Access and Feeds

Health Care: Slow Road to Implementing Security Controls

By Dick Weisinger

Tripwire/Ponemon recently surveyed 1320 health care IT staff and management members about risk-based security management in the healthcare and pharmaceutical industries.

  • 70 percent of health care organizations said that it’s very difficult to communicate upward from departments and line of businesses to senior executives about the importance of security risks
  • Only 52 percent of organizations include security threats as part of their formal risk assessments
  • Only 58 percent have fully or partially deployed change control and security configuration management

Dwayne Melancon, chief technology officer for Tripwire, said that “it is true that healthcare organizations rank better than average in some areas of this survey, but there is still a lot of room for improvement.  About half of healthcare and pharmaceutical organizations are not using any kind of formal risk assessments, and they are also far less open to challenging current assumptions. Both of these factors could cause them to be blindsided by the increasing number of cybersecurity threats to their businesses.”

The report finds that the health care industry lags others in the implementation of security controls.  Yet the penalties and fines levied on organizations with security issues is growing.  The report cites a $1.2 million fine on Affinity Health Plan in August for Health Insurance Portability and Accountability Act (HIPAA) violations and a similar fine levied against WellPoint in July.  Changes made to HIPAA earlier in 2013 increased the fines for security violations both in size and frequency.

Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)

Leave a Reply

Your email address will not be published. Required fields are marked *

*