Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
1
2
3
4
5
6
7
8
9
10
14
15
16
17
18
19
20
21
22
24
25
27
31
12:00 AM - EXPO.health
1
2
3
4
11 Jul
2019-07-11 - 2019-07-13    
All Day
2019 Annual Meeting and Scientific Seminar is Oraganized by American College of Neuropsychiatrists/American College of Osteopathic Neurologists and Psychiatrists (ACN/ACONP) and will be held from [...]
Breast Cancer: New Horizons, Current Controversies 2019
2019-07-11 - 2019-07-13    
All Day
Breast Cancer: New Horizons, Current Controversies is organized by Harvard Medical School (HMS) and will be held from Jul 11 - 13, 2019 at Boston [...]
11 Jul
2019-07-11 - 2019-07-12    
All Day
Pediatric Colorectal Scientific Meeting (PCSM) is organized by Intermountain Healthcare Interprofessional Continuing Education (IPCE) and will be held from Jul 11 - 12, 2019 at [...]
12 Jul
2019-07-12 - 2019-07-14    
All Day
Infectious Disease for Primary Care is organized by Medical Education Resources (MER) and will be held from Jul 12 - 14, 2019 at Disney's Contemporary [...]
12 Jul
2019-07-12 - 2019-07-14    
All Day
Dermatology for Primary Care is organized by Medical Education Resources (MER) and will be held from Jul 12 - 14, 2019 at Disney's Grand Californian [...]
12 Jul
2019-07-12 - 2019-07-14    
All Day
Office Orthopedics for Primary Care is organized by Medical Education Resources (MER) and will be held from Jul 12 - 14, 2019 at Bellagio Hotel [...]
13 Jul
2019-07-13 - 2019-07-19    
All Day
Association for Healthcare Philanthropy (AHP) Madison Institute is organized by Association for Healthcare Philanthropy (AHP) and will be held during Jul 13 - 19, 2019 [...]
13 Jul
2019-07-13 - 2019-07-14    
All Day
Red Cells Gordon Research Seminar (GRS) is organized by Gordon Research Conferences (GRC) and will be held from Jul 13 - 14, 2019 at Salve [...]
47th Annual Institute and Conference - "Advancing Nursing Practice: Innovation, Access and Health Equity"
2019-07-23 - 2019-07-28    
All Day
47th Annual Institute and Conference - "Advancing Nursing Practice: Innovation, Access and Health Equity" is organized by National Black Nurses Association (NBNA), Inc. and will [...]
2nd International Conference on  Medical and Health Science
2019-07-26 - 2019-07-27    
All Day
Date: July 26-27, 2019 Melbourne, Australia Theme: Scrutinize the Modish of Medical and Health Science "2nd International Conference on Medical and Health Science" on July [...]
Pediatric and Adolescent Medicine, Pediatric Critical Care, Developmental Pediatrics, and ADHD
2019-07-26 - 2019-08-02    
All Day
Pediatric and Adolescent Medicine, Pediatric Critical Care, Developmental Pediatrics, and ADHD is organized by Continuing Education, Inc and will be held from Jul 26 - [...]
Cosmetic Pearls for the General Dental Practitioner
2019-07-26 - 2019-08-02    
All Day
Cosmetic Pearls for the General Dental Practitioner is organized by Continuing Education, Inc and will be held from Jul 26 - Aug 02, 2019 at [...]
Neuroethology: Behavior, Evolution and Neurobiology Gordon Research Conference (GRC) 2019
2019-07-28 - 2019-08-02    
All Day
Neuroethology: Behavior, Evolution and Neurobiology Gordon Research Conference (GRC) is organized by Gordon Research Conferences (GRC) and will be held from Jul 28 - Aug [...]
Molecular and Cellular Biology of Lipids Gordon Research Conference (GRC) 2019
2019-07-28 - 2019-08-02    
All Day
Molecular and Cellular Biology of Lipids Gordon Research Conference (GRC) is organized by Gordon Research Conferences (GRC) and will be held from Jul 28 - [...]
37th Annual Conference on Pediatric Infectious Diseases
