The data security firm analyzed data risk assessments from 3 billion files at 58 companies to determine how data is exposed.
Six key study findings:
- The average healthcare organization had 31,000 sensitive files, including HIPAA-protected data and financial information, open to everyone.
- Twelve percent of sensitive files are available to every employee, and 19 percent of all healthcare files are open to every employee.
- Healthcare organizations average nearly 30,000 exposed folders containing healthcare files per terabyte.
- Of the analyzed companies, 77 percent had at least 500 accounts with passwords that never expire.
- It takes six to eight hours per healthcare data folder to manually remove open access. This means it would take years to mitigate security risks created by open access.
- The average life cycle of a healthcare data breach is 329 days, the highest of any industry.
More articles on cybersecurity:
March healthcare data breaches triple February numbers
Does a vaccine passport violate HIPAA? Experts weigh in
More than 1 million affected by data breaches in March
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.