A survey on risk-based security management in the healthcare and pharmaceutical industries was conducted in April 2013 by IT security product firm Tripwire with the Ponemon Institute
The health and pharmaceutical industries have undergone significant information security changes in 2013 in the US, and Health Insurance Portability and Accountability Act (HIPAA
Findings include:
70 percent say communicating the state of security risk to senior executives is not effective because communications are contained in one department or line of business.
Only 52 percent use formal risk assessments to identify security threats.
Only 58 percent have fully or partially deployed change control and security configuration management.
Dwayne Melancon, chief technology officer for Tripwire, said: “It is true that healthcare organizations rank better than average in some areas of this survey, but there is still a lot of room for improvement. About half of healthcare and pharmaceutical organizations are not using any kind of formal risk assessments, and they are also far less open to challenging current assumptions. Both of these factors could cause them to be blindsided by the increasing number of cybersecurity threats to their businesses.”
For more information about this survey, visit http://www.tripwire.com/ponemon/2013/