Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceCybersecurity NewsHospitals & Medical Centers

Don’t let your guard down over IT security during the pandemic

By Lee Barrett
From the ER to the Executive Suite, Hospitals Tighten Up
October 30, 2020

Healthcare providers remain firmly focused on dealing with the global pandemic, juggling the often-conflicting demands of providing care while keeping patients and staff safe. The financial impact of the pandemic has left many providers on the brink of bankruptcy amid falling patient visits deferred elective surgeries, and insufficient government aid to “fill the gap.”

The Office of Civil Rights (OCR) has relaxed rules around telehealth to keep some revenue flowing while anxious patients receive the care they need from home. Many healthcare staff are still working from home, using their personal computer networks and firewalls to access protected health information (PHI).

While these are truly unprecedented times, healthcare organizations must continue to ensure maintaining that their technology infrastructure remains immune to accidental or purposeful data breaches.

In a recent interview, the chief information security officer (CISO) at a Los Angeles hospital summed up his security concerns this way: “Organizations with new remote and hybrid workforces will need to adjust their cybersecurity budget and strategy to accommodate this new normal, working to better protect their assets from evolving risks associated with maintaining a decentralized workforce.

“Additionally, they will need to adjust their strategies around training and awareness, asset management, vulnerability management, identity and access management, as well as data loss prevention, backups and supporting policies,” the CISO said.

The cost of a healthcare data breach recently passed $7 million, so organizations cannot afford to take their “eye off the ball” — even in the midst of a pandemic. A third-party risk assessment of technology makes sense to protect vital resources.

 

Confluence of factors contributes to danger

Cybercriminals can strike in numerous ways, but many intrusions can be linked to weak security protocols such as when employees at healthcare providers unintentionally infect technology infrastructure with malware by using their cell phones or tablets to connect with an EMR system, informatics system or data exchange.

Healthcare apps can be another point of entry. More than 400,000 healthcare apps are currently available through app stores, but only a small percentage go through a security type review before being launched to the consumer.

Connectivity to Internet of Things (IoT) or Internet of Medical Things (IoMT) devices can open up a provider to attack. A recent analysis or more than 5 million IoT, IoMT and unmanaged devices across several industries, including healthcare, found up to 20% of medical devices running on unsupported or outdated Microsoft Windows platforms.

The same analysis showed that nearly 90% of organizations with devices regulated by the Federal Drug Administration had recall notices on 10 or more devices. The FDA issues a device recall when it is defective or could pose a risk to patient safety, enterprise safety — or both.

There also are inherent risks associated with data exchange among various public health departments on the state and federal levels, increasing the risk of PHI being exposed. And because the systems may not be interoperable, the risk of exposing private patient information is high as clinicians, lab techs and other providers act quickly to share crucial information like test results for tracing and quarantining. Human errors will inevitably occur.

 

Calm before the storm?

Over the first six months of 2020, 10% fewer healthcare breaches were reported to OCR, with 83% fewer breached records. Before healthcare providers take credit for a job well-done, however, security analysts believe that underreporting plays a critical role at present.

As a healthcare strategist commenting on the report says, “With the likely notion that most healthcare organizations are not accurately reporting attacks and breaches, this draws attention to the fact that there will likely be a dramatic increase in discovery in the next six months.”

In addition to the inherent security issues associated with IoT and IoMT devices, their use has increased in conjunction with the meteoric rise in telehealth visits in the wake of COVID-19 facility shutdowns/slowdowns and relaxed privacy standards.

“Many medical devices continue to use outdated operating systems such as Windows 7, making them an easy entry point into a hospital network for a hacker,” says the CIO of a West Coast hospital. “Add to this the expanded use of telehealth and remote patient monitoring and the plane of entry to a hospital's network is widened further. I only see the situation getting worse unless we take remedial action soon.”

Temporary treatment locations due to an influx of patients and temporary testing facilities also can weaken security protocols. Working with new suppliers and quickly onboarding temporary staff often lead to shortcuts that can result in a breach.

 

How organizations can protect themselves

Even while dealing with the pandemic, healthcare organizations should be working toward the 2021 implementation of the 21st Century Cures Act and the Trusted Exchange Framework and Common Agreement (TEFCA), both of which seek the secure exchange of healthcare data among providers. Opening up computer networks to greater connectivity also opens them up to the potential for a successful cyberattack.

Regardless of competing priorities, it’s crucial for healthcare organizations to manage their overall risk strategies and risk exposure internally and with covered entities and business associates. The risk exposure continues to be high, with organizations taking on more risk than they should be. That’s why having appropriate industry accreditation is so important to promote adherence to standards and best practices while protecting the security, privacy and confidentiality of patient data.

The impact of a cyberattack can cause lasting damage, particularly when it comes to stakeholder credibility and patient impact. Organizations engaged with third-party entities cannot afford to let down their guard and must remain as vigilant now as they were before COVID-19.

KEYWORDS: COVID-19 cyber security healthcare security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Lee barrett ehnac headshot

Lee Barrett is executive director and CEO of the Electronic Healthcare Network Accreditation Commission (EHNAC) where he continues to work on key HIT industry initiatives that lay the foundation for health information technology – including support and implementation of key healthcare legislative mandates and speaks nationally regarding security, privacy, ransomware and cybersecurity risk management/assessment and mitigation strategies, tactics and best practices. He is a member of both the Executive Steering Committee for the ONC Payer + Provider FAST FHIR Task Force and the HHS Cybersecurity Task Force (405d), and Chair of the National Trust Network Data Sharing and Cybersecurity Task Group.

 

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Top Cybersecurity Leaders
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Cybersecurity
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Cybersecurity Education & Training
    By: Charles Denyer
Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Coding

AI Emerges as the Top Concern for Security Leaders

Half open laptop

“Luigi Was Right”: A Look at the Website Sharing Data on More Than 1,000 Executives

Person working on laptop

Governance in the Age of Citizen Developers and AI

patient at healthcare reception desk

Almost Half of Healthcare Breaches Involved Microsoft 365

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

August 27, 2025

Risk Mitigation as a Competitive Edge

In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • lightning in colorful clouds

    Don’t let the weather take down security and life safety systems

    See More
  • ransomware-enews

    Don’t Let Cyber Attacks Hold Your Patients Hostage

    See More
  • The Long and Winding Road to Cyber Recovery

    Shadow IT was a security crisis. Now Shadow IT 2.0 is looming. Let’s skip the crisis this time.

    See More

Related Products

See More Products
  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!