Healthcare Software Security Assessed by BSIMM Study
Aetna, ANDA, McKesson, The Advisory Board Company, Siemens and Zephyr Health have all been assessed as part of the latest Building Security in Maturity Model (BSIMM) study, published yesterday, with healthcare software security discovered to be well behind other industry sectors. This is the first time that healthcare firms have been assessed by the study, which looks at 12 different software security practices. The study assesses enterprise software security development, which for the healthcare industry is severely lagging behind other industries in all 12 of the software security practices tested. This is the first time in the history of the study that one industry has performed so consistently poorly, and has come bottom of the list in all of the security practices tested. The main industries assessed as part of the study were healthcare, the financial services, consumer electronics organizations and independent software companies, as well as a smaller number of organizations from the insurance, retail and telecoms industries. The results of the BSIMM study give organizations...
Kaspersky Labs Report Probes Security Attitudes Among BYOD Participants
The rise in popularity of mobile devices has seen many companies adopt a Bring Your Own Device (BYOD) scheme. According to a recent survey by Kaspersky Labs, over half of consumers are now using their own mobiles, laptops and tablets at work and take part in such a scheme. Due to the benefits of BYOD schemes, they have now been adopted by many HIPAA-covered entities, although the strict regulations covering data privacy and security have, to a certain extent, restricted use of the devices for work purposes more than in other, less well regulated industries. A Lack of Concern for Work Data The latest Kaspersky BYOD survey may have shown BYOD schemes have been widely adopted in the United States, but organizations operating such a scheme must effectively deal with the cybersecurity risks the schemes can introduce. While operators of the schemes may address security issues, not all organizations have fully assessed the risks posed by the devices. Furthermore, it would appear that many participants in BYOD schemes are not particularly concerned about data security. Only 10% of...
Is the Risk of Cyberattacks Really Increasing? Study Says No
The Department of Health and Human Services’ Office for Civil Rights breach portal lists all of the self-reported healthcare data breaches submitted by HIPAA covered entities, for all data-exposing security incidents, including hacks. A look at the headlines would suggest hackers are gaining access to patient data with increasing regularity, as malicious attacks on healthcare networks are widely reported in the media. When hacking incidents do occur, they tend to be headline news as they often involve the exposure of vast quantities of data. So far in 2015, multi-million-record data breaches have been suffered by a number of healthcare providers, health plans and Business Associates of covered entities, but is the risk of cyberattacks actually increasing? A recent study conducted by the University of New Mexico’s Department of Computer Science suggests that despite a number of major healthcare cybersecurity breaches being reported in 2014 and 2015, the risk of cyberattacks occurring has actually changed very little over the past decade, and that we are perhaps not actually in as...
New Cybersecurity Bill of Rights Announced by NAIC
The National Association of Insurance Commissioners (NAIC) has chosen National Cybersecurity Awareness month to announce a new bill of rights aimed at protecting consumers, which sets new standards for insurers to follow, and protects subscribers whose personal information is exposed in an insurance data breach. The new cybersecurity bill of rights has been summarized in a PDF file which is available for viewing and download on the NAIC website. The document outlines the rights of consumers following a data breach that exposes personal information. While the new bill of rights has now been made available, how it is applied may actually vary depending on where insurance consumers live, as consumer rights will still be governed by data breach laws in each state. Monica J. Lindeen, the Montana Insurance Commissioner and current NAIC president, spoke of the new bill of rights earlier this month. “Cybersecurity is one of the biggest challenges facing businesses today and this is one of our association’s key priorities,” she went on to say, “Our commitment to strengthening the...
Android Smartphone Security Continues to Cause Concern
How Secure is an Android Smartphone? Android Smartphone security continues to cause concern, even after Google’s decision to start issuing monthly security updates for the Android platform. Fears about Android device security were not alleviated by a new University of Cambridge (UK) study (partially funded by Google) which suggests that despite the new monthly security updates, 87.7% of Android Smartphones contain at least one critical security vulnerability. Study Confirms Serious Android Smartphone Security Issues The study involved researchers collecting version numbers and build numbers of over 20,400 devices, via the Device Analyzer App available through Google Play Store. Each phone was also tested against 13 known “critical” security vulnerabilities. The study looked at different Android mobile phone manufacturers and assessed the security of the devices, revealing there are considerable differences in the degree of protection offered to users. Each manufacturer was assigned a security score by the research team, the calculation of which involved an analysis of a number of...



