Survey: Healthcare Orgs Not Taking Mobile Security Seriously Enough | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

Survey: Healthcare Orgs Not Taking Mobile Security Seriously Enough

October 25, 2016
by Rajiv Leventhal
| Reprints

More than half (56 percent) of healthcare professionals believe their organization could be doing more to educate employees on Health Insurance Portability and Accountability Act (HIPAA) compliance and the rules around sharing protected health information (PHI), according to a survey from security and compliance company Scrypt, Inc.

More than three quarters (78 percent) of healthcare professionals use mobile messaging at work, yet when asked if policies existed within their organization relating to the use of mobile messaging specifically, over half (52 percent) of respondents answered ‘no’ or ‘not sure’, according to the survey’s data. And, of those who have sent PHI via mobile messaging, 70 percent confess to having done so using a non-secure application, such as iMessage, WhatsApp or their device’s native messaging client.

As such, more than half of survey respondents believe their organization could be doing more to educate employees on HIPAA compliance and the rules around sharing protected health information. Despite these revelations, the vast majority (80 percent) of respondents consider their own knowledge of HIPAA compliance to be good or very good, which would suggest people have more faith in themselves, than others, or their employer.

Human error was cited as the leading cause of healthcare data breaches in 2015, which should serve to remind organizations that people are frequently the biggest vulnerability in the security equation. This considered, it is worrying that many organizations may be falling short when it comes to promoting best practices in line with HIPAA compliance and cyber security more generally, the surveyors concluded.

Other key survey findings include:

  • 65 percent of those who use a mobile device at work also use the same device for personal use.
  • More than half (52 percent) respondents say they have free reign over the applications they download and use at work.
  • Only a quarter of those who use mobile messaging at work use a secure solution.
  • One in five (17 percent) have sent or received PHI via mobile message, with names (24 percent), telephone numbers (19 percent) and email addresses (13 percent) the commonly shared identifiers.
  • 96 percent use at least one security measure to protect their device, however of those, one in five (18 percent) use one method only, most commonly passcode or PIN protection.

“We understand the challenges healthcare providers face when it comes to managing and exchanging PHI,” said Scrypt, Inc. CEO, Aleks Szymanski. “In an industry as closely regulated as healthcare, where the margin for error is minimal. It is essential that organizations invest not only in the best HIPAA-secure technology, but also in instilling a culture of security through appropriate training and education.”

Get the latest information on Health IT and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More

Topics

News

HIT Advisory Committee Advances Recommendations on Core Data Sets for Interoperability

The Health Information Technology Advisory Committee, a federal advisory committee to the Office of the National Coordinator for Health IT (ONC), voted Wednesday to approve nine recommendations to update the list of data elements that vendors must exchange to be considered interoperable.

ACP Study: Only 37 Percent of MIPS Measures Are Valid

A new study from the American College of Physicians Performance Measurement Committee rated as valid only 37 percent of the 86 Quality Payment Program measures for 2017 deemed relevant to ambulatory general internal medicine.

Intermountain Healthcare Launches Study to Unlock Genomic Data

Researchers from the Salt Lake City, Utah-based Intermountain Healthcare have announced a long-term prospective study that they think has the potential to help physicians and others unlock genomic data.

UNC Health Care Receives HIMSS Analytics Stage 7 Designation

UNC Health Care, an integrated health care system based in Chapel Hill, N.C., has achieved Stage 7 designation on the HIMSS Analytics’ Electronic Medical Record Adoption Model (EMRAM).

FDA Announces Plan to Advance Medical Device Safety and Cybersecurity

The Food and Drug Administration (FDA) has announced new proposals aimed at advancing medical device cybersecurity, including placing new responsibilities on manufacturers, both before and after their devices hit the market.

Black Book: 9 in 10 Small Practices Not Optimizing Advanced EHR Functionalities

Eighty-eight percent of small practices of six or less practitioners still aren't optimizing advanced EHR (electronic health record) tools such as patient engagement, secure messaging, decision support and electronic data sharing, according to the latest Black Book survey