Skip to main content

Australia’s healthcare data security is sick – but there is a cure

If you ever want to find out what sorts of data cyber-criminals are targeting, there's a simple rule; follow the money. And some of the most valuable commodities threat actors are looking for comes from the healthcare sector. As hospitals, medical practitioners and allied health professionals digitise more of their systems and workflow, and people use more wearable devices to monitor and improve their health, the amount of data that is being exposed is growing.

In Australia, the Office of the Australian Information Commissioner (OAIC) publishes a report every six months detailing the most common types of data breaches and which sectors are targeted. Health service providers reported the most breaches in the latest report, and that number has risen for every period the report has been issued. Almost half of those breaches were the result of malicious activity or criminal acts, according to the OAIC.

Right across the Asia Pacific region, we are seeing attacks that specifically attack the healthcare sector. There have been several attacks in Singapore, with one even exposing the Prime Minister's health data. The WannaCry malware continues to be an issue and healthcare data is now readily available over the dark web.

Australians' confidential medical data can be purchased on the dark web.

Healthcare industry ‘not keeping up’

The old school approach to business IT security – ensuring end-point protection is up to date and there's a firewall in place – is no longer good enough. Cyber incidents, where threat actors are able to bypass security controls account for more than half of the reported breaches in 2019, with the remainder spilt almost evenly between the theft of data storage devices and paperwork, and rogue employees.

Putting all this together, we are seeing the digitisation of healthcare is occurring faster than the sector's ability to protect the valuable information it creates and holds.

At a recent event, Stephan Neumeier, Managing Director for Asia Pacific at Kaspersky, said that, "Data is sick. Confidential medical records being breached and advanced devices turning a human into a bionic man. These ideas have since crossed the bridge between fictional stories and our physical world. They are well within our reality. As rapid digitalisation penetrates the healthcare sector, cybercriminals are seeing more opportunities to attack this lucrative and critical industry."

Stolen medical records openly sold on the dark web

When we follow the money in any industry – and cybercrime is one of the most profitable industries on the planet – we find there are marketplaces where skills and information are traded. Senior Security Researcher from GReAT Korea, Seongsu Park recently presented at a cybersecurity forum and discussed an Australian-based dark web seller called Ausprdie. This platform trades in medical data. 

Park said medical records can be considered more valuable than a simple credit card because a hospital generally requires a patient’s personal and financial credentials before a check-up or an admission. Those online forums are even advertising in order to access confidential medical data. And those breaches, like the fallout from a nuclear incident, can have long-term repercussions.

Stephan Neumeier, Managing Director of Kaspersky APAC, explained that the dangers of healthcare IT hacks were making cautionary science-fictional concepts into a reality at the recent Cybersecurity Weekend in Myanmar.

How the industry can better protect itself

With such a well-organised adversary, it's important to take a forward-looking posture when planning a defence. Hoping that a "walls and moats" approach will be sufficient is not enough. Attackers use tactics such as phishing attacks, where a large volume of emails are sent containing fraudulent instructions that seek to dupe people into giving up log in data or other valuable information. Or, they can take a more focussed approach, where they try to trick someone with a higher level of data access to hand over information – a targeted tactic called spear-phishing. As we know from the OAIC's data, malicious insiders are also a major challenge.

Rather than trying to block all the possible attacks it's important to actively seek threats that may already be inside the network. That means having tools that actively seek potential threats that are already inside your firewall. For healthcare providers, this means looking for unusual activity. For example, detecting when something like a blood test report is being sent to an x-ray technician. This could indicate that an email account has been compromised, as that type of data is not usually shared between those two parties.

New methods for breaching systems, often called attack vectors, are constantly being created by criminals. Trying to keep up with the latest types of attacks is not easy, but there are threat feeds and other types of intelligence from external parties that not only keep healthcare providers informed, but help them detect when the risk of a new type of attack is rising so that appropriate counter-measures can be put in place.

Rather than waiting to become a victim, hospitals, doctor's offices and other healthcare facilities can get on the front foot and hunt for threats before they escalate and become cyber incidents.

Protecting healthcare data is about more than ensuring data is as well-protected as possible when it's at rest and when it's in transit. It's about proactively looking for where the risks are, then taking active steps to mitigate those potential losses and any unauthorised access.

As it stands today, the healthcare sector is lagging as security pays catch up with the digital transformation effort. By taking a forward-looking approach, where risks are constantly assessed and mitigation strategies are put in place, the sector can move forward.

Kaspersky is a global leader in cybersecurity for both consumer and business users. To discover how it’s helping healthcare providers protect their critical data, click here.



from TechRadar - All the latest technology news https://ift.tt/2oNitpH

Comments

Popular posts from this blog

The future of Magic Leap's promising AR efforts dim after layoffs

The Magic Leap Two is now further away than ever, unfortunately. Today in a blog post the augmented reality pioneer announced major layoffs and has decided to cut up to half of its workforce, according to some reports. The original Magic Leap One was supposed to be one of the first mainstream augmented reality headsets when it launched in 2018, but a high price point and lack of interest from developers left the headset high and dry after launch. According to the blog post, Magic Leap says it will be focusing its efforts on enterprise solutions (a statement HTC has made recently as well) and shift its focus away from consumer technology… at least for the time being.  The company has been open about creating a second headset that would offer improved specs for some time, but how that work will now have to go forward without half of the team , according to some estimates, remains to be seen. Is the window closing on augmented reality?  Although it’s just one company, Magic...

Airship acquires SMS commerce company ReplyBuy

Airship is announcing that it has acquired mobile commerce startup ReplyBuy . The startup (which was a finalist at TechCrunch’s 1st and Future competition in 2016) works with customers like entertainment venues and professional and college sports teams to send messages and sell tickets to fans via SMS. It raised $4 million in funding from Sand Hill Angels, Kosinski Ventures, SEAG Ventures, Enspire Capital, MRTNZ Ventures and others, according to Crunchbase . Airship, meanwhile, has been expanding its platform beyond push notifications to cover customer communication across SMS, email, mobile wallets and more. But CEO Brett Caine said this is the first time the company is moving into commerce. While sports and concerts tickets might not be a booming market right now, Caine suggested that the company is actually seeing increased purchasing activity “in and around the Airship platform” as businesses try to drive more in-app purchases. He also suggested that both the COVID-19 pandem...

Du offers new roaming bundle for summer

UAE-based telecom operator du is offering roaming bundle for travelers valid for seven days. The summer bundle features unlimited calling and 2.5GB of data to 174 destinations - all from their own UAE number. Priced at AED 300 (per week) this latest addition to du’s roaming bundles will be available for customers travelling to 174 countries, including GCC countries, UK, US, European destinations, and Egypt, starting from May 30. The postpaid mobile subscribers can subscribe to the roaming bundle by sending the SMS U to 5102. Fahad Al Hassawi, Deputy CEO – Telco Services at EITC, the parent company of du, said that the roaming bundle will enhance the subscribers’ connectivity while travelling overseas and minimise their current pain points. Etisalat doubles internet speeds for eLife Unlimited subscribers from TechRadar - All the latest technology news http://bit.ly/2KbK1O8