HIMSS Cybersecurity Survey: Only 71 percent of respondents were able to identify percent of their organization’s budget allocated for cybersecurity. 60 percent say cybersecurity represented 3 percent or more of the budget, while the rest say the percentage is lower. Despite high-profile cyber threats, many healthcare organizations still have relatively skimpy information security budgets. The most commonly adopted is the National Institute of Security and Technologies cybersecurity framework. The vast majority of respondents say that they conduct a risk assessment at least once a year, but only a third of them say their organizations conduct penetration testing on an annual.”]
Source: https://www.govinfosecurity.com/health-data-security-making-progress-a-10186

