With the expansion of telehealth and more recently electronic prescribing in Melbourne, computer systems have become more important than ever for general practice.
The estimated losses from cyber attacks and data breaches in 2019 for the healthcare industry are $25 billion with the average cost of ransomware attacks on businesses being $133,000. The Health sector is increasingly being targeted by criminal organisations, individuals and state actors with attacks up 151% in the last ten years and 15% of all breaches involving Healthcare organisations. In Australia from July–December 2019, Australia’s health sector accounted for 22% of all data breaches, making it the highest reporting sector in the country. Given the sensitivity of the data held and managed by health care providers there is additional risk to healthcare providers reputation, the possibility of legal action by distressed patients as well as fines from regulatory bodies for any breaches.
Firstly a hacker can expect to receive $250 per health record on the black market vs the next highest paid record being $5.40 per record for Payment card records.
Secondly healthcare is vulnerable due to the high number of interconnected devices and third-party vendors, meaning that hackers have many entry points to test for weaknesses that they can exploit. 59% of data breaches in the healthcare sector are attributed to third-party vendors. Additionally once in a hacker has access to a large quantity of personal information in the one location.
Healthcare is unique in that it has the largest number of breaches attributed to internal actors which stands at 53%. Denial of Service attacks are less frequent as are ransomware, although there was several instances of this in Australia in February (2019) alone. The internal actor’s motivations are not often malicious and mostly comprise phishing incidents and sending the information to the wrong recipient (Misdelivery) – the most common error type. Here are some Health related security events that show just how easy it is for mistakes to be made when managing patient data:
There are many things that you can do to protect your business. Take a deep breath and start by taking care of the small things. The cumulative effect will be that your business is protected in a BIG way
References
At the helm of our privately owned, global RegTech firm are industry experts who understand that security controls should never get in the way of business growth. We empower companies large and small to remain resilient against potential threats with easily accessible software solutions for implementing information security governance, risk or compliance measures.
We don't just throw a bunch of standards at you and let you try and figure it out! We have designed a thoughtful way of supporting all businesses consider, articulate and develop security controls that suit the needs of the organisation and provide clever reporting capability to allow insights and outcomes from security assessments to be leveraged by the business and shared with third parties.
Our platform places customers at the heart of our design process, while providing access to expert knowledge. With simple navigation and tangible results, we guarantee that all data is securely encrypted at-rest and in transit with no exceptions – meeting international standards with annual security penetration testing and ISO 27001 Certification.