Cyberattacks on the healthcare industry have spiked. More than 90% of healthcare organizations have experienced a breach of some sort in the last five years. In 2019, data breaches will cost the healthcare community upwards of $4 billion.
Threats and attacks are clearly part of the challenge, but professionals in the space will also note that culture plays a role too. Cybersecurity teams are competing for a budget in a culture that rightfully holds patient safety above all else it can be challenging to make the case for security against that benchmark.
Since many of our customers serve the healthcare community, weve poured over several reports to help break down the state of affairs. Here are the cliff notes to five studies about healthcare security along with links to the underlying sources for those interested in reading more.
An analysis of detection data by Malwarebytes found a 60% increase in threats at endpoints across the healthcare community. That spike occurred in just the first nine months of 2019 as compared to the full year in 2018, according to a report titled Cybercrime Tactics and Techniques: the 2019 state of healthcare.
Even more worrisome, the report indicates the pace of growth has continued to surge. Malwarebytes says it has seen a 45% growth in endpoint detections from Q2 to Q3 of 2019. The top methods of attacks the report identified were:
[Healthcare] Budgets are diverted to research, patient care, and technology innovation while ignoring necessary staff training and solutions for endpoint and network security, the report concludes. Add to this the proliferation of electronic health records and IoT, and you have a prescription for cyber chaos.
Nearly three quarters (74%) of respondents to the 2019 HIMSS Cybersecurity Survey said their organization had experienced a significant security incident in the past 12 months. Of the 166 respondents to the annual HIMSS survey, the vast majority attributed the initial point of compromise in those incidents to three sources business email compromise or BEC (59%), human error (25%) and third parties (10%).
Security budgets in healthcare vary widely and cybersecurity is typically buried within the IT budget, according to the survey. About 45% of respondents said security spending ranges from between 1% and 10% of the IT budget. Surprisingly, 26% indicated they are piecing together security spending as there is there is no specific cybersecurity carve out within the IT budget.
On the bright side, it does appear that as an industry, healthcare is investing more in cybersecurity. When asked specifically how their organizations cybersecurity budgets compared to the previous year, 72% of respondents indicated their budgets increased by 5% or more, according to the survey.
>>> Related: Aligning Security with Patient Safety: 8 Insights for Healthcare Cybersecurity by Healthcare Cybersecurity Pros
Every new device added to the network widens the surface area for potential attackers and the healthcare community is experiencing this with IoT medical devices. A full 82% of healthcare companies suffered an IoT-focused cyberattacks in the past 12 months.
Thats according to the Irdeto Global Connected Industries Cybersecurity Survey which was conducted by the market research firm Vanson Bourne. The survey polled 700 security decision-makers who manufacture IoT devices across the healthcare, transport and manufacturing markets. The report breaks out the results by each vertical.
Among the healthcare vertical, respondents put the financial impact of those attacks at an average of $346,205. However, the impact of attacks can extend beyond just those costs that can be quantified and include productivity, reputation and safety. When asked about what impacts concerned them the answers tallied up as follows:
Most respondents believed they could boost the security of IT devices their organization manufactured 38% said they could improve it to a great extent and 61% to some extent. Just one out of every two IoT device manufacturers (52%) in healthcare said they update the security of their devices for the device lifetime (beyond warranty).
Threat intelligence research shows stolen healthcare records can be worth 10 times more than a credit card on the black market. To get ahead of this, healthcare companies are paying an average of $1,088.16 to researchers who can help them identify vulnerabilities before adversaries use them to steal data.
That dollar figure was reported in a study by Bugcrowd called the State of Healthcare Cybersecurity. The company says it represents an 83% increase year-over-year. Its worth pointing out the figure is just an average as healthcare companies are paying as much as $3,425 for vulnerabilities identified as high severity.
The criticality scale for a vulnerability submission ranges from Priority 1 (P1) to Priority 5 (P5), 1 being the most critical, 5 being the least critical, according to the report. Across programs run by healthcare organizations, more than 12% of all submissions are classified by the organization as P1 submissions, the most critical vulnerabilities, and the majority of the vulnerability submissions fall in the P3 level of criticality, just over 42%.
>>> Related: Cybersecurity Must be Both Strategic and Tactical: 7 Takeaways from a Webinar for Healthcare Security Pros
Health data breaches have significant consequences for patients, providers, and payers and contribute to quality of care problems. Importantly, its not just the breach, but the response to the breach that contributes. Those were the findings of a study by Health Services Research titled, Data breach remediation efforts and their implications for hospital quality.
The study merged data from 311 hospital breaches with public data on hospital quality measures for 20122016. It found breach remediation efforts were associated with deterioration in timeliness of care and patient outcomes.
