Norwegian security firm Norse, in collaboration with the SANS Institute, published a paper on cyberattacks against American healthcare organizations.
The study covers the period between September 2012 and October 2013, and is based on the analysis of approximately 50,000 reported security incidents. However, it should be noted that this number represents only a small sample of the total volume of data collected by Norse.
According to the results of the investigation, the networks and devices of 375 organizations were compromised, while some of them are still at risk.
The list of compromised devices includes firewalls, webcams, mail servers and medical imaging software, while VPNs were the most targeted systems.
“It is concerning that hackers can easily steal sensitive patient information, and can even manipulate medical devices used in intensive care units,” a SANS spokesperson said.
“For many organizations governed by strict regulations, a violation can lead to huge fines. In 2013, these fines ranged from $150,000 to $1.7 million.”.
Finally, Norse CEO Sam Glines said: “The number of attacks perpetrated against healthcare organizations is overwhelming. And while most organizations continue to look for ways to effectively protect themselves, a large percentage of them are unable to properly secure critical data, resulting in companies and consumers paying the price.”.

