Hospitals Lack Proper Web Security Programs, HIMSS Analytics Reports | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

Hospitals Lack Proper Web Security Programs, HIMSS Analytics Reports

November 30, 2015
by Heather Landi
| Reprints

While healthcare leaders under the risks to their data security, many still do not understand the best way to address these challenges, leaving hospitals and health centers vulnerable to cybersecurity threats, according to a survey by HIMSS Analytics.

The survey found that 39 percent of healthcare organizations do not have an on-premise Web Application Firewall installed to protect their data center, which is the most traditional line of defense against Web application attacks, according to the survey authors. And, additionally, 23 percent of survey respondents said they have no web security programs in place at all, and nearly half of those respondents are from hospitals with 200 beds or more.

The HIMSS Analytics survey, in partnership with Akamai, was designed to highlight the current state of web security in healthcare as well as what plans are in place to improve preparedness. Survey respondents were comprised of 94 healthcare IT executives, including CIOs, CSOs, directors of IT and technology, IT security officer and chief compliance officer.

The survey also found that only 42 percent of healthcare organizations have implemented Distributed Denial of Service (DDoS) protection solutions, with only 13.2 percent planning to implement such a solution.

“This leaves 35 percent of healthcare organizations vulnerable to a type of cyberattack that is increasing in frequency and size across all industries, including healthcare, and is a significant threat to network availability,” the survey authors stated.

Additionally, only 21 percent of respondents say they have a cloud web application firewall (WAF), which, according to the authors, could help mitigate cybersecurity threats, and only 16.5 percent intend to implement one.

Respondents seem aware of their vulnerabilities, with 57 percent saying they “somewhat agree,” “agree,” or “strongly agree” with the statement, “Requirements for interoperability with entities and systems outside of my organization’s network is a security issue my organization faces.” And, despite the lack of protection, 61 percent of respondents said that they “agree” with the statement, “My organization is adequately protected against web application attacks.”

“Overall, the survey indicates a troubling reality relating to cybersecurity in healthcare: Since web-based attack methods become more pervasive as the healthcare industry becomes more connected, healthcare organizations need to increase their sense of urgency and their investment in implementing fundamental web security solutions,” the survey authors concluded.

Get the latest information on Health IT and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More



NIH Releases First Dataset from Adolescent Brain Development Study

The National Institutes of Health (NIH) announced the release of the first dataset from the Adolescent Brain Cognitive Development (ABCD) study, which will enable scientists to conduct research on the many factors that influence brain, cognitive, social, and emotional development.

Boston Children's Accelerates Data-Driven Approach to Clinical Research

In an effort to bring a more data-driven approach to clinical research, Boston Children’s Hospital has joined the TriNetX global health research network.

Paper Records, Films Most Common Type of Healthcare Data Breach, Study Finds

Despite the high level of hospital adoption of electronic health records and federal incentives to do so, paper and films were the most frequent location of breached data in hospitals, according to a recent study.

AHA Appoints Senior Advisor for Cybersecurity and Risk

The American Hospital Association (AHA) has announced that John Riggi has joined the association as senior advisor for cybersecurity and risk.

Report: Healthcare Accounted for 45% of All Ransomware Attacks in 2017

Healthcare fell victim to more ransomware attacks than any other industry in 2017, according to a new report from global cybersecurity insurance company Beazley.

Study: Use of EHRs Does Not Reduce Administrative Costs

A recent study by Duke University and Harvard Business School researchers found that costs for processing a single bill ranged from $20 for a primary care visit to $215 for an inpatient surgical procedure, or up to 25 percent of revenue.