Practice Economics

Survey: Most health care organizations had a recent security breach


 

References

More than two-thirds of health care organizations responding to a survey have experienced a significant and recent security event, according to the Health Information and Management Systems Society (HIMSS).

The single largest source of significant security incidents were negligent insiders, defined as well-meaning individuals who unwittingly caused a breach. However, 64% of respondents reported that their organization had been the victim of an attack from an external actor – usually an online scam artist. The results are part of the 2015 HIMSS Cybersecurity Survey, which polled 297 health care leaders and information security officers.

©Sebastian Duda/Thinkstock

Most of the security incidents resulted in limited disruption of IT systems with limited impact on clinical care, according to the report. The majority of respondents said security incidents were detected within 24 hours of occurrence, “approximately 20% of these security incidents ultimately resulted in loss of patient, financial, or operational data.”

While security breaches may seem like an IT issue, Jennifer Horowitz, senior director of research at HIMSS, said physicians need to be aware of what they can do to help keep their systems secure.

“This is a rapidly changing environment and I think that physicians also need ... to do their part: adhering to the security policies and protocols as their organization,” Ms. Horowitz said in an interivew, highlighting particularly that physicians need to be aware of potential phishing scams sent via email that could comprompise data security.

gtwachtman@frontlinemedcom.com

Recommended Reading

Legislation aims to improve treatment of serious mental illness
MDedge Internal Medicine
Are clinical part-timers less well liked?
MDedge Internal Medicine
House passes IPAB repeal bill
MDedge Internal Medicine
Supreme Court upholds use of federal subsidies under ACA
MDedge Internal Medicine
Vermont leads the way in marketplace enrollment
MDedge Internal Medicine
VIDEO: Addiction-treatment workforce too small to cope with demand
MDedge Internal Medicine
CMS improves Open Payments system, but not enough
MDedge Internal Medicine
MOC: ABIM eliminates ‘underlying certification’ requirement
MDedge Internal Medicine
Hospital clinicians commonly work while sick
MDedge Internal Medicine
CMS considers easing two-midnight rule for hospital stays
MDedge Internal Medicine