Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Meaningful Use
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • May 2012
    • April 2012
    • March 2012
    • February 2012
    • January 2012
    • December 2011
  • Blog
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Events
  • HIMSS JobMine
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Healthcare top target for hackers

February 24, 2010 | Mike Miliard, Managing Editor
From the March 2010 print issue

ATLANTA – The information security service SecureWorks, which protects 82 healthcare companies in the United States, reported last month that attempted hacker attacks aimed at its clients doubled in the fourth quarter of 2009.

While the first nine months of the year averaged 6,500 attack attempts per day, the last three months saw that number leap to 13,400, SecureWorks reports. Most striking about those figures is that other companies protected by the firm saw no similar increase.

"Healthcare happens to be a good target for hackers because it has a lot of different types of information," Beau Woods, solutions architect for SecureWorks, tells Healthcare IT News. "If you go into a billing system, one of the things you could potentially get out of there is credit card information, name and address, and social security information to create fake identities - but also health insurance information: Medicare, Medicaid, etc."
SecureWorks says the most worrisome attempted breaches involved the most recent version of the Butterfly/Mariposa Bot malware, which, if it infects a computer, can be used to harvest data from the victim’s browser (passwords, etc.) and launch denial-of-service attacks. It can also be spread to other computers via peer-to-peer networking and USB devices.

The news comes at a critical moment for healthcare systems security, as hospitals, care centers, and their business associates try to meet the security rules mandated by the HITECH Act - something for which "most organizations are at best partly prepared," as Rob Seliger, CEO of Sentillion, an identity and access management technology company, told Healthcare IT News this past November.

Indeed, a survey this fall by HIMSS Analytics revealed that, while 87 percent of health providers were aware of the need to meet new security requirements put forth in the federal Health Insurance Portability and Accountability Act (HIPAA), just one third of their business associates were.

“Business associates could represent a risk to healthcare organizations, especially hospitals,” said Lisa Gallagher, senior director, privacy and security, HIMSS.

Meanwhile, the survey found, 50 percent of large hospitals experienced at least one data breach in 2009, and 68 percent felt that the HITECH Act's expanded breach notification requirements would result in the discovery and reporting of more such incidents.

While outside malware attacks spark the most concern and grab the most attention, Seliger says that "the real risk is within the four walls, is not bad people trying to break in." Most breaches are perpetrated by "caregivers working within the enterprise,"who – whether motivated by malice, curiosity, or unfamiliarity with security protocols – gain unauthorized access to records, he notes.

Such vulnerability could be worrisome to providers considering the switch to electronic medical records. But Woods hopes they won’t be deterred from the effort. "The effort to move over to EMRs is about trying to save lives," he says. "I hope people don’t abandon their attempts to go to electronic medical records because of these threats. You just want to protect that information once it's there. [Hospitals] should just do more up front and make sure they're securing their systems."
 

Mike Miliard
Managing Editor of Healthcare IT News
Follow Mike on Twitter @MikeMiliardHITN
Related Topics:
  • March 2010
  • Atlanta
  • Beau Woods
  • Medicare
  • Mike Miliard
  • Rob Seliger
  • United States

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • 6 reasons physicians need to be on social media
  • Lawsuit seeks Allscripts CEO's removal
  • Tablet adoption by docs soars
  • Healthcare part of White House mobility mandate
  • Oregon to implement new statewide HIE
  • Lawsuit seeks Allscripts CEO's removal
  • Web First: Q&A with Allscripts CEO Glen Tullman
  • 6 reasons physicians need to be on social media
  • Oregon to implement new statewide HIE
  • Tablet adoption by docs soars
more news

WEBINARS AND WHITE PAPERS

  • UPCOMING WEBINARS
    June 6th @ 2PM ET--Healthcare Best Practices: 4 Critical IT Strategies to Avoid Data Breaches
  • WHITE PAPERS
    The Christ Hospital Case Study: Improving Operations and Ensuring the Best Possible Patient Care with ECM
  • ON DEMAND WEBINARS
    Redefining Value and Success in Healthcare: Charting the Path to the Future
  • WHITE PAPERS
    Sharp HealthCare: Growing Content Management into an Enterprise Strategy
  • WHITE PAPERS
    Mobility Advantage: Health Care Made Easier
More Resources
Syndicate content

HIMSS JOBMINE

  • Regional Senior Quality Analyst - Memorial Medical Center - Modesto, CA
  • Network Engineer II - Carilion Clinic - Roanoke, VA
  • EMR Implementation - Project Manager Rothman Specialty Hospital - Rothman Specialty Hospital - Bensalem, PA
  • Director of Information Systems - Mission Regional Medical Center - Mission, Texas
  • Biostatistician II - Saudi Aramco - Dhahran, Saudi Arabia
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy