<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>hacking Archives - InnoHEALTH magazine</title>
	<atom:link href="https://innohealthmagazine.com/tag/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>https://ec2-3-6-81-159.ap-south-1.compute.amazonaws.com/tag/hacking/</link>
	<description>India&#039;s first magazine on healthcare innovations</description>
	<lastBuildDate>Thu, 27 Jun 2019 07:27:18 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://innohealthmagazine.com/wp-content/uploads/2017/11/innohealthmagazine-favicon.png</url>
	<title>hacking Archives - InnoHEALTH magazine</title>
	<link>https://ec2-3-6-81-159.ap-south-1.compute.amazonaws.com/tag/hacking/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">139068796</site>	<item>
		<title>Cybersecurity Business Evangelist</title>
		<link>https://innohealthmagazine.com/2019/in-focus/theme/cybersecurity-business-evangelist/</link>
					<comments>https://innohealthmagazine.com/2019/in-focus/theme/cybersecurity-business-evangelist/#respond</comments>
		
		<dc:creator><![CDATA[InnoHEALTH Magazine]]></dc:creator>
		<pubDate>Thu, 27 Jun 2019 07:27:18 +0000</pubDate>
				<category><![CDATA[Theme]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[business evangelist]]></category>
		<category><![CDATA[cloud threats]]></category>
		<category><![CDATA[cyber threat]]></category>
		<category><![CDATA[cyber threat protection]]></category>
		<category><![CDATA[cyber vulnerabilities]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[Data collection]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[healthcare data]]></category>
		<category><![CDATA[healthcare data breach]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[malware attack]]></category>
		<category><![CDATA[medial device]]></category>
		<category><![CDATA[network access]]></category>
		<category><![CDATA[operating system]]></category>
		<category><![CDATA[patient data]]></category>
		<category><![CDATA[Personal health information]]></category>
		<category><![CDATA[personal indentifiable information]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[phishing attack]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[social security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[WannaCry]]></category>
		<guid isPermaLink="false">https://ztt.nrm.mybluehostin.me/innohealthmagazine?p=6227</guid>

					<description><![CDATA[<p>Healthcare data breaches have risen nearly every year from 2010 through 2019 and the cybersecurity risks jeopardize hundreds of millions of patients records.</p>
<p>The post <a href="https://innohealthmagazine.com/2019/in-focus/theme/cybersecurity-business-evangelist/">Cybersecurity Business Evangelist</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[
		<div id="fws_69aa7ec282da4"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row top-level"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><a href="https://innohealthmagazine.cominnovatiocuris/disha-act/">Healthcare data breaches</a> have risen nearly every year from 2010 through 2019 and the cybersecurity risks jeopardize hundreds of millions of patients records. Although physical theft used to be the data breach method of choice, now hacking has become the most prevalent method. This partly stems from more information being stored electronically and network servers becoming a more attractive hacking target.</p>
<p style="text-align: justify !important;">However, much like the rest of the world, healthcare organizations are shifting work to cloud services in order to improve accessibility and patient care. The migration of these workloads and moving valuable information such as PHI (personal health information) and PII (personally identifiable information) to the cloud has also led to cyber criminals taking a particular interest in the industry. Having shifted workloads to the cloud, healthcare organizations have highly connected systems that run the risk of being deeply affected even if the attack takes place on smaller,partial systems. In other words, a <a href="https://innohealthmagazine.comcybersecurity/the-vulnerability-of-medical-institutions-to-cyber-attacks/">cyber attack</a> in one place could bring down the entire system. In May2017, the <a href="https://innohealthmagazine.comissues/ransomware-epidemic/">WannaCry ransomware</a> attack forced multiple hospitals across the United Kingdom to turn away ambulances transporting patients and cancel surgeries that were within minutes of starting. Even basic processes like admitting patients and printing wrist bands were compromised.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec28484b"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;">The number of <a href="https://www.akamai.com/us/en/resources/what-is-ransomware.jsp?gclid=EAIaIQobChMIjbe_nYuJ4wIVQ5SPCh0vogWXEAAYASAAEgIsu_D_BwE&amp;ef_id=EAIaIQobChMIjbe_nYuJ4wIVQ5SPCh0vogWXEAAYASAAEgIsu_D_BwE:G:s&amp;utm_source=google&amp;utm_medium=cpc">ransomware</a> and other malware attacks is rising incredibly fast in the healthcare industry, putting human lives as well as critical data at risk.One of the key aspects making healthcare organizations a top target is the value of their data. Commonly, a single stolen credit card number yields an average $2,000 profit and quickly becomes worthless. Healthcare data, however, such as PHI or PII, is extremely valuable on the black market.</p>
<p style="text-align: justify !important;">A single PHI file, for example, can yield a profit of up to $20,000. This is mainly because it can take weeks or months for a healthcare data breach to be discovered, enabling cyber criminals to extract much more valuable data. Moreover, because healthcare data can contain dates of birth and Social Security numbers, it is much more difficult or even impossible to change, so thieves can take advantage of it fora longer period of time.</p>
<p style="text-align: justify !important;"><img fetchpriority="high" decoding="async" class="size-full wp-image-6236 aligncenter" src="https://innohealthmagazine.comwp-content/uploads/2019/06/cyber-security-business-evangelist-2.png" alt="cyber security business evangelist 2" width="570" height="369" srcset="https://innohealthmagazine.com/wp-content/uploads/2019/06/cyber-security-business-evangelist-2.png 570w, https://innohealthmagazine.com/wp-content/uploads/2019/06/cyber-security-business-evangelist-2-300x194.png 300w" sizes="(max-width: 570px) 100vw, 570px" /></p>
<p style="text-align: justify !important;">Data breaches cost the healthcare industry approximately $5.6 billion every year, according to Becker’s Hospital Review. The Breach Barometer Report: Year in Review additionally found that there was an average of at least one health data breach per day in 2016, attacks that affected more than 27 million patient records.</p>
<p style="text-align: justify !important;">The continued under investment in cybersecurity has left many so exposed that they are unable to even detect cyber attacks when they occur. While attackers may compromise an organization within a matter of seconds or minutes, it often takes many more weeks – if not months – before the breach is detected, damage is contained and defensive resources are deployed to prevent the same attack from happening again.</p>
<p style="text-align: justify !important;">As organizations seek to protect their patient information from these growing threats, demand for health informatics professionals who are familiar with the current state of cybersecurity in healthcare is on the rise.</p>
</div>



