protections that will minimize your vulnerabilities and thwart the cyberthreats that are sure to come.

________________________________

If you need the security knowledge and expertise of certified specialists with over 20 years of hospital privacy and security experience, contact us.

ABOUT D’ARCY GUERIN GUE

Vice President, Industry Relations

D’Arcy Guerin Gue is a co-founder of Phoenix, with over 25 years of experience in executive leadership, strategic planning, IT services, knowledge leadership, and industry relations —  and a special focus on patient engagement and federal compliance issues.

Phoenix is a division of Medsphere Systems.