October 6, 2017 By George Moraetes 3 min read

In an ever-changing, dynamic threat landscape, a chief information security officer (CISO) in the health care sector must have knowledge in multiple areas and understand that data breaches have severe repercussions that affect employees, patients and the organization at large. To respond effectively to health care security risks, a CISO must possess well-rounded experience in several areas that go beyond privacy and security.

Health Care Security Risks on the Rise

Cybercriminals often target health care organizations because they are notoriously vulnerable to identity theft. Personal health information (PHI) is lucrative, and fraudsters relentlessly attack networks, systems and applications that have been misconfigured or poorly maintained. These threats can pose life-or-death situations if they target heart monitors, intravenous pumps or other hospital devices that can be disabled or altered.

Threat actors have also been known to inject fraudulent data or otherwise falsify patients’ health records. They might modify a record to show, for example, that a patient has a serious condition from which he or she does not suffer, or that the patient requires medication that could be dangerous.

Ransomware is one of the most dangerous threats to health care security because it can disable workstations, medical devices and critical record-keeping systems. Hospital employees are often too busy to apply patches and update applications, and workstations are typically operated by several different clinical staff members, all of whom are more focused on patient care than data security. This environment creates a virtually unlimited number of attack vectors for threat actors to exploit.

Most of these health care security challenges can be attributed to a lack of awareness. According to Harvard Business Review, the medical industry has been slow to adopt effective strategies to protect medical data stored on stolen or lost mobile devices. As a result, many health care workers are ignorant to security risks that threaten the integrity of patient data.

The increasing use of connected medical devices in home care and other medical services further complicates security. If compromised, these devices can potentially lead to widespread attacks and directly impact the individual’s physical well-being. Additionally, health care professionals may take medical data off the grid when they use personal devices to increase productivity.

Mitigating Threats to Health Care Security

To combat these health care security risks, the CISO must develop a holistic approach to security. The security leader should take a page out of the financial industry’s incident response playbook, which calls for a focus on information sharing, stronger authentication and education about cybersecurity risks.

Security professionals should also ensure that the organization’s security program is compliant with the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH), which continually update as new cybercriminal tactics targeting health care data emerge.

Of course, one of the most basic data security tactics is encryption. Health care security leaders should invest in strong encryption solutions and restrict privileges to employees who must access sensitive data to perform their jobs. The same goes for third-party vendors. Other effective health care security measures include multifactor or biometric authentication on workstations and mobile devices, chip cards to streamline patient identification and blockchain to verify recorded transactions between multiple parties.

The CISO is responsible for protecting patients’ health data, which requires collaboration across the organization and with business partners such as vendors and insurers. For the common good of the health care industry at large — which includes individual practitioners, third parties and, most importantly, patients — all health care organizations must invest in solutions and strategies to protect PHI and manage risks to critical systems.

Learn More About Implementing Security Across Industries

More from Healthcare

Why safeguarding sensitive data is so crucial

4 min read - A data breach at virtual medical provider Confidant Health lays bare the vast difference between personally identifiable information (PII) on the one hand and sensitive data on the other.The story began when security researcher Jeremiah Fowler discovered an unsecured database containing 5.3 terabytes of exposed data linked to Confidant Health. The company provides addiction recovery help and mental health treatment in Connecticut, Florida, Texas and other states.The breach, first reported by WIRED, involved PII, such as patient names and addresses,…

Ransomware on the rise: Healthcare industry attack trends 2024

4 min read - According to the IBM Cost of a Data Breach Report 2024, the global average cost of a data breach reached $4.88 million this year, a 10% increase over 2023.For the healthcare industry, the report offers both good and bad news. The good news is that average data breach costs fell by 10.6% this year. The bad news is that for the 14th year in a row, healthcare tops the list with the most expensive breach recoveries, coming in at $9.77…

Cybersecurity risks in healthcare are an ongoing crisis

4 min read - While healthcare providers have been implementing technical, administrative and physical safeguards related to patient information, they have not been as diligent in securing their medical devices. These devices are critical to patient care and can leave hospitals at risk for cyberattacks, causing major disruptions to patient care. In fact, 88 million individuals were affected by large breaches, compromising vast amounts of electronic protected health information (ePHI) last year according to the U.S. Department of Health & Human Services. This year,…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today