際際滷

際際滷Share a Scribd company logo
Information
Security in
Health Sector
Dr. Lasantha Ranwala
MBBS, MD  Health Informatics
Cert. in Ethical Hacking & Cyber Forensic
Senior Registrar in Health Informatics
Why Information
Security for
Health Care???
Health information security 1 overview
2018 Cost of a
Data Breach
 Source: IBM/Ponemon
Data
Breaches
Complete health insurance
credentials can be sold for 10 to
20 times more than a U.S. credit
card on underground markets 
- Dell Secure Works.
Health Sector
is one of main
the targets for
Hackers
What causes the
data breach?
Main Cyber
Security Risks
In Healthcare
Limited spending on cyber security
High demand for medical records
in the black market
Ransomware
Bring Your Own Device (BYOD)
policy
Employee negligence
Why
Healthcare
data so
valuable?
 Difficult to replace :
 Credit card information has a relatively
short shelf life, with new cards
 but health organizations often have
complete profiles of people including
Social Security numbers and medical
health information that is much more
difficult / not possible to change.
 Health data breaches is often not caught as
quickly as financial fraud
 Life threaten conditions Eg: if your records
are contaminated by someone else's
information -different blood group,
 Irreversible - If Information about mental
health or HIV treatments could be made
public, and there's no way to make it
private again
Common
Attack types
in Health
Sector
WannaCry Attack in 2017
Source : https://phys.org/news/2017-05-alarm-global-ransomware.html
Challenges in
Health
information
Security
Multiple stakeholders
 Medical Staff
 Paramedical Staff
 Administrative Staff
 Supportive services
 3 party suppliers
 IT service providers
 Health insurance providers
Multiple data types
 Plain text
 Images
 Audio
 Video
High Sensitivity
Lack of Awareness
Lack of Policies
 Ex: data storage location/ storage capacity /data
decomposition
Lack of Legislations

More Related Content

Health information security 1 overview