Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - Less Than A Third Of Global Healthcare Organisations Remain Untouched, As Data Breaches Rise Across The Industry
Study & Research

Less Than A Third Of Global Healthcare Organisations Remain Untouched, As Data Breaches Rise Across The Industry

ISBuzz TeamBy ISBuzz TeamMarch 5, 20184 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

2018 Thales Healthcare Data Threat Report reveals pressures to drive digital transformation, while maintaining the security of sensitive information

 

Thales, a leader in critical information systems, cybersecurity and data security, today announces the results of its 2018 Thales Data Threat Report, Healthcare Edition, revealing only 30% of global healthcare organisations have remain untouched by a data breach. Worryingly 39% of these organisations have been breached in the last year alone, while the majority of respondents (70%) reported being breached in the past – a 17% increase from the 2016 report. Issued in conjunction with analyst firm 451 research, the findings also highlight the negative impact cyber criminals are having, with over half (55%) feeling ‘very’ or ‘extremely’ vulnerable to data breaches.

Click to Tweet: 70% of global #healthcare orgs report being breached in past in @thalesesecurity #2018DataThreat [insert link]

Digital transformation: Enabling better healthcare, but creating risks

In an effort to provide more efficient services – and with an eye towards cutting costs – the healthcare industry has more recently been turning its attention towards embracing digitally transformative technologies, including cloud, big data, Internet of Things and containers. These technologies allow organisations to better create and manage data, as well as store critical information more efficiently.

Almost all (93%) of global respondents reported using these technologies with sensitive data. With each new technology comes unique data security challenges that must be addressed, as they increase the attack surface available. Among some of the more notable findings from this year’s report:

  • All (100%) global respondents surveyed are leveraging cloud technologies, with 54% using three or more cloud vendors for infrastructure (IaaS) as opposed to having it onsite
  • One-third (33%) of global respondents are using more than 50 cloud based software applications (SaaS); and 54% are using three or more cloud based platform (PaaS) environments
  • Almost all (99%) of global respondents are using big data; 94% are working on or using mobile payments, and 94% have a blockchain project implemented or are in the process of implementing one
  • 96% are leveraging IoT technologies, which may include internet-connected heart-rate monitors, implantable defibrillators and insulin pumps

Consequently, these organizations have emerged as a prime target for hackers, putting valuable medical data at risk. While a stolen credit card has a time-limited value, PHI and electronic medical records (EMR) are packed with immutable data that can, and do, fetch hundreds of dollars per stolen record on illegal online markets.

Compliance playing larger role in influencing global healthcare security attitudes

Past global healthcare reports have shown the U.S. to place more of an emphasis on compliance, compared to its global counterparts. This is primarily driven by a privately focused healthcare system, which contends with a complex web of regulations and standards. The effectiveness of a compliance-based strategy is debatable: 77% of U.S. healthcare respondents reported at least one breach at some time in the past, making it the most breached among all U.S. verticals polled in this year’s report.  Despite U.S. struggles, 64% of global healthcare respondents still believe compliance requirements are ‘very’ or ‘extremely’ effective at preventing data breaches, with compliance ranking first among global healthcare respondents as a driver of security spending (51%), higher than any other sector and higher than the U.S. (44%).

Encryption viewed as critical – but does spending reflect this?

While 83% of global healthcare respondents plan to increase spending on security (a number that is above the global average), only 40% of global respondents are increasing spending for data-at-rest security tools. This stance is puzzling, when reflecting on other findings from the report. For example, the looming deadline for the General Data Protection Regulation (GDPR) means data sovereignty is top of mind for most international companies. Globally, encryption is the top choice for complying with privacy regulations (36%). Unlike their U.S. counterparts, who ranked data-at-rest defenses second-to-last in terms of effectiveness, 76% of global healthcare respondents also ranked data-at-rest defenses (such as encryption or tokenization) as the number one tool for protecting data (tied with data-in-motion defenses).

Peter Galvin, Chief Strategy Officer, Thales e-Security says:

“When it comes to data security, the global healthcare industry is increasingly under duress, which is why some of this year’s findings are so counterintuitive. For example, 63% of global respondents are investing money in endpoint security, even though it offers little help in protecting data once perimeters have been breached. Data security spending needs to match healthcare’s reality – which is that of an industry embracing digitally transformative technologies – in the form of investments in encryption solutions offering protection to known and unknown sensitive data that has moved beyond the traditional four walls of the healthcare environment.”

[su_box title=”About Thales e-Security” style=”noise” box_color=”#336588″][short_info id=’65137′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The next phase of endpoint security starts with simplicity

June 24, 20266 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}