<div class="img-with-aniamtion-wrap center" data-max-width="100%" data-max-width-mobile="100%" data-shadow="none" data-animation="fade-in" >
      <div class="inner">
        <div class="hover-wrap"> 
          <div class="hover-wrap-inner">
            <img decoding="async" class="img-with-animation skip-lazy" data-delay="0" height="312" width="572" data-animation="fade-in" src="https://innohealthmagazine.com/wp-content/uploads/2019/06/cyber-security-business-evangelist-1.png" alt="cyber security business evangelist 1" srcset="https://innohealthmagazine.com/wp-content/uploads/2019/06/cyber-security-business-evangelist-1.png 572w, https://innohealthmagazine.com/wp-content/uploads/2019/06/cyber-security-business-evangelist-1-300x164.png 300w" sizes="(max-width: 572px) 100vw, 572px" />
          </div>
        </div>
        
      </div>
    </div>
			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec288afd"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p>“So, What is Wrong With the Picture?”</p>
<p style="text-align: justify !important;">The base question to ask is “Who would be interested in hacking patient data?” It is precisely this attitude together with the rat eat which healthcare refreshes its technology that exposes healthcare organizations to a high risk of cyber-attack. The fact that makes the industry appealing to hackers: ransom for money;denial of service for malice and money; stealing confidential data;compromising data; identity theft and compromising devices. The scale of disruption and impact to busy healthcare settings already operating at capacity caused by a cyber-attack needs no explanation. The reality covers the four main domains:</p>
<ul>
<li>Leadership: Ownership of the issue</li>
<li>Culture/Staff responsibility/awareness: Training and awareness of cybersecurity and its related implications</li>
<li>Policies and procedures: Understanding of business continuity processes and incident response procedures</li>
<li>General cybersecurity knowledge: Use of fundamental security processes that are currently followed within the organization to mitigate security breaches, e.g., use of USB, on- and off-boarding processes, password policies,organizational asset register,and so on.</li>
</ul>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec28cbff"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>The Challenges</strong><br />
The newest cyber vulnerabilities are not necessarily an organization’s biggest cyber threat. Consequently, many common threats continue to be problematic in healthcare, including:</p>
<ul>
<li><strong><em>Malware and ransomware:</em></strong> Cyber criminals use malware and ransomware to shut down individual devices, servers or even entire networks. In some cases, a ransom is then demanded to rectify the encryption.</li>
<li><strong><em>Cloud threats:</em></strong> An increasing amount of protected health information is being stored on the cloud. Without proper encryption, this can be a weak spot for the security of healthcare organizations.</li>
<li><strong><em>Misleading websites:</em></strong> Clever cyber criminals have created websites with addresses that are similar to reputable sites. Some simply substitute .com for .gov, giving the unwary user the illusion that the websites are the same.</li>
<li><strong><em>Phishing attacks:</em></strong> This strategy sends out mass amounts of emails from seemingly reputable sources to obtain sensitive information from the users.</li>
<li><strong><em>Encryption blind spots:</em></strong> While encryption is critical for protecting the health data, it can also create blind spots where hackers can hide from the tools meant to detect breaches.</li>
<li><strong><em>Employee error:</em></strong> Employees can leave healthcare organizations susceptible to attack through weak passwords, unencrypted devices and other failures of compliance.</li>
</ul>
<p>Another growing threat in healthcare security is found in medical devices. As pacemakers and other equipment become connected to the internet, they face the same vulnerabilities as other computer systems.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec28e055"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>How are Hackers Achieving this, You Would Ask?</strong></p>
<p style="text-align: justify !important;">Hackers usually access information in one of two ways. They can try‘social hacking’, which means tricking a human being into giving oversensitive information or security credentials which in turn allows access to sensitive information. This could happen by tricking either someone who works directly for the provider, or an outside contractor. An unsophisticated example could be, ‘Hi, I am an IT provider for your company, and I need to carry out some maintenance, could you please provide these sensitive details for me?’. The second way is brute force:directly attacking a security system.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec2912e1"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>Once Hackers Get Access to The Data, What Do They Do with It?</strong></p>
<p style="text-align: justify !important;">In some cases, hackers access sensitive data, extract it, and lock it off. They can then sell it back to the company. If the company does not have backups, buying it back is probably the only viable option. The alternative is for them to lose all records of their patients which they will never be able to replace.Another possibility, is hackers stealing data and selling it to the public. The information may be sold to criminal groups on the dark web who wish to use sensitive information for blackmail or fraud purposes.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec291738"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>What Can the Healthcare Industry Do to Mitigate Cyber Threats?</strong></p>
<p style="text-align: justify !important;">The industry must realize that cybersecurity is human-centric. Gaining insight into the users&#8217; behavior, for example, or the flow of data in and out of the organization improves risk response.</p>
<p style="text-align: justify !important;">Additionally, the industry should be aware that cybersecurity isn&#8217;t just the responsibility of the IT department: everyone should be aware of the risks, from management down to brand-new contract staff.</p>
<p style="text-align: justify !important;">Healthcare security professionals need to understand the threats they face and the regulations they must comply with, and they must be provided with best practices for strengthening cybersecurity defenses. This means implementing comprehensive security awareness training that educates all people on current threats, red flags to look for in an email message or web link, how to avoid infection, and what to do in case of an active exploit. And since the threat landscape is constantly changing, training should be repeated and updated regularly.</p>
