Showing posts with label Ponemon Institute. Show all posts
Showing posts with label Ponemon Institute. Show all posts

Tuesday, May 30, 2017

Manufacturers, Healthcare providers fear attack likely on medical devices

Manufacturers, Healthcare providers fear attack likely on medical devices

The healthcare providers and the medical devices manufacturers that use these devices are primarily unprepared to defend against cyber attacks on their devices, in accordance to the outcomes of a recent survey on security preparedness.

The research by the Ponemon Institute indicates that both makers and users of medical devices are concerned about the likelihood that key medical equipment could be hacked. Two-thirds of device makers and 56% of healthcare providers say an attack on devices is likely during the next year, in accordance to the Ponemon survey.

The Ponemon Institute conducted the research for Synopsys, which sells a platform to handle security and quality problems in software development. The survey covered 242 device makers and 262 healthcare delivery organizations in the North America market.

Some 80% of device firms and healthcare respondents recognized the development of secure devices as a key challenge, asserting that devices remain vulnerable due to coding errors, lack of expertise on secure coding practices and pressure to meet product deadlines.

Despite those complications, fewer than 10% of respondents test devices at least yearly, with 53% of healthcare agencies and 43% of manufacturers report that they do no testing on devices, a finding that surprises Larry Ponemon, chair and founder of Ponemon Institute.

“I was blinded when we discovered that,” he contends. “I would have assumed (providers and manufacturers would have) testing; you would think there would be more due to the cyber threat, but that does not seem to be a driver for change.”

Ponemon puts the onus for change on healthcare organization management, not essentially on chief information officers and chief information security officers, who are attempting to do the right things but do  not have the resources or backing of senior leaders.

He claims that, when an attack happens, the CISO often is the fall guy and is fired, even though he or she may have been forcing for higher security. But the main mission for device makers and healthcare agency is to produce and distribute the product.

The survey discovered that one-third of all respondents reported that no person or function in their agency is primarily responsible for medical device security. Only half of device makers and 44% of healthcare organizations follow Food and Drug Administration guidance on mitigating device security risks.

The challenges that providers face with medical devices, which involve clinician mobile devices like smartphones, are overwhelming. Clinicians, Ponemon says, rely on their devices to efficiently serve sufferers, yet security protocols or architecture built in devices rarely adequately protects data. Security funding increases often occur merely after a serious attack, and encryption is not widely used with Internet of Thing devices.

Too often, Ponemon asserts, providers assume that security of pacemakers, insulin pumps and other devices brought into the hospital is the responsibility of the vendor.

“Healthcare doesn’t prioritize security as much as other industries,” he says. “Healthcare providers are thinking of patient safety, not security risks. We see pressures on healthcare providers to have products available to meet the needs of patients. Are we even capable of knowing if we have been hacked?”

Ponemon was glad to see the Food and Drug Administration recently issue guidance on cybersecurity, which he calls “pretty decent but not prescriptive—it does not tell you step-by-step what to do.” But he fears that following the guidance could be seen by device manufacturers and providers as just adding to existing costs.

“We’re living in a world where everything is a connected device. As we have more connected Internet of Things devices, risks increase. IOT devices are convenient to hack. In healthcare, this could kill people,” he claims.

The full report is available here.

 

Monday, January 16, 2017

Organizational complexity is the highest risk to cybersecurity

Some 83% of agencies consider that they are most at risk for cyberattack due to the organizational complexity, in accordance to a latest survey of organizations by the Ponemon Institute.

“Workers aren’t following corporate security requirements as an organizational complexity because they are too tough to be productive, plus policies hinder their capability to work in their preferred manner,” the research noted. “It’s no surprise that shadow IT is on the rise because workers need simpler ways to get their work done.”

The research, which was sponsored by Citrix, finds that workers are increasingly putting data on their personal devices, meaning vital organization information is accessible from any laptop, phone or tablet left sitting at a desk or coffee shop. And data assets are increasing, putting more data at risk, in accordance to 87% of survey respondents.

Survey results also discovered that security and IT experts are increasingly concerned about their current operations:

  • 79% of respondents are worried about security breaches including high-value information.



  • The protection of apps and data is more critical than ever, with 74% of organization saying that a latest IT security framework is required to improve security posture and decrease risk.



  • 71% say there is threat from their inability to control employees’ devices and apps.


As for planning for the future:

  • 73% say data management, 76% say configuration management, and 72% say app management, are the keys to decreasing the security risk over the next 2 years in building a new information technology infrastructure.



  • 75% say their agency is not completely prepared to deal with the potential security risks resulting from Internet of Things (IoT).


“In every region of the world, businesses must agree to the fact that security practices and policies require evolving in case to deal with threats from disruptive technologies, cybercrime and compliance,” in accordance to Larry Ponemon, chairman and founder of the Ponemon Institute.

