Skip to content
MarketScale
‹ Back to IndustriesHealthcare

Fixing Breaches in Your Healthcare IT System

We’re only halfway through 2018 and there have already been numerous security breaches in healthcare. The more information gets integrated and connected, the more it’s at risk; yet healthcare information perhaps requires the highest levels of connection and integration to be most useful. This information, though, is highly sensitive and the legal consequences of improperly…

This story was produced through MarketScale. See how Healthcare teams put it to work with Executive Thought Leadership.

Share

Get featured

Want to get featured in MarketScale Healthcare?

Create a free MarketScale workspace and get your company's expertise featured across our Healthcare coverage. No credit card, no demo required.

Start free

We’re only halfway through 2018 and there have already been numerous security breaches in healthcare. The more information gets integrated and connected, the more it’s at risk; yet healthcare information perhaps requires the highest levels of connection and integration to be most useful. This information, though, is highly sensitive and the legal consequences of improperly distributing it can be quite severe, so anything that might increase the risk of a security breach is very worrisome. There may be few areas outside government where data needs to be extremely secure.

Michael Beeson, an IT Security Professional with experience in government and health care, sees many systematic problems in healthcare IT security. “The original samsam encryption attack largely took advantage of the fact that many hospitals don’t have inhouse IT and just hire people to handle their web stuff on occasion then don’t maintain anything beyond content,” Beeson said. “The attackers take advantage of long-known vulnerabilities and gain access to the hospital network through those compromised servers.” He argues that the solution to this problem would be to patch known vulnerabilities when possible and to use web application firewalls.

Another part of the problem, according to Beeson, is that most hospitals use “flat networks” in which all the departments are connected. He says that best practice is to separate workstations by departments and to use VLANs to segregate information. This would prevent infections from jumping from one department to another. Strong internal firewalls that would only allow traffic to the electronic medical record system server that’s needed would be key to creating such a system.

While most people are going to think of computers and servers, Beeson argues that there’s a major security gap in medical devices. The issue is that “medical devices are typically very lax in security,” Beeson says. “Things like pumps and monitors use wi-fi without any additional encryption.” Pacemakers use MQTT unencrypted, which would allow a hacker access to all the information in the device and even change the settings. Unfortunately, as Beeson notes, “the only thing that can be done there is for the equipment manufacturers to start configuring MQTT with encryption from the start.”

This opens up an entirely new area of concern. The last thing you want to worry about when you get a pacemaker is whether or not someone could hack into it and give you a heart attack. A malevolent hacker could certainly wreak havoc by targeting a large variety of medical devices. This is a threat to people’s lives and not merely making private information public or stealing your financial information. Clearly we need to make online security in the healthcare field a full-time concern.

Your experts belong here

Every story in MarketScale Healthcare starts with a company putting its clinicians, service-line leaders, and field engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Service-line buyers vet vendors quietly, and your clinicians become the proof they find while doing it.

Get your team featuredSee how it works15 minutes, straight to a calendar.

Follow Healthcare Insights

Get new expert content in your inbox.

Healthcare: are you visible to AI?

Before they reach out, Healthcare buyers ask AI engines which vendors to trust. Explore how your experts, customers, and partners can become useful content for buyers and AI search.

Free plan

You just read one Healthcare expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your clinicians, service-line leaders, and field engineers into the articles, video, and social content Healthcare buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale workspace, up to 10 people
One professional video edit a month for qualifying companies
Media requests to your crowd, remote recording, AI writing tools
$0, no credit card, nothing that expires

More Healthcare Insights

July partnerships show hospitals aligning without ownership change

July partnerships show hospitals aligning without ownership change

A July McDermott Will & Schulte analysis and four July partnership announcements tracked by Becker’s Hospital Review point to affiliation models that stop short of mergers. St. Christopher’s signed a nonbinding letter of intent with Nemours, Jefferson and Temple; Palomar UC San Diego Health began operating July 1 under a joint powers authority. Several announcements explicitly rule out ownership change, shifting the work to contracts covering governance and other terms.

  • 01In an alliance, the contract does the integrating that an org chart does in a merger: McDermott Will & Schulte says governance design, exclusivity, antitrust review, community commitments and exit rights all have to be settled before signing.
  • 02Purchasing is now explicitly on the table in at least one no-ownership deal, the St. Peter's Health and Billings Clinic-Logan Health talks in Montana, which means shared supply contracts can arrive without a change of control.

Sep 19, 2026

Eye telemedicine hits limits without home retinal imaging

Eye telemedicine hits limits without home retinal imaging

An Ophthalmology Times commentary by T.Y. Alvin Liu, Ferdinand Hui and Phillip Phan sorts eye patients into three telemedicine tiers by clinical need. Patients needing regular OCT scans benefit less unless a home device can send the image. Video tools already sit inside Epic and Cerner; the deciding purchase for retina clinics is the imaging device in the patient's living room.

  • 01The dividing line for eye telemedicine is imaging, not video: patients who need regular OCT scans benefit less from remote visits unless a device at home can send the scan, so a video license alone shifts few of those encounters.
  • 02The provider-side requirement, a HIPAA-compliant secured video platform, was already built into Epic and Cerner by 2020; the patient-side requirements (1.5 MB up and down bandwidth, a quiet private room, comfort with the technology) sit outside the health system's control and are the ones worth screening for at scheduling.
  • 03Self-administered home color fundus photography for tracking non-proliferative diabetic retinopathy was named as the nearer route into retina telemedicine; home OCT for wet AMD is the harder gate and the device to watch.

Sep 19, 2026

Value-based care reaches a quarter of revenue at 30% of surveyed health organizations

Value-based care reaches a quarter of revenue at 30% of surveyed health organizations

Wolters Kluwer Health argues value-based care software is judged on whether customers hit incentive thresholds and avoid penalties. A Fierce Healthcare-reported survey it cites puts value-based care at a quarter or more of revenue for 30% of organizations. The analysis is a vendor publication that ends by pitching its own UpToDate Connect API.

  • 01The sharper question for any population health or care coordination platform is whether it changes what a clinician does at the moment of decision, or only reports afterward what happened. Wolters Kluwer's reading of the evidence is that many platforms still struggle with the first.
  • 02Vendors selling into value-based contracts now face a build-or-license decision on clinical content, because Wolters Kluwer names current, trusted content, consistent clinician adoption across sites, and a traceable link from guidance to quality metrics as the three hard problems.

Sep 18, 2026

Explore More Healthcare Insights

Read more expert perspectives from across Healthcare.

Browse Healthcare Hub

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Healthcare and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512