<p style="text-align: justify !important;">Furthermore, implementing the right cybersecurity measures, such data loss prevention, user behavior analytics, and endpoint security technologies, will further protect an organization&#8217;s infrastructure and patient data from ransomware attacks. By creating a system that guards the human point — where people interact with critical business data and intellectual property — and takes into account the intersection of users, data, and networks, the healthcare industry can improve its cyber threat protection.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec291b42"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>In Simple Terms: How Do We Improve Cybersecurity?</strong></p>
<p style="text-align: justify !important;">Due to the significant financial impact of data breaches in healthcare, health informatics and other professionals need to play an important role in ensuring that medical organizations remain secure. Individual healthcare organizations can improve their cybersecurity by implementing the following practices:</p>
<ul>
<li><strong>Establish a security culture:</strong> Ongoing cybersecurity training and education emphasize that every member of the organization is responsible for protecting patient data, creating a culture of security.</li>
<li><strong>Protect mobile devices:</strong> An increasing number of health care providers are using mobile devices at work. Encryption and other protective measures are critical to ensure that any information on these devices is secure.</li>
<li><strong>Maintain good computer habits:</strong> New employee on boarding should include training on best practices for computer use, including software and operating system maintenance.</li>
<li><strong>Use a firewall:</strong> Anything connected to the internet should have a firewall.</li>
<li><strong>Install and maintain anti-virus software:</strong> Simply installing anti-virus software is not enough. Continuous updates are essential for ensuring health care systems receive the best possible protection at any given time.</li>
<li><strong>Plan for the unexpected:</strong> Files should be backed up regularly for quick and easy data restoration. Organizations must consider storing this backed-up information away from the main system if possible.</li>
<li><strong>Control access to protected health information:</strong> Access to protected information should be granted to only those who need to view or use the data.</li>
<li><strong>Use strong passwords and change them regularly:</strong> The Verizon report found that 63 percent of confirmed data breaches involved taking advantage of passwords that were the default, weak or stolen. Healthcare employees should not only use strong passwords, but ensure they are changed regularly.</li>
<li><strong>Limit network access:</strong> Any software, applications and other additions to existing systems should not be installed by staff without prior consent from the proper organizational authorities.</li>
<li><strong>Control physical access:</strong> Data can also be breached when physical devices are stolen. Computers and other electronics that contain protected information should be kept in locked rooms in secure areas.</li>
</ul>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec291fdb"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>How to Defend Against the Growing Threat?</strong><br />
Deterrence, prevention, detection and response all have their place.</p>
<p style="text-align: justify !important;">Prevention is preferable to detection and reaction. But without data collection, an organization cannot successfully detect or react to anything.</p>
<p style="text-align: justify !important;">Alerts or alarms should be designed to detect event sequences with potentially negative consequences. Statistical and anomaly detection methods are particularly good for these purposes, as are rule-based detection mechanisms.</p>
<p style="text-align: justify !important;">Security information and event management or log management tools can augment data collection efforts.</p>
<p style="text-align: justify !important;">In addition to deploying technology tools to help defend against and detect intrusions, it&#8217;s important to formally define roles and responsibilities for incident response. Organizations need to document procedures that specify what the response team should do if there&#8217;s an incident and test those procedures periodically.</p>
<p style="text-align: justify !important;">It&#8217;s not just one technology, it is multiple technologies in order to repel these highly sophisticated and organized attacks. That includes deploying SIEM, as well as multi factor authentication to enter critical systems.</p>
<p style="text-align: justify !important;">The Internet is increasingly a swamp. It&#8217;s no longer sufficient to just look at standard security logs. You need integrated security information event management that brings together network logs, users log, application logs and server logs, and looks for non obvious associations.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec296044"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>In Conclusion</strong></p>
<p style="text-align: justify !important;">To improve cybersecurity in health care, organizations need to hire informatics professionals who not only collect, manage and leverage data, but protect it as well. In addition, health data professionals need to on a continuous basis develop new strategies and best practices to ensure the safety of sensitive health data, protecting both the patient and organization from financial loss and other forms of harm.We know that reaching 100% security against cyber attacks is not realistic but, with a few steps, healthcare organizations can make sure that it&#8217;s too complex or unprofitable for threat actors to attack them, which will result in them moving on to another target.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec29931c"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<h2>About the author</h2>
<p style="text-align: justify !important;"><em><strong>Kris Seeburn</strong> is an enterprise trainer and a member of Advisory Board of The New Security Foundation, Member of The American College of Forensic Examiners &amp; Institute of Forensics Science</em></p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
<p>The post <a href="https://innohealthmagazine.com/2019/in-focus/theme/cybersecurity-business-evangelist/">Cybersecurity Business Evangelist</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://innohealthmagazine.com/2019/in-focus/theme/cybersecurity-business-evangelist/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">6227</post-id>	</item>
		<item>
		<title>Cybersecurity Trends, Challenges, and Threats in Healthcare</title>
		<link>https://innohealthmagazine.com/2019/cybersecurity/cybersecurity-trends-challenges-threats-healthcare/</link>
					<comments>https://innohealthmagazine.com/2019/cybersecurity/cybersecurity-trends-challenges-threats-healthcare/#respond</comments>
		
