Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Securing The Healthcare Industry With End-To-End Encryption
Articles

Securing The Healthcare Industry With End-To-End Encryption

ISBuzz TeamBy ISBuzz TeamJuly 13, 2016Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
New Ransomware Attack Hits Health Insurer Point32Health
New Ransomware Attack Hits Health Insurer Point32Health
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The easily accessible, highly valuable nature of healthcare records is seeing people’s most personal data becoming increasingly accessible to cybercriminals. No other single record bank contains as much Personally Identifiable Information (PII) as that held by healthcare organisations, which makes this data invaluable to hackers.

Nowhere else are hackers able to get their hands on information that allows them to form such a thorough profile of their potential victims. Healthcare records not only offer up a patient’s name, address and social security details, but also often include their financial and insurance information – which ultimately can enable attackers to commit identity fraud and financial exploitation.

Further exacerbating this problem is the incredibly complex network of IT systems now deployed by healthcare organisations, to help patients communicate with healthcare professionals and to provide access to electronic health records and medical devices. This leaves businesses within the healthcare industry even more vulnerable to cybercriminals’ increasingly sophisticated tactics and ever-evolving techniques.

Safe and secure communications

 Healthcare organisations are poorly prepared for protecting their data and that of their patients from mobile security threats. There are fundamental concerns with how these businesses approach cybersecurity, due to a complete lack of know-how, budget and resources when it comes to preventing potential cyberattacks.

Indeed, healthcare organisations have been advised that they should be spending at least 10 per cent of their IT budget on cybersecurity yet the industry average is just 3 per cent, according to the 2015 Health Information Management and Systems Society Leadership Survey.

This lack of investment is further impaired by healthcare organisations underestimating the importance of and lack of investment in mobile security, a failure to implement basic prevention measures, and ignoring key security tools such as encryption. The end result of this is offering cybercriminals an open goal to infiltrating their systems.

Embracing end-to-end encryption

In this digital age, healthcare professionals must be able to communicate with colleagues and patients as securely as if they were speaking to them face-to-face without fear of their communications being intercepted. Security tests have repeatedly proven that end-to-end security is the only way to prevent cybercriminals, intruders, corporate espionage, hackers, rogue nation states and more from violating mobile communications.

With that in mind, healthcare organisations must provide their employees with encrypted mobile communication services. We are not talking about consumer messaging platforms that have recently begun tagging encryption onto their services as an after-thought, but communications services that have been built with security in mind from the get-go.

The rapid rise in sophistication of techniques deployed by cybercriminals means that encryption has to keep on evolving too. We’re now seeing security systems that deploy RSA 4096-bit encryption, which researchers have estimated would take over 1,000 years to crack. Furthermore, they use encryption keys that are kept encrypted in a secure cloud that can only be accessed when a user validates they are who they say are – meaning even if an organisation like the NSA wanted to get to them, they couldn’t.

Through technology like this, healthcare professionals would be able to communicate with one another and their patients safe in the knowledge that their messages will only be seen their intended recipient. Furthermore, they will also be notified of any attempted attack on their privacy, giving them confidence their communications are as secure as possible.

Time to act

The vast quantity of PII available in the healthcare industry guarantees it will remain an attractive target to attackers and a weak point for employees, unless organisations make serious changes to their communications policies. Healthcare executives must place more focus on the danger that cyberattacks pose to their organisations, and put more emphasis on protecting their data and that of their patients by deploying industry-leading security tools.

Improved, ongoing security training for employees will also ensure they are onboard with this culture shift. It’s all well and good having security policies in place but if employees don’t have a thorough understanding of what the cyber threats are, how dangerous they are and how to be resilient against them, then they are rendered useless.

Now is the time for healthcare organisations to embrace end-to-end encryption and boost their chances of countering breaches and avoiding the high costs of remediation.

[su_box title=”About Jonathan Parker-Bray” style=”noise” box_color=”#336588″][short_info id=’60694′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}