The Importance of Cyber Security in Healthcare
Cyber risk in healthcare has increased dramatically – in part due to the expanding ecosystem of technology providers that healthcare organizations rely on.
According to HealthITSecurity, in 2022 more than 590 organizations reported healthcare data breaches to the Department of Health and Human Services that impacted upwards of 48 million individuals. Moreover, third-party vendors with access to protected health information (PHI) were responsible for most of the ten biggest data breaches.
But a lack of resources and scalable methods to assess and mitigate third-party risk means healthcare companies often engage with vendors without adequate due diligence or risk assessments. This exposes the health organizations and their patients to risks.
In this blog, we explore the criticality of healthcare vendor risk management (VRM), the risks that healthcare organizations must address, and how they can overcome common challenges.
Healthcare Vendor Risk Management
The delivery of medical services requires the involvement of hundreds if not thousands of technology providers and third parties. Many of these vendors have access to sensitive systems and data and even provide patient care. Increasingly, threat actors are targeting these vendors to breach the networks of interconnected healthcare organizations.
The cost of these attacks is enormous. Relentless attacks can expose PHI and threaten patient care. The financial impacts are also alarming. A study by the Ponemon Institute and IBM found that the average cost of a data breach across all industries is now $9.44 million. Healthcare is hit particularly hard. The cost of a breach in this sector has risen 42% since 2020.
Effective VRM can mean reduced operational risk and dollars saved. But there are also major regulations that mandate a robust healthcare VRM program, including the Health Insurance Portability and Accountability Act (HIPAA) and HITECH:
- HIPAA requires that PHI is stored and protected against emerging risks and threats – both internally and across applicable third-party vendors.
- HITECH mandates the security and privacy of the electronic transmission of health information (which often happens between healthcare organizations and their vendors).
Violation of these regulations, and others such as PCI DSS, can result in financial penalties and reputational losses.
Typical Risks that Healthcare Organizations Face
In order to create an effective healthcare vendor risk management program, healthcare security and risk managers should prioritize the following areas:
1. Third-party access to medical devices
According to IBM, there are 10-15 million medical devices in U.S. hospitals and an average of 10-15 connected devices per patient bed. These devices are often supported by maintenance contracts; however these contracts typically don’t stipulate if a vendor will have access to the device, how it will be supported remotely, or what cybersecurity hygiene measures they have in place. Even more troubling, many vendors outsource device support and maintenance, which further increases supply chain risk.
2. Vulnerabilities on medical devices and internal systems
Unpatched systems are one of the main attack vectors used by threat actors. Poor patching performance doubles the likelihood of a breach and increases the risk of ransomware sevenfold.
Given the vast digital healthcare environment, outdated systems are a huge problem and diligence is essential.
3. Vendor access to PHI and employee PII
Third-party vendors often have access to PHI and employee personally identifiable information (PII) – an extremely valuable commodity to hackers. To reduce the risk of a supply chain attack that breaches this data, healthcare organizations must identify which vendors have access to such data and take steps to understand each vendor’s cybersecurity health on a continuous basis.