This page contains a Flash digital edition of a book.
Healthcare’s Slack Security Costs $


WRITTEN BY ERIN MCCANN I


F you’re shirking your security systems’ obligations all to save a few pennies, better think


again. Chances are, it will end up costing much more down the road— a whopping $1.6 billion more. Most healthcare organizations


nationwide, some 61 percent to be exact, reported a security related incident in the form of security breach, data loss or unplanned downtime at least once this past year, according to a new health IT report by MeriTalk, a public-private organization working to improve government information technology.


The Rising Costs of Security Breaches These security events cost U.S.


hospitals an estimated $1.6 billion each year. Breaking it down by incident, hospitals should expect to hand over on average $810,000 per security breach, which occurs at nearly one in five healthcare organizations nationwide. The bulk of those security breaches,


58 percent, result from malware and viruses; outsider attacks account for 42 percent; and physical security, which includes equipment loss or theft, accounts for 38 percent.


Hardware Failure, Data Loss, and Unplanned Outages It’s not just the breaches,


however, that are costing healthcare organizations some serious cash. It’s also hardware and software failures that can result in big time data loss and unplanned outages. Data loss has affected nearly one


in three healthcare organizations this past year, costing on average $807,571 per incident. The biggest culprits? Hardware failure at 51 percent; loss of power at 49 percent; and loss of backup power at 27 percent. What’s more is providers know


they’re not prepared. Most are even confident they won’t be able to restore 100 percent of the data required by SLAs following an emergency. The majority—82 percent—say their technology infrastructure is not fully prepared for a disaster recovery incident. Resultantly, some are working to change that.


The Long Road to Compliance “Healthcare organizations are


making significant IT investments to transform IT infrastructure and ensure that patient information is secure, protected and highly available,” said Scott Filion, General Manager, Global


26 CONNECTION/HEALTHCARE IT 2014.Q2


Healthcare at EMC Corporation—the report underwriter—in a Feb. 3 statement. “Healthcare organizations have always focused on information security, but today they must do more to protect data and ensure accessibility to meet ARRA HITECH HIPPA requirements.” Despite these report findings, only


a moderate number of healthcare organizations indicated they are taking the necessary steps to prepare and prevent security events in the future. For instance, only 42 percent said they were moving forward with encryption initiatives, and 44 percent said they were getting single sign-on and authentication for Web-based applications and portals. Moreover, despite the uptick in


HIPAA privacy and security breaches this past year in addition to HHS’ Office for Civil Rights Director Leon Rodriguez promising a comprehensive audit program in 2014, only 32 percent are moving forward with security analytics to help with breach prevention.


ABOUT THE AUTHOR Erin McCann is Associate Editor at Healthcare IT News. She covers healthcare privacy and security, meaningful use, ambulatory care, and healthcare policy.


1.6B


Page 1  |  Page 2  |  Page 3  |  Page 4  |  Page 5  |  Page 6  |  Page 7  |  Page 8  |  Page 9  |  Page 10  |  Page 11  |  Page 12  |  Page 13  |  Page 14  |  Page 15  |  Page 16  |  Page 17  |  Page 18  |  Page 19  |  Page 20  |  Page 21  |  Page 22  |  Page 23  |  Page 24  |  Page 25  |  Page 26  |  Page 27  |  Page 28  |  Page 29  |  Page 30  |  Page 31  |  Page 32  |  Page 33  |  Page 34  |  Page 35  |  Page 36