Insider access to patient data top worry

KLAS report on security reveals challenges healthcare providers face
By Bernie Monegain
06:25 AM

Identity management and unauthorized data access by employees present the biggest threat to security and privacy of patient data, according to healthcare providers across the country.

Researchers from Orem, Utah-based KLAS  spoke with 106 providers to find out where they felt the most at risk for breaches and to see which third-party firms they were turning to for assistance.

The results are detailed in a new KLAS report, "Security and Privacy Perception 2014: High Stakes, Big Challenges," and they seem to line up with the findings in a recent healthcare security report from Verizon, which indicated that theft and loss of unencrypted devices were among the biggest security problems in healthcare.

The Verizon report revealed that the healthcare sector also recorded its second highest numbers for insider misuse, with 15 percent of healthcare security incidences attributed to insider misuse – higher than 13 other industries.
 
 

For the KLAS research, providers mentioned 46 different firms for security services. CynergisTek, Deloitte and Verizon were mentioned most often followed by Dell Services, Fortrex Technologies, Hayes Management Consulting, IBM and Santa Rosa Consulting. 

Healthcare IT consultants are offering fewer services than healthcare security service firms, according to the healthcare providers.

"We are hearing from providers that security and privacy concerns are becoming a part of their everyday discussions," said Erik Westerlind, the report's author, in a statement. "At this point, a market leader has yet to be established. As the stakes get higher, healthcare organizations are using multiple firms for their security and privacy needs to ensure they are covering all of their bases."

[See also: How Kaiser does privacy and security.]

The vendors in this study include Accuvant, Cerner, Check Point, Coalfire, CSC, Cylance, CynergisTek, Dell Services, Deloitte, Denim Group, Dixon Hughes Goodman, EY, FishNet Security, Forsythe, Fortrex Technologies, FRSecure, Gotham Digital Science, GreenPages, Hayes Management Consulting, HIPAA One, IBM, Info@Risk, Leidos Health, Netgain, PatchAdvisor, Pondurance, Presidio, Protiviti, PwC, Santa Rosa Consulting, Secure Healthcare Solutions, Siemens, Sword & Shield, Symantec, Technical Financial Solutions, Verizon, Walsh Consulting and Xerox.

Want to get more stories like this one? Get daily news updates from Healthcare IT News.
Your subscription has been saved.
Something went wrong. Please try again.