News | Cybersecurity | August 20, 2019

New Report Examines Hospital Cybersecurity Challenges in Georgia

Report summarizes cybersecurity challenges faced by CIOs across the state, highlights recommended actions to protect patient data

August 20, 2019 — Healthcare data breaches are currently being reported at a rate of more than one a day, according to a new report from the nonprofit Institute for Healthcare IT (IHIT). And for those who think it can’t happen to them, the odds are not in their favor. Breaches reported between 2009 and 2018 have resulted in the theft or exposure of almost 190 million healthcare records, a number equal to 59 percent of the U.S. population, according to the HIPAA Journal.

A breach can be problematic for large hospitals with the resources and budget to survive a cyberattack, but it can absolutely devastate a smaller facility, and with it, the surrounding community. That thought started keeping Georgia Sen. Bruce Thompson awake at night a few years ago. He was the impetus behind a grassroots initiative that brought together hospital chief information officers (CIOs) statewide to research and discuss the magnitude of the problem along with measures to support cybersecurity. The efforts of Thompson and the hospital CIOs have been summarized in the new IHIT report, titled “The State of Cybersecurity Among Georgia Hospitals.”

“I learned that a fifth of the nation’s rural hospitals are near insolvency and at a high risk of closing, according to a recent Navigant analysis,” Thompson said. “If you want to watch a rural community die, kill its hospital. After Lower Oconee Community Hospital (Glenwood, Ga.) shut down in 2014, other mainstays of the community followed. The bank and the pharmacy shuttered, and the only grocery store in the county closed. On Main Street, building after building closed or fell into disrepair.”

Hospitals have become a popular target among hackers because the electronic healthcare record (EHR) is worth more than any other data on the black market. Medical records could be worth $1,000 each while social security numbers are just 10 cents and credit card numbers are worth 25 cents.

Beginning in October 2017 and continuing through 2019, Georgia hospital CIOs gathered to explore the issues and determine ways they could work together to make a difference. These meetings included hospital CIOs from across the state, with regional working groups pulling together small groups to discuss specific challenges and exchange ideas on ways to solve them.

Among the top issues were: 

  • Preventing phishing attacks; 
  • Maintaining legacy technology that was not built to withstand the sophistication and volume of today’s cybersecurity attackers; 
  • Managing the increasing number of third-party systems that require access to patient health information; 
  • Grappling with the shortage of IT security talent, especially in rural markets; and
  • Overestimating the protection afforded by cybersecurity insurance policies.

The IHIT report summarizes recommendations from the CIOs around two primary initiatives:  establish a healthcare-specific resource center offering Georgia hospitals and healthcare providers access to the most current cybersecurity tools and information; and establish regional online networks for IT Safe Zones where providers can confidentially share threat and incident response insights.

At the heart of the IHIT recommendations is the need to immediately mobilize both executive branch and legislative resources to prepare for the next cyberattack before it sinks a community hospital, and its community.

Calvin Rhodes, the CIO of the State of Georgia, has embraced the IHIT findings and is working with the hospital CIOs to identify ways to offer support. “We saw a real need to extend the cyber academy training developed for state employees to cities and counties in Georgia, and we want to encourage hospital participation as well. Georgia’s new state-of-the-art Cyber Center is serving companies ranging in size from start-ups to the Fortune 500.”

The state is also offering organizations access to a service that provides a seasoned information security officer who will work with an organization one or more days a week with a one-year commitment. “We’re looking to other states for best practices as well,” said Rhodes. “One item that a couple other states often speak to is the benefits of the formation of a volunteer cyber event response task force; in those states it required legislation that provides liability protection for not only the volunteers but also the companies that employ the volunteers.”

For more information: www.instituteforhealthcareit.org

Related Cybersecurity Content

PODCAST: 5 Low-Cost Ways To Slow Hackers

PODCAST: Hear and Now: How to Boost Cybersecurity in Medical Imaging

Agents of Change: Cybersecurity In A World Of Old And New

VIDEO: Cybersecurity in the Medical Imaging Department

 

Related Content

This study shows that thanks to deep learning analysis applied to digitized pathology slides, artificial intelligence can classify patients with localized breast cancer between high risk and low risk of metastatic relapse in the next five years.

Getty Images

News | Artificial Intelligence | September 22, 2021
September 22, 2021 — The RACE AI study conducted by Gustave...
To get more flexibility and cost savings from storage, healthcare organizations are increasing their investments in the cloud
Feature | Information Technology | September 15, 2021 | By Kumar Goswami
Healthcare organizations today are storing petabytes of medical imaging data — lab slides,...
Revenues for teleradiology reading service providers are forecast to follow a similar profile over this period.

Outlook for 2021 and Beyond. As displayed in the figure below, these six market drivers are projected to result in teleradiology reading service volumes increasing by 21% in 2021 and nearly doubling by 2025. Revenues for teleradiology reading service providers are forecast to follow a similar profile over this period.

Feature | Teleradiology | September 15, 2021 | By Arun Gill
The closely tied relationship between...
Cloud services have been utilized within healthcare organizations for more than a decade. Now with the growth of artificial intelligence (AI) it is very common to see organizations adopting cloud services.

Getty Images

Feature | Information Technology | September 14, 2021 | By Jef Williams
Figure 1: MWT Schematic of a typical setup for detecting malignant tissues/tumors.

Figure 1: MWT Schematic of a typical setup for detecting malignant tissues/tumors.

Feature | Radiology Imaging | September 14, 2021 | By Brendon McHugh
This certification, which covers Agfa HealthCare’s Class IIa Enterprise Imaging and XERO Viewer solutions, ensures that Agfa HealthCare can continue to deliver to customers innovative solutions that meet their real challenges and address their needs and requirements.
News | Enterprise Imaging | September 09, 2021
September 9, 2021 — Agfa HealthCare is proud to be one of the first companies to receive the new European Medical Dev
Insignia Medical Systems, a leading UK-based enterprise imaging provider, announced it has been acquired by Intelerad Medical Systems, a global leader in medical image management solutions. The deal signals an important step in expanding next-generation imaging solutions and resources to help modernise hospital trusts across the UK. 

Getty Images

News | Radiology Business | September 08, 2021
September 8, 2021 — Insignia Medical Systems, a leadi
Videos | Enterprise Imaging | September 03, 2021
ITN Editor Dave Fornell collected numerous examples of how...
Canon's Vitrea PACS enterprise imaging system was one of several systems demonstrated at HIMSS 2021 that had easily modified hanging protocols. This included ease of use to customize what each radiologists prefers, including slice thickness. #HIMSS #HIMSS21

Canon's Vitrea PACS enterprise imaging system was one of several systems demonstrated at HIMSS 2021 that had easily modified hanging protocols. This included ease of use to customize what each radiologists prefers, including slice thickness. Photo by Dave Fornell

Feature | Enterprise Imaging | September 02, 2021
Taking advantage of new technology advances, several ...