Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

5/27/2015
10:30 AM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
100%
0%

Escalating Cyberattacks Threaten US Healthcare Systems

Electronic health records are prime targets because healthcare organizations lack the resources, processes, and technologies to protect them. And it's only going to get worse.

Imagine a hostile nation-state with your psychiatric records. Or an organized crime ring with your child’s medical file. Or a disgruntled employee with your medical insurance information.

It’s scary but true. Cyber criminals—from unhappy employees to the most sophisticated hackers—are targeting healthcare data, findings from the Fifth Annual Benchmark Study on Privacy & Security of Healthcare Data indicate. And no healthcare organization, from an 18-bed county hospital in Illinois to healthcare insurer CareFirst to insurance giant Anthem, is immune to these attacks. Without fear or favor, these criminals want to hack into healthcare systems to seize your medical data either to make a profit or to expose the security vulnerabilities of the U.S. healthcare system.

For money-hungry criminals, healthcare records are a treasure trove of easily accessible information. According to the FBI, criminals are targeting the healthcare sector because individuals’ personal information, credit information, and protected health information (PHI) are accessible in one place, which translates into a high return when monetized and sold.

“Credit cards can be say five dollars or more where PHI records can go from 20 say up to—we've even seen $60 or $70,” says Jim Trainor, second in command at the FBI’s cyber security division.

The motivations are more complex for politically-minded criminals. The most recent Sony breach became a model of many of the new risks surrounding cyberattacks and the resulting data breaches: disruption of business operations; intellectual property theft; public embarrassment; damaged relationships with business partners, clients, and employees.

The recent Anthem breach reveals an additional threat. There was speculation that organized cybercriminals may hold healthcare records for ransom, demanding payment for not releasing the information online or to other criminal groups. And in healthcare breaches, where lives can literally be at stake, no provider can afford to ignore a threat of compromise to patient healthcare records.

The many faces of criminal attacks
Healthcare records are prime targets for criminals because they recognize that healthcare organizations lack the resources, processes, and technologies to prevent and detect attacks, and thus protect patient data. It’s no surprise, then, that criminal attacks are up 125 percent since 2010, according to benchmark study data. For the first time, in fact, criminal attacks are now the number one root cause of data breaches, rather than user negligence/carelessness or system glitches.

The Ponemon study found that criminals are using a variety of methods to access healthcare records, from spear phishing to web-borne malware attacks to exploiting an existing software vulnerability. According to John Riggi, the FBI’s Cyber Division Section Chief, criminals often use personal social media profiles to craft highly effective spear phishing attacks, a tactic that occurred in 88 percent of healthcare organizations in the Ponemon study as a means for gaining access. They then simply “phone home” while escalating privileges and building a network map. Once data is exfiltrated, they use the Dark Web to monetize the stolen information.

Riggi also said that cyber threats by both nation states and organized crime are growing, most typically from Eastern Europe, Russia, China, and Iran. As James Comey, director of the FBI, has said, “There are two kinds of big companies in the United States. There are those who've been hacked by the Chinese and those who don't know they've been hacked by the Chinese.”

Despite these growing threats, half of all organizations have little or no confidence in their ability to detect all patient data loss or theft. In addition, only 40 percent of covered entities and 35 percent of business associates are concerned about cyber attackers.

This lack of concern is reflected in a lack of appropriate budget. CBS News referenced a 2014 survey of healthcare technology professionals, in which half of respondents spent three percent or less of their technology budgets on cybersecurity. The standard investment is 10 percent, experts say.

Tom Turner, executive vice president of sales and marketing at Bitsight Technologies, an organization that rates companies on cyber security, said he is “absolutely” worried about the security of his own health care records.

“Healthcare is absolutely performing at the bottom of the other industries,” Turner told CBS News. "If you'd like a letter grade for that, maybe a C or D.”

Highly motivated criminals are realizing and exploiting the political and financial value of healthcare data, putting patients’ medical and financial health in jeopardy. Unless healthcare organizations become as adept at protecting patient data as criminals are at attacking it, we could experience a tsunami of healthcare data breaches and medical identity theft the likes of which we’ve never seen. This is just the tip of the iceberg.

Rick Kam, CIPP/US, is president and co-founder of ID Experts. ID Experts(r) provides software and services to simplify the complexities of managing privacy and security incident response. Rick has extensive experience leading organizations in the development of policies and ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Data Leak Week: Billions of Sensitive Files Exposed Online
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/10/2019
Intel Issues Fix for 'Plundervolt' SGX Flaw
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5252
PUBLISHED: 2019-12-14
There is an improper authentication vulnerability in Huawei smartphones (Y9, Honor 8X, Honor 9 Lite, Honor 9i, Y6 Pro). The applock does not perform a sufficient authentication in a rare condition. Successful exploit could allow the attacker to use the application locked by applock in an instant.
CVE-2019-5235
PUBLISHED: 2019-12-14
Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone to be abnormal.
CVE-2019-5264
PUBLISHED: 2019-12-13
There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro;Honor V10;Changxiang 7S;P-smart;Changxiang 8 Plus;Y9 2018;Honor 9 Lite;Honor 9i;Mate 9). The software does not properly handle certain information of applications locked by applock in a rare condition...
CVE-2019-5277
PUBLISHED: 2019-12-13
Huawei CloudUSM-EUA V600R006C10;V600R019C00 have an information leak vulnerability. Due to improper configuration, the attacker may cause information leak by successful exploitation.
CVE-2019-5254
PUBLISHED: 2019-12-13
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have an out-of-bounds read vulnerability. An attacker who logs in to the board m...