A Look at Email Security in the US Healthcare Sector

Stu Sjouwerman | Mar 11, 2020

iStock-115676504390% of US healthcare organizations experienced email-based attacks in the past year, and 25% of these organizations said the attacks were extremely or very disruptive, according to a new report from HIMSS Media. The report found that, on average, healthcare organizations are taking steps to improve their security, but they continue to fall victim to phishing attacks.

Emails are the most effective and practical way to gain access to any given organization.

Email attacks are so prevalent because email is one of the most ubiquitous applications in the world. Pretty much any organization that an attacker is interested in has people using email. And, it’s easy for an attacker to reach into an organization via email. All an attacker needs to know is someone’s email address.

Emails allow attackers to send malware-laden attachments and malicious links directly into your organization, and all they have to do is trick the end-user.

All the reasons email is useful for legitimate purposes, make it useful for malicious purposes because they work.

The report also found that 77% of healthcare professionals believe security awareness training is necessary to defend against these attacks, but 40% said their organization provided security training less than quarterly.

People frequently fixate just on the technologies and assume they are protected because they are using an antivirus system, a backup system, an email security system, and other tools. All of this is good. However,  information technology professionals also need to think about other elements of a program.

Employee education should be an integral part of every organization’s security posture. New-school security awareness training can enable your employees to thwart phishing attacks.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.