The HIPPA Journal broke out the key findings down this way:
According to the study, the time it took from a patient arriving at the hospital to an electrocardiogram being performed increased by up to 2.7 minutes at hospitals that had experienced a data breach. A ransomware attack that prevents clinicians from accessing patient data will limit their ability to provide essential medical services to patients, so a delay in conducting tests and obtaining the results is to be expected.
However, the delays were found to continue for months and years after a cyberattack was experienced. The study showed that 3-4 years after a breach had occurred there were still delays in providing electrocardiograms to patients. The waiting time for electrocardiograms to patients was found to be up to 2 minutes longer than before the breach occurred.
Hospitals that experienced a data breach also saw an increase in the 30day acute myocardial infarction mortality rate. The mortality rate at breached hospitals increased by as much as 0.36%.
The authors conclude hospitals should be cautious about remediation efforts put in place following a breach to limit inadvertent delays and disruptions associated with new processes, procedures, and technologies.
Convincing Leaders in Healthcare to do More
Given the rash of activity in healthcare, how can security professionals drive greater support for cybersecurity?
The key is getting the business to understand the risks, and I dont mean using fear tactics, according to Steve Swansbrough, who has more than 20 years of experience in the field, in a previously published interview.
What you have to do is present this in a risk mitigation and risk acceptance format. For example, youve got to demonstrate that youve done an assessment or penetration test on the network, and then list all the vulnerabilities you found. Its very different when you show the business how an experienced hacker can gain access to the systems in five minutes and have root access to servers within 10.
* * *
Note: Bricata has simplified the four critical capabilities healthcare organizations need for comprehensive network protection: visibility, threat detection, threat hunting, and post-detection actions. If youd like to see our solution in action, you are welcome to schedule a live demonstration.
If you enjoyed this post, you might also like:Cybersecurity Case Study: Securely Integrating a Business Network After a Merger and Acquisition
Recent Articles By Author
*** This is a Security Bloggers Network syndicated blog from Bricata authored by Bricata. Read the original post at: https://bricata.com/blog/state-cybersecurity-healthcare/
Read the original:
Cliff Notes to 5 Studies about the State of Cybersecurity in Healthcare - Security Boulevard
- ST-Segment Elevation Myocardial Infarction - verywell.com [Last Updated On: May 12th, 2018] [Originally Added On: May 12th, 2018]
- Myocardial infarction (Heart Attack) - Health Facts [Last Updated On: June 21st, 2018] [Originally Added On: June 21st, 2018]
- Heart Attack and Acute Coronary Syndrome - Lab Tests Online [Last Updated On: June 21st, 2018] [Originally Added On: June 21st, 2018]
- Myocardial Infarction - ECGpedia [Last Updated On: September 21st, 2018] [Originally Added On: September 21st, 2018]
- Myocardial Infarction Clinical Presentation: History ... [Last Updated On: September 25th, 2018] [Originally Added On: September 25th, 2018]
- Myocardial infarction diagnosis - Wikipedia [Last Updated On: September 25th, 2018] [Originally Added On: September 25th, 2018]
- Myocardial Infarction Treatment & Management: Approach ... [Last Updated On: October 9th, 2018] [Originally Added On: October 9th, 2018]
- Myocardial infarction - Simple English Wikipedia, the free ... [Last Updated On: October 18th, 2018] [Originally Added On: October 18th, 2018]
- ST-Segment Elevation Myocardial Infarction [Last Updated On: October 18th, 2018] [Originally Added On: October 18th, 2018]
- ECG localization of myocardial infarction / ischemia and ... [Last Updated On: October 18th, 2018] [Originally Added On: October 18th, 2018]
- Heart Attack (Myocardial Infarction) Symptoms | Cleveland Clinic [Last Updated On: November 15th, 2018] [Originally Added On: November 15th, 2018]
- Myocardial Infarction (Heart Attack) Ischemia Pathophysiology, ECG, Nursing, Signs, Symptoms Part 1 [Last Updated On: November 15th, 2018] [Originally Added On: November 15th, 2018]
- Myocardial Infarction (MI) NCLEX Questions [Last Updated On: November 30th, 2018] [Originally Added On: November 30th, 2018]
- Myocardial Infarction NCLEX Review (Part 1) [Last Updated On: December 3rd, 2018] [Originally Added On: December 3rd, 2018]
- Acute Myocardial Infarction, Myocardial infection. Patient [Last Updated On: December 4th, 2018] [Originally Added On: December 4th, 2018]
- Heart Attack | Myocardial Infarction | MedlinePlus [Last Updated On: December 16th, 2018] [Originally Added On: December 16th, 2018]
