Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • ARRA/Stimulus
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • February 2012
    • January 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
  • Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • HIMSS JobMine
  • RSS
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News » Privacy and Security
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Healthcare websites among the most secure

March 14, 2011 | Molly Merrill, Associate Editor

Suggested Content

  • First Rate
  • New rating, reference site launches at Health 2.0
  • Intel to acquire McAfee
  • GE and Intel partner for home health initiative
  • Data storage of top concern to healthcare providers
  • $600M to boost construction, IT at community health centers
  • El Camino Hospital opens new hi-tech facility

Related Resources

  • An IDC Health Insights and Intel Webcast: mHealth and The Second Wave of Clinical Mobility
  • Providers' Perceptions Series: Mobility in Healthcare
  • West Tennessee Healthcare: Accelerating Access to Patient Records with SSO and Context Management
  • Patch Management: 4 Best Practices for Today's Healthcare IT
  • Enabling Collaborative Healthcare Delivery: Care Coordination Strategies with 21st Century Technology

SANTA CLARA, CA – A new report, which reviewed vulnerabilities online during 2010, shows that even in industries that are heavily regulated like healthcare, 14 percent of sites had a serious vulnerability throughout the year.

The report, by WhiteHat Security, a provider of website risk management solutions, found the average website falls into the "always" and "frequently" vulnerable categories – meaning they were exposed more than 270 days of the year. When looking at "window of exposure" across industries, researchers said it becomes apparent there's a vast difference in the approach to website security.

[See also:  Healthcare organizations at risk for more breaches]

Researchers reviewed 3,000 websites across 400 organizations and found that the average website has serious vulnerabilities more than nine months of the year and data leakage has overtaken cross-site scripting as the most common website vulnerability.

Researchers said that, next to social networking and retail, which have two of the largest windows of exposure (58 and 51 percent, respectively), healthcare websites have one of the lowest exposure rates. They suggest that social networking sites' vulnerability may be a reflection of the rate at which they update sites and introduce new code.

"It's inevitable that websites will contain some faulty code – especially in sites that are continually updated,"  said Jeremiah Grossman, founder and CTO of Whitehat Security. "Window of exposure is a useful combination of the vulnerability prevalence, the time it takes to fix vulnerabilities, and the percentage of them that are remediated. Specifically for CIOs and security professionals, measuring window of exposure offers a look at the duration of risk their business and user data is exposed to by not having sufficient remediation processes in place."

Although healthcare industries lead in the new window of exposure metric, they still fall far short of rigorous security processes researchers conclude.

Related Topics:
  • Santa Clara
  • Whitehat Security
  • Privacy and Security

Reader Comments (3)Login to Post a Comment

JeffC says: Legit Access
March 18, 2011 | 2:18PM GMT

In the rush to get apps online and functioning there appears to be a substantial amount of risk. This is, of course, unacceptable in a healthcare environment. In this instance security will need to take precedence over the extra little piece of profit that may be gained by pushing something that hasn't been tested properly out of the door.

browniesrn says: I hope in this race to
March 15, 2011 | 2:26PM GMT

I hope in this race to meaningful use and what you need to achieve in a prescribed time period, security will also be evaluated when testing the success of a particular EHR. With increased access comes increased risk.

allenma3 says: the human factor
March 22, 2011 | 9:24AM GMT

cyber security is huge right now. The most important thing with medical records though is to train your people it seems. In most examples (and ones Ive seen with the VA), it's when people aren't trained well to handle medical records when problems happen. In general though, electronic records are here to stay, so we better continue to evolve our cyber security along with all the changes that are happening.

Most Popular

Latest Headlines
Most Popular
  • ICD-10 inches closer to delay, ICD-11 in the wings
  • 8 trends for a changing healthcare workforce
  • 5 tips for preparing for a potential privacy incident or data breach
  • HIMSS announces transfer of mHealth Summit
  • Interoperability still a barrier to meaningful use, experts find
  • HIMSS12 Twitter recap: The untethered doctor
  • ONC team lays out transition to permanent EHR certification program
  • Mercy Health rises from the ashes, thanks in part to IT
  • Building a new financial infrastructure for healthcare
  • CMS expected to release Stage 2 proposed rule Thursday

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Sharp HealthCare: Growing Content Management into an Enterprise Strategy
  • ON DEMAND WEBINARS
    The Value of Document and Content Management in Healthcare Transformation
  • ON DEMAND WEBINARS
    Improve care quality, coordination, and revenue with Apixio Community Search
  • WHITE PAPERS
    Driving Meaningful Use of Enterprise Content Management
  • WHITE PAPERS
    The Christ Hospital Case Study: Improving Operations and Ensuring the Best Possible Patient Care with ECM
More Resources
Syndicate content

HIMSS JOBMINE

  • Manager, Specialty Education - HIMSS - Chicago, IL
  • Implementation Consultants - Peer Consulting - USA/Canada
  • SW engineer - Healarium - Boston, MA
  • Vice President & Chief Information Officer (VP/CIO) - Greater Hudson Valley Health System - Middletown, NY
  • Director of Measurement Services - URAC - Washington, DC
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy