Skip to content Skip to navigation

Survey Paints Mixed Picture of Security Compliance for Healthcare Industry

January 22, 2014
by Gabriel Perna
| Reprints

 

According to a recent survey of IT managers, the healthcare industry has made considerable gains in security and compliance when compared to other sectors. 
 
The survey, from DataMotion, a Morristown, N.J.-based email encryption software and health information service provider (HISP), discovered that 90.4 percent of healthcare IT managers say their company has security and compliance policies for transferring files electronically. Approximately, 84 percent of respondents said their employees/co-workers have the capability to encrypt email and 86 percent are striving for full compliance. 
 
Overall, DataMotion found that healthcare was above other industries in terms of security and compliance. Still, the industry is not without faults, the survey revealed. For instance, 87.7 percent of respondents said their company permits the use of mobile devices for email, 40.3 percent report there is no bring your own device (BYOD) policy and 11.7 percent are unsure.
 
"It’s good to see improvements in security and compliance since last year, and healthcare has made significant gains, but serious problems remain and new ones have cropped up,” DataMotion’s Chief Technology Officer, Bob Janacek, said in a statement. “For healthcare specifically, there have been widely publicized incidents of mobile devices being lost or stolen that contain protected health information, potentially resulting in a HIPAA breach."
 
For the survey, DataMotion polled more than 400 IT and business decision-makers across the U.S. and Canada. Thirty-seven percent were from healthcare, the largest industry sampling. 
 
Topics

Comments

Thank you for the recap Gabriel. Did the survey mention anything about the number of healthcare facilities who have instituted policies to restrict access to sensitive patient data through the use of single sign-on or another data security method?

Didn't see anything on single-sign on. Did say more than a quarter in healthcare have used free consumer-type file transfer and only 30.5 percent have restricted those services. So I can't imagine that number is too high.

Thank you for the feedback Gabriel!

News

IBM Security: Healthcare Cyber Attacks Prevalent, but Less Records Breached in ’16

A new report from IBM Security found that healthcare—not too long ago the most attacked industry by cyber criminals—fell out of the top five of most breached industries.

FBI Notification: Cyber Criminals Targeting FTP Servers to Compromise PHI

The Federal Bureau of Investigation issued a warning that cyber criminals are actively targeting File Transfer Protocol (FTP) servers operating in “anonymous” mode and associated with medical and dental facilities to access protected health information (PHI).

Texas HIE Approved as CMS Qualified Registry

Healthcare Access San Antonio (HASA), a health information exchange (HIE) organization in San Antonio and surrounding Texas counties, has received clearance from the Centers for Medicare & Medicaid Services (CMS) to become a qualified registry.

Media Report: Evolent Health Exploring Merger with Advisory Board

Evolent Health, an Arlington, Va.-based healthcare technology provider, is exploring a potential combination with The Advisory Board, a Washington, D.C.-based healthcare consulting firm, according to a report from Reuters published on Friday.

Urology Austin Falls Victim to Ransomware Attack, Alerts 200K Patients

The Texas-based Urology Austin has acknowledged that it fell victim to a ransomware attack in January, and has since notified some 200,000 patients that their information might have been breached.

University of Maryland Medical System Earns HIMSS Stage 6 Recognition

The University of Maryland Medical System (UMMS), based in Baltimore, has achieved Stage 6 on HIMSS Analytics’ Electronic Medical Record Adoption Model (EMRAM) for the ambulatory environment.