Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
1
2
6
7
9
10
11
12
13
14
18
19
20
21
23
27
28
30
12:00 AM - Hepatology 2021
31
1
2
3
4
Heart Care and Diseases 2021
2021-03-03    
All Day
Euro Heart Conference 2020 will join world-class professors, scientists, researchers, students, Perfusionists, cardiologists to discuss methodology for ailment remediation for heart diseases, Electrocardiography, Heart Failure, [...]
Gastroenterology and Digestive Disorders
2021-03-04 - 2021-03-05    
All Day
Gastroenterology Diseases is clearing a worldwide stage by drawing in 2500+ Gastroenterologists, Hepatologists, Surgeons going from Researchers, Academicians and Business experts, who are working in [...]
Environmental Toxicology and Ecological Risk Assessment
2021-03-04 - 2021-03-05    
All Day
Environmental Toxicology 2021 you can meet the world leading toxicologists, biochemists, pharmacologists, and also the industry giants who will provide you with the modern inventions [...]
Dermatology, Cosmetology and Plastic Surgery
2021-03-05 - 2021-03-06    
All Day
Market Analysis Speaking Opportunities Speaking Opportunities: We are constantly intrigued by hearing from professionals/practitioners who want to share their direct encounters and contextual investigations with [...]
World Dental Science and Oral Health Congress
2021-03-08 - 2021-03-09    
All Day
About The Webinar Conference Series LLC Ltd invites you to attend the 42nd World Dental Science and Oral Health Congress to be held in March 08-09, 2021 with the [...]
Euro Metabolomics & Systems Biology
2021-03-08 - 2021-03-09    
All Day
Euro Metabolomics 2021 will be a platform to investigate recent research and advancements that can be useful to the researchers. Metabolomics is a rapidly emerging [...]
International Summit on Industrial Engineering
2021-03-15 - 2021-03-16    
All Day
Industrial Engineering conference invites all the participants to attend International summit on Industrial Engineering during March15-16, 2021 Webinar. This has prompt keynotes, Oral talks, Poster [...]
Digital Health 2021
2021-03-15 - 2021-03-16    
All Day
The use of modern technologies and digital services is not only changing the way we communicate, they also offer us innovative ways for monitoring our [...]
Genetics and Molecular biology 2021
2021-03-15    
All Day
Human genetics is study of the inheritance of characteristics by children from parents. Inheritance in humans does not differ in any fundamental way from that [...]
Food Science and Food Safety
2021-03-16 - 2021-03-17    
All Day
Food Safety. It also provides the premier multidisciplinary forum for researchers, professors and educators to present and discuss the most recent innovations, trends, and concerns, [...]
Traditional and Alternative Medicine
2021-03-16 - 2021-03-17    
All Day
Traditional Medicine 2021 welcomes attendees, presenters, and exhibitors from all over the world. We are glad to invite you all to attend and register for [...]
Carbon and Advanced Energy Materials
2021-03-16 - 2021-03-17    
All Day
Materials Science 2021 was an enchanted achievement. We give incredible credits to the Organizing Committee and participants of Materials Science 2021 Conference. Numerous tributes from [...]
Advancements in Tuberculosis and Lung Diseases
2021-03-17 - 2021-03-18    
All Day
Tuberculosis is a communicable disease, caused by the infectious bacterium Mycobacterium tuberculosis. It affects the lungs and other parts of the body (brain, spine). People [...]
Herbal Medicine and Acupuncture 2021
2021-03-22 - 2021-03-23    
All Day
The event offers a best platform with its well organized scientific program to the audience which includes interactive panel discussions, keynote lectures, plenary talks and [...]
Hospital Management and Health Care
2021-03-22 - 2021-03-23    
All Day
Healthcare system refers to the totality of resource that a society distributes with in organization and health facilities delivery for the aim of upholding or [...]
Hematology and Infectious Diseases
2021-03-22 - 2021-03-23    
All Day
Hematology is the discipline concerned with the production, functions, bone marrow, and diseases which are related to blood, blood proteins. The main aim of this [...]
Aquaculture & Marine Biology
2021-03-24 - 2021-03-25    
All Day
The 15th International Conference on Aquaculture & Marine Biology is delighted to welcome the participants from everywhere the planet to attend the distinguished conference scheduled [...]
Artificial Intelligence & Robotics 2021
2021-03-24 - 2021-03-25    
All Day
The Conference Series LLC Ltd organizes conferences around the world on all computer science subjects including Robotics and its related fields. Here we are happy [...]
Tissue Engineering & Regenerative Medicine
2021-03-24 - 2021-03-25    
All Day
Tissue Engineering & Regenerative Medicine mainly focuses on Stem Cell Research and Tissue Engineering. Stem cell Research includes stem cell treatment for various disease and [...]
Nursing Research and Evidence Based Practice
2021-03-25 - 2021-03-26    
12:00 am
Global Nursing Practice 2021 has been circumspectly organized with various multi and interdisciplinary tracks to accomplish the middle objective of the gathering that is to [...]
Earth & Environmental Science 2021
2021-03-26 - 2021-03-27    
All Day
Earth Science 2021 is the integration of new technologies in the field of environmental science to help Environmental Professionals harness the full potential of their [...]
Earth & Environmental Science 2021
2021-03-26 - 2021-03-27    
All Day
Earth Science 2021 is the integration of new technologies in the field of environmental science to help Environmental Professionals harness the full potential of their [...]
Nanomaterials and Nanotechnology
2021-03-26 - 2021-03-27    
All Day
Nanomaterials are the elements which have at least one spatial measurement in the size range of 1 to 100 nanometre. Nanomaterials can be produced with [...]
Smart Materials and Nanotechnology
2021-03-29 - 2021-03-30    
All Day
Smart Material 2021 clears a stage to globalize the examination by introducing an exchange amongst ventures and scholarly associations and information exchange from research to [...]
World Nanotechnology Congress 2021
2021-03-29    
All Day
Nano Technology Congress 2021 provides you with a unique opportunity to meet up with peers from both academic circle and industries level belonging to Recent [...]
Nanomedicine and Nanomaterials 2021
2021-03-29    
All Day
NanoMed 2021 conference provides the best platform of networking and connectivity with scientist, YRF (Young Research Forum) & delegates who are active in the field [...]
Hepatology 2021
2021-03-30 - 2021-03-31    
All Day
Hepatology 2021 provides a great platform by gathering eminent professors, Researchers, Students and delegates to exchange new ideas. The conference will cover a wide range [...]
Events on 2021-03-03
Events on 2021-03-05
Events on 2021-03-17
Events on 2021-03-25
Events on 2021-03-30
Hepatology 2021
30 Mar 21
Articles