		<dc:creator><![CDATA[InnoHEALTH Magazine]]></dc:creator>
		<pubDate>Tue, 28 May 2019 06:57:20 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cybersecurity framework]]></category>
		<category><![CDATA[cybersecurity policy]]></category>
		<category><![CDATA[cybersecurity threats]]></category>
		<category><![CDATA[cyberspace]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data privacy]]></category>
		<category><![CDATA[Digital Health]]></category>
		<category><![CDATA[digital health data]]></category>
		<category><![CDATA[digital information]]></category>
		<category><![CDATA[DISHA]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[healthcare websites]]></category>
		<category><![CDATA[Internet of Medical Things]]></category>
		<category><![CDATA[IoMT]]></category>
		<category><![CDATA[Mental Health]]></category>
		<category><![CDATA[National Health service]]></category>
		<category><![CDATA[physicaal health]]></category>
		<category><![CDATA[telecommunication]]></category>
		<category><![CDATA[WannaCry]]></category>
		<guid isPermaLink="false">https://ztt.nrm.mybluehostin.me/innohealthmagazine?p=5928</guid>

					<description><![CDATA[<p>The healthcare industry is particularly vulnerable to cyber threats not least because of the minimal amount of investment they put in cybersecurity measures.</p>
<p>The post <a href="https://innohealthmagazine.com/2019/cybersecurity/cybersecurity-trends-challenges-threats-healthcare/">Cybersecurity Trends, Challenges, and Threats in Healthcare</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[
		<div id="fws_69aa7ec2b0fa5"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;">Likewise, the global trends, the growth of the Internet in India is incredibly fast-paced, with an estimated addition of 10 million active users each month. Along with the increase in the number of users, the adoption rate of going digital by various stakeholders in our society is also growing exponentially. Unfortunately, this also increases our vulnerability to potential hacks or security breaches that come from individual hackers to organized groups to even attacks from nation states. Cybersecurity, thus, entails protection of our cyberspace, and all the critical infrastructures like banking and finance, defense, healthcare, manufacturing, nuclear reactors, and commercial facilities from being the target to any sort of attack, damage, misuse or act of espionage.</p>
<p style="text-align: justify !important;">The healthcare industry is particularly vulnerable to cyber threats not least because of the minimal amount of investment they put in cybersecurity measures. Hospitals, insurance companies, pharmacies, developers/ owners of healthcare websites, manufacturers of medical devices, or handsets, or third-party vendors to which sensitive patient data gets shared; all represent a leaky pipeline through which hackers can enter a system and cause extensive damage. The types of attacks can include access to patient’s medical history, prescriptions, financial and personal details or using the Internet of Medical Things to disrupt implanted medical devices or devices like drug infusion pumps. Healthy cybersecurity practices have, therefore, never been more important than today when a ransomware attack like WannaCry has the potential to literally shut down a country’s (UK) National Health Service.</p>
</div>



<div class="img-with-aniamtion-wrap center" data-max-width="100%" data-max-width-mobile="100%" data-shadow="none" data-animation="fade-in" >
      <div class="inner">
        <div class="hover-wrap"> 
          <div class="hover-wrap-inner">
            <a href="http://bit.ly/2IY3u54" target="_blank" class="center">
              <img decoding="async" class="img-with-animation skip-lazy" data-delay="0" height="60" width="728" data-animation="fade-in" src="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png" alt="cyber4healthcare-online-course-bottom-ad (2)" srcset="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png 728w, https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2-300x25.png 300w" sizes="(max-width: 728px) 100vw, 728px" />
            </a>
          </div>
        </div>
        
      </div>
      </div>
			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec2b2d09"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>Where India stands today?</strong></p>
<p style="text-align: justify !important;">According to the International Telecommunication Union (ITU), a UN telecommunications agency, India ranked 23rd amongst 165 nations on the Global Cybersecurity Index (GCI) in 2017. GCI ranks nations for their commitment towards cybersecurity using various measures &#8211; legal, technical, organizational, capacity building, and cooperation. With the rapid rise in cyber threats, India’s growing investment in protecting its data is absolutely a positive development. Nevertheless, a quick look at the current status on cybersecurity and data protection laws in India highlights the gap we must fill in as we move towards complete digitizing of various infrastructures in the 21st century.</p>
<p style="text-align: justify !important;">For instance, it was last in 2000 when the legal provisions related to cybersecurity were formulated in the Information Technology Act (ITA) when the nature of threats revolved only around viral or malware attacks. The ITA was later amended in 2008 and now deals with cyber crimes such as hacking, tampering, data or identity theft, cheating, phishing, etc. Sections 43 and 63–74 provide provisions for civil and criminal prosecution in case of different cyber offenses. The ITA requires entities holding private data of users to maintain specified security standards and provides provisions to users for airing grievances in case of the data breach.</p>
<p style="text-align: justify !important;">India established its first cybersecurity policy &#8211; the National Cyber Security Policy (NCSP), in 2013, after much mayhem caused by Edward Snowden’s allegations of NSA snooping on India. The policy designated CERT-In (Indian Computer Emergency Response Team), a national nodal agency to respond to and analyze incidents of cybersecurity breaches. CERT-In provides alerts of cybersecurity incidents, conducts emergency measures for handling such incidents, coordinates necessary response activities and issues guidelines, etc., regarding cybersecurity measures. In the case of a data breach, an organization holding confidential user data must report to CERT-In promptly.</p>
</div>



