Symantec teamed up with Healthcare Information and Management Systems Society Analytics to compile the third annual IT Security and Risk Management Study.
Here are eight report insights.
1. Healthcare providers (60 percent) are investing more in risk assessment, as opposed to HIPAA compliance.
2. Providers are increasingly adopting cybersecurity frameworks, with 40 percent using more than one.
3. The three most common frameworks are the National Institute of Standards and Technology Cybersecurity Framework (63 percent), the Health Information Trust Alliance (37 percent) and the Information Technology Infrastructure Library (31 percent).
4. Fifty-nine percent of providers identified “performance against risk frameworks” as a top security concern.
5. Although eight in 10 providers conduct a cybersecurity brief at board meetings, about half said it is done so on an ad-hoc basis.
6. Most providers (73 percent) said budget was the most significant barrier to their security programs, followed by staffing and skillsets.
7. About 74 percent of providers dedicate 6 percent or less of their total IT budget to IT security. The average IT security spend has remained flat over the last three years, according to the report.
8. About three of four providers are using the cloud, but 71 percent of providers said they have widespread security concerns about doing so.
More articles on cybersecurity:
KLAS: Healthcare consulting firms, ranked
EHR vendors stock report: Week of Feb. 26 – March 2
6 questions on patient-generated health data, answered
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.