Clearwater Says New National Survey Findings A ‘Wake-up Call’ for Health System Cybersecurity
CHIME HealthCare’s 2018 Most Wired Survey Cites Profound Need for Foundational Security and Disaster Recovery Measures
“Due to a growing number of internal and external security threats, it has become increasingly more difficult for healthcare organizations to protect their sensitive information, including patients’ personal health information,” according to CHIME HealthCare’s Most Wired: National Trends 2018 report issued today during the annual
“The question every board of directors and executive leadership team should be asking themselves is, have we done a sufficient risk analysis, and if not, why not?” said Staynings. “In our own analysis of the past 57 OCR settlements involving a breach of electronic protected health information, in 88 percent of the cases, the healthcare organization failed to do a sufficient risk analysis. That’s pretty mind boggling.”
The Anthem data breach, affecting nearly 79 million people, is the largest ever reported, and statistics show healthcare breaches are on the rise, with 277 breaches through the first nine months of 2018, compared with 271 during the same period the year before. Most breaches stemmed from hacking or “IT incidents,” according to the
While Most Wired found most respondents have taken at least one step toward an incident-response plan (97 percent said they have a documented EHR-outage prodecure, for example), only 29 percent reported having a comprehensive cybersecurity program in place, just 26 percent surveyed said they had adopted all 10 critical components of an incident response plan, while 43 percent had adopted 7-9 components, and 31 percent reported adoption of fewer than seven.
“Before provider organizations can achieve outcomes with their strategies for population health management, value-based care, patient engagement, and telehealth, they must first ensure that foundational pieces such as integration, interoperability, security, and disaster recovery are in place,” the CHIME report concluded.
The annual Most Wired survey is designed to identify and recognize healthcare organizations that exemplify best practices through their adoption, implementation and use of information technology. This is CHIME’s first year to oversee the Most Wired program since acquiring it from the
This year’s research added a new emphasis on measuring key areas to help identify gaps in healthcare organizations’ technology adoption and strategies and to highlight areas in which the industry has opportunities to make progress. The key areas that emerged from this year’s research were:
- Foundational Technologies:
- Integration and Interoperability
- Security and Disaster Recovery
- Transformational Technologies:
- Population Health Management and Value-Based Care
-
Patient Engagement and Telehealth
Clearwater has long been a leader in cyber risk management solutions, and its founder and executive chairman,
Chaput’s chapter includes practical advice and analytical tools for use in organizational compliance and cyber risk management programs in addition to a timely and thorough analysis.
The chapter includes topics such as:
- What constitutes an OCR-quality risk analysis
- Jump-starting an effective cyber risk management program
- The consequences of an inadequate risk analysis
- Critical building blocks for a comprehensive, enterprise-wide information risk management program
- Three pillars of HIPAA compliance
- Governance
- Most common risk analysis mistakes
- A case study:
St. Joseph Health
The chapter addresses the misconception that compliance risk management and cyber risk management are synonymous. Chaput explains the differences between the two, and gives healthcare organizations the information they need to evaluate where gaps may exist in their compliance and cyber risk management programs. The chapter focuses on what is involved in a comprehensive risk analysis, and offers actionable steps an organization can take to move toward a comprehensive information risk management program.
“Compliance risk management is a critical component of any healthcare organization’s overall risk management program,” said Chaput. “Yet, compliance is only one part of a much bigger information risk management picture. Cyber risk management takes a more complete look at an organization’s information assets, threats and vulnerabilities than compliance risk management does.”
The 2019 Edition of the book can be purchased from
About Clearwater
Clearwater provides the most complete and trusted, enterprise-class cyber risk management solution available. Designed for healthcare providers and their partners, Clearwater’s IRM|Pro™ platform and experienced professional services team provide insights and actions to address compliance, cyber and patient safety risks. Clearwater is a 2017 Inc. 5000 fastest-growing company, the 2018 Best in KLAS winner in Cybersecurity Advisory Services, the 2017 and 2018
View source version on businesswire.com: https://www.businesswire.com/news/home/20181031005243/en/
Clearwater
[email protected]
Source: Clearwater
A.M. Best Affirms Credit Ratings of The Travelers Companies, Inc. and Its Main Subsidiaries
Obamacare enrollment begins Nov. 1: NJ residents should know these 3 things
Advisor News
Annuity News
Health/Employee Benefits News
Life Insurance News