Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • ARRA/Stimulus
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • January 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • August 2011
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • HIMSS JobMine
  • RSS
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Attempted hacker attacks in healthcare on the rise

January 27, 2010 | Mike Miliard, Managing Editor

Suggested Content

  • Healthcare top target for hackers
  • McKesson acquires peerVue
  • Minnesota: A healthy appreciation for HIT
  • Medicare cuts, ACOs to cause slowdown in diagnostic ECG device market
  • HIE on the upswing
  • Microsoft embeds HIPAA compliance into Office 365
  • Open Health Tools, Georgia Tech to spur IT adoption
  • PwC predicts top 10 issues in 'seminal year' for healthcare

ATLANTA – The information security service SecureWorks, which protects 82 healthcare companies in the United States, reported Tuesday that attempted hacker attacks aimed at its clients doubled in the fourth quarter of 2009.

While the first nine months of the year averaged 6,500 attack attempts per day, the last three months saw that number leap to 13,400, SecureWorks reports. Most striking about those figures is that other companies protected by the firm saw no similar increase.

"Healthcare happens to be a good target for hackers because it has a lot of different types of information," Beau Woods, solutions architect for SecureWorks, tells Healthcare IT News. "If you go into a billing system, one of the things you could potentially get out of there is credit card information, name and address, and social security information to create fake identities - but also health insurance information: Medicare, Medicaid, etc."

SecureWorks says the most worrisome attempted breaches involved the most recent version of the Butterfly/Mariposa Bot malware, which, if it infects a computer, can be used to harvest data from the victim’s browser (passwords, etc.) and launch denial-of-service attacks. It can also be spread to other computers via peer-to-peer networking and USB devices.

The news comes at a critical moment for healthcare systems security, as hospitals, care centers, and their business associates try to meet the security rules mandated by the HITECH Act - something for which "most organizations are at best partly prepared," as Rob Seliger, CEO of Sentillion, an identity and access management technology company, told Healthcare IT News this past November.

Indeed, a survey this fall by HIMSS Analytics revealed that, while 87 percent of health providers were aware of the need to meet new security requirements put forth in the federal Health Insurance Portability and Accountability Act (HIPAA), just one third of their business associates were.

Meanwhile, the survey found, 50 percent of large hospitals experienced at least one data breach in 2009, and 68 percent felt that the HITECH Act's expanded breach notification requirements would result in the discovery and reporting of more such incidents.

While outside malware attacks are the most worrisome and attention grabbing, Seliger says that "the real risk is within the four walls, not bad people trying to break in." He notes that most breaches are perpetrated by "caregivers working within the enterprise" who, whether motivated by malice, curiosity, or unfamiliarity with security protocols, gain unauthorized access to records.

Such vulnerability could be worrisome to providers considering the switch to electronic medical records. But Woods hopes they won’t be deterred from the effort. "The effort to move over to EMRs is about trying to save lives," he says. "I hope people don’t abandon their attempts to go to electronic medical records because of these threats. You just want to protect that information once it's there. [Hospitals] should just do more up front and make sure they're securing their systems."

Related Topics:
  • Atlanta
  • Mike Miliard
  • Rob Seliger
  • United States

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • 10 most outlandish kinds of ICD-10 codes
  • 5 stages of EHR maturity and patient collaboration
  • 5 simple ways to realize ROI from your EHR
  • 'Obamacare' a lightning rod, but what about health IT?
  • Remote health monitoring pegged at 3 million users by 2016
  • H.I.T. Men and Women to pick up awards at HIMSS12
  • University challenge targets NCDs with mHealth and social media
  • Indiana health exchange taps AT&T to scale up
  • eHealth Initiative releases recommendations for accountable care
  • One surgeon's take on need for culture change in medicine

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Business Intelligence for Hospitals: Empowering Healthcare Providers to Make Informed Decisions
  • WHITE PAPERS
    Driving Meaningful Use of Enterprise Content Management
  • ON DEMAND WEBINARS
    Case Study: Sentara Healthcare Completes an Award-Winning EHR with Enterprise Content Management
  • WHITE PAPERS
    The Christ Hospital Case Study: Improving Operations and Ensuring the Best Possible Patient Care with ECM
  • WHITE PAPERS
    The Scarborough Hospital: Establishing a Document Management Strategy for EHRs
More Resources
Syndicate content

HIMSS JOBMINE

  • Director, Sales - HIMSS - Arlington, VA
  • Program Analyst - Mathematica Policy Research - Princeton, NJ
  • Oracle Implementation Analyst - Virginia Mason Medical Center - Seattle, WA
  • Web and Custom Development Manager - Virginia Mason Medical Center - Seattle, Washington
  • Epic Analyst/Builder - Vitalize Consulting Solutions - Nationwide
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy