3 common threats to healthcare privacy

Sep 25, 2019 | Insights

It’s a normal day, John strolls into his clinic clutching a steaming cup of coffee, as the beams of sunlight reflect from the tall glass windows that surround the reception area. Everything is as usual, a typical day in the life of a healthcare worker. John enters the front door and, as the morning reflections fade, his eyes refocus to behold terror on the faces of the receptionists and nurses scrambling about.

“There’s been a breach, John. It was caused by YOU!”

Despite the passing of HIPAA Law in 1996 and subsequent updates to protect patient’s privacy and security we are seeing more infringements than ever. Living in 2019 we have seen some truly dumbfounding scandals from hospitals, insurers and small local clinics alike.

The days of only the big financial institutions being targeted are long gone; anyone and everyone who holds patient records is a target.
Nowadays, it’s not the disgruntled high school students compromising systems for fun, boredom or, as in “Ferris Buller’s Day Off,” to change attendance records. Modern attacks are performed by sophisticated networks of cyber criminals using complex hacking tools.

Despite the plethora of attack vectors, below are 3 common faults that enable attackers and lead to patient’s data being lost or stolen.

1. Lack of two-factor authentication for health systems

Going back to our example of John, the night before the breach he had received a seemingly innocent email. It came from ADP which his company uses to process payroll.

The email informed him that he needed to update his account info immediately or have delays in receiving his paycheck. John clicked through the email’s links without questioning the authenticity and entered his system credentials into a website with a strange URL. It redirected him out of the page after capturing his credentials and after a long day John decided to return home and talk to HR later.

What John didn’t know is that a malicious user had created the fake email and fake login page to capture John’s credentials. Those stolen credentials were then used to connect to and compromise the clinics networks and systems overnight from a remote location.

The systems had no secondary means of verifying the user’s identity and thus allowed full access. This can be prevented by implementing multi-factor authentication, which uses a text message, phone permissions or email to validate logins, on top of the username and password.

2. Failure to keep systems up to date with patches

After the hacker infiltrated the clinics healthcare systems using John’s credentials, they still had a problem. John wasn’t the primary admin and did not have access to each of the clinic’s patient records.

The savvy hacker looked up the name of the system in a web search and found the common vulnerabilities listed online. Vendors publish known vulnerabilities along with patches that fix these issues so users can protect their systems.

Unfortunately, John’s clinic outsourced their IT but seldom communicated with their IT firm — usually only when there was a problem. The hacker noticed that their IT managers had not run a few of the patches from the vendor’s website and exploited these known vulnerabilities to get full admin privilege.

3. Storing sensitive data in plaintext form

Now that the hacker has full access to the system’s collection of patient records, they typically have another issue – all the records are kept in an encrypted and unreadable form.

Encryption, which HIPAA Law requires for sensitive PHI or protected health information, renders records useless to hackers. However, once again the IT team did not properly encrypt all of the system and the malicious actor stole hundreds of confidential records.

Nick Blog Says About Threats Thumbnail

A lack of awareness and training is the biggest contributor to the poor state of cybersecurity. Well over 90% of successful attacks against healthcare providers involve exploiting people in some form to reveal sensitive information, and therefore the most effective way of preventing an attack is to invest in a comprehensive and periodic training program for staff.  

Stakeholders can also boost their organizations’ cybersecurity efforts by enabling multi-factor authentication for all user accounts. It is by far the fastest, least costly and most simple way to drastically reduce a criminal’s chances of exploiting healthcare systems. 

 

Reynaldo Villar

Rey has worked in the health technology and digital health arena for nearly two decades, during which he has researched and explored technology and data issues affecting patients, providers and payers. An adjunct professor at UW-Stout, Rey is also a digital marketing expert, growth hacker, entrepreneur and speaker, specializing in growth marketing strategies.

AI-Powered Pathways

Create and assign treatment-specific pathways for individual patients or frequent groups — that your patients can then follow on their mobile phone or PC.

360-Degree Views

Integrate and analyze patient data from EHRs, lab results, health apps, wearables, digital health gear and remote patient monitoring (RPM) medical devices.