<div class="divider-wrap" data-alignment="default"><div style="height: 25px;" class="divider"></div></div>
<div class="wpb_text_column wpb_content_element " >
	<p>Also Read:<br />
<a href="https://innohealthmagazine.comexpert-opinion/cyber4healthcare/">Cyber4Healthcare: An Issue of Today &amp; Tomorrow</a><br />
<a href="https://innohealthmagazine.cominnovatiocuris/disha-act/">DISHA – Need of the hour</a></p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec2b4af2"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>Healthcare specific provisions</strong></p>
<p style="text-align: justify !important;">While the above-mentioned regulations provide a general legal cybersecurity framework for all the organizations, no separate provisions are in place viz a viz the healthcare sector. India decided to fill in this gap last year when the Ministry of Health and Family Affair, the Government of India proposed the Digital Information Security in Healthcare Act (DISHA) and placed it in public domain on 21 March 2018 for comments by various stakeholders. DISHA aims to ensure reliability, data privacy, confidentiality, and security of digital health data. The act, applicable to entire India except for Jammu and Kashmir, establishes eHealth Authorities and Health Information Exchanges at the state and national levels while also outlining the guidelines on standardizing/ regulating the processes related to the collection, storing, transmission and use of digital health data (DHD) in India.</p>
<p>Accordingly, DHD means any electronic record of health-related information</p>
<ul>
<li>concerning the physical or mental health of a person</li>
<li>on any health service provided to an individual</li>
<li>on a donation of any body part of any bodily substance</li>
<li>derived from testing or examination of a body part or bodily substance</li>
<li>collected during providing health services</li>
<li>relating to details of the clinical establishment accessed by a person</li>
</ul>
<p style="text-align: justify !important;">DISHA also specifies the rights of the owner of digital health data, outlines the purposes for which DHD can be collected and explicitly mentions all clinical establishments holding DHD to be duty-bound in maintaining privacy and confidentiality of the patient’s data. Importantly, DISHA touches upon what constitutes a breach of digital health data, compensation in the event of one happening and what punishments an individual or a company might face if convicted of a cybercrime.</p>
</div>



<div class="img-with-aniamtion-wrap center" data-max-width="100%" data-max-width-mobile="100%" data-shadow="none" data-animation="fade-in" >
      <div class="inner">
        <div class="hover-wrap"> 
          <div class="hover-wrap-inner">
            <a href="http://bit.ly/2IY3u54" target="_blank" class="center">
              <img decoding="async" class="img-with-animation skip-lazy" data-delay="0" height="60" width="728" data-animation="fade-in" src="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png" alt="cyber4healthcare-online-course-bottom-ad (2)" srcset="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png 728w, https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2-300x25.png 300w" sizes="(max-width: 728px) 100vw, 728px" />
            </a>
          </div>
        </div>
        
      </div>
      </div>
			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec2bac8f"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>Marching ahead</strong></p>
<p style="text-align: justify !important;">The breach of data far more often in the healthcare sector compared to other sectors highlights the value of information stored in digital health records. It is, therefore, important that cybersecurity takes precedence for all the healthcare providers. Proactive measures include identifying likely targets, securing and updating systems in a timely manner, constant monitoring for malware or security breaches and reinforcing good user behavior among the employees. Similarly, the response to data breach incidents needs to be swift to minimize the extent of damage when a cybercrime occurs. Like the adage, ‘prevention is better than cure’, the healthcare providers also have a necessary task ahead of themselves to up their security measures in accordance with the current legal framework, before a patient’s data or the trust gets compromised.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec2bb138"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<h2>About the author</h2>
<p><em><strong>Dr. Urvashi (Raheja) Bhattacharyya</strong> is a Senior Research Analyst at StudyMode. She indulges in machine-learning methods during office hours and enjoys writing about healthcare and education in her free time.</em></p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
<p>The post <a href="https://innohealthmagazine.com/2019/cybersecurity/cybersecurity-trends-challenges-threats-healthcare/">Cybersecurity Trends, Challenges, and Threats in Healthcare</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://innohealthmagazine.com/2019/cybersecurity/cybersecurity-trends-challenges-threats-healthcare/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">5928</post-id>	</item>
		<item>
		<title>Upcoming Cyber Security Threats in Health Sector</title>
		<link>https://innohealthmagazine.com/2017/issues/cyber-security-threats/</link>
					<comments>https://innohealthmagazine.com/2017/issues/cyber-security-threats/#respond</comments>
		