The organizations consider that they are most at risk for cyberattack due to the organizational complexity, in accordance to a latest survey of organizations by the Ponemon Institute.

“The research discloses respondents’ awareness of the need to challenge the status quo of their Information technology security strategies and consider a latest IT security architecture to safeguard their agencies from cyber risks,” Ponemon adds.

Tuesday, July 19, 2016

Healthcare and pharma least ready for external cyber risks

Just 16% of healthcare and pharmaceutical agencies have a formal procedure for checking the Internet and social media for external cyber risks.


Additionally, just 26% of respondents in the healthcare and pharmaceutical industry consider they have the devices and resources to observe and understand external dangers; 29% say they have the devices and resources to reduce such threats; and 34% claims that they’ve the tools and resources to monitor these dangers.


Those are among the findings of a latest survey taken by the Ponemon Institute and sponsored by cybersecurity vendor BrandProtect. Particularly, respondents were surveyed about external cyber risks—those that arise outside an agency’s conventional firewall and security perimeter, and utilize online channels and utilize email, mobile apps, social media, or domains as their key attack technology.


“When it comes to the real capability of agencies to have the tools and resources essential to monitor, observe, and reduce these external threats, sadly healthcare trailed in every category,” claims Greg Mancusi-Ungaro, chief marketing officer at BrandProtect. “However there is awareness of this problem, the security teams across the healthcare industry are demonstrating they are behind the curve.”


The 591 information technology and IT security practitioners in the US surveyed were drawn from 6 industries—health and pharma, industrial and manufacturing, financial services, public sector, services and retail—to evaluate differences in preparedness for addressing the external cyber dangers.


In accordance to the findings, the financial services industry is most ready to monitor and mitigate external risks, and is most likely to have a formal monitoring procedure. Instances of external risks involve malware or other payloads; socially engineered attacks; brand-based attacks with ransomware, executive impersonations; rogue social domain activity; hactivism/activism; and activities that breach agreement or regulatory needs.


The frequency of these external threats and their financial prices for industry are important. Survey respondents reported that they experienced an average of 32 material cyber threats during the last 24 months, or moderately more than 1 per month, costing them an average of $3.5 million yearly.


“What this report calls attention to is the chance to genuinely become a tougher target by paying attention to these types of probing-style external threats,” summarizes Mancusi-Ungaro. “These attacks do not merely happen overnight. They are the outcome of a long procedure of reconnaissance, investigation, planning, and external task.”

Monday, June 6, 2016

How a Proactive Approach Make better the Healthcare Cybersecurity

A recent survey indicated that most companies do not utilize a data security vendor until after a data breach, which could affect the effectiveness of healthcare cybersecurity policies.


While healthcare data breaches were the most reported data security incident in the year 2015, it is not shocking that more agencies are employing or seeking a third-party managed security services vendor to assist identify and react to healthcare cybersecurity threats. Yet, many healthcare agencies are waiting until a significant data loss before using cybersecurity professionals.


According to a recent survey from Raytheon and the Ponemon Institute, about two thirds of businesses reported that their agencies only engage a cybersecurity vendor after a significant data breach occurs. This reactive approach to data security has been attributed to an increase in data loss.

Friday, May 27, 2016

Do Worker Errors Jeopardize Healthcare Information Security?

A recent survey disclosed that 55% of companies experienced a security incident as the outcome of an employee error, which could demonstrate challenges to healthcare data security.

Several people have heard the adage that humans are not perfect. But, when it comes to patient data, human imperfections can lead to serious healthcare data security issues.

In a recent survey from Experian Data Breach Resolution and Ponemon Institute, researchers discovered that 55% of respondents at companies across industries have experienced a security incident or data breach because of a malicious or negligent employee.

Furthermore, 66% of survey participants reported that employees were the biggest challenge to developing and implementing robust data security postures.

Monday, May 16, 2016

Survey: No slowdown in the way of healthcare violations

Almost 90% of healthcare agencies were the victims of a data violation in the past 2 years, and 45% had more than 5 data breaches during that similar time period.

Criminal attacks are the major cause of these health data breaches, with 50% of healthcare agencies and 41% of business associates reporting such attacks, while worker mistakes, third-party snafus, and stolen computer tools are the cited reasons for the other violations.

Those are among the conclusions of a latest study by the Ponemon Institute, sponsored by software and services vendor ID Experts, in which denial-of-service attacks; malware, ransomware, and phishing are enlisted as the top cyber risks confronting healthcare agencies and business associates.

As the cyber risk has sustained to increase, 79% of healthcare agencies experienced various data breaches (2 or more) in the past 2 years—up 20% since the year 2010. And, 34% of healthcare agencies experienced 2 to 5 breaches.