- Heart Attack (Myocardial Infarction) - medicinenet.com [Last Updated On: December 17th, 2018] [Originally Added On: December 17th, 2018]
- Myocardial infarction (acute): Early rule out using high ... [Last Updated On: December 20th, 2018] [Originally Added On: December 20th, 2018]
- Conditions We Treat: Myocardial Infarction | Johns Hopkins ... [Last Updated On: December 23rd, 2018] [Originally Added On: December 23rd, 2018]
- Myocardial Infarction - Heart Home Page [Last Updated On: December 25th, 2018] [Originally Added On: December 25th, 2018]
- Myocardial infarction: signs symptoms and treatment ... [Last Updated On: December 25th, 2018] [Originally Added On: December 25th, 2018]
- ECGs in Acute Myocardial Infarction - ACLS Medical Training [Last Updated On: December 25th, 2018] [Originally Added On: December 25th, 2018]
- Myocardial Infarction - Eccles Health Sciences Library [Last Updated On: December 27th, 2018] [Originally Added On: December 27th, 2018]
- Myocardial Infarction: Practice Essentials, Background ... [Last Updated On: December 27th, 2018] [Originally Added On: December 27th, 2018]
- Myocardial infarction - Wikipedia [Last Updated On: December 27th, 2018] [Originally Added On: December 27th, 2018]
- Nursing Care Plan for Myocardial Infarction | NRSNG [Last Updated On: December 29th, 2018] [Originally Added On: December 29th, 2018]
- Cardiovascular disease - Myocardial infarction | Britannica.com [Last Updated On: January 11th, 2019] [Originally Added On: January 11th, 2019]
- Heart Attack (Myocardial Infarction) - Cedars-Sinai [Last Updated On: January 11th, 2019] [Originally Added On: January 11th, 2019]
- Top 5 MI ECG Patterns You Must Know | LearntheHeart.com [Last Updated On: January 11th, 2019] [Originally Added On: January 11th, 2019]
- Anterior Myocardial Infarction LITFL ECG Library Diagnosis [Last Updated On: January 11th, 2019] [Originally Added On: January 11th, 2019]
- Electrocardiography in myocardial infarction - Wikipedia [Last Updated On: January 11th, 2019] [Originally Added On: January 11th, 2019]
- Myocardial Infarction Therapeutics Market, Share, Growth ... [Last Updated On: March 13th, 2019] [Originally Added On: March 13th, 2019]
- Heart Attack (Myocardial Infarction) - Drugs.com [Last Updated On: April 20th, 2019] [Originally Added On: April 20th, 2019]
- STEMI (ST Elevation Myocardial Infarction): diagnosis ... [Last Updated On: April 20th, 2019] [Originally Added On: April 20th, 2019]
- Heart attack - Symptoms and causes - Mayo Clinic [Last Updated On: April 20th, 2019] [Originally Added On: April 20th, 2019]
- Cardiovascular models including myocardial infarction ... [Last Updated On: April 27th, 2019] [Originally Added On: April 27th, 2019]
- Myocardial infarction - Osmosis Video Library [Last Updated On: May 1st, 2019] [Originally Added On: May 1st, 2019]
- Myocardial Infarction [Last Updated On: September 17th, 2019] [Originally Added On: September 17th, 2019]
- Creatinine Rises After RAS Inhibitor Initiation Tied to Worse Outcomes - Renal and Urology News [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Ventricular Tachycardia Treatment Market Growth in Technological Innovation, Competitive Landscape Mapping the Trends and Outlook - NewsVarsity [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- FDA Action Alert: Merck and Amarin - BioSpace [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Resverlogix Provides Update on BETonMACE Phase 3 Trial Toronto Stock Exchange:RVX - GlobeNewswire [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Marijuana Use Linked to Improved Acute-HF Hospital Survival - Medscape [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Population Health vs. Personalized Medicine: Lost in Translation? - American Council on Science and Health [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Bariatric Surgery Tied to Less MACE in Obesity, Diabetes - Medscape [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- A Novel Algorithm for Improving the Diagnostic Accuracy of Prehospital ST-Elevation Myocardial Infarction - DocWire News [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Shock and Awe: ARNI for Acute HF May Be Safely Started in ICU - Medscape [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Global Myocardial Infarction Treatment Market Will Reach USD 1726.3 million by end of 2022 - Market News Store [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Frequency and Factors Related to Not Receiving Acute Reperfusion Therapy in Patients with ST Elevation Myocardial Infarction; A Single Specialty... [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Research Offers 10-Year Forecast on Myocardial Infarction Treatment Market - Rapid News Network [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- University of Colorado study suggests Cannabis aids in surviving heart... - Communities