Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

5/27/2015
10:30 AM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
100%
0%

Escalating Cyberattacks Threaten US Healthcare Systems

Electronic health records are prime targets because healthcare organizations lack the resources, processes, and technologies to protect them. And it's only going to get worse.

Imagine a hostile nation-state with your psychiatric records. Or an organized crime ring with your child’s medical file. Or a disgruntled employee with your medical insurance information.

It’s scary but true. Cyber criminals—from unhappy employees to the most sophisticated hackers—are targeting healthcare data, findings from the Fifth Annual Benchmark Study on Privacy & Security of Healthcare Data indicate. And no healthcare organization, from an 18-bed county hospital in Illinois to healthcare insurer CareFirst to insurance giant Anthem, is immune to these attacks. Without fear or favor, these criminals want to hack into healthcare systems to seize your medical data either to make a profit or to expose the security vulnerabilities of the U.S. healthcare system.

For money-hungry criminals, healthcare records are a treasure trove of easily accessible information. According to the FBI, criminals are targeting the healthcare sector because individuals’ personal information, credit information, and protected health information (PHI) are accessible in one place, which translates into a high return when monetized and sold.

“Credit cards can be say five dollars or more where PHI records can go from 20 say up to—we've even seen $60 or $70,” says Jim Trainor, second in command at the FBI’s cyber security division.

The motivations are more complex for politically-minded criminals. The most recent Sony breach became a model of many of the new risks surrounding cyberattacks and the resulting data breaches: disruption of business operations; intellectual property theft; public embarrassment; damaged relationships with business partners, clients, and employees.

The recent Anthem breach reveals an additional threat. There was speculation that organized cybercriminals may hold healthcare records for ransom, demanding payment for not releasing the information online or to other criminal groups. And in healthcare breaches, where lives can literally be at stake, no provider can afford to ignore a threat of compromise to patient healthcare records.

The many faces of criminal attacks
Healthcare records are prime targets for criminals because they recognize that healthcare organizations lack the resources, processes, and technologies to prevent and detect attacks, and thus protect patient data. It’s no surprise, then, that criminal attacks are up 125 percent since 2010, according to benchmark study data. For the first time, in fact, criminal attacks are now the number one root cause of data breaches, rather than user negligence/carelessness or system glitches.

The Ponemon study found that criminals are using a variety of methods to access healthcare records, from spear phishing to web-borne malware attacks to exploiting an existing software vulnerability. According to John Riggi, the FBI’s Cyber Division Section Chief, criminals often use personal social media profiles to craft highly effective spear phishing attacks, a tactic that occurred in 88 percent of healthcare organizations in the Ponemon study as a means for gaining access. They then simply “phone home” while escalating privileges and building a network map. Once data is exfiltrated, they use the Dark Web to monetize the stolen information.

Riggi also said that cyber threats by both nation states and organized crime are growing, most typically from Eastern Europe, Russia, China, and Iran. As James Comey, director of the FBI, has said, “There are two kinds of big companies in the United States. There are those who've been hacked by the Chinese and those who don't know they've been hacked by the Chinese.”

Despite these growing threats, half of all organizations have little or no confidence in their ability to detect all patient data loss or theft. In addition, only 40 percent of covered entities and 35 percent of business associates are concerned about cyber attackers.

This lack of concern is reflected in a lack of appropriate budget. CBS News referenced a 2014 survey of healthcare technology professionals, in which half of respondents spent three percent or less of their technology budgets on cybersecurity. The standard investment is 10 percent, experts say.

Tom Turner, executive vice president of sales and marketing at Bitsight Technologies, an organization that rates companies on cyber security, said he is “absolutely” worried about the security of his own health care records.

“Healthcare is absolutely performing at the bottom of the other industries,” Turner told CBS News. "If you'd like a letter grade for that, maybe a C or D.”

Highly motivated criminals are realizing and exploiting the political and financial value of healthcare data, putting patients’ medical and financial health in jeopardy. Unless healthcare organizations become as adept at protecting patient data as criminals are at attacking it, we could experience a tsunami of healthcare data breaches and medical identity theft the likes of which we’ve never seen. This is just the tip of the iceberg.

Rick Kam, CIPP/US, is president and co-founder of ID Experts. ID Experts(r) provides software and services to simplify the complexities of managing privacy and security incident response. Rick has extensive experience leading organizations in the development of policies and ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
US Turning Up the Heat on North Korea's Cyber Threat Operations
Jai Vijayan, Contributing Writer,  9/16/2019
MITRE Releases 2019 List of Top 25 Software Weaknesses
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2019
Preventing PTSD and Burnout for Cybersecurity Professionals
Craig Hinkley, CEO, WhiteHat Security,  9/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-14994
PUBLISHED: 2019-09-19
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version 4.1.3, from version 4.2.0 before version 4.2.5, from version 4.3.0 before version 4.3.4, and version...
CVE-2019-15000
PUBLISHED: 2019-09-19
The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.0 before 6.1.8 (the fixed version for 6.1.x), from 6.2.0 before 6.2.6 (the fixed version for 6.2.x), from 6.3.0 before 6....
CVE-2019-15001
PUBLISHED: 2019-09-19
The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.1.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote attackers with Administrator permissions to gain rem...
CVE-2019-16398
PUBLISHED: 2019-09-19
On Keeper K5 20.1.0.25 and 20.1.0.63 devices, remote code execution can occur by inserting an SD card containing a file named zskj_script_run.sh that executes a reverse shell.
CVE-2019-11779
PUBLISHED: 2019-09-19
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.