Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - Report Reveals Health Care Security Gaps
Study & Research

Report Reveals Health Care Security Gaps

ISBuzz TeamBy ISBuzz TeamOctober 23, 2015Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Health Care Security Gaps
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Ninety-One Percent of Health Care Workers Believe Their Organizations are Cybercrime Targets

Trustwave® released the 2015 Security Health Check Report—based on a survey of 398 full-time health care professionals—that quantifies the security snags and shortcomings facing the health care industry. According to the study, 91 percent of technical respondents believe criminals are increasingly targeting health care organizations; however, only 10 percent or less of their IT budget goes toward cybersecurity and protecting their patients’ highly sensitive information.

The size of the global electronic healthcare record (eHR) system will grow at an annual rate of 5.5 percent and reach $22.3 billion by the end of 2015, up from $18.8 billion in 2012, according to a study by Accenture. With incentives from the federal Affordable Care Act to move away from paper records, organizations are increasingly adopting eHR systems to track patient information. As businesses make the shift, the expanding threat surface is creating a critical need for health care entities to test everything across databases, networks and applications.

“Today’s health care industry is under attack. From hospitals to physicians to urgent care clinics, health care organizations are swimming in consumer data and must make security a priority in order to protect it,” said Steve Kelley, senior vice president of corporate and product marketing at Trustwave. “Security challenges are nothing new for any business but the level of distress exponentially increases when someone’s life may actually depend on the protection of sensitive data.”

Key findings in the 2015 Security Health Check Report from Trustwave include :

  • Health care under fire: 91 percent of technical respondents believe criminals are increasingly targeting health care organizations, compared to 77 percent of non-technical respondents who believe similarly.
  • Patients are a virtue: 79 percent of technical respondents and 77 percent of non-technical respondents are most concerned about losing patient data, above other types of information, if their organization is breached.
  • Cognitive disconnect: 77 percent of non-technical respondents believe criminals are increasingly targeting health care organizations, but an overwhelming majority (86 percent) said their organization has not experienced a breach.
  • No compromise over compromised data: 74 percent of technical respondents are concerned about their organization getting breached, compared to 51 percent of non-technical respondents.
  • Security expertise gap: 35 percent of technical respondents said their company does not have enough staff and security expertise dedicated to security.
  • Guessing, not testing: More than a third (34 percent) of technical respondents say their business performs vulnerability testing just once a year.
  • Under the knife: Nearly a quarter (23 percent) of technical respondents said their organization has experienced a breach, yet studies have shown the rate to be much higher.
  • Fatal budget diagnosis: Half of technical respondents said 10 percent or less of their overall IT budget goes toward cybersecurity. And 27 percent reported their annual security budget has not changed in the past year.
  • Don’t blame us: 65 percent of non-technical respondents believe that external threats pose more of a concern than insider threats (35 percent).
  • Health care lacks the cure: A quarter of non-technical respondents believe their organizations don’t have incident response plans.

To obtain as complete a perspective as possible, the report is organized into two sections: One features technical respondents (predominantly CIOs, CISOs, IT managers, IT directors and IT vice presidents), while the other features non-technical respondents (predominantly doctors, nurses, senior executives, board members, office managers, office administrators, and finance professionals).

To download a complimentary copy of the report, which includes a list of recommendations for health care organizations, visit HERE.

Methodology

Trustwave commissioned a third-party research firm to survey 398 full-time health care professionals. The objective of the survey was to measure the challenges facing health care organizations of all sizes and the security awareness and expectations of their employees. Survey takers consisted of 198 technical respondents and 200 non-technical respondents. The survey was deployed through emails between May and June 2015 and analyzed in September 2015. Results have a margin of error of +/- 5 percent.[su_box title=”About Trustwave” style=”noise” box_color=”#336588″]trustwaveTrustwave helps businesses fight cybercrime, protect data and reduce security risk. With cloud and managed security services, integrated technologies and a team of security experts, ethical hackers and researchers, Trustwave enables businesses to transform the way they manage their information security and compliance programs. More than 2.7 million businesses are enrolled in the Trustwave TrustKeeper® cloud platform, through which Trustwave delivers automated, efficient and cost-effective data protection, risk management and threat intelligence. Trustwave is a privately held company, headquartered in Chicago, with customers in 96 countries.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}