Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Healthcare Organizations Must Strengthen Their Cybersecurity Immunity To Avoid Falling Victim To Cybercriminals
Articles

Healthcare Organizations Must Strengthen Their Cybersecurity Immunity To Avoid Falling Victim To Cybercriminals

ISBuzz TeamBy ISBuzz TeamJuly 2, 2018Updated:July 4, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Cybercriminals looking to make a profit are turning their attention towards an industry known for housing sensitive consumer data with weak security protocols: healthcare.

In April of 2018, Utah-based company HealthEquity reported 23,000 accounts were compromised in a data breach when an employee fell for a phishing scheme. As a result of human error, information like employee names, deduction amounts and social security numbers were exposed.

The HealthEquity breach is hardly an isolated incident in healthcare. A former employee, for example, was caught inappropriately accessing the medical records of 29,000 patients at SSM Health in St. Louis, Missouri. In Chicago, two of Sinai Health Systems employee email accounts were caught in a phishing scam, impacting the records of 11,350 patients. 2017 alone saw the U.S. Department of Health and Human Services report an approximate 477 healthcare breaches and the exposure of more than five million patient records.

While organizations can’t control the actions of cybercriminals and rogue staff members, they can address how employees approach security and mitigate the risk of a breach by strengthening internal cybersecurity habits.

Healthcare providers are feeling the impact of putting off cybersecurity for years

Historically, healthcare organizations have neglected cybersecurity best practices in order to focus on what they do best: providing excellent patient care. But this has left employees wholly unprepared to deal with cyber threats when they inevitably occur.

Given the sheer volume of breaches caused by human error, it’s no surprise to learn that 80 percent of health IT professionals are concerned about employee security awareness.  Employees are the weakest link within an organization — more often than not, breaches are the result of human error because someone didn’t comply with or understand security best practices. Today, employee mistakes account for more than one third of ‘threat actions’ hurting the healthcare industry.

Seemingly innocuous activities, like sending sensitive files over email instead of a secure intranet, can actually help hackers bypass the even the strongest security measures. Similarly, connecting unauthorized applications to healthcare networks pokes holes in existing defense mechanisms. That popular messenger app everyone’s been talking about? If employees use it on a hospital’s network, it could be putting internal servers and sensitive information at risk. A recent Igloo Software survey found 30 percent of healthcare employees will use apps that provide the greatest convenience over ones that have been approved by their employer’s IT team.

Education is the key to eliminating risk brought on by human error

Healthcare organizations continue to struggle to provide sufficient awareness training to their internal teams, making it difficult for employees to strengthen their security hygiene. And IT professionals agree the lack of education is taking a toll on their organization’s ability to respond to threats. A recent study conducted by the Ponemon Institute revealed 52 percent of American healthcare executives believe the lack of security awareness impacts their security posture.

The need for security education is so important that regular training is now a requirement to demonstrate compliance with Health Insurance Portability and Accountability Act (HIPAA) Rules. Because cyber attacks are evolving every day, effective awareness programs need to provide regular training to employees whenever threat intelligence is shared. Ideally, cybersecurity updates should be given monthly while security training should be provided a couple of times per year.

Within the training program, employees should learn how to distinguish between different threats and have the opportunity to act out their response in simulated environments. A routine phishing test, for example, evaluates an employee’s ability to distinguish between a real and a fake email. Quarterly reminders about the dangers of phishing and easily accessible learning materials can also help workers keep cybersecurity top of mind. In addition to training sessions and skills tests, healthcare providers can encourage security best practices by:

  • Incorporating cybersecurity education in new employee onboarding materials.
  • Administering routine phishing tests and regularly assessing employees’ security knowledge.
  • Notifying teams when new threats emerge with real examples and ways to respond.

Organizations can’t afford to ignore the state of their cybersecurity, not when there’s personally identifiable information (PII) at stake. In order to successfully tackle online threats, healthcare providers will need to empower their employees to be a robust first line of defense against impending cyber attacks.

Augment employee training with robust tools for total security coverage

To create a truly holistic cybersecurity environment, organizations should supplement awareness training with security tools monitoring networks and devices around the clock. Securing a healthcare environment requires a multi-pronged approach — layered defenses, not one dimensional strategies, will ensure PII and other sensitive information remain safe from criminals.

One common best practice organizations are using is requiring employees to enable multi-factor authentication (MFA) when connecting to workspace and company accounts. By adding an extra layer of security, such as a code sent via text message or fingerprints, MFA ensures stolen login credentials can’t be used to infiltrate internal systems. As employees bring their personal devices into work, healthcare organizations can deploy a bring your own device (BYOD) policy, clearly articulating what files and servers workers can connect to on their mobile device.

In addition to strengthening account security and policing mobile devices, healthcare providers can leverage tools like antivirus software and content filtering solutions to protect healthcare environments. Firewalls, analytics and machine learning tools also help hospitals detect threats in real-time and stop hackers in their tracks. Implementing an identity access management (IAM) solution enables organizations to monitor employee access to PII and immediately restrict access to information when authorized users are detected. Regularly auditing healthcare networks for vulnerabilities also allows healthcare organizations to test their cyber resiliency and make adjustments when necessary.

With proper awareness training, employees are less likely to fall for spam emails and avoid creating vulnerabilities that hackers are waiting to exploit. Using a combination of education and security software, healthcare organizations can minimize the human element risk and strengthen their overall security posture. By empowering employees with the tools to address cyber threats head on, healthcare organizations can stay a step ahead of criminals and shut down a breach before it even takes place.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}