
| Characteristic | Percentage of respondents |
|---|---|
| Network | 67% |
| Workstations and servers | 63% |
| 58% | |
| Cybersecurity policies and procedures (and documentation) | 58% |
| Remote access servers | 54% |
| Cybersecurity roles and responsibilities | 52% |
| Physical security | 52% |
| Comprehensive (i.e., end-to-end) | 50% |
| Business and financial information systems | 50% |
| Inventory of assets | 49% |
| Clinical information systems (including electronic health record systems) | 48% |
| Legacy systems | 45% |
| Communications plan | 41% |
| Cybersecurity policies and procedures (and documentation) of a vendor, consultant, client, or customer | 40% |
| Mobile devices | 39% |
| Cloud provider/service | 37% |
| Infrastructure or services of a vendor, consultant, client, or customer | 33% |
| Insider threat actors and activity | 33% |
| Shadow IT (e.g., unauthorized applications, services, etc.)) | 32% |
| Medical devices | 29% |
| Internet of Things | 26% |
| Telephone systems | 24% |
| Website of a vendor, consultant, client, or customer | 21% |
| Procurement | 20% |
| Social media | 18% |
| Building automation system and/or other industrial control systems | 18% |
| Videoconferencing systems | 17% |
| Supply Chain | 15% |
The chart is not accessible to screen readers. Please switch to the table view to access the data.
Loading statistic...
Download
Source
Release date
November 2020
Region
United States
Survey time period
2020
Number of respondents
167 respondents
Special properties
qualified information security professionals in U.S. healthcare organizations
Method of interview
Online survey
Supplementary notes
Original question: "When conducting a security risk assessment, what does your security risk assessment include? Please select all that apply."
Citation formats









