Hospitals are under cyber attack. Are they able to defend themselves? A new study published in the Journal of the American Medical Informatics Association (JAMIA) provides brand new perspectives on the state of hospital cybersecurity performance.
The study, which was conducted by academic researchers from Vanderbilt University and the University of Central Florida, found that while hospitals continue improving their security defenses, they significantly underperform Fortune 1000 firms. It also found that hospitals with low Bitsight Security Ratings (scores of 400 or lower) were associated with significant risk of a data breach—with the probability of a breach in a given year ranging from 38.3% to 49.4% (see graph below).
The study provides a unique analysis of hospital cybersecurity issues. Historic studies of healthcare and hospital cybersecurity performed by researchers have relied on qualitative survey data as opposed to quantitative organizational-performance data.
Predicted probabilities of breach risk by security rating among hospitals with 95% confidence intervals.
The study concluded that quantifying cybersecurity risk is an important step in developing an effective security program. Additionally, it recommended that hospitals implement a method to quantify cybersecurity risks to make informed decisions about allocating resources. Finally, the study found that objective risk measurement tools, such as Bitsight’s cybersecurity rating system, can help hospital decision makers make informed choices.