Building a 911 Cyber Civil Defense System for Healthcare episode artwork

EPISODE · Mar 12, 2024

Building a 911 Cyber Civil Defense System for Healthcare

from Info Risk Today Podcast · host InfoRiskToday.com

The healthcare sector needs a 911-style cyber civil defense system that can help all segments of the industry, including under-resourced groups, to more rapidly and effectively respond to cyberattacks and related incidents, said Erik Decker, CISO of Intermountain Health and a federal cyber adviser.

Episode metadata supplied by the publisher feed · Published Mar 12, 2024

Embed this episode

NOW PLAYING

Building a 911 Cyber Civil Defense System for Healthcare

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary Ann Colbasek McGee, executive editor at Information Security Media Group, and I'm here with him speaking with Erica Decker, who is the CEO of Intermountain Health. Erica is also co-chair of the 405D Cybersecurity Task Group that advises the U.S. Department of Health and Human Services. Hi, Eric.

Hi, I'm Anne. So, Eric, back in December, the Biden Administration released a concept paper outlining a strategy for improving cybersecurity in the healthcare sector. Since then, the U.S. Department of Health and Human Services has issued guidance detailing essential and enhanced voluntary cybersecurity performance goals for the healthcare sector.

What do you think of these essential and enhanced goals? How do they differ from what organizations should be doing under the HEPA Security Rule, for instance, or by what's recommended by the Health Sector Coordinating Council's Health Industry Cybersecurity Practices, or HICAP, for instance? Yes. I like to think of the CPGs as clarity, to very specific adversarial tactics that bad actors are using.

So, the way we get beat today, by and large, is through hygiene issues, or lack of hygiene. And the CPGs were actually written to take into consideration, first of all, HICAP, the Cybersecurity Framework, the other 16 critical infrastructure CPGs that were announced two years ago. And, you know, and HICAP has been around for almost 20 years now, the HICAP is a security rule. And all of these are really, if you think about a nice venn diagram, they all co-mingle with one another.

The easiest way to think about the CPGs are they are very specific outcome statements that will help you drive resiliency inside your organization, and they map directly to HICAP. So, if you've already done HICAP, then you're actually probably already done the CPGs, you should just go back and look at that specific outcome statement and see are we meeting the intent of what that is. If you haven't done HICAP yet, then the outcome statement is going to tell you what you need to do. So, speaking of the coordinating council, it recently updated its five-year strategic plan, what stands out about this plan, what's changed the most over the last five years, and how does this plan compare or contrast with what HHS has set out so far in terms of the Biden administration's plans for boosting healthcare cybersecurity?

Yeah, so first of all, I think the plan is for sure complimentary of a national cybersecurity plan. You know, this plan essentially contemplates what do we need to do to get from critical condition that we're in today to stable condition by 2029. And we looked at the five major trends that are happening in healthcare. So things like convergence in mergers acquisitions, emerging technology that's happening, hospital into the home, you know, those kinds of market pushes that are happening by the sector.

And then ultimately, what are 10 goals that we need to face in order to achieve a stable environment, 12 objectives that would actually do those goals, and a mobilization of exercise. You know, the strategic plan, back in 2017, the original strategic plan that was released was called the HK Task Force Report. And so we took that, we took actually some of the earlier members of that group, and we updated all of that in the new landscape. I think some of the stuff has changed.

I mean, for sure, the financial pressure has been astronomical. The emerging technology, you know, the AI has been around for a long time, but the emergence of generative AI and large language models is really, you know, pushing the seams of stuff. And so this plan ultimately gives us the framework to work within in order to meet those challenges. So the five-year strategic plan from the health sector coordinating council, this kind of spotlight the idea of a 911 cyber civil defense.

What might that look like? What do you envision? And do you think this will ever happen? I wanted to have to.

You know, think of it as like mutual aid, you know, fire fire departments within, especially like rural areas. They don't have enough firefighters in one particular area to deal with a catastrophic issue. So they have mutual aid agreements with other firefighters. And if something happens, you need a five, six, seven, ten alarm, you know, response, you can bring in those companies, those other fire departments and do that.

You know, a mutual aid, a 911 for civil defense is like that. You know, it's how can Intermountain help others, you know, how can we either drop ship in cyber people or clinical people in order to deal with response to other folks? How can the federal government actually enable responses like this? I mean, we could, we know for a fact that some of the most important services in the middle of a ransomware attack are imaging services or lab services.