2019-07-28 - 2019-08-02    
All Day
37th Annual Conference on Pediatric Infectious Diseases is organized by Children's Hospital Colorado and will be held from Jul 28 - Aug 02, 2019 at [...]
32nd Annual Summer Seminar in Health Care Ethics & Surgical Ethics
2019-07-29 - 2019-08-02    
All Day
32nd Annual Summer Seminar in Health Care Ethics & Surgical Ethics is organized by University of Washington School of Medicine (UWSOM) Continuing Medical Education (CME) [...]
3-Day Physician Assistant PANCE / PANRE Board Review Course by Certified Medical Educators (CME) - Salt Lake City
2019-07-29 - 2019-07-31    
All Day
3-Day Physician Assistant PANCE / PANRE Board Review Course is organized by Certified Medical Educators (CME) and will be held from Jul 29 - 31, [...]
Four Week Radiologic Pathology Correlation Course (Jul 29 - Aug 23, 2019)
2019-07-29 - 2019-08-23    
All Day
Four Week Radiologic Pathology Correlation Course is organized by American Institute for Radiologic Pathology (AIRP) and will be held from Jul 29 - Aug 23, [...]
Third Annual Philadelphia Trauma Training Conference
2019-07-30 - 2019-08-01    
All Day
Third Annual Philadelphia Trauma Training Conference is organized by Thomas Jefferson University (TJU) and will be held from Jul 30 - Aug 01, 2019 at [...]
IDAA Annual Meeting 2019
2019-07-31 - 2019-08-04    
All Day
International Doctors in Alcoholics Anonymous (IDAA) 70th Annual Meeting 2019 is organized by International Doctors in Alcoholics Anonymous (IDAA) and will be held from Jul [...]
EXPO.health
2019-07-31 - 2019-08-02    
All Day
EXPO.health Schedule July 31 - August 2, 2019 - Location: Boston, MA Join us at EXPO.health (Formerly Healthcare IT Expo – HITExpo) 2019 happening July [...]
01 Aug
2019-08-01 - 2019-08-03    
All Day
UCSF CME: Neurosurgery Update 2019 is organized by The University of California, San Francisco (UCSF) Office of Continuing Medical Education and will be held from [...]
PBI Medical Ethics & Professionalism (ME-22) - Irvine
2019-08-02 - 2019-08-03    
All Day
PBI Medical Ethics & Professionalism (ME-22) is organized by Professional Boundaries, Inc. (PBI) and will be held from Aug 02 - 03, 2019 at Wyndham [...]
The 8th Beijing International Top Health & Medical Exhibition (BIHM)
2019-08-02 - 2019-08-04    
All Day
The 8th Beijing International Private Health and Medical Exhibition will be held at the China International Exhibition Center from August 2nd to August 4th, 2019. [...]
Angiogenesis Gordon Research Seminar (GRS) 2019
2019-08-03 - 2019-08-04    
12:00 am
Angiogenesis Gordon Research Seminar (GRS) is organized by Gordon Research Conferences (GRC) and will be held from Aug 03 - 04, 2019 at Salve Regina [...]
Lung Development, Injury and Repair Gordon Research Seminar (GRS) 2019
2019-08-03 - 2019-08-04    
All Day
Lung Development, Injury and Repair Gordon Research Seminar (GRS) is organized by Gordon Research Conferences (GRC) and will be held from Aug 03 - 04, [...]
Platelet Rich Plasma for Aesthetics Course - Miami (Aug 2019)
Platelet Rich Plasma for Aesthetics Course is organized by Empire Medical Training (EMT), Inc and will be held on Aug 04, 2019 at GALLERYone - [...]
Physician Medical Weight Loss Training (Aug 04, 2019)
2019-08-04    
All Day
Physician Medical Weight Loss Training is organized by Empire Medical Training (EMT), Inc and will be held on Aug 04, 2019 at The Platinum Hotel [...]
Events on 2019-07-11
Events on 2019-07-30
Events on 2019-07-31
IDAA Annual Meeting 2019
31 Jul 19
Knoxville
EXPO.health
31 Jul 19
Boston
Events on 2019-08-01
01 Aug
Articles

