Healthcare Leaders Admit Serious Gaps in Data Breach Response, Survey Finds | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

Healthcare Leaders Admit Serious Gaps in Data Breach Response, Survey Finds

March 5, 2018
by Rajiv Leventhal
| Reprints

When it comes to responding to a cybersecurity attack, healthcare leaders point to serious gaps in the processes about how to respond to a breach, particularly about training and being informed about standard operating procedures, according to a recent poll conducted by KPMG.

In a survey of 154 healthcare and life sciences leaders, KPMG found that more than half (51 percent) of respondents said that written operating procedures about how to respond to a cyber attack either don't exist or they are unaware of what those standards are for responding to varying types of cyber events and elevated incidence that impact an organization. 

With so many different types of threats, from insider threats, to malware, to direct hacking and penetration, organizations need to have multiple cyber response plans and process as well as simulate these through annual "war games,” according to the researchers.

The poll, which was conducted during a recent KPMG webcast, It's not a question of if you will experience a breach, it's a question of when. Are you able to respond to today's cyber threats?, also found:

  • 29 percent of respondents did not know what actions an organization took once a cyber attack or data breach was resolved. Technology upgrades were seen by 15 percent of respondents and training was improved at another 14 percent. Staffing or leadership were changed in a combined 17 percent of respondents' organizations. Another 24 percent responded that they didn't have a breach.
  • 25 percent of respondents said data compromises after a cyber attack were resolved within a day and another 15 percent said "a few days" and 16 percent found the issue to linger more than a week.
  • Lack of training was the biggest weakness in cyber security defenses (29 percent), topping dealing with third parties (20 percent).
  • The loss of confidential information from a cyber-attack was the biggest source of damage from a breach (41 percent), but the second largest response was "reputation damage" at 27 percent. 

"To borrow a phrase from the movie ‘Cool Hand Luke,’ ‘What we've got here is a failure to communicate,' and that certainly applies to healthcare organizations in their cyber attack protocols and response plans," said Michael Ebert, partner, and KPMG's cyber leader for healthcare. "Healthcare IT leaders need communicate more effectively and frequently about the tremendous risks and potential ramifications tied to cyber incidents, and that includes training. If you look at cyber strategy as needing people, processes and technology, many organizations are falling short on the process."

Get the latest information on Health IT and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More



ONC Avoids 2018 Budget Cuts in New Spending Bill

The Office of the National Coordinator for Health IT’s (ONC) funding for 2018 will hold steady through September, at $60 million, as part of a House spending bill that was passed on Thursday.

Global Survey: Nearly Half of Physicians are Not Aware of Blockchain Technology

A survey, conducted by SERMO of 3,700 physicians across the globe, found that nearly half (47 percent) of polled physicians said that they were not aware of blockchain technology.

Wyoming Department of Health to Form Statewide HIE

Wyoming Department of Health plans to form a statewide, medical community-owned health information exchange (HIE), called the Wyoming Frontier Information Exchange (WYFI).

Four Organizations Plan to Form National Health IT Safety Collaborative

Four healthcare- and patient safety-focused organizations have indicated plans to establish a national health IT safety collaborative and are urging the Agency for Healthcare Research and Quality (AHRQ) and the Office of the National Coordinator for Health IT (ONC) to support their efforts.

Finger Lakes Health’s IT Systems Still Down Following Ransomware Attack

Finger Lakes Health, a three-hospital healthcare delivery system in Geneva, New York, continues to use manual and paper processes following a ransomware attack over the weekend, according to local media reports.

Arizona ACO Pilots Blockchain Platform to Improve Clinical Outcomes, Reduce Costs

Arizona Care Network, a Phoenix-based accountable care organization (ACO), plans to pilot a blockchain technology platform developed by Solve.Care with the aim of improving clinical outcomes, relieving healthcare’s administrative burdens, and reducing waste within the system.