Report: Healthcare Industry Needs to Improve Application Security Practices | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

Report: Healthcare Industry Needs to Improve Application Security Practices

October 18, 2016
by Heather Landi
| Reprints

The healthcare Industry significantly lags behind other industries when it comes to fixing security vulnerabilities and has the highest prevalence of cryptographic and credentials management issues, according to a security report by Veracode. Given the recent ransomware and other cyber attacks on healthcare organizations, the industry’s low performance on these application security benchmarks is troubling, the Veracode report states.

In its annual State of Software Security Report (SoSS), Veracode, a software security firm, presents metrics drawn from code-level analysis of billions of lines of code across 300,000 assessments performed over the last 18 months.

The report revealed that the continued and persistent use of components in software development is creating systemic risk in the country’s digital infrastructure. However, the report also found that companies achieve accelerated benefits when their application security programs reach maturity. These finding indicate that the growing trend of focusing on digital risk at the application layer and building security into DevOps processes (DevSecOps) can yield great results for organizations in reducing risk without slowing down software development.

One of the key findings of the report is that the prevalent use of open-source and third-party components is creating unmanaged risk. Approximately 97 percent of Java applications contained at least one component with a known vulnerability, according to the report authors.

“The prevalent use of open source components in software development is creating unmanaged, systemic risks across companies and industries,” Brian Fitzgerald, CMO at Veracode, said in a statement. “Today, a cybercriminal can focus on a single vulnerability in one component to exploit millions of applications. Software components are used by every industry and for software of all kinds, and given our dependence on applications, the ease at millions of applications can be breached has the potential to create havoc in our digital infrastructure and economy.”

When looking at healthcare specifically, healthcare as an industry now has the lowest vulnerability fix rate, second-lowest OWASP (Open Web Application Security Project) pass rate and the highest prevalence of cryptographic and credentials management issues. The healthcare industry OWASP policy compliance pass rate is 33 percent, with government being the lowest at 25 percent.

According to the report authors, one of the most telling measures of the state of software security by industry is the vulnerability fix rate. When looking at fix rates by industry vertical, the healthcare industry ranks last for its vulnerability fix rate, and it lags the top performer, manufacturing, by a two-to-one ratio when it comes to fixing critical cyber errors.

“Does the gap reflect an inability to appropriately address vulnerabilities once they’ve been found, or does it point to some other structural constraint that holds healthcare back?” the report authors asked.

The research also highlights the challenges that still exist in software development more broadly. For example, 60 percent of applications failed basic security requirements upon first scan, which means fewer than four out of 10 applications pass security policy requirements on initial assessment. “The fact that this number fundamentally doesn’t change year over year indicates that there’s a lot of software out there that has still not been brought through a formal security improvement process—whether unremediated legacy code or new code that’s not developed via a rigorous secure software development lifecycle (SDLC),” the report authors wrote.

The report found that when companies follow best practices and implement programs with consistent policies and practices for secure development, they are able to remediate vulnerabilities at a higher rate. The study showed that the top quartile of companies fix almost 70 percent more vulnerabilities than the average organization. Additionally, best practices like remediation coaching and eLearning can improve vulnerability fix rates by as much as six-times.

According to the report, giving software developers more power improves security as developers using sandbox technology to scan apps prior to assurance testing show a significant improvement in fix rates.

Additionally, training matters, the report authors wrote, as best practices like remediation coaching and eLearning can improve vulnerability fix rates by as much as six times over.



Get the latest information on Health IT and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More



Arizona ACO Pilots Blockchain Platform to Improve Clinical Outcomes, Reduce Costs

Arizona Care Network, a Phoenix-based accountable care organization (ACO), plans to pilot a blockchain technology platform developed by Solve.Care with the aim of improving clinical outcomes, relieving healthcare’s administrative burdens, and reducing waste within the system.

Protenus February Breach Report: Number of Incidents Remain Steady

The number of healthcare data breach incidents continues to remain steady, and in February’s Breach Barometer report from Protenus, it was revealed that last month, a ransomware attack was responsible for the largest single incident.

Prior Authorization Burdens Hindering Patient Care, AMA Survey Finds

Approximately 64 percent of physicians in a recent American Medical Association (AMA) survey said they wait at least one business day before getting a response from a health plan regarding a prior authorization (PA) decision.

Intermountain Healthcare to Build Global DNA Registry with AncestryDNA, 23andMe Data

Intermountain Healthcare is building a new global DNA registry based on medical histories from people around the world, using existing genetic test results and electronic health histories.

NH-ISAC Accelerates Cyber Threat Sharing for Healthcare Industry

The National Health Information Sharing and Analysis Center (NH-ISAC) is partnering with Anomali, a provider of threat management solutions, to enable seamless, secure threat sharing within the healthcare community.

Enterprise Telemedicine Strategies Gaining Steam, Survey Finds

Healthcare providers are increasingly leveraging a centrally-managed (enterprise) approach to telemedicine, according to the results of the REACH Health 2018 U.S. Telemedicine Industry Benchmark survey.