Healthcare aware of security threats, but not really ready for them

medsphere

You may be suffering from IT security fatigue at this point, for which I offer a half-hearted apology.

Yes, only half-hearted, because the numbers say healthcare is aware of various security threats but still remains vulnerable, making it imperative that the subject stay top of mind until patient data is reliably protected.

For example, the Sixth Annual Benchmark Study on Privacy and Security of Healthcare Data, published earlier this month, offers interesting perspectives on both healthcare organizations and business associates.

For this ID Experts-sponsored study, The Ponemon Institute engaged 91 covered entities (health plans, healthcare clearinghouses, healthcare providers) and 84 business associates (BAs) like healthcare IT companies. Given that business associates often have access to patient data, it’s appropriate that this study and future research projects include partners not involved in actual provision of care.

A review of the Benchmark Study reveals some overarching themes and messages that may prove valuable to healthcare providers and business associates.

Data breaches are common and happening more frequently.

You know this already, right? Probably, but the frequency suggests that only the really big breaches make it into the healthcare IT press.

In the last two years, 89 percent of healthcare organizations and 61 percent of BAs experienced at least one breach that resulted in a loss of patient data. In that same time period, 45 percent of healthcare organizations had more than five breaches and 28 percent of BAs had more than two.

“The annual economic impact of a data breach has risen over the past six years, as has the frequency of data breaches,” the report reads. “Criminal attacks and internal threats are the leading cause of data breaches.”

Employees are both your strongest asset and greatest liability.

How do your employees at all levels feel about working there? How well trained are they in all aspects of their jobs? Are you aware of any particularly disgruntled employees?

Where once these were primarily questions for human resources, now they are highly relevant to the security of your operation.

When asked what type of security incident they most fear, a majority of both healthcare organizations (69 percent) and BAs (53 percent) identified employee negligence and carelessness.

These percentages remain roughly the same as last year, even while the most common cause of data breaches with healthcare organizations—fully 50 percent—is criminal attacks. Among BAs, an unintentional employee action (55 percent) is still the manner by which patient data is most often compromised.

What may provide some comfort for both healthcare organizations and BAs is that a malicious insider (13 and 6 percent, respectively) is not often the cause of lost patient information.

While concerns about employee carelessness might be more statistically relevant for BAs than healthcare organizations, in both entities the gap between negligence and malice represents an opportunity to make employees the first and most effective line of defense.

Indeed, for most BAs (58 percent), data breaches were discovered by employees. On the healthcare organization side, audits (74 percent) most often received credit for data breach recognition, with employee detection second at 47 percent.

Healthcare organizations and BAs recognize that employees are essential to better security. Both entities said better training, as well as more effective policies and procedures, were the most effective way to combat loss of patient data.

Data security spending and organizational preparation are still not where they need to be.

All of healthcare IT is aware of cyberattacks and the potential danger of losing patient data, and yet IT budgets remain stuck. Among healthcare organizations, 62 percent say their budget for incident response has either decreased (10 percent) or stayed the same (52 percent).

There remains a gap, Ponemon says, between awareness and funding.

“Recent big healthcare data breaches have increased the healthcare industry’s awareness of the growing threats to patient data, resulting in more focus on their security practices and implementing the appropriate policies and procedures, however the research indicates that it is not enough to curtail or minimize data breaches. According to the findings, half of these organizations still don’t have the people or the budget to detect or manage data breaches.”

Perhaps most disconcerting is that while 60 percent of healthcare organizations and 54 percent of BAs assess their organizational vulnerabilities, the overwhelming majority do so on either an annual (41 and 35 percent, respectively) or ad hoc (43 and 35 percent) basis.

Data breach insurance is becoming a standard part of providing healthcare.

The information on data breach insurance from the Ponemon study is interesting and somewhat curious. In the study group, one-third of healthcare organizations and 29 percent of BAs are insured against data breaches and cyberattacks. Of that group, a majority of both healthcare organizations (57 percent) and BAs (52 percent) purchased up to $5 million in coverage.

What do these numbers say about healthcare and preparation for cyberattacks? For one thing, we know that healthcare organizations and BAs are both concerned about liability; the coverage most frequently provided (just north of 70 percent for both groups) by the selected data breach policies is legal defense.

Other than that, it’s hard to draw any definitive conclusions based on the figures alone. On an individual basis, some organizations may find it more affordable to insure than fully prepare. Others may pursue both strategies.

It does seem clear that most of healthcare is under no illusions about how well prepared the industry is for hackers and cyberattacks. When asked why healthcare has a bullseye on its back, healthcare organization respondents said quite clearly that the industry is not doing enough, offering these perspectives:

  • 51 percent: Healthcare organizations are not vigilant in ensuring their partners and other third parties protect patient information.
  • 44 percent: Healthcare organizations are not hiring enough skilled IT security practitioners.
  • 41 percent: Healthcare organizations are not investing in technologies to mitigate a data breach.

The rise in cyberattacks puts many healthcare organizations in a difficult spot. Millions have already been spent on IT systems and security, and in many ways and for many providers, it simply isn’t enough. Insurance is one way to guard against disaster, but more successful attacks will lead to higher premiums, making vigilance and adequate preparation the only realistic option.

D’Arcy Gue is Director of Industry Relations for Medsphere Systems Corporation. 

Source Medsphere