Actually, even before the EMR needs to come back online, those need to be online. So there already exist today, remote imaging solutions or the ability to drop ship, you know, mobile imaging systems, you know, into areas. Or why can't we stand up a cloud-based EMR that is just on the side ready to turn on in the case of one of these very disruptive events to just kind of weather through it. So those are some examples.

Are we going to get there? Boy, we're going to push hard on this. And the thing is that's really insightful and just that's exciting is we have that partnership in place now. We spent the last five years, you know, really establishing that.

We have the ear of the highest levels of the United States government and they all are nodding their heads saying we need to do something like this. Now it's just the means of how do we do it? Like how do we actually accomplish it? So that's next.

So now HHS says it plans to update the HEPA security rule. What sort of updates would you like to see? And is there a risk of an updated rule becoming too prescriptive? Yeah.

The classic thing, HEPA security rule has been around for a long time. That's either a positive thing or it's a negative thing, you know, and that it hasn't changed. So does that mean that it's whether the test of time, which is the reason why it hasn't changed or something else? You know, I think we have to hit the balance between a level of uniformity of the very basic things that must be done.

And you know, I really do believe that there's an environment of care for cybersecurity and I do believe that at least the essentials and the CPGs, you know, meet that. And you know, just like you don't go into an operating room without having the right environmentalist in place, the right temperature, the right sterilizer equipment, without scrubbing up, without masking up and allowing everybody in that operating room to stop the procedure in the case of something dangerous going on, not just the surgeon. We don't have that in cyber and health care and we need that. You know, some baseline that says this is, this has to be at least the minimum.

The thing that I worry about and that everybody worries about is everybody will just run to the minimum and then just say that's enough, like and nothing else is needed. We have to make that balance. I hope that the security rule when that gets updated will acknowledge the need for both. For sure, we'll provide that kind of input into it.

And you know, but at the end of the day, you know, we all must be thinking about this and adversarial mindset. We are getting beeped through hygiene. We are getting beeped. If you look at the essentials and the CPGs, those are the methods by which we get initially compromised.

And if we can get better at that defense, it's honestly going to be that much harder than for the bad guys to do what they do. And that's a good thing. And Eric, you mentioned AI and health care. What are you watching in terms of potential impact on cybersecurity of health care organizations, both the good and the bad when it comes to AI in health care?

Yeah, so this is very new. And I think the practical things that we've seen already are, you know, the deep fakes and the ability to do very targeted attacks through AI. You know, I've heard some very scary stories about, you know, people getting phone calls from their kids. And it's not their kids.

It's just a couple of snippets of soundbites that have been thrown through an AI algorithm and they were able to make it sound like that as an extortion mechanism or, you know, using that to do more social engineering types of attacks. And I think as the AI models that specifically the generative AI models get better and more accurate, for sure they will use it after the basics that they're doing today are nullified. So we just got to stand of course with that. You know, I hear a lot of stuff out there about self-replicating malware through, you know, I heard another one just the other day where it was an attack against like co-pilot where you send an email that has some embedded malicious code inside of it and it causes co-pilot to go out and do stuff.

I mean, that's an interesting tactic, nothing that I've seen actually materialized yet, but I could see that becoming a future thing, you know, just leveraging the AI models themselves to do bad and harm by triggering them in some method, you know, inside your environment. So just, we have to keep an eye on that and keep at it. And finally, what else are you keeping your eyes on these days with cybersecurity and the threats particularly in healthcare and being back to healthcare? I mean, the biggest thing I'm focusing on right now is hygiene and what I call hygiene to the edge because it makes it sound so easy to just do hygiene, but it's not.

I mean, like we do it every day all day, we're practicing good hygiene or bad hygiene, you know, when you fail to wash your hands, the time you're supposed to wash your hands, that's failure in hygiene. Unfortunately, in our space, that could be a technology that's on the Internet or it could be a third party vendor that has a connection to us and they failed something and it just takes one little miss of that to cause the initial compromise, initial activity of an incident. And, you know, I think we have to, for me, it's about measuring that, like, how do we get to a really more comprehensive understanding of where our hygiene is and the continual nature of the performance of that hygiene, of those hygiene practices? And I think that's a really important skill, really important thing to have inside your arsenal.

Well, thank you so much, Eric. I've been speaking to Eric Decker. I'm Mary Ann Kolbasak-Bighi of Information Security Media Group. Thanks for joining us.

Thank you very much.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on March 12, 2024.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!