		<dc:creator><![CDATA[InnoHEALTH Magazine]]></dc:creator>
		<pubDate>Thu, 16 Nov 2017 06:25:35 +0000</pubDate>
				<category><![CDATA[Issues]]></category>
		<category><![CDATA[Authentication mechanism]]></category>
		<category><![CDATA[Bitcoin]]></category>
		<category><![CDATA[Bot]]></category>
		<category><![CDATA[Bot Traffic]]></category>
		<category><![CDATA[Breaches]]></category>
		<category><![CDATA[Breeding]]></category>
		<category><![CDATA[Communication Interfaces]]></category>
		<category><![CDATA[Crime]]></category>
		<category><![CDATA[Criminal Businesses]]></category>
		<category><![CDATA[Currency]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Weapon]]></category>
		<category><![CDATA[Data leak]]></category>
		<category><![CDATA[Denial attack]]></category>
		<category><![CDATA[Diagnosis]]></category>
		<category><![CDATA[Dick Cheney]]></category>
		<category><![CDATA[Digital System]]></category>
		<category><![CDATA[Dollar]]></category>
		<category><![CDATA[Electronic Device]]></category>
		<category><![CDATA[Encrypts]]></category>
		<category><![CDATA[Estonia]]></category>
		<category><![CDATA[Gadgets]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Hacker]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Health Sector]]></category>
		<category><![CDATA[Health Systems]]></category>
		<category><![CDATA[Healthcare Delivery]]></category>
		<category><![CDATA[Hospital Information System]]></category>
		<category><![CDATA[Infection]]></category>
		<category><![CDATA[innovatiocuris]]></category>
		<category><![CDATA[Interent]]></category>
		<category><![CDATA[Internet of Things]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[KLoC]]></category>
		<category><![CDATA[Lawmaker]]></category>
		<category><![CDATA[Lethal Attack]]></category>
		<category><![CDATA[Lung Diseases]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Marc Andreessen]]></category>
		<category><![CDATA[Medical devices]]></category>
		<category><![CDATA[mHealth]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Mitigation Strategy]]></category>
		<category><![CDATA[Nuclear program]]></category>
		<category><![CDATA[Programming code Snippet]]></category>
		<category><![CDATA[Ransom ware]]></category>
		<category><![CDATA[Russia]]></category>
		<category><![CDATA[Sachin Gaur]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[Silicon Walley]]></category>
		<category><![CDATA[Smartphone]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[software Code]]></category>
		<category><![CDATA[software programmer]]></category>
		<category><![CDATA[Stealing Identity information]]></category>
		<category><![CDATA[Stethoscope]]></category>
		<category><![CDATA[Stuxnet]]></category>
		<category><![CDATA[Tallinn Square]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Thermometer]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[Treatment]]></category>
		<category><![CDATA[Vice president]]></category>
		<guid isPermaLink="false">http://innovatiocuris.com/?p=2359</guid>

					<description><![CDATA[<p>By Sachin Gaur</p>
<p>The post <a href="https://innohealthmagazine.com/2017/issues/cyber-security-threats/">Upcoming Cyber Security Threats in Health Sector</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[
		<div id="fws_69aa7ec2c148b"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-2 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				<div class="img-with-aniamtion-wrap center" data-max-width="100%" data-max-width-mobile="100%" data-shadow="none" data-animation="fade-in" >
      <div class="inner">
        <div class="hover-wrap"> 
          <div class="hover-wrap-inner">
            <img decoding="async" class="img-with-animation skip-lazy" data-delay="0" height="150" width="150" data-animation="fade-in" src="https://innohealthmagazine.com/wp-content/uploads/2015/07/Sachin-Gaur-Team-InnovatioCuris.jpg" alt="Sachin Gaur - Team InnovatioCuris"  />
          </div>
        </div>
        
