The 2015 Anthem breach was a wake-up call for the healthcare industry, but are organizations truly prepared today? According to the latest Security Scorecard report, healthcare cybersecurity remains a critical weakness. The industry struggles not only with existing threats but also with emerging risks from mobile devices and IoT systems.
Security Scorecard analyzed data from over 1,200 healthcare organizations, highlighting two key findings:
- How healthcare performs compared to other major U.S. industries.
- Persistent vulnerabilities within healthcare organizations that put patient data at risk.
Key Findings from the Security Scorecard:
- Industry Ranking: Out of 18 major U.S. industries, healthcare ranked 15th in cybersecurity preparedness, just above pharma, telecom, and education.
- High-Value Data: Electronic Protected Health Information (ePHI) can fetch up to $100 per record on the Dark Web, making healthcare a prime target for cybercriminals.
- Endpoint Vulnerabilities: Mobile devices, tablets, PCs, and IoT systems often lack sufficient security, putting patient data at risk.
- Human Factor Risks: Convenience frequently trumps security. Staff may access patient records on unsecured devices that lack sufficient encryption or access controls.
- Social Engineering Threats: Healthcare workers face frequent phishing attempts and malware attacks. Organizations should implement regular cybersecurity training, including simulated phishing exercises.
- Network Security Gaps: Active IP filtering and strict internet access controls help prevent ransomware and malware infections.
- Patch Management Issues: Slow or inconsistent deployment of security patches leaves systems vulnerable. The May 2017 WannaCry ransomware outbreak highlighted the consequences of this neglect, particularly in the NHS system.
Actionable Step:
Conduct a comprehensive security assessment of all software, hardware, and security processes. Identify vulnerabilities, patch gaps, and implement best practices to strengthen your healthcare cybersecurity posture.
RSI Security provides expert HIPAA-compliant cybersecurity assessments for healthcare organizations. Contact RSI Security us today for a free evaluation to identify and remediate gaps in your cybersecurity infrastructure.
Download Our HIPPA Checklist