Healthcare
Overview
Healthcare is the most exploited industry via fraudulent emails. Hacking and IT security attacks have progressively increased over the last few years, and many healthcare organizations have battled to defend their network perimeter and keep cybercriminals at bay. However, when it comes to safeguarding themselves from brand impersonation, BEC, and other phishing schemes, the healthcare industry falls short.
Investing in a healthcare organization’s cybersecurity can mean the difference between life and death. The first known death as a direct result of a hack occurred in a 2020 hospital ransomware outbreak. While most attacks do not have such a dire consequence, they often result in loss of money and a tainted reputation.
Only 23% of healthcare companies use DMARC in any fashion, according to research released jointly by the National Health Information Sharing and Analysis Center, and the Global Cybersecurity Alliance. The research findings also report that only 2% of organizations utilize DMARC to safeguard their external users such as patients from phishing and spoofing by employing quarantine or reject policies on their domains. Another 21% use DMARC to monitor unauthenticated emails but do not use it to reject phishing emails.
Spoofing of email domains, also known as impersonation assaults, is still a leading vector for cyberattacks for the vast majority of significant healthcare organizations across the world. Phishing and spear-phishing are two of the most common attack vectors in healthcare, and they can result in patient harm, financial fraud, or breaches of protected health information (PHI), as well as fines under the Health Insurance Portability and Accountability Act (HIPAA). Because phishing emails are simple to create and deliver, threat actors are enticed to employ them again.
Such attacks occur frequently because the healthcare industry hasn’t adopted DMARC (Domain-based Message Authentication, Reporting, and Conformance) on a large scale. DMARC is an email authentication protocol that identifies and prevents email spoofing. On implementing DMARC, healthcare organizations can safeguard their email systems so that employees aren’t the only line of defense between attackers and their targets.
Before a fake email enters an employee’s inbox, DMARC gives an automated command to eliminate it. In this way, DMARC assists in preventing hackers from pretending to be associated with your organization from sending emails to internal or external parties.

Healthcare Data Breaches Stats
- Hospitals account for 30% of all large data breaches.
- 18% of teaching hospitals reported that they had experienced a data breach.
- 6% of pediatric hospitals reported data breaches.
- 34% of healthcare data breaches come from unauthorized access or disclosure.
- By the end of 2020, security breaches costed healthcare companies $6 trillion.
- Between 2017 and 2021, the healthcare industry is estimated to spend roughly $65 billion on cybersecurity.
- In February 2020 alone, 1,531,855 records were compromised in 39 healthcare data breaches.
- In 2020, data breaches affected 26.4 million records in the US alone.
- At $408 per record, healthcare data breaches are the most expensive of any industry.
- Hackers or other IT incidents are responsible for 47% of healthcare data breaches.
- Unauthorized access or disclosure is responsible for 34% of healthcare data breaches.
- A breach was only discovered by 39% of healthcare institutions months after it occurred.
- Healthcare will be the target of about 240 million hacking attempts by 2020.
- The Anthem breach impacted nearly 80 million people.

Healthcare Industry DMARC Adoption
DMARC adoption – Currently, 390 large healthcare organizations do not have a DMARC record on their domains, accounting for 71% of all large healthcare companies.
None Policy – The None (Monitor) policy is used by 25% of healthcare institutions.This policy detects but does not prevent authentication abuse. We may conclude that over 92% of healthcare firms are exposed to domain abuse, leaving their customers and email receivers vulnerable to phishing and email fraud.
Quarantine Policy – The Quarantine policy, which forwards emails that fail authentication to the defined spam folder, was applied by about 1% (8 enterprises).
Reject Policy – Reject policies have been implemented by 3% (16 enterprises) to prohibit messages that fail authentication. This is the ideal state because it prevents attackers from impersonating a brand.

How can DMARC help?
Apart from giving companies and organizations guaranteed security and complete control of their email domains through DMARC’s implementation, EmaiAuth has many other advantages. You can read more about them here.
EmailAuth provides a free DMARC Record Checker to display your record, test it, and verify that it is valid. All you need to perform a DMARC check is to provide your domain name. The tool will then analyze and display your DMARC record along with other information. Similarly, you can also verify your DKIM and SPF records using EmailAuth’s free and automated tools: DKIM record checker and SPF record checker.
In case you don’t have a DMARC record published for your domain, you can use our DMARC Record Generator to generate a record instantly.