Rick Kam, president of ID Experts, point outs that the 2016 report is the 6th annual report gave in partnership with the Ponemon Institute and that the there is not much change in the statistics over the passage of time. “That in itself appears to be a problem,” he states. “The figures, frequency, and intensity of breaches in the healthcare sector sustain to be high.”

Kam considers the issue is just going to get worse before it gets better. In that regard, the research also discovered that however most surveyed agencies consider they are susceptible to a data breach, they are unprepared to deal latest risks like ransomware and deficiency the resources to secure patient data.

In fact, 59% of healthcare agencies and 60% of business associates surveyed do not consider their agency’s security budget is enough to curtail or minimize information breaches.
These agencies are in the unenviable post of either paying now by contributing in cyber defense or paying later in regards of economical losses. As the report discloses, data violations are costing the healthcare industry $6.2 billion yearly, with the average price of data violations for covered entities surveyed now standing at more than $2.2M while the average price to business associates in the research pegged at more than $1 million. Medical records are the most usually exposed information, followed by the insurance and billing records, and payment details.

In the research, 38% of healthcare agencies and 26% of business associates are aware of medical identity theft cases impacting their own sufferers and clients. Nevertheless, 64% of healthcare agencies and 67% of BAs surveyed do not give any protection services for victims whose data has been breached.

The CISA act would develop a cybersecurity framework particularly concentrated on healthcare and instructs the Department of Health and Human Services to recognize a particular leader on cyber preparedness, as well as directs HHS to make a series of best practices for health industry leaders to follow—on a voluntary basis—to assist them keep their agency’s data as safe as possible.

Thursday, April 21, 2016

Increasing rate of endpoints raises healthcare susceptibility

The threat of criminal approach to networks and cyber attacks is increasing due to endpoint vulnerabilities, in accordance to results of a latest survey by the Ponemon Institute.

The survey, performed by Ponemon on behalf of CounterTack, has important implications for healthcare agencies, which have seen raised the access to networks and data through the utilization of many types of devices, like laptops and smartphones.

The logic that more devices are in utilization to access an agency’s network—often in the hands of unsophisticated consumers who may be careless with security practices—increases the number of ways that networks can be hacked.

The Ponemon research, which observed at data system security across various industries, disclosed that protection of endpoint tools has not kept up with threats that confront them. “With all the data we have collected, there appears to be a stalemate,” claims Larry Ponemon, founder of security research firm Ponemon Institute. “Companies are doing a lot more, but cannot keep up with the crooks.”

The healthcare industry is a high-profile aim due to the value of the information that contributors and payers hold.

Endpoint security is an increasing concern across companies. Endpoint devices can involve servers, desktop and laptop computers, printers, smartphones, point-of-service devices and more, and they communicate information with an agency’s data network. “The endpoint is the doorway to enterprise networks,” Ponemon elaborates. “Attack vectors converge on connected devices, and then infiltrate the network.”

Specifically in healthcare, with the increased utilization of mobile devices, not sufficient attention has been paid to how to assess either a device is secure, but several industries are not making a more secure atmosphere. “If you have 100 connected devices, it is difficult to determine which one is the aim,” Ponemonll claims. While there are many tools and devices to make endpoint security improved, the truth is that various agencies sustain in a status quo setting and aren’t being proactive.”

Negligent workers and the devices they utilize in the workplace sustain to be the greatest source of endpoint risk, the Ponemon survey discovered. Some 81% of respondents claimed the greatest challenge is minimizing the issue of negligent or careless workers who don’t follow security policies. The risk caused by the increasing number of insecure mobile tools in the workplace increased to 50% from 33% in the year 2013, respondents claimed.

Further 60% of respondents stated that it has become harder to handle endpoint risk, and 80% of respondents consider their mobile endpoints have been the aim of malware over the last 12 months, up from 68% only 2 years ago. Laptops and smartphones pose the greatest endpoint risk, in accordance to 43% and 30% of respondents, respectively. Respondents assume that an average of one-third of all endpoints linked to their agency’s network is not protected

Ransomware has become a major issue because not merely can a healthcare agency or another company be hit once, but ransomware can make lateral movements in an agency—stamp it out in 1 part and it indicates up in another.

That is why endpoint security has become so significant, in accordance to Ponemon. Many agencies in healthcare and other parts have followed a Fort Knox strategy of constructing powerful perimeter defenses. But even the greatest firewalls cannot recognize every piece of malware, and the idea of information has changed, he further adds. “It is all over the place and unstructured, like email.”

Healthcare agencies haven’t been at the leading edge of network security, in part because they mostly do not have the resources or consider that criminals were aiming other sectors, like banking and finance, Ponemon states. But other sectors have complicated their network defenses, and healthcare’s security seems soft by comparison, specifically considering the rate of business associates included in care, which might not be as security-conscious as they should be.