Digital News [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- SRH part of regional system award recognizing care for heart attacks - Index-Journal [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- TherOx Announces Key SuperSaturated Oxygen Therapy Presentations at TCT 2019 - Yahoo Finance [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Incidence, Characteristics and Outcomes in Very Young Patients with ST Segment Elevation Myocardial Infarction - DocWire News [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Health Recovery After Acute MI Similar in Young Adults With and Without Diabetes - The Cardiology Advisor [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Rapid Diagnosis Protocol for Chest Pain Does Not Improve Outcomes - Diagnostic and Interventional Cardiology [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Diagnosis of Myocardial Infarction At Autopsy: AECVP Reappraisal in the Light of the Current Clinical Classification - DocWire News [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Global Myocardial Infarction Drug Market 2019 BioCardia, Inc., Biscayne Pharmaceuticals, Inc., Capricor Therapeutics, Inc., Cell - Market News Times [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Abiomed to Highlight Importance of Optimal PCI Treatment to Improve Outcomes for High-Risk Patients at TCT 2019 - Yahoo Finance [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- ENTRUST-AF PCI Supports Safety of Dual Therapy With Edoxaban - Medscape [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Preoperative opioid use leads to perioperative consequences in foot and ankle surgery - Healio [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- CV, General Safety of Long-Term PPI Use Examined - The Cardiology Advisor [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Effect of Delayed vs Immediate Interventions in Transient STEMI - The Cardiology Advisor [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Cardiorenal Disease Is the Most Common CVD Manifestation in Patients With T2D - Endocrinology Advisor [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- DAPA-HF Published: 'Stunning Consistent Benefit With Dapagliflozin' - Medscape [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Geomagnetic Disturbances and Cardiovascular Mortality Risk - On Health - BMC Blogs Network [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- Reconsidering the Safety of Intravenous Thrombolysis for Ischemic Stroke After Recent Myocardial Infarction - Neurology Advisor [Last Updated On: September 19th, 2019] [Originally Added On: September 19th, 2019]
- The Lowdown on Lipoprotein(a) - Medscape [Last Updated On: October 9th, 2019] [Originally Added On: October 9th, 2019]
- Protamine use found to significantly reduce reoperations for patients who undergo carotid endarterectomy - Vascular News [Last Updated On: October 9th, 2019] [Originally Added On: October 9th, 2019]
- Left Main Treated With PCI or CABG Have Similar Outcomes at Five Years - Diagnostic and Interventional Cardiology [Last Updated On: October 9th, 2019] [Originally Added On: October 9th, 2019]
- Sen. Sanders released from the hospital after heart attack - WXYZ [Last Updated On: October 9th, 2019] [Originally Added On: October 9th, 2019]
- E-Selectin Gene Haplotypes are Associated with the Risk of Myocardial Infarction - DocWire News [Last Updated On: October 9th, 2019] [Originally Added On: October 9th, 2019]
- BioVentrix Enrolls and Treats First Patient in REVIVE-HF European RCT for Ischemic Heart Failure Patients - P&T Community [Last Updated On: October 9th, 2019] [Originally Added On: October 9th, 2019]
- Quantitative Flow Ratio guided Residual Functional SYNTAX Score for Risk Assessment in Patients with ST-Segment Elevation Myocardial Infarction... [Last Updated On: October 9th, 2019] [Originally Added On: October 9th, 2019]
- Coronary Calcium Scan: The Role of Calcium Scoring in Preventing a First Myocardial Infarction - Consultant360 [Last Updated On: October 9th, 2019] [Originally Added On: October 9th, 2019]
- Sanders plans to 'change the nature' of campaign after heart attack - New York Post [Last Updated On: October 9th, 2019] [Originally Added On: October 9th, 2019]
- Early MI Linked to High Recurrent Events, Mortality - Medscape [Last Updated On: October 9th, 2019] [Originally Added On: October 9th, 2019]
- Sudden Cardiac Arrest and Ventricular Arrhythmias following first type I Myocardial Infarction in the Contemporary Era - DocWire News [Last Updated On: October 9th, 2019] [Originally Added On: October 9th, 2019]
- E-Cigarette Use and Myocardial Infarction - Physician's Weekly [Last Updated On: October 9th, 2019] [Originally Added On: October 9th, 2019]
- Sen. Bernie Sanders had heart attack; chest pains diagnosed as myocardial infarction - KIRO Seattle [Last Updated On: October 9th, 2019] [Originally Added On: October 9th, 2019]