Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Experts Comments on New Ponemon Healthcare Security Findings
News & Analysis

Experts Comments on New Ponemon Healthcare Security Findings

ISB Editorial StaffBy ISB Editorial StaffMay 16, 2016Updated:December 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
NextGen Healthcare Hit By Data Breach, Over 1M+ Details Exposed
NextGen Healthcare Hit By Data Breach, Over 1M+ Details Exposed
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The 6th annual “Ponemon Institute Benchmark Study on Privacy & Security of Healthcare Data” reflects the sector’s escalating security issues as a primary target for malicious actors.  The study finds that 89% of healthcare institutions and organizations surveyed had a data breach in the past two years, with 79% reporting two or more in 24 months, and nearly half (45%) reporting more than five. Also, a full  60% of 3rd party business associates have also been breached in the last two years.  In addition to the potential impacts on privacy and even (in the case of ransomware attacked) quality of care, the financial impact of breaches is major: an estimated $6.2 Billion this last year.

Brad Bussie,  Director of Product Management, STEALTHbits Technologies:

Brad-Bussie“The core issue that seems to be facing healthcare is the shift in the value of information. Banks went through a very similar issues years ago where the security measures they had implemented were insufficient for the emerging internet. The target for attackers was money. They knew where the cash was and they were going after it. As banks matured and funneled more funding into security, it became harder for bad actors to get paid. Now look at healthcare. They don’t necessarily have cash sitting around for someone to steal but they do have something equally as valuable in this day and age; patient information. Patient information is the path to money. It takes more effort to steal and effectively use identity information but look at the fire sales going on in the dark web. This stuff has value and is being used for financial gain. Healthcare is vulnerable because of the finger pointing and infighting on who should handle security. Until patient information has the same monetary recognition as a handful of cash, we are all in for a long road of identity monitoring.”

“A good tactic that healthcare and third party business associates could adopt is in-sourcing security professionals. Cyber Security is advancing exponentially and organizations can capitalize on this explosive growth. There are firms that specialize in securing healthcare and third business associates with models that cater to capital expenditures or operating expenditures. The excuse that there is lack of budget, people, or expertise to manage data breaches is no longer valid. Security by obscurity is to blame and unfortunately for healthcare, the spotlight has been turned directly towards where they have been hiding.”

Adam Laub, Sr. Vice President, Product Marketing, STEALTHbits Technologies:

adam-laub-sm“The findings of the Ponemon study are consistent with what most would have guessed about the state of security in the healthcare industry.  It’s also not surprising that BA’s and healthcare organizations are pointing fingers at each other either; and they’re both right.  However, a recent survey conducted by the Nasdaq and Tanium found that over 90% of corporate executives admitted to not being able to read or understand a cyber security report, and 40% felt no personal responsibility for cyber security or securing customer data.  So, if you want to point a finger, point it up.  Until corporate executives in the healthcare industry feel the same level of pressure concerning the security of their corporate networks and are measured as such, like they are from a financial perspective, this problem with persist.”

Craig Kensek, security expert, Lastline:

“Security is going to take a coordinated effort between health care organizations and every doctor who sends/receives patient records is a potential source of data loss, either where data is stored, or while it’s transit. In effect, this study is another potential call for off-network backups and the encryption of critical data.  In some respects, health data/patient records is more valuable than financial data to consumers as well as bad actors. You can always open new accounts, change institutions, and do a variety of things – short of changing your social security number. Your health records are “forever” and can now be used for a variety of fraud purposes, which is why the cost of a stolen health record on the dark web is greater than that for a financial record.

“For both financial institutions and health organizations, this is a call for cooperation in best practices against the bad guys. Institutions need to cooperate – the reliability of their security should not be a marketing tool for competing against each other. 

“Institutions must invest in penetrating testing before they are breached, rather than wait until after. It’s time to end the ‘closing the door after the horse is gone’ mindset. Penetration testing is much less expensive to invest in than breach remediation, as are security detection and prevention, and avoid the impacts on actual losses, brand losses, loss of consumer confidence, etc.  Rigorous employee training is essential, such as random “attacks” initiated by the institutions themselves.

“BYOD continues to be a weakness. Institutions must enforce policies and ensure that employees adhere to them, regarding the employee’s own devices. Make sure there are ‘phone home’ capabilities and if the device is lost, the institution should be allowed to make it into a brick, rendering the device useless.”

ISB Editorial Staff
  • ISB Editorial Staff
    Navigating the Cyber Threat Landscape: Key Insights from Trellix ARC’s Q1 2023 Report
  • ISB Editorial Staff
    Experts’ Responses: Cyber Security Predictions 2022
  • ISB Editorial Staff
    ISB Virtual Conference: Key Cyber Security Challenges and Solutions in 2021
  • ISB Editorial Staff
    Cyber Security Predictions 2021: Experts’ Responses

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}