Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

5/27/2015
10:30 AM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
100%
0%

Escalating Cyberattacks Threaten US Healthcare Systems

Electronic health records are prime targets because healthcare organizations lack the resources, processes, and technologies to protect them. And it's only going to get worse.

Imagine a hostile nation-state with your psychiatric records. Or an organized crime ring with your child’s medical file. Or a disgruntled employee with your medical insurance information.

It’s scary but true. Cyber criminals—from unhappy employees to the most sophisticated hackers—are targeting healthcare data, findings from the Fifth Annual Benchmark Study on Privacy & Security of Healthcare Data indicate. And no healthcare organization, from an 18-bed county hospital in Illinois to healthcare insurer CareFirst to insurance giant Anthem, is immune to these attacks. Without fear or favor, these criminals want to hack into healthcare systems to seize your medical data either to make a profit or to expose the security vulnerabilities of the U.S. healthcare system.

For money-hungry criminals, healthcare records are a treasure trove of easily accessible information. According to the FBI, criminals are targeting the healthcare sector because individuals’ personal information, credit information, and protected health information (PHI) are accessible in one place, which translates into a high return when monetized and sold.

“Credit cards can be say five dollars or more where PHI records can go from 20 say up to—we've even seen $60 or $70,” says Jim Trainor, second in command at the FBI’s cyber security division.

The motivations are more complex for politically-minded criminals. The most recent Sony breach became a model of many of the new risks surrounding cyberattacks and the resulting data breaches: disruption of business operations; intellectual property theft; public embarrassment; damaged relationships with business partners, clients, and employees.

The recent Anthem breach reveals an additional threat. There was speculation that organized cybercriminals may hold healthcare records for ransom, demanding payment for not releasing the information online or to other criminal groups. And in healthcare breaches, where lives can literally be at stake, no provider can afford to ignore a threat of compromise to patient healthcare records.

The many faces of criminal attacks
Healthcare records are prime targets for criminals because they recognize that healthcare organizations lack the resources, processes, and technologies to prevent and detect attacks, and thus protect patient data. It’s no surprise, then, that criminal attacks are up 125 percent since 2010, according to benchmark study data. For the first time, in fact, criminal attacks are now the number one root cause of data breaches, rather than user negligence/carelessness or system glitches.

The Ponemon study found that criminals are using a variety of methods to access healthcare records, from spear phishing to web-borne malware attacks to exploiting an existing software vulnerability. According to John Riggi, the FBI’s Cyber Division Section Chief, criminals often use personal social media profiles to craft highly effective spear phishing attacks, a tactic that occurred in 88 percent of healthcare organizations in the Ponemon study as a means for gaining access. They then simply “phone home” while escalating privileges and building a network map. Once data is exfiltrated, they use the Dark Web to monetize the stolen information.

Riggi also said that cyber threats by both nation states and organized crime are growing, most typically from Eastern Europe, Russia, China, and Iran. As James Comey, director of the FBI, has said, “There are two kinds of big companies in the United States. There are those who've been hacked by the Chinese and those who don't know they've been hacked by the Chinese.”

Despite these growing threats, half of all organizations have little or no confidence in their ability to detect all patient data loss or theft. In addition, only 40 percent of covered entities and 35 percent of business associates are concerned about cyber attackers.

This lack of concern is reflected in a lack of appropriate budget. CBS News referenced a 2014 survey of healthcare technology professionals, in which half of respondents spent three percent or less of their technology budgets on cybersecurity. The standard investment is 10 percent, experts say.

Tom Turner, executive vice president of sales and marketing at Bitsight Technologies, an organization that rates companies on cyber security, said he is “absolutely” worried about the security of his own health care records.

“Healthcare is absolutely performing at the bottom of the other industries,” Turner told CBS News. "If you'd like a letter grade for that, maybe a C or D.”

Highly motivated criminals are realizing and exploiting the political and financial value of healthcare data, putting patients’ medical and financial health in jeopardy. Unless healthcare organizations become as adept at protecting patient data as criminals are at attacking it, we could experience a tsunami of healthcare data breaches and medical identity theft the likes of which we’ve never seen. This is just the tip of the iceberg.

Rick Kam, CIPP/US, is president and co-founder of ID Experts. ID Experts(r) provides software and services to simplify the complexities of managing privacy and security incident response. Rick has extensive experience leading organizations in the development of policies and ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
5 Ways to Up Your Threat Management Game
Wayne Reynolds, Advisory CISO, Kudelski Security,  2/26/2020
Exploitation, Phishing Top Worries for Mobile Users
Robert Lemos, Contributing Writer,  2/28/2020
Kr00k Wi-Fi Vulnerability Affected a Billion Devices
Robert Lemos, Contributing Writer,  2/26/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-4301
PUBLISHED: 2020-02-28
BigFix Self-Service Application (SSA) is vulnerable to arbitrary code execution if Javascript code is included in Running Message or Post Message HTML.
CVE-2019-7007
PUBLISHED: 2020-02-28
A directory traversal vulnerability has been found in the Avaya Equinox Management(iView)versions R9.1.9.0 and earlier. Successful exploitation could potentially allow an unauthenticated attacker to access files that are outside the restricted directory on the remote server.
CVE-2019-10803
PUBLISHED: 2020-02-28
push-dir through 0.4.1 allows execution of arbritary commands. Arguments provided as part of the variable "opt.branch" is not validated before being provided to the "git" command within "index.js#L139". This could be abused by an attacker to inject arbitrary commands.
CVE-2019-10804
PUBLISHED: 2020-02-28
serial-number through 1.3.0 allows execution of arbritary commands. The "cmdPrefix" argument in serialNumber function is used by the "exec" function without any validation.
CVE-2019-10805
PUBLISHED: 2020-02-28
valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe user-input to examine an object. It is possible for a crafted payload to overwrit...