Bolstering Healthcare Cybersecurity: The Regulatory Outlook episode artwork

EPISODE · Feb 7, 2024

Bolstering Healthcare Cybersecurity: The Regulatory Outlook

from Info Risk Today Podcast · host InfoRiskToday.com

The Biden administration's strategy for bolstering health sector cybersecurity, which includes newly released voluntary cyber performance goals and plans to update the HIPAA Security Rule, is fueling uncertainty in some organizations, said privacy attorney Iliana Peters of law firm Polsinelli.

Episode metadata supplied by the publisher feed · Published Feb 7, 2024

Embed this episode

NOW PLAYING

Bolstering Healthcare Cybersecurity: The Regulatory Outlook

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary Ann Kolbasek McGee, executive editor at Information Security Media Group. Today I'm speaking with privacy attorney, Iliana Peters of the law firm Pulse and Ellie. We're going to be discussing efforts underway by the Biden administration aimed at raising the bar for cybersecurity in the healthcare sector. So Iliana, the Biden administration in December, issued a strategy document outlining a number of proposals for how to improve cybersecurity in the healthcare sector.

As part of that effort, the Department of Health and Human Services recently issued guidance specifying certain voluntary cybersecurity performance goals that healthcare sector entities should strive for. Those CPGs are broken into two categories, essential and enhanced. HHS also indicated that these so-called voluntary goals will inform new enforceable cybersecurity standards. So with all of that said, what do you think of this strategy overall as it's been discussed so far?

What stands out about the cybersecurity performance goals? So I think in order just to sort of level that here, as you mentioned, this is, you know, a White House initiative, this administration's initiative. It's much bigger than healthcare, obviously, and not just HHS, but as you mentioned, HHS published a white paper or concepts paper that they're calling concepts paper that really walk through sort of four specific steps that HHS intends to take to make improvements to the sector, the healthcare sector related to cybersecurity. And so the first of these was to establish these voluntary cybersecurity goals for the sector.

Obviously, there are three other initiatives as part of this white paper that were published. You know, there's some thoughts about at least initially what some additional investments and resources for the sector might look like right now. HHS is targeting high-need healthcare providers, turning using the white paper, and they basically say that includes sort of very low-resourced hospitals, and potentially an incentive program for all hospitals. So, interesting to me that they are sort of focusing on hospitals in this respect because, of course, they are critical infrastructure and we absolutely want to make sure that our hospitals have the resource they need to implement cybersecurity, but the healthcare sector is very big and there are a lot of folks with problem-desired hospitals that are arguably critical to the sector too.

So it's interesting to me first of all that they focus this particular piece on hospitals. And then, you know, there's some conversations about additional guidance and additions to goals, and then, you know, they have this third piece that is about greater enforcement and accountability. And, you know, I just really wanted to sort of process our conversation because I think this ties very closely into your question about the goals themselves. Is that they're, you know, this particular focus on greater enforcement and accountability, I find somewhat problematic because there are indications in a white paper and, you know, on the HHS regulatory calendar, the secretary's school-making calendar that HHS and the office for civil rights, so that's the office I used to work in that's responsible for HIPAA jurisdiction and enforcement, is that that office will be undertaking updates to the security role and according to the white paper to include new cybersecurity requirements.

Interestingly, the goals that were published right after this white paper to address the first piece of the white paper, that is, again, to provide the industry with voluntary goals, these goals are arguably already required under the HIPAA security role. So, and they're, you know, the goals are very interesting because if they divide the goals into essential goals and enhance goals. And the essential goals are obviously, you know, very important things like encryption, training, ensuring that we have the correct access controls, planning and preparedness for incidents for security evidence. Again, all of that is already required under the HIPAA security role.

Similarly, the enhanced goals, so this would be sort of even going above and beyond these essential goals, these would arguably be more of a best practices type of idea, at least a way that is characterized in the guidance from HHS with regard to enhanced goals. These two are things that are arguably already required under the HIPAA security role, after inventories, understanding where your vulnerabilities are, incident reporting, responder reporting, testing, you know, all of those things are arguably required under the HIPAA security role. So, I ended up a little confused after getting these additional guidance documents and taking a look at them because it's not clear to me first from the, you know, the original concept paper where the HIPAA security role really needs improvement. Maybe the idea is we're just going to make things more clear in terms of cyber security overlap with what's already there.

All of these pieces are meant to increase the confidentiality, integrity, and availability of electronic data discovered by HIPAA. And so maybe this is about just clarifying, okay, these are the cyber security pieces that are very important, part of all of that underlying data security work that you're doing to comply with HIPAA. But, you know, I frankly was very surprised that these goals aren't particularly advanced goals. They are arguably already what the vast majority of the health care sector should be doing if they're trying to comply with HIPAA.

So, I think there's a bit of disconnect in terms of where we're trying to go and the resources that are available at least so far, particularly given that, you know, HHS focuses its enforcement on entities that are already reporting breaches. They're already reporting to HHS when they're having a cyber security incident. And, arguably, there are a lot of entities out there that are, and HHS isn't looking at those right now. And it has the authority to do that already.

You know, they have a lot of compliance with the authority, they have audit authority after the high tech act, they haven't used in years. And so it's very, it's just been clear to me where the sort of additional work that HHS intends to do in terms of improving sector security is as part of these four articulated steps in the concept paper, and then as far as the goals are articulated in the additional guidance that was just published. With that said, Iliana, do you think HHS might try to make the HIPAA security world more prescriptive, you know, because they're diving into types of encryption or anything that's more specific? And I thought the whole idea of not being overly prescriptive was to leave it sort of general enough to sort of fit into whatever the technology is all in the future.

Exactly right, Maryam. And I think that's a really hard question, right? Because you're exactly right. The HIPAA security role is always meant to be flexible and scalable, and the safeguards that are required are supposed to be reasonable and appropriate for the enterprise.

And that looks very differently depending on the organization that we're talking about. You know, one box shop that outsorts all of its cybersecurity to IT vendors or cloud vendors and really has no ability to control the safeguards for their data because they outsource everything. And that's a very different kind of problem in quotation marks in terms of cybersecurity problems from a very large health system. And those risks look very different for those two types of organizations.

So again, I think your question is right on because it's just not clear to me what these changes to the HIPAA security role are going to look like. And maybe you're right. Maybe it is more prescriptive or more specific requirements or revisions to requirements that make it more clear exactly what's expected. You know, maybe reviving some of these factors or implementation from addressable to required.

You know, if we always have that pushback about encryption for example, and whether or not it's optional, even though it's not, it's just meant to be addressable to your point. We must implement encryption or the equivalent of that in our enterprise. So maybe there are clarifications that HHS is contemplating to make these requirements more specific in order to address specific cyber issues. But if that's the case, then, you know, it's a bad example.

If we move to quantum computing and the HIPAA security role says encryption is required and quantum computing is at some point better than encryption. You know, we're going to get stuck with encryption and not be able to pivot. So I think, I think, you know, this remains the rub with making very specific requirements into law and data security because things change so quickly. And we have to be nimble in order to make sure that the next best safeguard is one that is deployed rather than being stuck with an out of date requirement.

And I think NIST is very good at that. You know, they are consistently updating special publications and guidance that they give to all latest related to what these different controls should look like in different sectors. And so, you know, I would hope that maybe what HHS is contemplating is, you know, something more along the lines of streamlining requirements such that we can more specifically integrate available guidance for industry, including from, for example, NIST. So, you know, that's part of the recognized security practices in quotation marks state hardware that Congress developed in a Trump signed related to kind of HIPAA enforcement, again, in quotation marks state hardware that turns not used in the statute.

But the statute specifically refers to NIST guidance and the implementation of NIST guidance in order to reduce penalties associated with, for example, HIPAA security role violations. So maybe, maybe that's where we're going. I think it could be really helpful in terms of referring more specifically to other federal government guidance documents that are much more specific but are regularly updated. So that, I think, would be very much appreciated by the industry while not sort of boxing up into any particular standard that could become obsolete at any moment.

So, Eliana, in terms of the concept paper from the White House sort of, I don't think, hinted or they outwardly said about perhaps new incentives for health care entities to raise the bar on cybersecurity efforts. Perhaps there's going to be sort of a mix of sticks and carrots when it comes to that idea of the enforceable regulations. What do you think we might say? Will there be new Medicare reimbursements, perhaps, to cybersecurity?

You have a fines. What do you think this might look like once it kind of shakes out? I wish I had a crystal ballroom because I think this is really where the rubber meets the road in terms of how this is going to significantly affect regulated entities, particularly have a regulated entities in the health care sector. Yes, I do think that, again, as I mentioned earlier, HHS is looking closely now because they said they are at trying to figure out the carrot approach.

What does that look like? And I think my concern, again, as I mentioned, is that the carrots are only going to be offered to certain types of hospitals. And I'm not convinced that hospitals are the only ones that need the carrot. So, you know, I think my hope is that once HHS starts sort of looking at what these carrots might look like, what these incentives and additional resources might look like, that they consider entities beyond certain types of hospitals.

This is a really hard question because the resources from sort of a beyond just a money perspective, personnel, devices, applications, this is hard work. And a lot of entities don't have the good support that they need, both from their own personnel because there's just not enough people to hire in this cyber sector, as well as from the contractors they may be using, because a lot of these contractors don't have familiarity with HIPAA. Don't understand what the HIP controls are supposed to look like. They don't know how to do written analyses and written management from a HIPAA perspective.

So, there is a real deficiency in terms of the resources available to all of these regulated entities and not just certain types of hospitals. So, it's still unclear to me that even if we make more funding available, how are we going to make sure that funding goes to the right thing, because a lot of times those things aren't available. I mean, there's just not enough people, there's not enough good contractors, there's not enough, you know, do it yourself kind of resources that the hospitals can implement. They're going to need help.

So, I would hope that HHS, in looking at how to distribute these additional funds, if that's where they go, whatever that looks like, is really tied to some type of additional education, other types of resources, not just money. And maybe it's the regional extension centers that need to be tasked with this. You know, maybe it's regional offices for HHS that need to go out and do education campaigns like we did with the high tech act and the state attorney general. You know, it's very, I think, important to look just beyond additional funding into how are we actually going to get these entities that resources that they need.

Of course, they need money. They always need money. But if we're really going to try them as a bar in cyber security, we need to know how to help these entities implement the right data. And that's of course funny, but it's also instruction, education, resources in terms of staffing and those types of issues.

And then on the other side, good question. Again, you know, yes, you're absolutely right, HHS is indicating that CMS is going to propose new requirements. I would expect those to be through participation requirements or other reimbursement requirements. We're still having issues trying to get meaningful use right.

And, you know, we don't even call it make a use anymore. We call it interoperability and information blocking. So that's been a multi-decade challenge in terms of the incentives there and the sticks there. So, you know, I don't know what CMS contemplates the cyber security requirements to look like in terms of what is, how is that even going to be implemented?

And then on top of that, from both of CMS and an OCR perspective, do we really want to be penalizing entities who are trying the best they can? And maybe it's not great, but maybe it's better than entities that aren't resourced by CMS and aren't reporting breaches to OCR or the data. Again, I'm still trying to figure out how we raise the bar with regard to those entities, and it would seem to make sense for at least OCR to look at some of those entities. Because if we can't raise the bar for the majority of entities in the healthcare sector, it's a very connected sector, both with regard to vendors, with regard to supply chain, with regard to systems and interoperable medical records.

You can't raise the bar for everyone, including those entities that arguably aren't doing much now, including not reporting breaches, then we're never going to raise the bar for the entire sector. So I would argue that HHS really needs to start looking more closely at how to get at not the entities that are reporting, because they're investigating all of those breaches now. And arguably those entities are trying to notify people of when these cyber security incidents occur, and really try and get to the entities that aren't putting any controls in place and aren't reporting. And I think that to me would be a more productive next step in terms of the stick, rather than just increasing the burden on those entities that are trying to do the right thing already.

So, Iliana, do any of the proposals by the Biden administration, the way they're kind of floated right now? You think any of them will require action by Congress, you know, extra authority for HHS to do certain things? And then what's the likelihood that we all see a divided Congress agree on anything related to healthcare cyber security regulations anytime soon? I think the answer is yes.

I mean, to the extent that we need increased civil penalties, civil money penalties, under HIPAA, for example, HHS has already indicated in the concept paper that the idea is that they will continue to work with Congress to try and increase those panels. They're already arguably quite high, despite the fact that the Trump administration sort of downgraded those penalties pursuant to a notice of enforcement discretion. So, you know, I think arguably HHS could just revoke that notice of enforcement discretion and go back to the law, the way it was written prior to that notice. But certainly, you know, HHS has indicated that they will continue to work with Congress on this.

In terms of a divided Congress, surprisingly, data privacy and security, and I think this is reflected in the recent issues related to children in social media. I think data security is surprisingly a bipartisan effort. So I think my concern there is less whether or not Congress could do this in terms of a bipartisan effort. I think they absolutely could.

I think my concern is more number one, what does this look like? And in my opinion, it should look like trying to enforce against those entities that aren't doing anything and aren't reporting breaches using the tools that HHS already has, but also the bandwidth. You know, I think Congress just, as you well know, and it doesn't have a lot of bandwidth now for a lot of these sort of more day-to-day and less cyber security is absolutely patient safety. And I think HHS trying to change the conversation in that way is really helpful, but trying to get Congress to focus on cyber security in that same way.

As compared to, for example, children who are committing suicide because of online bullying and those sorts of issues, you know, obviously, Congress is going to concentrate on the issues where there are immediate life circumstances and not necessarily the ones where we absolutely know patient safety isn't to show particularly in certain types of cyber attacks, but maybe isn't quite as visible. You know, so I think the arguments are absolutely there. And I think this is certainly something that Congress could get on board with, but it's still not clear to me what the specifics should be and whether or not Congress will have the bandwidth to actually address those specifics. So, Eliana, when it comes to potential rulemaking, such as potential changes to the HIPAA security rule, as we know, the rulemaking process is very slow.

So, realistically, if the Biden administration wants to see changes made to the HIPAA security rule or any other sort of related regulations that would need rulemaking to, you know, raise the bar on cyber security, how much time does HHS realistically have before a potential new administration comes in January, for instance? We've seen it before where, you know, some rulemaking with HIPAA started, I think, under the Trump administration, and it didn't really go anywhere after that. What's the likelihood that, you know, the Biden administration could start something with rulemaking with the HIPAA security rule, but then those plans get scrapped, and it kind of leaves the industry wondering, well, what's next? Excellent point.

I mean, we were all, I think, very interested to see where the rulemaking for coordinated care in the privacy role, the HIPAA privacy role, was going to end up, even though the proposed rulemaking, and as you know, Mary Ann, that's been trapped to your point. Because this administration priorities are not necessarily that coordinated therapies and are more related to reproductive health, which we have a forthcoming final rule on, and then this cyber security piece. So, we know that the Department is prioritizing and notice that proposed rulemaking related to cyber security and changes in the HIPAA security role. We know that's already on the Secretary's calendar for publication in the fall of a notice of proposed rulemaking, but you're absolutely right.

To the extent there is a different administration, or even if it's the same administration and the priorities shift, then we could end up in a situation where, again, we have yet another notice of proposed rulemaking that's never finalized. And I think that, you know, that's obviously problematic, because we've had several of these tips and starts related to the enforcement after the high-tech rule. We still don't have a final rule related to, or even a notice of proposed rulemaking related to how we're going to share penalties with armed individuals, the accounting of disclosures, requirements for the high-tech acts of number and finalized, you know, the coordinated care pieces, which would arguably be really helpful, particularly given HHS has a current enforcement initiative on just those issues, and we still don't have the guidance on them. It's really hard for the industry to be dealing with all of these questions.

It means I will always have a job, but I would love for my client to be able to, you know, figure this out on their own, and until we get additional guidance from HHS and Office for Civil Rights specifically, if we're talking about HIPAA, that's going to be really hard. So I think it is important for my perspective that these rulemaking efforts are followed through to completion, and if we have a change in political leadership, that's going to be really difficult. It's going to be hard to continue to have these in conversations and make sure that we get good guidance from HHS about these issues. And finally, Iliana, anything else that you're keeping a close eye on in terms of cyber security regulations or legislation, or any other issues pertaining to the health care sector this year, that we haven't mentioned?

You know, I think that's a really good question. I'm always looking out for additional guidance from, for example, NIST. You know, I think we're all watching the contribution of the ongoing related to website tracking in Texas, because that particular piece of HIPAA guidance has been extremely problematic for the industry, for a multitude of reasons, and that does arguably have a bit of overlap with the data security requirements, not necessarily cyber, but certainly data security and security response and breach and all of those questions. So definitely watching that and looking for additional clarification from the department on that piece.

And then certainly we're watching the enforcement, because as I said, you know, we're seeing really aggressive enforcement by HHS and the Office of Civil Rights right now. And it's related to, for example, ransomware, because ransomware is so prevalent in the industry right now. And so we're getting really onerous requests in terms of these investigations. These investigations are taking years to reach a conclusion, and many of these are resulting in conversations about settlement with HHS.

So I think we're going to see a lot more of these types of cases coming out of OCR in terms of settlement and civil money penalties. And I, again, I'm not sure that's the best use of industry dollars. In other words, HHS OCR used to have a reputation of really aggressively working with regulated entities to take funds and fix the problems in their organization in a proactive way through proactive action without a settlement agreement or stable or civil money penalties. And now we're seeing a shift.

I think it's been a long time coming, but the shift really is about, you know, moving those dollars to OCR and not about investing those dollars back in the organization. You know, so I think we're all watching those enforcement pieces because it's been a really challenging few months in that respect, both from the fact that we're having to respond to these massive ransomware incidents. We as an industry, and then we're having to respond really about the enforcement related to those statements. So it's a lot of fatigue.

And I'm hoping that, you know, HHS will take that into account as they provide additional resources, additional data, additional rules to try and make it easier. I would hope for the regulated industry. Well, thank you so much, Iliana. It's been a pleasure.

I've been speaking to privacy attorney, Iliana Peters. I'm Mary Ann Coba, Second Guy of Information Security Media Group. Thanks for joining us.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on February 7, 2024.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!