Endpoint

10/27/2016
09:37 AM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Healthcare Suffers Security Awareness Woes

Weak security practices are putting patient data at risk, new SecurityScorecard report shows.

Healthcare organizations have suffered 22 major data breaches in the past year, resulting in the exposure of millions of patient information, a new study shows.

The 2016 Healthcare Industry Cybersecurity Report from SecurityScorecard illustrates the ills in healthcare's cybersecurity posture. SecurtiyScorecard conducted an analysis of 700 healthcare organizations including medical treatment facilities, health insurance agencies, and healthcare manufacturing businesses. The study covers the period of August 2015 through August 2016.

Network security, IP reputation, and patching cadence are among healthcare's biggest struggles, the study found. Seventy percent of health insurance providers are not adequately protecting patient information, and 63% of the 27 largest US hospitals received a C or lower in Patching Cadence, as they don't fix bugs in their software. More than 75% of the industry suffered malware infections. 

"The greatest security threat comes in the form of malware that will take data and provide access to database resources," says Alex Heid, chief research officer at SecurityScorecard.

Healthcare also suffers from a security awareness problem among users.

"We found a significant correlation between malware infections, and security awareness and social engineering of employees within enterprises," says Heid. Combined with a high amount of vulnerable endpoints, including web browsers and operating systems, this leads to a spike in malware from healthcare organizations.

Healthcare is a target for exploitation because its businesses are sitting on the same data financial companies collect, Heid explains. This includes full names, dates of birth, social security numbers, and other information that can be used for identity theft. 

However, healthcare providers don't have the same protection as financial institutions, he continues. The purpose of banks is to transfer and protect finances, as well as the technology to support them. 

Healthcare companies are focused on human health and healing, and ensuring their services are operational to provide medical care. They weren't thinking about security difficulties because they hadn't happened yet, he continues. "Now, they have to learn by getting scratched." 

"There's a need to balance security and functionality that has been difficult for the healthcare industry," he says. "The security aspect has always taken a backseat because it was never considered to be as large of a target as it has become."

How Healthcare Orgs Get Hit

A common way for malware to enter organizations is through employees who engage with suspicious websites from work, using their corporate email addresses. These may include adult online dating sites or webpages promising opportunities to make money from home.

While this trend spans all industries, Heid notes in healthcare there is a correlation between malware and high numbers of employees entering information on these websites from work computers. This is a sign of poor security awareness; workers who interact with these sites are also likely to open potentially malicious email attachments.

Black Hat Europe 2016 is coming to London's Business Design Centre November 1 through 4. Click for information on the briefing schedule and to register.

 

The study also sheds light on the growing risk of network-connected devices, aka IoT: wireless medical devices and tablets, for example. New hardware has enabled medical advancements and benefited hospitals and patients, but quick deployment has resulted in weak security. 

Further, more modern IoT medical devices are being used to collect sensitive health data and require tougher network security. "It's very important hospitals understand the full capabilities of advanced medical devices they're implementing before potentially fatal accidents occur," says Heid.

Another security challenge for healthcare organizations is updating legacy Web applications. Many insurance companies and healthcare providers have merged or been acquired, and their old networks and infrastructure have been grandfathered in.

This heightens security risk, says Heid, as many companies are still using legacy Web apps that are over ten years old, and have been fixed with band-aids over the years. Now, they need a full overhaul. 

Heid says healthcare organizations must patch their systems, run up-to-date endpoint software, and conduct continuous monitoring and vulnerability assessments to understand where the weak points are.

Going forward, the healthcare industry will continue to experience myriad security problems: new hacked databases from third-party providers will circulate; new medical devices will enter the market.

However, healthcare organizations are becoming more security-savvy, he says. "Healthcare businesses and their leadership are definitely starting to pay attention," he says. "Nobody wants to be the next headline."

Related Content:

Kelly Sheridan is Associate Editor at Dark Reading. She started her career in business tech journalism at Insurance & Technology and most recently reported for InformationWeek, where she covered Microsoft and business IT. Sheridan earned her BA at Villanova University. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Printers: The Weak Link in Enterprise Security
Kelly Sheridan, Associate Editor, Dark Reading,  10/16/2017
20 Questions to Ask Yourself before Giving a Security Conference Talk
Joshua Goldfarb, Co-founder & Chief Product Officer, IDDRA,  10/16/2017
Why Security Leaders Can't Afford to Be Just 'Left-Brained'
Bill Bradley, SVP, Cyber Engineering and Technical Services, CenturyLink,  10/17/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.