Considerations for Building Successful Security Governance episode artwork

EPISODE · Apr 18, 2023

Considerations for Building Successful Security Governance

from Info Risk Today Podcast · host InfoRiskToday.com

Effective security governance in a healthcare entity is a balancing act that requires sponsorship by top leadership and careful consideration of the concerns of clinicians and others in the organization, according to Eric Liederman and deputy CISO Steven Frank of Kaiser Permanente.

Episode metadata supplied by the publisher feed · Published Apr 18, 2023

Embed this episode

NOW PLAYING

Considerations for Building Successful Security Governance

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary Ann Kolbasak-McGee, Executive Editor at Information Security Media Group. I'm here at HIMS today speaking with Dr. Eric Lederman, an internal medicine physician who serves as Director of Medical Informatics for the Permanente Medical Group and is National Leader of Privacy, Security, and IT Infrastructure for the Permanente Federation and also Steve Frank, who is Deputy Sissau of Kaiser Permanente. Welcome, Eric and Steve.

Thanks for joining us. Thank you. Thank you. So we hear a lot about the importance of cybersecurity governance, but what should healthcare entities be thinking about when implementing a cyber governance program and what are the considerations that the security teams should keep in mind when it comes to the impact of their programs on physicians and ultimately on patients?

Eric, you want to start? Sure. So protection is really just the other side of the coin from production. Everything that you want to have needs to be preserved, or else it may not be there, so you might as well not even put it in the first place.

So therefore, when taking the view, my view, anyway, of security governance is it needs to do mirror that of any other kind of important governance for the systems, technology, and operations that you have. It needs to go all the way to the top of the organization, and in our case, we have that. We have an executive sponsors group, but you also need to have a layer down, people closer to the ground. We have a steering committee with these folks with a broad array of perspectives, HR, compliance, medical group colleagues and I who are informatists, IT, and of course, you know, privacy and technology professionals and others, and then we have, you know, focus subcommittees on various topics.

Just the same way we do for making decisions around implementing and supporting our technology and operations in the first place, because if we don't protect it, then we might as well not have it. And Steve, from your perspective? Well, in the CISO world, I'm driven mostly by technology. I come in every day thinking about technical risk, and all the nuances around vulnerabilities and threats and sort of technology, but it's really only one part of the equation.

So when I think about governance, I want to make sure that the decisions I'm making, the solutions I'm recommending, aren't going to add unnecessary friction into the business, into care delivery in particular. That would be a recipe for disaster, right? I don't want to be the friction point. Now, how do I do that?

Well, we need a governance structure that can help us ensure that the decisions we make have been well thought through, that the impact of those decisions, whether that's on technical risk, privacy, technology delivery, or care delivery, is understood. I want to know that I have executive sponsorship, that what we're discussing is not going to be a surprise or inject any sort of chaos into the planning or budgeting or forecasting or human resources aspects of the business, but most importantly, I want to be timely and I want to have a governance structure that works. So we have a fortunate history of having good collaboration between the clinical side of the business and the technology side of the business at multiple levels. So now I understand that Kaiser Permanente designed and implemented a multi-layered joint security governance structure that simultaneously reduces security vulnerability while also enabling patient care and business operations.

What can you tell us about this and what went into building it? You want to start? Sure. So it all starts at the top, right?

So again, I want to know that when we're implementing a security program, there's buying it right at the very beginning. So our executive sponsors layer, the top layer, has the most senior representatives across a number of our critical functions to include legal and the CEO of our business. And this means that there's a backstop and there is endorsement for what we're doing. Then we have the steering committee level where we have representatives from technology or CIO, our CSO functions, our risk and privacy functions, and that way we can do the strategic engagement, planning, forecasting, understanding business risk and impact.

But then there's a level lower, more tactical, more technical, closer to the problem. We actually have two strategies there. One is our countermeasures forum, which exists in a structured way to bring both the clinical and the security side together each month to talk about any proposals that are coming, which could impact care delivery. And we also have domain-specific working groups that focus on things like cloud technologies or clinical technologies because there might be different players that need to come together for those environments.

There are many advantages to having a structured approach to governance that is implemented last over a long period of time and goes all the way up to the top of the organization. In addition to what you just discussed, Steve, I would say that as new issues and threats and challenges are identified, we have a structure to hang these off of. And so we don't have a bunch of free-floating ad hoc committees that are basically sponsorless and involve just talking with no action. I think we've all experienced being in committees like that in large organizations.

