THANK YOU FOR SUBSCRIBING
Healthcare organizations, particularly large providers, should adopt a zero-trust architecture to reduce the risk of account compromise. This architecture removes implicit trust and assumes a constant threat actor.
Fremont, CA: Healthcare entities face significant cyber risks due to large amount of sensitive patient data and crucial services they provide. This article examines the current cybersecurity issues in healthcare and proposes solutions at both government and organizational levels to mitigate these risks.
Current Cybersecurity Issues in Healthcare
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
A report ranks healthcare as the 6th most attacked industry, up from 7th in the previous year, despite a decrease in total breaches and individuals affected. Let’s dive deeper into some of the current cybersecurity issues in healthcare.
Ransomware Not Going Away
Ransomware, accounting for 38% of healthcare cyberattacks, poses a persistent threat due to perceived higher costs. Healthcare providers often employ double extortion tactics, exfiltrating sensitive patient data and holding them to ransom. Their low tolerance for downtime makes ransomware attacks unlikely to disappear soon.
Medical Device Security Concerns
Healthcare companies face security challenges in medical devices due to reliance on legacy devices and the proliferation of medical IoT devices. A shocking 53% of connected medical devices have critical security vulnerabilities, highlighting the need for improved security measures in healthcare IT environments to protect patient health during cyberattacks.
Proposed Solutions
So, what’s being done to address healthcare’s dominant modern cybersecurity challenges? Here are four solutions covering government input and strategies that healthcare providers can enact autonomously.
Healthcare Cybersecurity Act Of 2022
The Healthcare Cybersecurity Act of 2022 is a US healthcare bill aimed at enhancing cybersecurity, requiring collaboration between CISA and the Department of Health and Human Services, a comprehensive risk study, asset owner and operator training, and workforce shortage assessment.
FDA Medical Device Guidance
The FDA has issued guidelines for designing cyber-secure medical devices, emphasizing cybersecurity in device safety, transparency for users about controls potential risks, and scaling cybersecurity design and documentation in premarket submissions based on device risks, which is crucial for minimizing risks in healthcare environments.
Movements to Zero Trust Architecture
Healthcare organizations, particularly large providers, should adopt a zero-trust architecture to reduce the risk of account compromise. This architecture removes implicit trust and assumes a constant threat actor. Resource access is dynamically authenticated based on request identity and context, with trust scores calculated per session.
More in News