Cybercrime 2018: Most Hospitals’ IT Security Is Still Not Enough

cybercrime 2018
BIRMINGHAM, UNITED KINGDOM - JUNE 14: A doctor at The Queen Elizabeth Hospital Birmingham does his rounds on the wards on June 14, 2006 in Birmingham, England. Senior managers of the NHS have said that the organisation needs to become more open in the future. (Photo by Christopher Furlong/Getty Images)

Have you noticed? We haven’t read shocking news of record-breaking security breaches, in fact not since 2015-2016. Remember Bon Secours Health System where the information of 655,000 patients was compromised via the internet? Or the breach at 21st Century Oncology Holdings that hit more than two million patients across 181 cancer treatment centers? A cyber attack on Banner Health affected 3.6 million people, and NewKirk Products, a business associate, was hacked to the tune of 3.5 million affected individuals. According to HHS’ Wall of Shame, over 113 million people were hit in 2015 by breaches of their personal data, and in 2016 more than 27 million patient records were impacted. But, in the whole of 2017 “only” about 4.7 million people were victimized, a four year low.  This may seem like good news, but before we get too comfortable with our seemingly safer data security today, here’s the story behind the story —  and it isn’t pretty.

Many big healthcare cybersecurity news stories have focused on ransomware, the frightening new weapon used by hackers to stop healthcare computing operations cold in order to extort bitcoin payoffs. Though ransomware attacks received a lot of press, it is clear that patient identity theft remains the most dangerous threat facing the healthcare industry. Even back  In 2016 the HIMSS Cybersecurity Survey reported that identity theft had become cyber criminals’ strategy of choice because of patient data’s sheer marketplace value.