      </div>
    </div>
			</div> 
		</div>
	</div> 

	<div  class="vc_col-sm-10 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;">Sachin Gaur is director operations at <a href="http://www.innovatiocuris.com">InnovatioCuris</a>. He is interested in topics of mHealth and Cyber Security.</p>
<p style="text-align: justify !important;"><strong>Abstract:</strong> We are seeing phenomenal technology shifts and human life is greatly impacted by them. Health sector is not untouched as the health systems now have deep IT integration and care givers increasingly rely on the information shown by digital systems. Hence, any compromise to the integrity of such systems would lead to wrong diagnosis or treatment. This paper investigates some of the early signals about the kind of threats out there relevant to the health systems.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec2c70e3"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><span style="color: #0071b2;"><strong>Introduction</strong></span></p>
<p style="text-align: justify !important;">The famous Silicon Valley investor Marc Andreessen says, “software is eating the world”. By, which he means that increasingly we are bringing software into systems to increase efficiency, lower down the cost or time involved in the process. Interestingly, humans also do software writing and humans are prone to make mistakes. It is estimated by various experts that 1000 lines of code (KLoC) has approximately 15-50 bugs present. Bugs here mean mistakes made by the software programmer while writing the software code. Bugs often result in some kind of malfunction or wrong output. Some of these bugs can lead to exploit by a third party making the larger system vulnerable or as we call hackable. As long as humans will write software, bugs will be there.</p>
<p style="text-align: justify !important;">In a typical software company as bugs are discovered, new code is written to fix these bugs. The new code might further result into new bugs hence the cycle continues. At the consumer end, we keep receiving software updates over the air, as we use our phone / laptops or other devices, which are many times an attempt of the software company to overcome the past mistakes.</p>
<p style="text-align: justify !important;">A lone computer hacker or an organized crime group looks at these software updates (sometimes called patches) very curiously as for them this could be a chance of hitting the jackpot! They reverse engineer it and try to understand the bug, that the patch is trying to cover. Very often systems are not updated with latest updates. Leading to most system having a known vulnerability, which the hacker can take advantage after understanding it well. Hackers further can create a simple script (programming code snippet) to some sophisticated software, which can then take advantage of the vulnerable system. We often call such a program as malware, as it is built with bad intention.</p>
<p style="text-align: justify !important;">Today, as we talk it has become from a hobby crime to organized crime! Software companies regularly receive communication from bounty hunters about exposing their critical software bugs and in exchange not to do so, hackers want to charge them bounty money. Some software companies have gone further and engaged these bounty hunters to reduce security risks in their software.</p>
<p style="text-align: justify !important;">In some cases the hacker is not interested in the bounty money (hence they do not inform the software maker) but rather interested in exploiting the bug. Sometimes, the bug is not known to the software maker or anyone else in the world and can be converted into a lethal attack. Such attacks are known as a zero day attack! As prior knowledge of such a vulnerability does not exist. Hence, most software security solutions, like anti virus software do not work on them. Further selling the knowledge of exploit as lethal software is now called as a cyber weapon. Nation states are now engaged in buying or building such software to infect systems of enemy states. Hence, we have come very far in the business of software bugs, where the enemy could be a lone developer, an organized crime group or a Nation state.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec2c79b2"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><span style="color: #0071b2;"><strong>How is software eating the health sector and the threats linked to it?</strong></span></p>
<p style="text-align: justify !important;">In the above section we discussed in general, how the exploitation of software is increasingly becoming a serious business. While, we have seen many examples in last 30 years from a hobby software programmer to Nation states taking advantage of the software driven vulnerabilities. We would like to share some examples closer to the health sector.</p>
<p><strong>1. Malware affecting data systems</strong></p>
<p style="text-align: justify !important;">Hospital information systems and similar information systems as part of the healthcare delivery have become very commonplace and one of the core component of the system. As pointed out in the introductory section, organized crime groups are now looking to exploit software bugs for commercial purposes. One of the ingenious way that they have developed is a malware known as ransomware . Ransomware is a malicious computer program which when executed on a system encrypts the data with very strong encryption making it unusable for hospitals or any other care provider to access patient records or other vital information. It then demands a ransom inform of bitcoins (a crypto currency) in order for the victim to have the key to decrypt the vital information. In recent incidents of ransomware infection, some hospitals in USA have even demanded millions of dollars as ransom and some have even paid.</p>
<p style="text-align: justify !important;">The mitigation strategy for countering ransomware for any organization would be a strong backup of data. Also, creating awareness among the employees on sources of malware and reducing the chances of accidental infection of the workplace systems.</p>
<p style="text-align: justify !important;">The long-term solution of tackling such organized crime is a better international legal framework, which allows international prosecution and cooperation among law enforcement agencies.</p>
<p><strong>2. Denial of service attacks on ehealth services</strong></p>
<p style="text-align: justify !important;">In 2007 there was a distributed denial of service attack that took place in Estonia. A statue of the Russian soldier was removed from the Tallinn Square, capital of the country. Which sparked a response from sympathizers from Russia and it brought down the Estonian economy for three days. Estonia being one of the most advance countries when it comes to take up of e governance services, ehealth being one of them. The entire attack costed less than 50,000 US dollars. That was the first Denial of service attack the world saw at the level of a nation state.</p>
<p style="text-align: justify !important;">The basic premise behind such an attack is that you have a service (e-service) to be provided to citizens over Internet like their own health records for example. The provider would have some finite amount of bandwidth and computing power at the backend of the service correlating to the average load on the service. In a distributed denial of service attack, the attacker uses compromised computing devices (commonly known as a bot) to access the Internet service. The botnet, which is a collection of such bots could be having thousands or millions of such devices that simultaneously access the service. The service provider is not able to distinguish the normal traffic from the bot traffic and often the server crashes under the heavy load. For a normal user trying to access the service, the service is unavailable because of the finite resources of the server being exhausted by the bot traffic. Hence, it is called a denial of service attack.</p>
<p style="text-align: justify !important;">Hence, when a city, state or a nation is considering providing an eservice to citizens it could witness such attacks. One strategy to mitigate such attacks is to have tracking of the server traffic for any anomalies and having redundancy available in the system. This is achieved many times by putting the service on a cloud, which can tolerate such traffic fluctuations.</p>
<p><strong>3. Data leak and breaches</strong></p>
<p style="text-align: justify !important;">Many health systems or systems require some kind of authentication mechanism to log in to the system in order to access the service. Many a times these are text password based systems behind which, important patient profile or health records information is stored. The largest of the companies like that of Google, Microsoft etc have seen attacks where the attacker is able to leak the passwords of millions of their customers. Such scenarios result in massive breach of data privacy and compromise for customers.</p>
