COVID-19 Fueling Phishing, Other Attacks on Healthcare Sector episode artwork

EPISODE · Mar 18, 2020

COVID-19 Fueling Phishing, Other Attacks on Healthcare Sector

from Info Risk Today Podcast · host InfoRiskToday.com

The global outbreak of COVID-19 is intensifying the already heightened threat of attacks, including phishing scams, on healthcare organizations, says attorney Lee Kim, director of privacy and security of the Healthcare Information Management and Systems Society.

Episode metadata supplied by the publisher feed · Published Mar 18, 2020

Embed this episode

NOW PLAYING

COVID-19 Fueling Phishing, Other Attacks on Healthcare Sector

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary Ann Kolbasak-McGee, Executive Editor at Information Security Media Group, and today I'm speaking with Lee Kim, Director of Privacy and Security at the Healthcare Information and Management Systems Society. So Lee, what have you been seeing and hearing about the top cybersecurity and privacy challenges that the healthcare sector has been dealing with these days, especially versus last year? What's changed, especially in light of the coronavirus situation? So speaking about coronavirus and other use and trends, the first and foremost way that these scammers, cyber criminals, and other threat actors are unfortunately trying to compromise and much of the time able to successfully compromise our healthcare organizations is through phishing, phishing of some sort.

So you just provided a really great example, everyone that I know of and including myself, we're all very much concerned as a public about coronavirus. So as a result, we have information about fake websites that have been stood up with coronavirus live maps that actually, if you were to access that supposed coronavirus live map website, assuming it's not legitimate, you may unwittingly introduce malware into your machine, just in case it's serving to that malicious website. Unfortunately, of course the scammers want to leverage the coronavirus panic and or pandemic as it were. And so there might be supposedly important information about coronavirus and what you can do to protect yourself and your loved ones in another example.

So again, because all of us are worried about it, these attackers, these scammers, what they do in terms of launching a rather effective phishing attack and by effective, I mean, you click on the link, you otherwise take the bait of some sort, whatever their design is, and they prey on fear, they prey on other things where we may be motivated to possibly respond or do what the threat actor wants us to do, we need to be that phishing message. And because it appeals to us at that visceral level, we may not stop and pause and have that almost surgical pause, so to speak, to say, wait a second, this seems like it's not legitimate or wait a second, this seems like a scam. So instead, we just instinctively respond either because we are very concerned about the topic and or we're dealing with a flood of emails and our attention and or critical thinking is just simply not there. So Lee, what sorts of emerging trends have you been seeing overall this year when it comes to security-related technologies?

So in terms of security-related technologies, certainly that is a must to keep up with the latest threats just as a preface. However, in terms of the technologies that are being currently implemented in the sense of greater traction, more healthcare organizations by the numbers implementing such technology in an effort to be more secure in an effort to achieve more defense in depth so that it's more difficult to get to the core where the sense of information may be accessed or kept. The security-related technologies this year as an example that healthcare organizations are embracing more and more and implementing include multi-factor authentication and biometrics biometrics because it's something that's relatively easy whether it's biometrics in terms of face geometry or fingerprint, a retina scan or otherwise, certainly one significant factor to adopting multi-factor authentication is user acceptance. Users don't accept it.

They'll certainly find workarounds and or they will go to the security department and try to challenge the implementation of a security technology that's meant to protect the organization that's meant to further secure things but instead they may really try to push all the levers and they will try to opt for that workaround or security program exception in their instance. The danger of that of course is once you deviate from your strong robust security program, your security program may end up looking like Swiss cheese or to the extent it looks like Swiss cheese. Think about a slice of Swiss cheese. The attacker that is can get them through those many holes in the cheese.

