I'm Mary Ann Kolbasek McGee, Executive Editor at Information Security Media Group, and I'm here at the HIMS Cyberform in Boston, speaking with Renee Broadbent, who is Chief Information Officer and Information Security Officer at Southern New England Health. Renee is also President of the HIMS New England Chapter. Hi, Renee. Hi, thank you for interviewing me today.
I'm looking forward to it. Thank you for joining me. So, Renee, for starters, for those who are not familiar with Southern New England Health, tell us a little bit about what kind of healthcare organization it is, where is it based, you know, what sort of patients to secure for. So Southern New England healthcare organization is based on a Connecticut, Massachusetts.
It is an accountable care organization in a clinically integrated network. We manage up to 18 different contracts from payers. We have about 175,000 lives under management, and we offer primary care, and we have specialists under our practices, and we basically manage to value-based care contracts. So, for example, our largest risk contract is MSP, right?
So, we're a Medicare population, and in Massachusetts, we have a Medicaid population management, Medicaid and Mass. So, we have a very diverse network that we manage the health of the most critically ill. So, now Renee, what are some of the biggest cybersecurity and privacy challenges that your organization is facing right now, and how have they been evolving lately? So, because we are an organization that's clinically integrated, right?
So, when you hear those words, you think about data, right? And data comes in all different sources. It comes from EMRs. It comes from the claims that the providers give you to help manage those patients.
So, the concerns we have is we have data from a lot of sources, and data has to get stored. And then we take that data, and we use it, send it to third parties for them to do work for us, like analytics and things like that. So, our biggest concern is the movement of data around, and at what points it's always protected and secured, and it's bigger than a bread box, right? So, it requires multiple stop points and checkpoints and things like that to make sure our data is, you know, encrypted at rest and movement, and that are folks that we're doing business with, that help us manage our business and deliver the report, and they also are setting the highest security standards.
And we put arrangements and agreements in place with them to ensure that they're protecting our data as well. So, it's an evolving thing because the cyber hackers of the world and thieves of the world are constantly evolving. Their skills, we have to stay on top of our skills too, and really be very introspective about what we do. So, now you also mentioned how important it is for the data that's exchanged to be secure, and as you know, we rely a lot on third-party vendors, and we're seeing a lot of large breaches, particularly this year, involving secure file transfer companies such as Progress, Software's Movement Application, Fort for Go Anywhere software, with that said, how do you get a better handle on those sorts of situations that might be out of your control, vulnerabilities in software, you know, being exploited, many clients of a software company being affected, and were you affected by any of those or others?
No, we've been fortunate, not going to would. However, we have, and actually we're just talking about it in the presentation I did that we didn't get to, and that is about how you manage your third parties that are doing your data, right? And I think a couple of things, one, you have to be super selective about the vendors you choose to do business with, right? And you have to exact high-level security standards out of them.
So, for example, if we're going to engage with a vendor who's going to provide any services that touch our organization, or that particularly touch our protected health and information, we have a whole litany of things that they have to do, right? They have to be high-trust certified. They have to do an NDA. They have to do a BAA.
They have to be subject to a random audit. If I feel like they need to have an audit, there's a whole litany of things that we do that they have to actually supply into all of those things before we'll sign on the dotted line, and if we're not willing to do that, then I'm not willing to do business with them. And that's what vendors who want to be in business with healthcare have to get used to that. We have to control what we can, and, you know, if we're doing business with them, they have to live up to the highest level of standards as well.
So now, as you know, we hear so much about generative AI and AI in general in healthcare. Are there any new or emerging use cases that you've either been implementing or are testing involving generative AI in your organization, and where do you see the most promise in general in healthcare? Yeah. So we're not implementing it right now.
So in an accountable care organization, yes, we have the oversight management for the management of the management line, but the doctors have their own practices, the hospitals have their own stuff. So, you know, we don't necessarily implement clinical measures in terms of, you know, using AI to help us do that. So we're a little bit kind of out of that realm for the moment, right? So I do think that there are opportunities from a medical continuity perspective, you know, clear notes, clear integration, but I think that there's a lot that needs to be done first before we get there.
And you know, we at New England HAMS are having a conference in October at the College of the Holy Cross, which our entire day has spent on how it's being used in health and in medicine. And I think there'll be some really good things that come out of that. But as far as I'm concerned, first zone, we're not there yet because of the role we play in the clinical management. I do think there's going to be some benefits to doctors down the road in patients as well.
In terms of the doctors and the patients, where do you think the biggest benefit will be? You're able to use generative AI to produce information that could potentially be helpful. So for example, you might produce something like for a patient about a particular illness or a particular medication that you can easily, you know, get all the data in one place and send it to them. I also think it helps in aid in documenting a more complete medical record.
Right? So some of the challenges right now with data and interoperability is, right? You don't get the complete medical record because this one won't give you their data. You don't have all the data.
But I do think AI has the opportunity to tie that complete medical record together. Are there any potential cybersecurity and privacy risks about AI that were you? All of them. I just think there's not a lot of guardrails around it right now.
And so I think there's a lot of potential for abuses. There's already been one reported case of a cybersecurity event using AI because it's relatively new. There's not a lot of education on it. So people are using it willy-nilly because you can get stuff for free.
You can do all this stuff. And I think what ends up happening is people see it as a solution and then just implement it without really applying the rigor that's associated with it. I think it's a whole new opportunity for the bad actors of the world. And I think we need to really get on top of it and start to explore.
But it's so new right now. You have to be worried about everything. And finally, as we look ahead to next year, what's on the top of your priority list when it comes to cybersecurity projects or priorities? So what we did is we created a strategic security plan that gets updated every year and we have specific tasks or things that we would like to implement.
We have, when I first got there, they needed a lot of work on a security thing. So we've come a long way. And I think for next year, we really want to look, we continue to look at our endpoints and things like that to see what other tools that we can use and other processes we can put in place to continue to protect our perimeter and that data in there. And I think we'll have to be tightening down the expectation from our vendors because the payers are requiring us to do it, right?
And so those are kind of some of the things on the horizon that I'm looking to do. The other thing is we have a real-time risk monitoring solution and we're really leveraging that to follow up with the vendors who are coming up in that report and, you know, whatever. So I think we're in a monitoring phase and then we want to kind of open up and see what we do need to be considering for AI and if we have a practice that's implementing it and then it gets mixed in with our data, like what do we do about that? So I think that there's a lot of opportunity around that.
Well, thank you so much. I've been speaking to Renee Broadbent and I am Mary Ann Cobas, like McKee, all the information security media group. Thanks for joining us. Thank you.
Appreciate it. Time.