Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
31
1
4
5
10
11
12
17
24
25
26
28
29
30
1
2
3
30 Mar
2020-03-30 - 2020-03-31    
All Day
This Cardio Diabetes 2020 includes Speaker talks, Keynote & Poster presentations, Exhibition, Symposia, and Workshops. This International Conference will help in interacting and meeting with diabetes and [...]
Trending Topics In Internal Medicine 2020
2020-04-02 - 2020-04-04    
All Day
Trending Topics in Internal Medicine is a CME course that will tackle the latest information trending in healthcare today.   This course will help you discuss options [...]
2020 Summit On National & Global Cancer Health Disparities
2020-04-03 - 2020-04-04    
All Day
The 2020 Summit on National & Global Cancer Health Disparities is planned with the goal of creating a momentum to minimize the disparities in cancer [...]
2020 Primary Care Kauai- Caring For The Active And Athletic Patient
2020-04-06 - 2020-04-10    
All Day
CMX Travel and Meetings programs meetings and group conferences for physicians and medical professionals throughout the United States. CMX Travel and Meetings programs meetings and [...]
ISER- 787th International Conference On Science, Health And Medicine ICSHM
2020-04-07 - 2020-04-08    
All Day
ISER- 787th International Conference on Science, Health and Medicine (ICSHM) is a prestigious event organized with a motivation to provide an excellent international platform for the academicians, [...]
RW- 801st International Conference On Medical And Biosciences ICMBS
2020-04-08 - 2020-04-09    
All Day
About the EventConference : RW- 801st International Conference on Medical and Biosciences ICMBS is a prestigious event organized with a motivation to provide an excellent [...]
Palliative Care 2020
2020-04-08 - 2020-04-09    
All Day
ABOUT PALLIATIVE CARE 2020 Palliative Care 2020 welcomes attendees, presenters, and exhibitors from all over the world to Dubai, UAE. We are glad to invite [...]
The 4th Annual Dubai International Paediatric Neurology Congress
2020-04-09 - 2020-04-11    
All Day
Based on the sound success of previous Dubai International paediatric Neurology congresses the 4th Annual Dubai International paediatric Neurology Conference expects to attract over 400 delegates devoted [...]
13 Apr
2020-04-13 - 2020-04-14    
All Day
IASTEM - 814th International Conference on Medical, Biological and Pharmaceutical Sciences (ICMBPS) will be held on 13th - 14th April, 2020 at Dammam, Saudi Arabia . ICMBPS is to bring together [...]
Patient Engagement USA At Eyeforpharma Philadelphia
2020-04-14 - 2020-04-15    
All Day
As we enter election year in 2020, the pressure has never been higher on our industry to justify what we add to the cost of [...]
28th International Conference On Clinical Pediatrics
2020-04-15 - 2020-04-16    
All Day
It is our great pleasure to invite you to participate in the 28th International Conference on Clinical Pediatrics Clinical Pediatrics 2020 which will take place [...]
5th World Congress On Public Health And Health Care Management
2020-04-16 - 2020-04-17    
All Day
We would like to invite you all people to take part in our Public Health and Health Care Management-2020 Conference in Miami, USA during 16-17 [...]
Topics In Emergency Medicine, Pain Management, And Palliative Care CME Cruise
2020-04-18 - 2020-04-25    
All Day
These set of lectures is designed to provide important updates in emergency medicine with a focus on anticoagulation and the management of venous thromboembolism as [...]
RW- 809th International Conference On Medical And Biosciences ICMBS
2020-04-19 - 2020-04-20    
All Day
RW- 809th International Conference on Medical and Biosciences (ICMBS) is a prestigious event organized with a motivation to provide an excellent international platform for the academicians, researchers, [...]
RF - 627th International Conference On Medical & Health Science - ICMHS 2020
2020-04-20 - 2020-04-21    
All Day
Welcome to the Official Website of the  627th International Conference on Medical & Health Science - ICMHS 2020. It will be held during 20th-21st April, 2020 at San [...]
30th Annual Art And Science Of Health Promotion Conference
2020-04-20 - 2020-04-24    
All Day
Integrating Health Promotion into the Organization’s and Community’s Core Values A common element of virtually every successful health promotion program in workplace, clinical and community [...]
ISER- 796th International Conference On Science, Health And Medicine ICSHM
2020-04-21 - 2020-04-22    
All Day
ISER- 796th International Conference on Science, Health and Medicine ICSHM is a prestigious event organized with a motivation to provide an excellent international platform for [...]
Biomolecular Condensates Summit
2020-04-21 - 2020-04-23    
All Day
An ever-increasing amount of evidence points towards the importance of Biomolecular Condensates function to health and disease. However, with many of the fundamental questions behind [...]
The Middle East Pharma Cold Chain Congress
2020-04-22 - 2020-04-23    
All Day
The pharma sector in the MENA region has witnessed rapid development, which has been largely fueled by high population growth, increased life expectancy coupled with [...]
45th Annual Regional Anesthesiology And Acute Pain Medicine Meeting
2020-04-23 - 2020-04-25    
All Day
ASRA was officially "re-founded" in 1975, led by Alon P. Winnie, MD, who had a dream of a society devoted to teaching regional anesthesia. (An [...]
25th International Conference on Dermatology & Skin Care
2020-04-27 - 2020-04-28    
All Day
About Conference Derma 2020 Derma 2020 welcomes all the attendees, lecturers, patrons and other research expertise from all over the world to 25th International Conference on Dermatology & [...]
Events on 2020-03-30
Events on 2020-04-02
Events on 2020-04-03
Events on 2020-04-08
Events on 2020-04-14
Events on 2020-04-15
Events on 2020-04-22
Events on 2020-04-23
Events on 2020-04-27
Articles

