ESET and the Ponemon Institute have announced results of The State of Cybersecurity in Healthcare Organizations in 2016.
According to the study, healthcare organizations average about one cyber attack per month with 48% of respondents said their organizations have experienced an incident involving the loss or exposure of patient information during the last 12 months. Yet despite these incidents, only half indicated their organization has an incident response plan in place.
The concurrence of technology advances and delays in technology updates creates a perfect storm for healthcare IT security,” said Stephen Cobb, senior security researcher at ESET. “The healthcare sector needs to organize incident response processes at the same level as cyber criminals to properly protect health data relative to current and future threat levels. A good start would be for all organizations to put incident response processes in place, including comprehensive backup and disaster recovery mechanisms. Beyond that, there is clearly a need for effective DDoS and malware protection, strong authentication, encryption and patch management
Key findings of the survey:
78% of respondents, the most common security incident is the exploitation of existing software vulnerabilities greater than three months old.
63% said the primary consequences of APTs and zero-day attacks were IT downtime
46% of respondents experienced an inability to provide services which create serious risks for patient treatment.
Hackers are most interested in stealing patient information
- The most attractive and lucrative target for unauthorized access and abuse can be found in patients’ medical records, according to 81% of respondents.
Healthcare organizations worry most about system failures
- 79% of respondents said that system failures are one of the top three threats facing their organizations
- 77% cyber attackers
- 77% unsecure medical devices
Technology poses a greater risk to patient information than employee negligence
- 52% of respondents said legacy systems and new technologies to support cloud and mobile implementations, big data and the Internet of Things increase security vulnerabilities for patient information
- 46% of respondents also expressed concern about the impact of employee negligence
- 45% cited the ineffectiveness of HIPAA mandated business associate agreements designed to ensure patient information security
DDoS attacks have cost organizations on average $1.32 million in the past 12 months
- 37% of respondents say their organization experienced a DDoS attack that caused a disruption to operations and/or system downtime about every four months. These attacks cost an average of $1.32 million each, including lost productivity, reputation loss and brand damage.
Healthcare organizations need a healthy dose of investment in technologies
- On average, healthcare organizations represented in this research spend $23 million annually on IT
- 12% on average is allocated to information security
- Since an average of $1.3 million is spent annually for DDoS attacks alone, a business case can be made to increase technology investments to reduce the frequency of successful attacks
Based on our field research, healthcare organizations are struggling to deal with a variety of threats, but they are pessimistic about their ability to mitigate risks, vulnerabilities and attacks,” said Larry Ponemon, chairman and founder of The Ponemon Institute. “As evidenced by the headline-grabbing data breaches over the past few years at large insurers and healthcare systems, hackers are finding the most lucrative information in patient medical records. As a result, there is more pressure than ever for healthcare organizations to refine their cybersecurity strategies