This year’s HIMSS 2018 Cybersecurity Survey of 239  information security professionals from various healthcare organizations reported a similar predominant trend of identity theft. The number of individuals impacted by security incidents decreased, but the number of incidents has not slowed down. Over 75% reported that their organizations had experienced a significant security incident in the last year. “If anything…significant security incidents will continue to grow in number, complexity, and impact,” according to the report.

Externally based incidents have gotten the most press. HIMSS reports that the three greatest perpetrators of recent significant security incidents are online scam artists (phishing exploiters), negligent hospital insiders, and criminal hackers. These are  followed by malicious insiders and social engineers — hackers who play fraudulent tricks on insiders using tools like phone calls and social media.

If we look a little deeper at the numbers below it becomes clear that our hospital insiders — physicians, nurses, IT and other staff — are complicit, mostly inadvertently (a few, deliberately), in at least 70 percent of security incidents.These would include staff or business associates that are taken in by online scam artists and criminal social engineers, in addition to negligent insiders. Take a look at this screenshot from HIMSS’ 2018 report:

We must squarely look at the unfortunate role of our well-meaning hospital insiders in the dangerous state of healthcare cybersecurity today and step up protections:

  • Phishing and social engineering by bad actors only work if we mere mortals don’t catch these threats before damage occurs. Such incidents accounted for 37.6 percent of security breaches last year.
  • Negligent insiders accounted for 21 percent of incidents.
  • Social engineering (almost five percent of last year’s incidents) succeeds only if our staff doesn’t recognize and catch it.
  • Over five percent of insiders were deliberately bad actors.

It’s clear that healthcare organizations must do more to reduce these internal vulnerabilities, as well as prevent external hacking in its many ever changing forms.

The somewhat good news: About 85% of respondents say that their organizations have increased the resources needed to manage cybersecurity concerns. The following graph shows the percentage of IT budgets allocated to cybersecurity in 2018.

We can all agree that any increased expenditures and efforts to protect our hospitals’ data are important actions, but we all should be concerned that the overall hospital industry’s response to the abundance of security risks has not been greater or more clearly defined as priorities in IT budgets.

Specific efforts focusing on internal vulnerabilities should be especially high priority. Potential issues like the following must be hit hard:

  • How thorough and frequent is staff training? Is it absolutely required of all staff?
  • Are stringent rules in place that clearly include severe consequences?
  • Is the IT department and security staff in control — or instead, overwhelmed or not effectively engaged?  For example, does IT follow and enforce best practices in secure network management, device management, and the simplest of protections, frequent password changes designed for difficulty? Is IT conducting frequent systems penetration testing? Is IT on top of the most dangerous, current potential cyberthreats?
  • Does the IT department include highly trained security staff, either employees or external contractors?
  • Are thorough security risk analyses conducted at least once a year — ideally, more frequently?
  • Is the C-suite committed to data security and privacy, and is this communicated enterprise wide?
  • Are necessary security and privacy protections adequately funded?

Most predictions indicate healthcare is headed into a period of increased cybersecurity risks in 2019 and beyond.  Hospitals, other providers and business associates should complete a security risk analysis soon, if they haven’t yet conducted one this year.  As always, well-qualified internal IT security professionals or an objective third part security professional must lead the process. Then they should calibrate your organization’s unique risks against potential costs — including the privacy costs of patients — to plan ahead for technical and social protections that will minimize your vulnerabilities and thwart the cyberthreats that are sure to come.

________________________________

If you need the security knowledge and expertise of certified specialists with over 20 years of hospital privacy and security experience, contact us.

ABOUT D’ARCY GUERIN GUE

Vice President, Industry Relations

D’Arcy Guerin Gue is a co-founder of Phoenix, with over 25 years of experience in executive leadership, strategic planning, IT services, knowledge leadership, and industry relations —  and a special focus on patient engagement and federal compliance issues.

Phoenix is a division of Medsphere Systems.