HITRUST Analysis Deems Healthcare “Reactive” to Cybersecurity | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

HITRUST Analysis Deems Healthcare “Reactive” to Cybersecurity

March 6, 2015
by Gabriel Perna
| Reprints

The Health Information Trust Alliance (HITRUST), a Frisco, Texas-based industry group working to establish a common security framework (CSF), analyzed how healthcare organizations tackle data security against cyber threats and risks, and found most were reactionary in their approach.

HITRUST’s three-month review of cyber risk management strategies for the healthcare industry revealed what many have already come to know: When it comes to data security from hackers, healthcare organizations are ill prepared. This is not exactly a startling finding, with a major hack of health insurer Anthem having just happened one month ago. Another report, from Redspin Inc., a Carpinteria, Calif.-based health IT security consultant, found that more than half of the breaches of protected health information reported to the Department of Health and Human Services (HHS) Office of Civil Rights (OCR) were the result of hacking, including the notable incident at Community Health System that affected 4.5 million patients. 

One element of this lack of preparation is the fact that most organizations aren’t able to understand the effectiveness of deployed information security products, especially in relation to emerging cyber threats. They also acknowledged they had minimal understanding of the impact of emerging cyber threats on their products and applications.

“Although we have made good progress in maturing our cyber risk management approach for industry, with significant improvements in information sharing, the real opportunity is to understand the emerging threats and model them against organization-specific defenses, configurations and applications,” Daniel Nutkis, chief executive officer, HITRUST, said in a statement.

HITRUST is rolling out a new strategy, a situational awareness and threat assessment tool, which will aim to help healthcare organizations increase visibility against emerging threats and how that could affect their current products. The organization partnered with NSS Labs, an Austin, Texas-based security research and advisory company, on the tool.

Get the latest information on Health IT and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More



NIH Releases First Dataset from Adolescent Brain Development Study

The National Institutes of Health (NIH) announced the release of the first dataset from the Adolescent Brain Cognitive Development (ABCD) study, which will enable scientists to conduct research on the many factors that influence brain, cognitive, social, and emotional development.

Boston Children's Accelerates Data-Driven Approach to Clinical Research

In an effort to bring a more data-driven approach to clinical research, Boston Children’s Hospital has joined the TriNetX global health research network.

Paper Records, Films Most Common Type of Healthcare Data Breach, Study Finds

Despite the high level of hospital adoption of electronic health records and federal incentives to do so, paper and films were the most frequent location of breached data in hospitals, according to a recent study.

AHA Appoints Senior Advisor for Cybersecurity and Risk

The American Hospital Association (AHA) has announced that John Riggi has joined the association as senior advisor for cybersecurity and risk.

Report: Healthcare Accounted for 45% of All Ransomware Attacks in 2017

Healthcare fell victim to more ransomware attacks than any other industry in 2017, according to a new report from global cybersecurity insurance company Beazley.

Study: Use of EHRs Does Not Reduce Administrative Costs

A recent study by Duke University and Harvard Business School researchers found that costs for processing a single bill ranged from $20 for a primary care visit to $215 for an inpatient surgical procedure, or up to 25 percent of revenue.