Health Super App

Improve patient engagement and compliance with a patient-centered app that guides, educates and motivates your patients to achieve their health goals.

Better Health Outcomes

Leverage the power of automation and AI to provide your patients with continuous guidance, automated support and access to helpful health tools.

Explore How Calcium Powers Modern Perioperative Medicine

Calcium is built for perioperative teams that are ready to move beyond manual coordination and fragmented tools and operate with greater clarity, consistency, and confidence across the surgical episode.

If your perioperative program is focused on improving readiness, reducing risk, and driving measurable surgical outcomes, Calcium provides the digital foundation to support that work at scale.

Calcium digital health platform - dashboard and app

Free E-Book

Orthopedics and Digital Health: A Synergistic Approach

Related Posts

Online casinos with low minimum deposit

elitedigitalcasinos ≡ Coupons Casino Sign In Guide Online casinos with low minimum depositThis article breaks down online casinos with low minimum deposit in Australia. We explain who benefits from them, what to expect, and who could skip them. You'll get a clear...

read more
Using EHR Patient Data to Create Tailored Treatment Pathways

Using EHR Patient Data to Create Tailored Treatment Pathways

Transforming Information Overload Into Streamlined, Patient-Centered Care Healthcare data is exploding—but can your practice actually use it to your advantage? In today’s value-driven care environment, data isn’t just about compliance or recordkeeping anymore. It’s...

read more
Why Mobile-First is the Future of Value-Based Care

Why Mobile-First is the Future of Value-Based Care

Reimagining Patient Connections and Clinical Insight Through Everyday Technology Healthcare is changing fast and mobile is leading the charge. As value-based care (VBC) becomes the new standard, providers are expected to deliver better outcomes, reduce costs and...

read more

Health Super App

Access powerful health tools and resources to help you take control of your health and reach your health and fitness goals.

Electronic Health Records

Access, organize and securely share your electronic health records (EHR), including lab results, prescribed medications and treatment plans.

Device Data Integration

Integrate your health and fitness data from hundreds of health apps, wearables and monitoring devices then share with your circle of care.

AI-Powered Pathways

Take advantage of our professionally designed pathways to guide you to better health and optimal fitness.

While looking for new slot experiences, rouge casino often appears in conversations about trusted gaming sites. Many users focus on the selection of slots, welcome bonuses, and smooth mobile gameplay before deciding where to play. For many players, finding the right balance between bonuses and game variety is essential.

When comparing modern gambling platforms, https://casino-magicwin.com/ often appears in conversations about trusted gaming sites. Many users focus on the selection of slots, welcome bonuses, and smooth mobile gameplay before deciding where to play. Because of that, experienced players tend to compare several platforms before choosing their favourite.

Among fans of online slots and table games, https://7goldcasino-gb.com/ is frequently mentioned by players comparing bonuses and game libraries. Modern casino fans often compare promotions, slot providers, and overall site usability. For many players, finding the right balance between bonuses and game variety is essential.

When reviewing popular casino websites, https://fortunica-gb.org/ often appears in conversations about trusted gaming sites. Many users focus on the selection of slots, welcome bonuses, and smooth mobile gameplay before deciding where to play. This is why reviews and community discussions remain important for casino players.

When reviewing popular casino websites, winomania casino no deposit bonus is one of the names players notice when browsing casino options. Modern casino fans often compare promotions, slot providers, and overall site usability. This is why reviews and community discussions remain important for casino players.

For many gamblers checking different platforms, slotty slots can come up when users discuss modern gambling platforms. Modern casino fans often compare promotions, slot providers, and overall site usability. Because of that, experienced players tend to compare several platforms before choosing their favourite.

When reviewing popular casino websites, https://purple-casino.com/ is frequently mentioned by players comparing bonuses and game libraries. Players usually pay attention to bonus terms, payment speed, and the variety of games available. This is why reviews and community discussions remain important for casino players.

Among players exploring online casinos, https://casinojoy-gb.com often appears in conversations about trusted gaming sites. Modern casino fans often compare promotions, slot providers, and overall site usability. For many players, finding the right balance between bonuses and game variety is essential.

treatment-diabetes-info.com