preview

Vulnerabilities In The Healthcare Industry

Decent Essays

Medical data contains some of the most sensitive information about a person, and because of its permanency, meaning it cannot be changed like canceling and replacing credit information, it is extremely valuable. This source of information makes the healthcare industry a prime target for cybercriminals. According to the Intel Security report, hackers are no longer just stealing medical data and selling it, they are extorting their victims (Landi, H., 2016). In one such case, a hacker stole more than 650,000 medical records from three separate healthcare institution databases. Then preceded to publicly advertised the records for sale in the dark web marketplace. After claiming to sell 100,000 in records, the hacker tried to extort money …show more content…

One major problem the industry faces today is unauthorized access into their computer software infrastructure. Vulnerabilities in the system software, especially the Remote Desktop Protocol (RDP), provides hackers the opportunity to completely take control of the affected systems, allowing them to steal protected patient data, install malicious software programs, and/or commit cybervandalism. However, if the attempt fails to exploit the system, Denial of Service (DoS) conditions could result, making it impossible for legitimate users to gain access. Desktop productivity software tools, such as Microsoft Access poses software vulnerabilities due to hidden bugs or program defects. Although businesses use encryption to protect digital information, hackers are finding ways to exploit the digital credentials of the Electronic Health Record (EHR) system by using phishing scams. From a security standpoint, the healthcare industry is ill-prepared in dealing with hackers looking to gain access to highly confidential data, even with HIPAA laws enforced. The organizations' failure to recognize where risks are and how to implement preventive security controls can have devastating repercussions on their stockholders. Although errors in application controls can be corrected with a process called patch management, those less prepared tend to be one step behind the threats, impacting the businesses’ time and bottom line. Identify theft, which has increased exponentially, can have a significant effect on customers’ financials and time lost by correcting erroneous information. As cybercrime increases, it is imperative healthcare organizations and their leaders start protective proactive measures, this includes performing risk assessments, implement a security policy, and conducting information systems audits to

Get Access