Healthcare Data Breaches Lag Other Industries
Other notable numbers from the report include:
- 48% involved privilege misuse
- 40% resulted from hacking
- 38% utilized malware
- 28% employed social tactics
- 15% comprised physical attacks
- 98% of all data breached came from servers
- 85% of attacks were not considered highly difficult
- 96% of breaches were avoidable through simple or immediate controls
In all, the report surmises that the biggest problem may be stolen and/or weak credentials.
"The amount of breaches that exploit authentication in some manner is a problem," the report says. "In our last report it was default credentials; this year it's stolen and/or weak credentials. Perhaps this is because attackers know most users are over-privileged. Perhaps it's because they know we don't monitor user activity very well. Perhaps it's just the easiest way in the door. Whatever the reason, we have some work to do here. It doesn't matter how hardened our defenses are if we can't distinguish the good guys from the bad guys."
Verizon and the Secret Service also offered these data security tips:
- Restrict and monitor privileged users. "Insiders, especially highly privileged ones can be difficult to control but there are some proven strategies. Trust but verify," the report says. "Use pre-employment screening to eliminate the problem before it starts. Don't give users more privileges than they need (this is a biggie) and use separation of duties."
- Watch for "minor" policy violations. Actively search for such indicators rather than just handling them as they pop up. They could lead to major violations.
- Implement measures to thwart stolen credentials: Keep credential-capturing malware off systems. That's "priority number one." Consider two-factor authentication where appropriate.
- The Secret to Physician Engagement? It's Not Better Pay
- Two-Midnight Rule Must be Fixed or Replaced, Say Providers
- Yale New Haven Health Partners with Tenet Healthcare in CT
- Don't Underestimate Emotional Intelligence
- 4 Reasons PCMH Principles Aren't Going Away
- Care Coordination Tough to Define, Measure
- Size Matters in Antibiotic Overuse
- Evidence-Based Practice and Nursing Research: Avoiding Confusion
- SCOTUS Review of NC Board Case 'A Very Big Deal' to Providers
- 4 Twitter Tactics for Savvy Healthcare Providers