• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

  • Opinion
  • Health IT
    • Behavioral Health
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Patient Engagement
    • Population Health Management
    • Revenue Cycle Management
    • Social Determinants of Health
  • Digital Health
    • AI
    • Blockchain
    • Precision Medicine
    • Telehealth
    • Wearables
  • Life Sciences
  • Investments
  • M&A
  • Value-based Care
    • Accountable Care (ACOs)
    • Medicare Advantage

Top 10 Hacking Exposure Areas for Healthcare IT Systems

by HITC Staff 02/01/2016 Leave a Comment

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

Security Data Breaches_Top 10 Hacking Exposure Areas for Healthcare IT Systems

Meditology Services, a professional services company specializing in IT solutions for healthcare organizations, announced new research based on a two year study from 2013-2015. As a follow up to this research endeavor, Meditology has released a white paper focused on ethical hacking, also known as penetration testing, and why it is a very effective way to test the security of healthcare information systems.

The paper, “Hacking Healthcare: Real-world Healthcare Security Exposures from Penetration Tests,” drives an increased awareness of the need for the healthcare industry to harden systems against both external and internal threats. The paper also helps healthcare organizations understand how to take a proactive security stance based on the concepts, methodology, approaches, and a description of various real-world penetration testing and related results.

According to the Ponemon Institute, criminal attacks on healthcare organizations have increased 100 percent since 2010 and represent the highest per-record cost to companies across industries.

Anatomy of a Penetration Test

Depending on the organization’s size and complexity, thorough penetration testing can take weeks to carry out and involves reconnaissance, surveying, testing and reporting to produce a final analysis across exposure areas. The paper outlines the top 10 hacking exposure areas based on the results of testing including physical security, phishing, medical devices, passwords and more. Both internal and external tests must be considered to address the full range of attack vectors.

“Hackers have expanded focus from technical vulnerabilities in public facing applications and networks to sophisticated social engineering and phishing attacks that psychologically manipulate people into divulging information,” Selfridge continues. “Medical devices also present an increasingly popular access point as they are configurable, and interconnected.”

Regular penetration testing is essential for organizations to identify weaknesses and gain the support they need to prevent data breaches. Domain expertise in the healthcare industry should be a top requirement when engaging a security firm to conduct penetration testing as patient safety, unique application issues, and specific regulatory requirements create a complex landscape that is different from other industries.

The following list is the top 10 most common security exposure areas that Meditology has observed from penetration tests of healthcare organizations across the country from the period of 2013 through 2015

1. Weak & Easily Guessable Passwords

2. Plain-text Credentials

3. Missing Critical Security Patches/Outdated OS’s

4. Weak Database Administrative Passwords

5. Generic or Default Accounts & Passwords

6. Network Shares with Improper Access Controls

7. Unauthenticated VNC Remote System Access

8. Insecure File Transfer Protocol (FTP)

9. Physical Security Gaps

10. Social Engineering Weaknesses

 

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

Tap Native

Get in-depth healthcare technology analysis and commentary delivered straight to your email weekly

Reader Interactions

Primary Sidebar

Subscribe to HIT Consultant

Latest insightful articles delivered straight to your inbox weekly.

Submit a Tip or Pitch

2026 Predictions & Trends

Healthcare 2026 Forecast: Executives on AI Survival, Financial Reckoning, and the End of Point Solutions

2026 Healthcare Executive Predictions: Why the AI “Pilot Era” Is Officially Over

Most-Read

OpenAI Debuts ChatGPT Health: A ‘Digital Front Door’ That Connects Medical Records to Agentic AI

OpenAI Debuts ChatGPT Health: A ‘Digital Front Door’ That Connects Medical Records to Agentic AI

From Genes to Hackers: The Hidden Cybersecurity Risks in Life Sciences

From Genes to Hackers: The Hidden Cybersecurity Risks in Life Sciences

Utah Becomes First State to Approve AI System for Prescription Renewals

Utah Becomes First State to Approve AI System for Prescription Renewals

NYC Health + Hospitals to Acquire Maimonides in $2.2B Safety Net Overhaul

NYC Health + Hospitals to Acquire Maimonides in $2.2B Safety Net Overhaul

KLAS Report: Why Hospitals Are Choosing Efficiency Over 'Agentic' AI Hype in 2025

KLAS Report: Why Hospitals Are Choosing Efficiency Over ‘Agentic’ AI Hype in 2025

Advanced Primary Care 2026: Top 6 Investments for Health Systems According to Harvard Medical School

Advanced Primary Care 2026: Top 6 Investments for Health Systems According to Harvard Medical School

AI Nutrition Labels: The Key to Provider Adoption and Patient Trust?

AI Nutrition Labels: The Key to Provider Adoption and Patient Trust?

Kristen Hartsell, VP of Clinical Services, RedSail Technologies

The Pharmacy Closures Crisis: How Independent Pharmacies Are Fixing Pharmacy Deserts

HHS Launches 'OneHHS' AI Strategy to Integrate AI Across CDC, CMS, and FDA for Efficiency and Public Trust

HHS Launches ‘OneHHS’ AI Strategy to Integrate AI Across CDC, CMS, and FDA for Efficiency and Public Trust

From Overwhelmed to Optimized: How AI Agents Address Staffing Challenges and Burnout in Healthcare

From Overwhelmed to Optimized: How AI Agents Address Staffing Challenges and Burnout in Healthcare

Secondary Sidebar

Footer

Company

  • About Us
  • Advertise with Us
  • Reprints and Permissions
  • Op-Ed Submission Guidelines
  • Contact
  • Subscribe

Editorial Coverage

  • Opinion
  • Health IT
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Population Health Management
    • Revenue Cycle Management
  • Digital Health
    • Artificial Intelligence
    • Blockchain Tech
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • Value-Based Care
    • Accountable Care
    • Medicare Advantage

Connect

Subscribe to HIT Consultant Media

Latest insightful articles delivered straight to your inbox weekly

Copyright © 2026. HIT Consultant Media. All Rights Reserved. Privacy Policy |