Healthcare Leaders Admit Serious Gaps in Data Breach Response, Survey Finds

March 5, 2018
When it comes to responding to a cybersecurity attack, healthcare leaders point to serious gaps in the processes about how to respond to a breach, particularly about training and being informed about standard operating procedures, according to a recent poll conducted by KPMG.

When it comes to responding to a cybersecurity attack, healthcare leaders point to serious gaps in the processes about how to respond to a breach, particularly about training and being informed about standard operating procedures, according to a recent poll conducted by KPMG.

In a survey of 154 healthcare and life sciences leaders, KPMG found that more than half (51 percent) of respondents said that written operating procedures about how to respond to a cyber attack either don't exist or they are unaware of what those standards are for responding to varying types of cyber events and elevated incidence that impact an organization. 

With so many different types of threats, from insider threats, to malware, to direct hacking and penetration, organizations need to have multiple cyber response plans and process as well as simulate these through annual "war games,” according to the researchers.

The poll, which was conducted during a recent KPMG webcast, It's not a question of if you will experience a breach, it's a question of when. Are you able to respond to today's cyber threats?, also found:

  • 29 percent of respondents did not know what actions an organization took once a cyber attack or data breach was resolved. Technology upgrades were seen by 15 percent of respondents and training was improved at another 14 percent. Staffing or leadership were changed in a combined 17 percent of respondents' organizations. Another 24 percent responded that they didn't have a breach.
  • 25 percent of respondents said data compromises after a cyber attack were resolved within a day and another 15 percent said "a few days" and 16 percent found the issue to linger more than a week.
  • Lack of training was the biggest weakness in cyber security defenses (29 percent), topping dealing with third parties (20 percent).
  • The loss of confidential information from a cyber-attack was the biggest source of damage from a breach (41 percent), but the second largest response was "reputation damage" at 27 percent. 

"To borrow a phrase from the movie ‘Cool Hand Luke,’ ‘What we've got here is a failure to communicate,' and that certainly applies to healthcare organizations in their cyber attack protocols and response plans," said Michael Ebert, partner, and KPMG's cyber leader for healthcare. "Healthcare IT leaders need communicate more effectively and frequently about the tremendous risks and potential ramifications tied to cyber incidents, and that includes training. If you look at cyber strategy as needing people, processes and technology, many organizations are falling short on the process."

Sponsored Recommendations

Clinical Evaluation: An AI Assistant for Primary Care

The AAFP's clinical evaluation offers a detailed analysis of how an innovative AI solution can help relieve physicians' administrative burden and aid them in improving health ...

From Chaos to Clarity: How AI Is Making Sense of Clinical Documentation

From Chaos to Clarity dives deep into how AI Is making sense of disorganized patient data and turning it into evidence-based diagnosis suggestions that physicians can trust, leading...

Bridging the Health Plan/Provider Gap: Data-Driven Collaboration for a Value-Based Future

Download the findings report to understand the current perspective of provider and health plan leaders’ shift to value-based care—with a focus on the gaps holding them back and...

Exploring the future of healthcare with Advanced Practice Providers

Discover how Advanced Practice Providers are transforming healthcare: boosting efficiency, cutting wait times and enhancing patient care through strategic integration and digital...