Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceCybersecurity NewsHospitals & Medical Centers

Don’t let your guard down over IT security during the pandemic

By Lee Barrett
From the ER to the Executive Suite, Hospitals Tighten Up
October 30, 2020

Healthcare providers remain firmly focused on dealing with the global pandemic, juggling the often-conflicting demands of providing care while keeping patients and staff safe. The financial impact of the pandemic has left many providers on the brink of bankruptcy amid falling patient visits deferred elective surgeries, and insufficient government aid to “fill the gap.”

The Office of Civil Rights (OCR) has relaxed rules around telehealth to keep some revenue flowing while anxious patients receive the care they need from home. Many healthcare staff are still working from home, using their personal computer networks and firewalls to access protected health information (PHI).

While these are truly unprecedented times, healthcare organizations must continue to ensure maintaining that their technology infrastructure remains immune to accidental or purposeful data breaches.

In a recent interview, the chief information security officer (CISO) at a Los Angeles hospital summed up his security concerns this way: “Organizations with new remote and hybrid workforces will need to adjust their cybersecurity budget and strategy to accommodate this new normal, working to better protect their assets from evolving risks associated with maintaining a decentralized workforce.

“Additionally, they will need to adjust their strategies around training and awareness, asset management, vulnerability management, identity and access management, as well as data loss prevention, backups and supporting policies,” the CISO said.

The cost of a healthcare data breach recently passed $7 million, so organizations cannot afford to take their “eye off the ball” — even in the midst of a pandemic. A third-party risk assessment of technology makes sense to protect vital resources.

 

Confluence of factors contributes to danger

Cybercriminals can strike in numerous ways, but many intrusions can be linked to weak security protocols such as when employees at healthcare providers unintentionally infect technology infrastructure with malware by using their cell phones or tablets to connect with an EMR system, informatics system or data exchange.

Healthcare apps can be another point of entry. More than 400,000 healthcare apps are currently available through app stores, but only a small percentage go through a security type review before being launched to the consumer.

Connectivity to Internet of Things (IoT) or Internet of Medical Things (IoMT) devices can open up a provider to attack. A recent analysis or more than 5 million IoT, IoMT and unmanaged devices across several industries, including healthcare, found up to 20% of medical devices running on unsupported or outdated Microsoft Windows platforms.

The same analysis showed that nearly 90% of organizations with devices regulated by the Federal Drug Administration had recall notices on 10 or more devices. The FDA issues a device recall when it is defective or could pose a risk to patient safety, enterprise safety — or both.

There also are inherent risks associated with data exchange among various public health departments on the state and federal levels, increasing the risk of PHI being exposed. And because the systems may not be interoperable, the risk of exposing private patient information is high as clinicians, lab techs and other providers act quickly to share crucial information like test results for tracing and quarantining. Human errors will inevitably occur.

 

Calm before the storm?

Over the first six months of 2020, 10% fewer healthcare breaches were reported to OCR, with 83% fewer breached records. Before healthcare providers take credit for a job well-done, however, security analysts believe that underreporting plays a critical role at present.

As a healthcare strategist commenting on the report says, “With the likely notion that most healthcare organizations are not accurately reporting attacks and breaches, this draws attention to the fact that there will likely be a dramatic increase in discovery in the next six months.”

In addition to the inherent security issues associated with IoT and IoMT devices, their use has increased in conjunction with the meteoric rise in telehealth visits in the wake of COVID-19 facility shutdowns/slowdowns and relaxed privacy standards.

“Many medical devices continue to use outdated operating systems such as Windows 7, making them an easy entry point into a hospital network for a hacker,” says the CIO of a West Coast hospital. “Add to this the expanded use of telehealth and remote patient monitoring and the plane of entry to a hospital's network is widened further. I only see the situation getting worse unless we take remedial action soon.”

Temporary treatment locations due to an influx of patients and temporary testing facilities also can weaken security protocols. Working with new suppliers and quickly onboarding temporary staff often lead to shortcuts that can result in a breach.

 

How organizations can protect themselves

Even while dealing with the pandemic, healthcare organizations should be working toward the 2021 implementation of the 21st Century Cures Act and the Trusted Exchange Framework and Common Agreement (TEFCA), both of which seek the secure exchange of healthcare data among providers. Opening up computer networks to greater connectivity also opens them up to the potential for a successful cyberattack.

Regardless of competing priorities, it’s crucial for healthcare organizations to manage their overall risk strategies and risk exposure internally and with covered entities and business associates. The risk exposure continues to be high, with organizations taking on more risk than they should be. That’s why having appropriate industry accreditation is so important to promote adherence to standards and best practices while protecting the security, privacy and confidentiality of patient data.

The impact of a cyberattack can cause lasting damage, particularly when it comes to stakeholder credibility and patient impact. Organizations engaged with third-party entities cannot afford to let down their guard and must remain as vigilant now as they were before COVID-19.

KEYWORDS: COVID-19 cyber security healthcare security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Lee barrett ehnac headshot

Lee Barrett is executive director and CEO of the Electronic Healthcare Network Accreditation Commission (EHNAC) where he continues to work on key HIT industry initiatives that lay the foundation for health information technology – including support and implementation of key healthcare legislative mandates and speaks nationally regarding security, privacy, ransomware and cybersecurity risk management/assessment and mitigation strategies, tactics and best practices. He is a member of both the Executive Steering Committee for the ONC Payer + Provider FAST FHIR Task Force and the HHS Cybersecurity Task Force (405d), and Chair of the National Trust Network Data Sharing and Cybersecurity Task Group.

 

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • lightning in colorful clouds

    Don’t let the weather take down security and life safety systems

    See More
  • ransomware-enews

    Don’t Let Cyber Attacks Hold Your Patients Hostage

    See More
  • The Long and Winding Road to Cyber Recovery

    Shadow IT was a security crisis. Now Shadow IT 2.0 is looming. Let’s skip the crisis this time.

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Risk Analysis and the Security Survey, 4th Edition

  • 9780367030407.jpg

    National Security, Personal Privacy and the Law

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing