IT Infrastructure
Dr. Manish Kohli, HIMSS Enterprise Board Chair, discusses physician burn-out and delivering insights for better clinical decision making, adding that success will come when the technology becomes invisible while patients are in front of doctors and nurses.
New Zealand’s Northern Region simulated a major cyberattack on its health system, saying it is a case of “when, not if” an attack will eventually occur.
healthAlliance systems operations manager Simon Long presented at the HiNZ Conference 2018 in Wellington on 23 November on the mock incident, called ‘hot chilli’, which was run by the shared services agency. healthAlliance is one of the most significant shared services organisations for the health sector in New Zealand and jointly owned by the four Northern Region district health boards (DHBs) : Northland, Waitemata, Auckland and Counties Manukau Health.
Long said low-scale cyberattacks on the health system happen on a daily basis and the mock incident escalated the scenario into a major attack that affected a number of systems.
“The objective was to create, test and improve a regional view of business continuity and the recovery capability,” he told attendees.
The exercise involved the four northern DHBs – Waitemata, Auckland, Northland and Counties Manukau – and was designed to be as close to real life as possible, so staff were not forewarned. Around 27,000 people work across the DHBs and healthAlliance.
The mock attack involved the email systems being unavailable due to hacking, no wi-fi access on the sites and the data integrity of the clinical systems being untrustworthy, meaning National Health Index numbers were not validated.
Webinar: The Future of Medicine: Protecting Privacy Without Impacting Quality of Care
The simulation started at 9am and finished around 4pm followed by a debrief and “it was a really interesting day for everybody involved,” said Long.
Key learnings were that one can never over-communicate in a crisis situation and the huge value of practice to get better and become more efficient.
Long said other organisations had since asked healthAlliance for help in this area and the agency is happy to share its learnings.
Ministry of Health chief security adviser Nick Baty presented with Long on his involvement with ‘hot chilli’ and how the experience has fed into the development of a health sector cybersecurity event response plan.
In the article “Ethical hacking: What to look for in a pen tester”, author Jessica Davis notes that simulated attacks on a healthcare organisation can help infosec leaders assess their security posture, but not all pen testers are created equal and not every provider is ready to be tested.
Pen testing is the practice of simulated cyberattacks on an organisation’s network or a specific function, such as IoT devices or web apps. The goal is to identify any system flaws or weaknesses and just how likely it is that a hacker can exploit these vulnerabilities. Lee Kim, director of privacy and security for HIMSS North America, said that a pen tester should have “real world experience and experience in business environments like [healthcare].”
A version of this article first appeared on eHealthNews.nz.
The device maker is betting the company's AI-powered security capabilities will help its enterprise customers, in healthcare and elseware, safeguard their connected devices.
Christiana Care Health System CISO Anahi Santiago discusses why hospitals have to invest in security tools to stay ahead of cyberthreats, but that it's just as important to focus on people and process as it is on technology.
John Daniels, VP of HIMSS Analytics, says there is more to digitizing an organization than installing EMR functions, and discusses other adoption and maturity models including artificial intelligence, continuity of care and infrastructure.
Cameron Ballantine, A/ Chief Information Officer at Metro South Health, discusses the challenges and rewards of his organization's journey toward becoming Australia's first digitized health service.
The Infrastructure Adoption Model helps hospitals and health systems benchmark how their IT systems stack up with mobility, security, collaboration, transport and data warehousing.
The issues shared during an Oct. 18 state senate meeting mirror those the healthcare sector faces: a lack of resources and an onslaught of attacks make it nearly impossible to keep up.
HITRUST launched a security program to help start-up companies bolster their privacy and security foundations, including the adoption of the most comprehensive risk management, compliance and security services.
WHY IT MATTERS
The goal is to support startups in adopting best practices as they grow. HITRUST is working closely with those small businesses to ensure these security features are baked into their products from the beginning.
To accomplish this, HITRUST is bundling and pricing its programs to align with small businesses that have been in business for less than three years, have fewer than 50 employees and less than $10 million in annual revenue. The program will streamline HITRUST adoption.
ON THE RECORD
“Navigating risk management and compliance requirements can be costly and a strain on internal resources and can be daunting for any company, but it can be compounded in start-ups that are focusing on bringing their vision to market,” Mike Parisi, HITRUST’s vice president of assurance strategy and community development, said in a statement.
THE TREND
HITRUST was formed in 2007 and is seen as one of the industry’s gold standards for security. In May, it launched a certification program for the NIST Cybersecurity Framework for hospitals and health systems to ensure security compliance.
The RightStart Program will ensure these startups embed these security standards into “their evolving business models,” Parisi added.
HITRUST officials stressed that often these types of security measures are seen as a barrier to adoption. And as a result, companies will add programs in an ad hoc way, which leads to a loss of time and money, without a guaranteed improved risk posture.
To Hoala Greevy, Paubox CEO, the hope is that the program will give the company the ability to adopt a security framework that will scale with the organization.
“HITRUST provides us with the tools for secure, compliant growth needed to increase our bottom line,” Greevy said in a statement. “Our customer focus demands we have security, compliance, and risk management in place by design and not as an afterthought.”
.jumbotron{ background-image: url("http://www.healthcareitnews.com/sites/default/files/u2231/cybersecurity-jumbotron-712.jpg"); background-size: cover; color: white; } .jumbotron h2{ color: white; }
Focus on Cybersecurity
In October, we take a deep dive into security strategy and pressing threats.
Twitter: @JF_Davis_
Email the writer: jessica.davis@himssmedia.com
A researcher discovered the North Carolina-based tech vendor is leaking protected patient data through its Amazon S3 bucket twice in a month.