Ponemon suggests taking a good glance at cloud computing vendors, as they have entered up with very secure atmospheres, making it possible for even the smallest contributors to have correct protection. Furthermore, recent steps to share threat information and integrate threat intelligence into security policies will make better the overall protection, he further adds. “Many contributors did not consider they had the right persons to assess the data, so they did not essentially make better the security.”

 

Friday, March 5, 2010

Medical identity theft: Nearly 1.5 million Americans have been victims

Medical identity theft is an alarming and often undetected offense affecting today’s consumers, according to a recent survey conducted by The Ponemon Institute and sponsored by ProtectMyID.com™, Experian’s multilayered identity theft detection, protection and fraud resolution product. According to the study, nearly 1.5 million Americans have been victims of medical identity theft. For many, the notion of identity theft is both upsetting and daunting, but few individuals realize the specific severity and potential repercussions of medical identity fraud. It is estimated that the costs associated with this type of theft total about $28.6 billion — or approximately $20,000 per victim. Not only is resolution of medical fraud an especially arduous endeavor, but the difficulty of recognition and the potential associated costs also make it particularly dangerous.



“We are proud to sponsor this groundbreaking study because when people are informed, we find that they are empowered to take steps to protect all their valuable information.”

“We are pleased to work with Experian’s ProtectMyID.com for this first-of-its-kind study,” said Dr. Larry Ponemon, chairman and founder of Ponemon Institute. “This is the first empirical study that attempts to measure the size and scope of the medical identity theft, and our results underscore the importance of informing the public why the protection of their medical records is of the utmost importance. This study confirms that there is not only a significant financial impact to medical identity theft, but that there is a very real danger of erroneous diagnosis and treatment because of medical records that contain false information. All this adds up to the need for urgency on the part of consumers to self-educate and take the proper steps to ensure the integrity of their medical identity.”

One of the most common instances of medical identity theft is the use of a stolen insurance ID card in order to receive medical services. The main problem in combating the theft is the time it takes to recognize that it has occurred. According to the study, more than 50 percent of consumers didn’t discover that they had been victimized until at least a year after the incident or incidents had occurred. Only 6 percent received a timely notification that their medical records had been breached. These unsettling figures indicate that a significant number of consumers are currently and unknowingly being targeted by medical identity thieves.

Adding to the number of those affected are the individuals who choose not to report wrongdoings to the authorities. In fact, 46 percent of respondents elected not to report incidents to law enforcement officials or other legal authorities. Within this group, the predominant reasoning for withholding such information is even more surprising: 49 percent of those surveyed said that they were close to the thief and did not wish to subject him or her to legal trouble. With so many unreported cases of medical identity theft, it is clear that the reach of such fraud goes far beyond the total number of documented incidents.

“The difficulty in detecting medical identity theft makes it a particularly dangerous form of fraud,” said Jennifer Leuer, general manager of ProtectMyID.com. “Arming yourself with the tools provided by a fraud protection product such as ProtectMyID.com can prove invaluable in early detection and resolution, especially knowing that if something does happen you won’t be alone in getting the matter resolved.”

The potential consequences of medical identity theft have proved to be extremely damaging. Forty-eight percent of respondents said they lost their health care coverage completely, and 32 percent noted an increase in their insurance premiums. Of those surveyed, nearly 80 percent suffered negative ramifications as a result of the theft.
In order to combat these risks, ProtectMyID.com offers coverage specifically designed to aid consumers who are victims of medical identity theft. The following features will be available this month:




  • Ongoing and daily monitoring for identity theft using insurance policy numbers. This will flag suspicious Internet activity involving personal medical information and keep customers informed along the way.

  • Dedicated resolution agents who are trained to notify and work with health care providers on behalf of customers to resolve any theft-related issue. This removes the mystery and uncertainty from dealing with providers and delegates the responsibility to a trained agent.

  • A lost wallet feature allows the consumer to make one call to a trained agent and receive assistance in the cancellation and reordering of lost wallet items, including credit cards and medical and dental insurance cards.

  • Alerts inform members when medically related collection actions occur.


Compounding the effects of medical identity theft is the reality that resolution is extremely difficult. Of those surveyed, only 9 percent of victims reported that they have completely resolved the crimes against them and restored their identity. In contrast, an overwhelming 40 percent of respondents had not reached resolution at the time of the study. As a result of the situation, 55 percent of victims lost confidence in their health care organizations. According to the study, medical identity theft is a pervasive issue that frequently goes untreated and often unnoticed by consumers.

“At ProtectMyID.com, we want to educate consumers about the risks associated with medical identity theft and give them the tools to better protect themselves against this crime,” said Leuer. “We are proud to sponsor this groundbreaking study because when people are informed, we find that they are empowered to take steps to protect all their valuable information.”

Source The Ponemon Institute®