Some additional technologies that are embraced in increasing numbers include encryption. We're finally seeing that organizations across the board are deploying encryption at rest as well as encryption in transit for all kinds of data including especially over the web and furthermore in terms of those web security gateways and other things to ensure that what you're browsing through the web is safe for your organization. We're also seeing a greater implementation of those security related technologies as it relates to the web as web application attacks have been significantly on the rise as recorded in various industry reports over the past two years or so and last but not least we are seeing in terms of something that's newly emerging even though it's not necessarily new but in terms of health care. We are seeing a few more organizations that have dedicated threat hunting teams to proactively see if there's anything that may be going on such as in terms of advanced persistent threat actor otherwise so that's fairly novel.

In addition, increasing numbers of health care organizations over the past five years really have been hiring specialists whether they're employees or whether they're consultants to regularly monitor the dark web to see if there's any chatter about their organization or their business affiliates or something of that elk so that they are just simply more situationally aware of what's going on and as appropriate their organization may reach out to law enforcement if they see that there may be something happening that may potentially target their organization or whether organization is as somehow part of multiple organizations that may be on the hit list so to speak in terms of cyber. So Lee what appears to be giving the health care sector the most trouble in terms of their security and privacy efforts? I can give you the answer and likely that answer won't change over time across any organization whether you are in private sector or public sector such as a health care organization or hospital that's private sector or one that's public sector that may be state or federally run. The weak point of any of these organizations will always be the people.

I've mentioned phishing for example there's certainly ways to see people such as by way of phishing emails or websites where the attacker doesn't have to breach that firewall or try to penetrate that really tough exterior that has been set up by the security pros. Instead they go right to the person such as by way of email, social media or otherwise where there's a specific individual contact and they try to infiltrate and exploit that way so really it is all about exploitation of the human and that's certainly a headache. So in other words in addition to these sophisticated threats that are happening all the time are all the more powerful it's the security threats that potentially take advantage of people's willing to help within health care and people's wish to do the right thing in health care that unfortunately is a double edged sword for us. Lee from a regulatory front what do you think health care sector entities should be watching most closely when it comes to cybersecurity and privacy related regulatory actions or developments this year?

There are two items that I can foresee coming down the pike. One is I believe that it is inevitable that HIPAA will likely change in some way, shape, or form in light of these increasing cyber attacks in light of the extreme damage and other consequences that cyber attacks can result in within the health care sector. So HIPAA is certainly one and changes thereof in light of our cybersecurity reality. The second strand that I wanted to address is on the privacy realm and that is we all know about the European Union's general data protection regulation GDPR and as a result there are various policy makers both at the state and federal level that are looking at it because GDPR unlike something like HIPAA it's not sector specific.

It applies to all sectors as long as territorial scope applies to GDPR. In other words if there's jurisdictionist GDPR or a controller data processor then GDPR may apply to you. So the question then is one of our seeing other states that may revisit their privacy related regulations to pass more GDPR like legislation for example the CCPA in California is one such GDPR like legislation. We may even see Congress that may look at GDPR like legislation for federal efforts as well.

I mean it's very difficult to predict but certainly the drumbeat is there in terms of that being potentially a model of a privacy related legislation. So Lee what do you think about the interoperability and information blocking rules of the Department of Health and Human Services recently released? What do you like and what do you dislike about the rules? Right now we are still in the preliminary phases as these rules are about over 1,700 pages but really in that respect and I'm speaking also as a person who's an attorney.

I think that it's a wonderful thing that HHS is so detail oriented in terms of feedback received in light of the proposed rule and of course we now have the published final rule as well where we will get a chance to as an organization and with the input of our members meaningfully respond to the rules that have been published so in a sense we get another bite of the apple. So not much can be said apart from that at this time I'm always in favor of really careful in-depth analysis before weighing in but certainly being a detail oriented person even at an individual level I think that that's definitely a plus in terms of very thoughtful regulation that has been published. Thanks Lee. I've been speaking to Lee Kim of Hymns.

I'm Mary Ann Coba-Sakmigee of Information Security Media Group. Thanks for listening.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on March 18, 2020.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!