Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Healthcare Businesses in the Crosshairs
Articles

Healthcare Businesses in the Crosshairs

ISBuzz TeamBy ISBuzz TeamMarch 27, 2015Updated:April 30, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Healthcare business
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot
Medical and healthcare data breaches on the rise – 27.5% increase, medical records fetch good coin on the black market.

In light of the recent Premera and Anthem breaches, a spotlight is now shining on healthcare businesses, regarding their ability to defend patients’ sensitive information. Security wonks have been warning for years that healthcare businesses are in a lot of trouble, security-wise. Criminals are targeting medical records because of their value, and as a result, medical breaches are the fastest growing type of breach. What can businesses do to get themselves out of the crosshairs?

According to the Identity Theft Resource Center, there were 783 medical breaches in 2014, compared with 614 breaches on the 2013 ITRC Breach List, a dramatic increase of 27.5 percent year over year. This has put healthcare industry breaches in first place for the largest number of breaches, for the last several years running, with over 40% of the total number of breaches. This is no surprise: medical records are worth more on the black market than payment card data.

So what can healthcare businesses do to help reverse this trend?

It is important to understand that there is no such thing as perfect security if you have a sufficiently determined adversary, but this does not mean we should not try to decrease risk and try to mitigate the damage if a security incident does occur. The biggest part of being successful at risk mitigation is decreasing the value of any one piece of the security puzzle, if it is successfully stolen. For instance, if an employee’s username and password are phished, they are of limited use if another factor of authentication is required to log into the user’s accounts.

Here are five things businesses should be doing to help decrease risk and mitigate damage in case of a breach:

  • Update promptly
    Regularly and promptly updating all software is one of the most important things you can do to minimize the vulnerabilities criminals can use to silently get into machines. And vendors often provide updates at no cost. When you get a notice from your vendor, be sure to go directly to the vendor’s website to get the update as soon as possible. This can be particularly problematic for medical machines, as older devices may still be running a version of Windows XP. This should either motivate businesses to upgrade those machines as soon as possible, or to at least put additional protection in place around the more vulnerable machines.
  • Passwords are not enough
    If you are protecting lots of patient data, a password alone is not enough. Consider two-factor authentication. This can be a biometric like a fingerprint or a one-time passcode that is provided to you, via a small digital key card or fob, or even an app on your smartphone.
  • Principle of Least Privilege
    The Principle of Least Privilege simply means that no person, machine, or system should have access to things they do not strictly need. For instance: Financial data should be in a different part of the network, and completely cut off from people who do not need to access it. And very few people, if any, should have Administrator-level access rights on their own machine. Any time you can restrict access without disrupting people’s ability to do their job, you should.
  • Encrypt everywhere
    When we have something that is valuable, we lock it up when it is not in use. It is the same with data; if you have valuable data, it should be encrypted whenever it is not directly in use. That means when it is in storage, it should be encrypted. When it is being accessed or sent over the network, it should be through an encrypted connection. Having encryption from end to end minimizes criminals’ ability to get any useful data, even if they do manage to breach your other defences.
  • Redundant defences
    Do not expect one security product to protect you against every possible threat. Make sure you have an anti-Malware suite on all devices that access your network (do not forget smartphones, Android tablets, Linux servers, and Mac computers along with your Windows machines). You should also have a firewall at the gateway to your network and on all your individual machines.

Medical records are likely to remain a tempting target as long as there is a sufficient return on criminals’ investment of time and effort. It is important for healthcare practitioners and businesses to take extra care of their patients’ data, as well as their health. By increasing security, you can decrease the return on investment for criminals, and they may pass your organisation by.

The original article is published here.

by Lysa Myers, ESET

About ESET

eset_logoESET is a pioneer of proactive protection against cyber threats with its award-winning NOD32 technology. Daily, it protects over 100 million computers, laptops, smartphones, tablets and servers, no matter the operating system. ESET solutions for home and business segment deliver a continual and consistent level of protection against a vast array of existing and emerging threats.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}