Cybercrime 2018: Most Hospitals’ IT Security Is Still Not Enough

cybercrime 2018
BIRMINGHAM, UNITED KINGDOM - JUNE 14: A doctor at The Queen Elizabeth Hospital Birmingham does his rounds on the wards on June 14, 2006 in Birmingham, England. Senior managers of the NHS have said that the organisation needs to become more open in the future. (Photo by Christopher Furlong/Getty Images)

Have you noticed? We haven’t read shocking news of record-breaking security breaches, in fact not since 2015-2016. Remember Bon Secours Health System where the information of 655,000 patients was compromised via the internet? Or the breach at 21st Century Oncology Holdings that hit more than two million patients across 181 cancer treatment centers? A cyber attack on Banner Health affected 3.6 million people, and NewKirk Products, a business associate, was hacked to the tune of 3.5 million affected individuals. According to HHS’ Wall of Shame, over 113 million people were hit in 2015 by breaches of their personal data, and in 2016 more than 27 million patient records were impacted. But, in the whole of 2017 “only” about 4.7 million people were victimized, a four year low.  This may seem like good news, but before we get too comfortable with our seemingly safer data security today, here’s the story behind the story —  and it isn’t pretty.

Many big healthcare cybersecurity news stories have focused on ransomware, the frightening new weapon used by hackers to stop healthcare computing operations cold in order to extort bitcoin payoffs. Though ransomware attacks received a lot of press, it is clear that patient identity theft remains the most dangerous threat facing the healthcare industry. Even back  In 2016 the HIMSS Cybersecurity Survey reported that identity theft had become cyber criminals’ strategy of choice because of patient data’s sheer marketplace value.

This year’s HIMSS 2018 Cybersecurity Survey of 239  information security professionals from various healthcare organizations reported a similar predominant trend of identity theft. The number of individuals impacted by security incidents decreased, but the number of incidents has not slowed down. Over 75% reported that their organizations had experienced a significant security incident in the last year. “If anything…significant security incidents will continue to grow in number, complexity, and impact,” according to the report.

Externally based incidents have gotten the most press. HIMSS reports that the three greatest perpetrators of recent significant security incidents are online scam artists (phishing exploiters), negligent hospital insiders, and criminal hackers. These are  followed by malicious insiders and social engineers — hackers who play fraudulent tricks on insiders using tools like phone calls and social media.

If we look a little deeper at the numbers below it becomes clear that our hospital insiders — physicians, nurses, IT and other staff — are complicit, mostly inadvertently (a few, deliberately), in at least 70 percent of security incidents.These would include staff or business associates that are taken in by online scam artists and criminal social engineers, in addition to negligent insiders. Take a look at this screenshot from HIMSS’ 2018 report:

We must squarely look at the unfortunate role of our well-meaning hospital insiders in the dangerous state of healthcare cybersecurity today and step up protections:

  • Phishing and social engineering by bad actors only work if we mere mortals don’t catch these threats before damage occurs. Such incidents accounted for 37.6 percent of security breaches last year.
  • Negligent insiders accounted for 21 percent of incidents.
  • Social engineering (almost five percent of last year’s incidents) succeeds only if our staff doesn’t recognize and catch it.
  • Over five percent of insiders were deliberately bad actors.

It’s clear that healthcare organizations must do more to reduce these internal vulnerabilities, as well as prevent external hacking in its many ever changing forms.

The somewhat good news: About 85% of respondents say that their organizations have increased the resources needed to manage cybersecurity concerns. The following graph shows the percentage of IT budgets allocated to cybersecurity in 2018.

We can all agree that any increased expenditures and efforts to protect our hospitals’ data are important actions, but we all should be concerned that the overall hospital industry’s response to the abundance of security risks has not been greater or more clearly defined as priorities in IT budgets.

Specific efforts focusing on internal vulnerabilities should be especially high priority. Potential issues like the following must be hit hard:

  • How thorough and frequent is staff training? Is it absolutely required of all staff?
  • Are stringent rules in place that clearly include severe consequences?
  • Is the IT department and security staff in control — or instead, overwhelmed or not effectively engaged?  For example, does IT follow and enforce best practices in secure network management, device management, and the simplest of protections, frequent password changes designed for difficulty? Is IT conducting frequent systems penetration testing? Is IT on top of the most dangerous, current potential cyberthreats?
  • Does the IT department include highly trained security staff, either employees or external contractors?
  • Are thorough security risk analyses conducted at least once a year — ideally, more frequently?
  • Is the C-suite committed to data security and privacy, and is this communicated enterprise wide?
  • Are necessary security and privacy protections adequately funded?

Most predictions indicate healthcare is headed into a period of increased cybersecurity risks in 2019 and beyond.  Hospitals, other providers and business associates should complete a security risk analysis soon, if they haven’t yet conducted one this year.  As always, well-qualified internal IT security professionals or an objective third part security professional must lead the process. Then they should calibrate your organization’s unique risks against potential costs — including the privacy costs of patients — to plan ahead for technical and social protections that will minimize your vulnerabilities and thwart the cyberthreats that are sure to come.

________________________________

If you need the security knowledge and expertise of certified specialists with over 20 years of hospital privacy and security experience, contact us.

ABOUT D’ARCY GUERIN GUE

Vice President, Industry Relations

D’Arcy Guerin Gue is a co-founder of Phoenix, with over 25 years of experience in executive leadership, strategic planning, IT services, knowledge leadership, and industry relations —  and a special focus on patient engagement and federal compliance issues.

Phoenix is a division of Medsphere Systems.