Addressing Security & Creating Stronger Passwords in Healthcare

2022-10-05 11:35:36
关注

How the Healthcare Sector Can Immunize itself from Hackers
Illustration: © IoT For All

One of the many permanent effects of the pandemic has been the shift to telehealth, telemedicine, and other connected technologies. This rapid pivot to digital service delivery for traditionally in-person services has expanded the threat landscape for cybercriminals, adding to the significant security headache with which hospitals and healthcare providers were already struggling. Let’s take a look at some of these security concerns, particularly for passwords, and what hospitals and healthcare providers can do.

'Connected health offers numerous benefits for patients and providers, but only if the latter gets a handle on the corresponding cybersecurity concerns.' -Michael GreeneClick To Tweet

Security Concerns in Healthcare

A recent report by the U.S. Department of Health and Human Services (HHS) found that the number of healthcare breaches in the first five months of 2022 nearly doubled from the same period last year. Ransomware is one of the growing threat vectors, with another study finding that 66 percent of healthcare organizations were hit by ransomware in 2021 compared to 34 percent in the prior year. 

But, there are also numerous new security concerns emerging with the increased adoption of digital health technologies. For example, the “State of Healthcare IoT Device Security 2022” found the following:

  • More than 50 percent of connected devices in the average hospital have critical security risks.
  • Nearly 75 percent of IV pumps have vulnerabilities that could negatively impact patient health if exploited.
  • Insecure passwords are the most common device risk.

In addition to these challenges, many healthcare organizations increasingly rely on mobile applications. These apps contain sensitive personal health details, representing yet another vulnerability that could lead to HIPAA breaches if not properly addressed. So, what’s the first step hospitals and healthcare providers can take to shore up these concerns? 

Creating Stronger Passwords

As mentioned above, numerous security vulnerabilities hinge on insecure, weak, or compromised passwords. That’s why the right identity authentication security strategy is essential to preventing threats and ensuring that only authorized personnel have access to systems. This helps protect against ransomware, criminal hacking, phishing, and password-based attacks. Healthcare organizations can deploy the following steps to help create stronger passwords.

#1: Multi-Factor Authentication

Adopting additional authentication measures like adaptive authentication and biometrics adds more layers of protection, reducing the risks of a password attack.

#2: Threat Intelligence Tools

These tools can automatically detect and prevent the use of compromised credentials. They are automated, which reduces the pressure on the IT team while improving security. By checking for exposed passwords before they are activated and monitoring them continuously, the risk of exposed passwords being used is removed. This approach stops systems from being an easy target for password-based attacks.

#3: Focus on Exposure

End the cycle of password resets. Don’t waste time and resources resetting passwords when the crux of the problem is exposure.

#4: Educate Employees

Healthcare providers must continually educate employees on password best practices. This can help instill better security hygiene and discourage the use of weak passwords, password reuse, and password sharing. Another simple step to alleviate password problems is to make every employee use a password manager before accessing any systems.

Handling Cybersecurity Concerns

Connected health offers numerous benefits for patients and providers, but only if the latter gets a handle on the corresponding cybersecurity concerns. It’s critical that healthcare organizations tighten up security across the board but also not overlook the basics like identity access management and securing the password layer. The success with which the industry rapidly rolled out digital offerings in response to the pandemic is a testament to how efficiently healthcare organizations can act in the face of urgency. It’s imperative that they harness this same resolve to tighten up security, otherwise, they face a never-ending barrage of attacks. 

Tweet

Share

Share

Email

  • Cybersecurity
  • Healthcare
  • IT and Security
  • Medical Devices
  • Privacy

  • Cybersecurity
  • Healthcare
  • IT and Security
  • Medical Devices
  • Privacy

参考译文
解决安全问题并在医疗保健中创建更强的密码
插图:© IoT For All → 新冠疫情带来的众多长期影响之一,就是向远程医疗(telehealth)、远程医学(telemedicine)及其他联网技术的转变。这一向传统上依赖线下服务的领域快速转向数字化服务,扩展了网络犯罪分子的威胁范围,并加剧了医院和医疗机构本已面临的重大安全挑战。让我们一起看看一些安全问题,特别是关于密码的问题,以及医院和医疗机构可以采取什么措施应对。“虽然连接式医疗为患者和医疗机构提供了诸多好处,但前提是后者能够妥善应对相应的网络安全问题。”——Michael Greene 点击推文 **医疗健康领域的安全问题** 美国卫生与公共服务部(HHS)最近一份报告指出,2022年前五个月的医疗健康数据泄露事件数量,相比去年同期几乎翻了一番。勒索软件是不断增长的威胁之一,另一项研究发现,2021年有66%的医疗机构遭受勒索软件攻击,而前一年只有34%。此外,随着数字健康技术的加速采用,也出现了许多新的安全问题。例如,2022年《医疗物联网设备安全状况》报告发现以下问题: - 平均一家医院中有超过50%的联网设备存在严重安全风险。 - 几乎75%的静脉注射泵存在漏洞,一旦被利用,可能会对患者健康造成负面影响。 - 不安全的密码是设备面临的最常见风险。 除了上述挑战,许多医疗机构正日益依赖移动应用程序。这些应用程序包含敏感的个人健康信息,如果未能妥善处理,还可能成为HIPAA违规的又一漏洞。那么,医院和医疗机构可以采取的第一步措施是什么? **创建更安全的密码** 如上所述,许多安全漏洞都与不安全、弱或已被泄露的密码密切相关。因此,制定正确的身份认证安全策略对于防止威胁至关重要,以确保只有授权人员才能访问相关系统。这有助于防范勒索软件、犯罪黑客攻击、网络钓鱼和基于密码的攻击。 医疗机构可以采取以下步骤来创建更安全的密码: **#1:多因素认证** 采用自适应认证和生物识别等额外的认证措施,可增加安全层级,从而降低密码攻击的风险。 **#2:威胁情报工具** 这些工具可以自动检测并阻止泄露凭证的使用。它们是自动化的,减轻了IT团队的压力,同时提升了安全性。通过在密码激活前检查是否已被泄露,并持续监控,可彻底消除泄露密码被利用的风险。这种方法可以有效防止系统成为基于密码攻击的易受攻击目标。 **#3:关注密码泄露** 打破频繁重置密码的循环。不要在问题核心在于密码泄露的情况下浪费时间和资源去重置密码。 **#4:培训员工** 医疗机构必须持续对员工进行密码最佳实践的培训。这有助于培养更好的安全习惯,并减少弱密码、密码重复使用和共享密码的行为。另一种缓解密码问题的简单方法是,要求所有员工在访问任何系统之前,都使用密码管理器。 **应对网络安全问题** 连接式医疗为患者和医疗机构带来了诸多好处,但前提是后者能够妥善应对相应的网络安全问题。医疗机构必须全面加强安全措施,同时也不能忽视身份访问管理和密码层保护等基础工作。 该行业在疫情爆发时迅速推出数字服务的成功,证明了医疗机构在面对紧急情况时能够迅速行动。他们也必须以同样的决心来加强安全措施,否则将面临不断来袭的攻击。 推文 分享 电子邮件 网络安全 医疗 健康 IT与安全 医疗设备 隐私 → 网络安全 医疗 IT与安全 医疗设备 隐私
您觉得本篇内容如何
评分

