Cybercriminals often target health care organizations because they are notoriously vulnerable to identity theft. Personal health information (PHI) is lucrative, and fraudsters relentlessly attack networks, systems and applications that have been misconfigured or poorly maintained. To respond effectively to health care security risks, a CISO must possess well-rounded experience in several areas that go beyond privacy and security. The CISO is responsible for protecting patients health data, which requires collaboration across the organization and with business partners such as vendors and insurers.”]
Source: https://securityintelligence.com/the-cisos-guide-to-minimizing-health-care-security-risks/

