October 1, 2007 - The board of the eHealth Vulnerability Reporting Program recently reported the results of a fifteen-month study assessing the security risks associated with electronic health record (EHR) systems, evaluating current industry information security practices and assessing level of risk related to EHR systems, finding that commercial EHR systems are vulnerable to exploitation given existing industry development and disclosure practices.

In all cases, evaluated EHR system vulnerabilities could be identified using standard tools and techniques. Subsets of these vulnerabilities were exploited to gain control of the application and access to data to demonstrate the potential consequences. EHR vendors are either not disclosing or inadequately disclosing system vulnerabilities to customers, preventing organizations from appropriately managing risk or implementing compensating controls.

No industry organization could be identified that has established guidelines or practices to appropriately mitigate and manage risks associated with ehealth systems. Also, no industry organization could be identified that has the responsibility, charter or mission to address security vulnerabilities in ehealth systems.

The study was supported by various working groups, penetration testing resources and demonstration sites and was overseen by a board of advisors. The study included a survey of over 850 provider organizations and penetration testing of seven ehealth systems, including five CCHIT certified ambulatory EHR systems. The evaluation and testing was performed on EHR systems targeting small, medium and large practices. It was not intended to be representative of a specific EHR system, but to understand the type and severity of vulnerabilities, and practices and processes implemented by vendors and customers to mitigate security related issues.

For more information: www.ehvrp.org


Related Content

News | Enterprise Imaging

June 28, 2024 — Konica Minolta Healthcare Americas announced today a strategic partnership with Apollo Enterprise ...

Time June 28, 2024
arrow
News | Radiology Imaging

May 31, 2024 — MDView, a virtual care and medical second opinion platform, surveys users of its Radiology Second Opinion ...

Time May 31, 2024
arrow
Feature | Digital Radiography (DR) | By Melinda Taschetta-Millane

Digital radiography (DR) continues to advance at a rapid pace with today’s technological innovations and evolving ...

Time May 06, 2024
arrow
Feature | Information Technology | By Jef Williams

The rapid growth of healthcare data has reached unprecedented heights, making up about 30% of the world’s stored data.¹ ...

Time April 30, 2024
arrow
News | Cybersecurity

March 14, 2024 — The American Medical Association (AMA) has issued a new letter to federal officials in which it praised ...

Time March 14, 2024
arrow
News | HIMSS

March 13, 2024 — The Health Information Management Systems Society, HIMSS, and the Korean Health Information Service ...

Time March 13, 2024
arrow
News | Enterprise Imaging

February 26, 2024 — Hyland Healthcare, a leading global provider of intelligent content and enterprise imaging solutions ...

Time February 26, 2024
arrow
Feature | Enterprise Imaging

The Healthcare Information and Management Systems (HIMSS24) Conference and Exhibition (March 12-14, in Orlando, Fla.) is ...

Time February 14, 2024
arrow
News | Point-of-Care Ultrasound (POCUS)

December 18, 2023 — Exo (pronounced “echo”), a pioneering medical imaging software and devices company, released its ...

Time December 18, 2023
arrow
News | Enterprise Imaging

November 16, 2023 — At the 2023 Radiological Society of North America (RSNA) Annual Meeting in Chicago on Nov. 26-30 ...

Time November 16, 2023
arrow
Subscribe Now