相关产品

Mettler-Toledo 梅特勒托利多 XP10002S DeltaRange 实验室天平

卓越加XP精密天平在受监管的环境中提供最大的安全性。触摸屏显示引导用户浏览应用程序,如果超出公差,则以颜色警告用户。创新的、内置的质量管理工具可为多达8个用户执行质量指导原则、管理密码和访问权限。由于免提操作和蓝牙无线数据传输,称量有毒物质变得比以往任何时候都更安全。

TC天诚 NB-700M NB物联网锁

NB-700M是江苏新巢天诚智能技术有限公司自主研制开发的一款针对B端场景化的人脸物联网锁,通过平台统一下发人脸、密码、IC卡(身份证)等数据来实现远程控制集中管理。开门记录、告警记录在保留人脸物联网锁锁端离线数据的同时实时传输到平台,提高使用过程的安全性和便利性。NB-700M是一款高安全性、高稳定性、高便捷性的人脸物联网锁,开放接口支持与第三方系统无缝对接。

TelephoneStuff.com 201550 耳机

BlueParrott B100蓝牙耳机功能:-距离底座75英尺(请参阅用户指南以最大限度地扩大范围)-专业噪音消除麦克风-耳机控制包括音量、开/关、呼叫应答、呼叫结束、配对,和静音-安全性:128位数字加密在无线通信过程中提供气密的安全性-还与蓝牙技术兼容,密码设置为0000-允许所有等待和三方通话-通话时间长达6小时,无需充电-待机时间:最长100小时-音质等于或比任何耳机、无绳或有线电话都好 Blueparrot Base功能:-兼容所有家庭无绳电话和有线电话

OMRON Industrial Automation 欧姆龙工业自动化 E5EN-R3MT-500-N AC100-240 温度控制器

增强的安全性â€\用户可选密码输出类型=继电器供电电压=100-240 V ac尺寸=48 x 96mm输出数量=3最小工作温度=-10°C最大工作温度=+50°C范围=-200-+2300(热电偶)°

Flowline 氟莱 LI25-2001 料位控制器

安全、密码保护的非易失性内存,确保参数保持不变输入数量=1安装样式=DIN导轨安装,面板安装供电电压=12-30 V dc总长度=119mm总宽度=62mm总深度=96mm最低工作温度=-40°C最高工作温度

SICK 西克 PBS-RB010SG1SSNAMA0Z 压力传感器

PBS压力传感器的特点包括:开关点和复位点(滞后)、开关延迟、最小/最大内存和密码保护,以防止意外的错误调整。必须采用紧凑的设计。可旋转外壳,安装灵活。两个开关输出(PNP或NPN)的标准配置。操作简单安全,设有三个大按钮,显示清晰。

PMA STB55-1000-000 温度控制器

安全温度限制器stb55用于需要监测热过程的任何地方,并且在发生故障时,电厂切换到安全状态。•操作员锁(密码保护)。•夹在顶帽DIN导轨上。

Dwyer Instruments 德威尔 16A2010 温度控制器

有四个安全级别的密码保护。可选择开关、P、PI或PID手动调优控制功能或控制器自动调优,以达到最佳PID控制效果。\ n16a在工艺和温度控制方面提供最具价值的标准功能。

Ludeca, Inc. VIBXPERT® 振动测量和分析仪

VIBXPERT配有一个便携袋,安全起见,它有一个可分离的肩带。VIBXPERT基本平台为单通道设备,可通过特殊密码升级至2个单独配置的通道。此升级不需要更改硬件。

Visual Sound ne4400 音频放大器和前置放大器

无前面板控制和密码访问的多级软件安全保证您的音频系统防篡改。

评论

您需要登录才可以回复|注册

提交评论

广告

iotforall

这家伙很懒,什么描述也没留下

关注

点击进入下一篇

影响卫星物联网连接状态的关键进展

提取码
复制提取码
点击跳转至百度网盘