HITRUST Analysis Deems Healthcare “Reactive” to Cybersecurity

March 6, 2015
The Health Information Trust Alliance (HITRUST), a Frisco, Texas-based industry group working to establish a common security framework (CSF), analyzed how healthcare organizations tackle data security against cyber threats and risks, and found most were reactionary in their approach.

The Health Information Trust Alliance (HITRUST), a Frisco, Texas-based industry group working to establish a common security framework (CSF), analyzed how healthcare organizations tackle data security against cyber threats and risks, and found most were reactionary in their approach.

HITRUST’s three-month review of cyber risk management strategies for the healthcare industry revealed what many have already come to know: When it comes to data security from hackers, healthcare organizations are ill prepared. This is not exactly a startling finding, with a major hack of health insurer Anthem having just happened one month ago. Another report, from Redspin Inc., a Carpinteria, Calif.-based health IT security consultant, found that more than half of the breaches of protected health information reported to the Department of Health and Human Services (HHS) Office of Civil Rights (OCR) were the result of hacking, including the notable incident at Community Health System that affected 4.5 million patients. 

One element of this lack of preparation is the fact that most organizations aren’t able to understand the effectiveness of deployed information security products, especially in relation to emerging cyber threats. They also acknowledged they had minimal understanding of the impact of emerging cyber threats on their products and applications.

“Although we have made good progress in maturing our cyber risk management approach for industry, with significant improvements in information sharing, the real opportunity is to understand the emerging threats and model them against organization-specific defenses, configurations and applications,” Daniel Nutkis, chief executive officer, HITRUST, said in a statement.

HITRUST is rolling out a new strategy, a situational awareness and threat assessment tool, which will aim to help healthcare organizations increase visibility against emerging threats and how that could affect their current products. The organization partnered with NSS Labs, an Austin, Texas-based security research and advisory company, on the tool.

Sponsored Recommendations

A Cyber Shield for Healthcare: Exploring HHS's $1.3 Billion Security Initiative

Unlock the Future of Healthcare Cybersecurity with Erik Decker, Co-Chair of the HHS 405(d) workgroup! Don't miss this opportunity to gain invaluable knowledge from a seasoned ...

Enhancing Remote Radiology: How Zero Trust Access Revolutionizes Healthcare Connectivity

This content details how a cloud-enabled zero trust architecture ensures high performance, compliance, and scalability, overcoming the limitations of traditional VPN solutions...

Spotlight on Artificial Intelligence

Unlock the potential of AI in our latest series. Discover how AI is revolutionizing clinical decision support, improving workflow efficiency, and transforming medical documentation...

Beyond the VPN: Zero Trust Access for a Healthcare Hybrid Work Environment

This whitepaper explores how a cloud-enabled zero trust architecture ensures secure, least privileged access to applications, meeting regulatory requirements and enhancing user...