<p style="text-align: justify !important;">Good security practices, proper encryption of data and regular updates of the system are some of the key considerations for avoiding such instances. Nowadays, two-factor authentication has become a standard practice for making the authentication systems more robust. However, still some user awareness is needed to opt for better security practices whenever possible.</p>
<p><strong>4. Hacking medical devices and health system</strong></p>
<p style="text-align: justify !important;">If we look at the building blocks of the health systems, where information technology is deeply integrated. We have already covered the health information systems, eservices and patient interface of authentication into the services. However, increasingly we hear about Internet of Things (IoT) devices in the health sector domain. Which means the integration of Internet services into traditional medical devices or new age devices, which have also connectivity. For example, a thermometer which can send the temperature data to your phone or a stethoscope which can record the patient breathing sound and upload in a server for finding patterns of lung diseases. These are powerful use cases and provide great opportunity to clinicians and care providers, where they have greater computation power available to them and they are able to do more with less. However, these IoT devices are prone to the same kind of attacks as any other communication device or a software program. They can be compromised to show wrong values and totally messing up the diagnosis. There are already such instances. One such instance not related to health sector but important is of the Stuxnet. Stuxnet was designed for the SCADA systems of Iranian nuclear program by USA and Israel in order to delay their nuclear program.</p>
<p><strong>5. Stealing identity information</strong></p>
<p style="text-align: justify !important;">As mentioned in the point 3, about data leaks and breaches at the system level. One problem, which can arise from such an attack, is a further more damaging attack that is stealing of identity information. In India, mobile phones to receive an sms message containing one time password is increasingly becoming a standard practise because of being cost effective, simple and secure. Any such application, which you may install on your phone, can also get access to the sms and other features of your phone. Meaning the incoming sms or calls can also be stolen by this application to complete the transaction on your behalf. As increasingly we have to prove ourselves using biometrics or passwords to online systems. It is possible for the attackers to steal these credentials and access our records without our knowledge. Hence, any third party applications that we install on our devices (especially phone) , we need to be very careful about the type of access control they have on our devices.</p>
<p><strong>6. Implantable medical devices with communication interfaces:</strong></p>
<p style="text-align: justify !important;">In 2007, the former US Vice President, Dick Cheney’s implanted pacemaker’s wireless communication was disabled fearing a terrorist attack. This sounds like science fiction to many but incident has already happened ten years back! Many of the medical devices are built with a communication interface and it is quite normal for a typical pacemaker or other such devices to have a Bluetooth or a similar communication technology based interface for remote diagnosis and other purposes. While, the communication ability of such a device was planned for looking at the state of the pacemaker it was not designed with keeping security in mind. Hence, it is possible that someone can connect to a critical device like pacemaker and shuts it down remotely.</p>
<p style="text-align: justify !important;">One more reason that such exploits are possible increasingly as computing is becoming cheaper. What seems strong security today might not be strong tomorrow. However, an implantable device might stay in the patient’s body for tens of years. Hence, we need to have a long-term view on the communication interfaces and their capabilities on such devices. We need to make considerations on control and information capabilities of these interfaces. Misuse of control capabilities can lead to even death and misuse of information capabilities can lead to breach of patient privacy.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec2c803d"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><span style="color: #0071b2;"><strong>Way forward: why Internet is the new breeding ground for crime?</strong></span></p>
<p style="text-align: justify !important;">The law of the land governs the Internet in every country and hence the legal regime globally is very fragmented. However, a user of Internet does not see any borders or walls and so is the criminal. They build their criminal businesses where they do not fear strict government action and often for paltry sums the user or the national law enforcement agencies do not pursue the criminal cases cross border.</p>
<p style="text-align: justify !important;">On top of it newer crypto currencies like Bitcoins, makes it easy to make such transaction in an anonymous manner. Dark net marketplaces provide a breeding ground for criminals to conduct illegal transactions of billions of dollars without getting caught. So, the three important components, weak legal enforcement, anonymous currency and secret marketplaces are enabling the cyber crime to flourish. If we want to slow it down, we will need greater international collaboration among lawmakers and user awareness at all levels.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec2c8597"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><span style="color: #0071b2;"><strong>Reference:</strong></span><br />
<strong>(i)</strong> <a href="https://www.wsj.com/articles/SB10001424053111903480904576512250915629460">https://www.wsj.com/articles/SB10001424053111903480904576512250915629460</a><br />
<strong>(ii)</strong> <a href="http://labs.sogeti.com/how-many-defects-are-too-many/">http://labs.sogeti.com/how-many-defects-are-too-many/</a><br />
<strong>(iii)</strong> <a href="https://www.ted.com/talks/mikko_hypponen_fighting_viruses_defending_the_net/transcript?language=en">https://www.ted.com/talks/mikko_hypponen_fighting_viruses_defending_the_net/transcript?language=en</a><br />
<strong>(iv)</strong> <a href="https://hackerone.com">https://hackerone.com</a><br />
<strong>(v)</strong> <a href="https://en.wikipedia.org/wiki/Zero-day_(computing)">https://en.wikipedia.org/wiki/Zero-day_(computing)</a><br />
<strong>(vi)</strong> <a href="https://en.wikipedia.org/wiki/Cyberweapon">https://en.wikipedia.org/wiki/Cyberweapon</a><br />
<strong>(vii)</strong> <a href="https://en.wikipedia.org/wiki/Ransomware">https://en.wikipedia.org/wiki/Ransomware</a><br />
<strong>(viii)</strong> <a href="https://en.wikipedia.org/wiki/Bitcoin">https://en.wikipedia.org/wiki/Bitcoin</a><br />
<strong>(ix)</strong> <a href="http://www.csoonline.com/article/3033160/security/ransomware-takes-hollywood-hospital-offline-36m-demanded-by-attackers.html">http://www.csoonline.com/article/3033160/security/ransomware-takes-hollywood-hospital-offline-36m-demanded-by-attackers.html</a><br />
<strong>(x)</strong> <a href="https://www.theguardian.com/technology/2016/feb/17/los-angeles-hospital-hacked-ransom-bitcoin-hollywood-presbyterian-medical-center">https://www.theguardian.com/technology/2016/feb/17/los-angeles-hospital-hacked-ransom-bitcoin-hollywood-presbyterian-medical-center</a><br />
<strong>(xi)</strong> <a href="http://innovatiocuris.com/looming-danger-of-ransomware/">http://innovatiocuris.com/looming-danger-of-ransomware/</a><br />
<strong>(xii)</strong> <a href="http://www.bbc.com/news/technology-24608435">http://www.bbc.com/news/technology-24608435</a></p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa7ec2c8a64"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p>Want to write for InnoHEALTH? send us your article at  <a href="mailto:magazine@innovatiocuris.com">magazine@innovatiocuris.com</a></p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
<p>The post <a href="https://innohealthmagazine.com/2017/issues/cyber-security-threats/">Upcoming Cyber Security Threats in Health Sector</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://innohealthmagazine.com/2017/issues/cyber-security-threats/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2359</post-id>	</item>
	</channel>
</rss>
