Phishing Continues to be the Source of Health Data Breaches Totaling Over 1M Breached Records

Stu Sjouwerman | Apr 22, 2019
Phishing-T

The beginning of 2019 has proven that data breaches in the health industry aren’t going anywhere. And from the intel on the breaches, phishing is playing a predominant role.

Patient Health Information (PHI) is very valuable – all kinds of information can be recorded: name, address, driver’s license, social security number, and insurance information. This data can serve as the basis for identity theft, insurance fraud, tax return fraud, and more. So, it’s no surprise that the health industry remains a target of cybercriminals.

Based on data from the U.S. Department of Health and Human Services, the top 5 Heath data breaches to date in 2019 total over 2 Million records:

4-16-19 Blog Image

Of these 5 breaches, 3 of them (Columbia Surgical Specialists, UConn Health, and Cornerstone Insurance) stem from phishing attacks that directly resulted in either an exfiltration of data or a ransomware attack. While health-related organizations continue to attempt to prepare themselves for what looks to be a busy year of cyberattacks, those utilizing frequent phishing testing are seeing massive reductions in risk and malware infection.

The use of phishing testing, along with Security Awareness Training, help to raise the employee’s mindfulness around the use of good security practices as part of their daily job. Phishing testing provide the organization with a feedback look, helping them understand which employees are the least security-conscious and, therefore, present the greatest risk to the organization.

From the data above, it looks like the health industry should expect phishing attacks to continue. Putting security measures in place that specifically – and effectively – address phishing is imperative to keep data from being breached.


Find out how affordable new-school security awareness training is for your organization. Get a quote now.

 
Get A Quote
Request A Demo
 

Topics: Phishing

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.