And what we have here is we have the ability to tag on some of the stuff. So, for instance, we first started this structure back 16 years ago during the Bush administration. Cloud wasn't an issue, right? I mean, we didn't have anything along those lines.

And many of the things that we've done over the time, we've been able to add to see here. So, for example, right now, we have a whole funded, insider threat program involving people who work for us and have logins to our PHI-containing systems who sometimes get tempted to snoop on folks, and they shouldn't, right? And so, we have a whole robust program in place to identify when people are doing that, or most likely are doing that, and to manage to manage to that. And it involves all kinds of trade-offs in some of the same ways that security does.

But it's a little bit different in that we need to make sure, in that particular case, that the program is sustainable. It's too easy to try to go after every last example of something like that and overwhelm our limited number of compliance and other HR investigators. We have a bunch of garbage, which is false positives. So, what we do is we are constantly attending together, Stephen and I are sponsors of that along with our colleagues and compliance, to focus on the false positive rate.

So, we want to make sure that everything we do is consumable by the investigators, and the existence of the program, even though it isn't completely thorough going, is plenty enough to deter our workforce from giving in a temporary temptation. We have the data to prove that, which makes everybody safer and lets all of our highly trained, longstanding professionals, who are just as human as the rest of us, keep their jobs because they don't do what for a few minutes they're tempted to do. And as we know, in healthcare, often the IT security team wants to implement tools or practices that the clinicians are not crazy about. And at the same time, the clinicians here are about cool technologies that they want to try out, whether it's AI, chat, GPT, or whatever it may be.

How do you balance that where you get pushback from both ends for about different things? You know, IT security, wanting to implement security tools, clinicians wanting to start using new technologies that maybe haven't been fully vetted yet for security and privacy. How do you balance that? Well, I think the start, again, goes back to having the structured conversations.

We have to recognize it's not just a technical decision, there's business implications, there's scary delivery implications, and we solve that by having the structured countermeasures reviews where we discuss the impact of our investments. You know, you can choose any type of security technology in most IT technologies and you are going to find a possible flashpoint. And even if it's something that we all have come to accept and know, for example, any security professional will tell you, I want you to have multi-factor authentication. It's great technology, we want it everywhere we can get it.

But it introduces friction into a care delivery setting. So you might agree that it's the right thing to do, but the question to me want to know is, okay, what form factor is appropriate? How long will I accept an authentication? You know, what is the way that I can reduce the amount of challenges?

These are examples that you need to discuss at a technical level and on an impact to care delivery level, which you can't do with only the optic of cybersecurity or only the clinician, and that's really the key for me. So we have a robust vendor risk management assessment team in the technology risk office in which you operate, Steve. And these folks are terrific, and by design, their work is core funded, and so there's no charge to anybody at PAP for asking for a vendor risk management assessment. So we encourage that strongly for any new vendor or vendor technology, and certainly we have certain gating points where we can make that happen.

So basically, anytime anybody comes looking for investment funding, then that's one of the things that happens. If there's any PHI or personal identifiable information, have you already gotten a vendor risk management assessment? And if so, send it to us. We also, on my side, in the medical group side, we have down to every department, we have physician IT leadership.

So we have department technology leaders, we have every one of our medical centers, we have physician leaders in technology, and of course, at the medical group level, and across all of Kaiser presidents. And so we constantly let them know that when they're hearing about the kind of innovation that involves sweat equity and people putting in their own ideas or maybe trying to cobble something together with a vendor, that they also use that as a way to have the conversation to get these folks involved with vendor risk management assessment. And we also understand that we don't want to choke off innovation. And so the vendor risk management folks and us, we've worked together over time, and what we do is, for something that's new, that involves, for instance, PHI, there'll be some more leeway defined more leeway.

I mean, specific, sort of separate, slightly looser guardrails around proof of technology, proof of concept stuff that involves a defined minimum number of patients PHI so that if there is a problem, that it's a containable problem while the larger assessment is going on. And so what we're trying to do is try to find the balance to not get in the way of innovation without also innovation causing us no end of problems. Well, thank you so much, Eric and Steve. I've been speaking to Eric Liedermann and Steve Frank.

I'm Mary Ann Colby-Sagmoghe of Information Security Media Group. Thanks for joining us. Hey, hey, thanks.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on April 18, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!