I'm Marianne Holbizak-McGee, Executive Editor at Information Security Media Group. Today I'm speaking with Christopher Friends, Assistant Vice President of Information Security and Infrastructure of Interfaith Medical Center in New York City about new guidance issued by the Association for Executives in Healthcare Information Security's Incident Response Committee, which he chairs. The guidance addresses IT and Information Security considerations for disease outbreaks such as COVID-19. Hi, Chris.
Hi, thank you for coming. Thanks for joining us. So Chris, as the U.S. health care system is dealing with the outbreak of coronavirus in this country, what are some of the top considerations potentially impacting IT and information security in those organizations?
There's actually quite a few. One of the first ones being supply chain issues. The region of China, which coronavirus initially hit, that was actually an area of the world, where a lot of the tech products will actually produce supply chains that have been a very big issue. As the pandemic comes closer to home, I think there's going to be issues with the labor shortages.
You're going to probably have an IT department that needs to prepare for a large temporary workforce because you're going to have a lot of workers calling that sick and doing temporary workers to cover those gaps. There's a lot of requests for remote access, which is good in some ways because not having employees come to work in the hospital will help keep them healthy and also prevent them from possibly infecting patients if they're carriers of the COVID-19. But at the same time, opening up all that remote access does create information security challenges. The hospitals have to take into consideration.
On top of that, there's going to be issues with physical security. If you have a huge influx of patients, you don't need a way to control all the panic and manage all those people that are coming into the organization. The other thing I worry about is actually a lot of the business partners hospitals use. You have a critical business partner and what if they're forced to shut down temporarily because of the pandemic?
How is that going to impact your operations? So there's lots of things hospitals actually need to begin to worry about as the pandemic approaches closer to home. So, Chris, when it comes to supply chain issues that impact the IT security operations, what sorts of supply chain problems should they be most concerned about? And what should they be doing?
The big supply chain issue right now is actually getting supplies in many cases. It's getting harder to requisition even basic stuff like PCs, whether it's a surge of multiple trying to request webcams, stuff like that, remote meetings, teleconferencing, things that promote those capabilities. So a lot of the basic computer equipment is getting harder together, more expensive to get a reach for the near future. And Chris, what about potential information security and technology, labor shortage issues?
How should healthcare organizations be preparing for that? One way they can do it within IT, within information security, is ensuring that employees are cross-strain. That's a damnate agenda. So that if one employee calls out sick, it's not a concept that only that one person in the organization has, that other people are actually able to fill in their role.
And that's one of the things that can be done within IT. IT is also a potential candidate for having some of their workforce work remotely to preserve their health and to still do their jobs. It may not be possible for help desk type positions, but a lot of other roles within IT, a lot of that work actually be done remotely to help preserve the health of the employees. In terms of nursing and doctors and things like that, labor shortage is definitely going to occur as well.
And IT departments really need to be prepared for taking on a large temporary workforce, figure out how they're going to provision a lot of accounts rapidly for agency doctors and nurses brought into full staff shortcomings, as well as how they handle the security risks as well as temporary employees. Now Chris, going back to the supply chain issues that you mentioned before, you mentioned that there's a lot of requests for webcams and et cetera, because you do have more people working from home, is there also a risk that some of these equipment will get pushed out to people before they're properly vetted or set up or configured, which might also lead to some security issues potentially? That's definitely a risk that any organization faces and that's one thing I think organizations need to do is actually begin to think about the policies and procedures they're going to use to get this equipment out there. Yes, it's probably essential that you do allow employees to work remotely in certain aspects but at the same time you don't have to make sure you do it securely.
You do want to make sure that you're thinking about this issue now, starting to establish a process for what are your conditions for a person accessing the hospital resources remotely? Most hospitals have policies and procedures rather already, but they have to be evaluated those in conjunction with the current needs of the pandemic to identify what the new considerations are, what new precautions are going to insist on, things like that. Now Chris, what about business continuity plans? Are there any special preparedness steps that healthcare information security teams need to be taking with coronavirus that might not be part of the usual business continuity plan?
And why? I think business continuity is something that organizations should constantly test particularly in healthcare. I'm a very big fan of constantly testing security, constantly testing of business continuity and disaster recovery abilities to make sure they work. The immediate concern for me would be ensuring that employees are adequately cross-trained.
Because if you do have employees called on sick, you need to ensure that your skill gap may exist. And that is to make a problem for a lot of the smaller hospitals in particular, where they may only have an IT department that comprises of a handful of people and one person's critical knowledge could be a real problem. So getting as much cross-training of employees right now is definitely a big plus and in general, yes, testing your backup and disaster recovery plans is something that we should always be concerned about and always be doing, but especially at a time like this, where you see an upswing in malware, testing in hospitals related to coronavirus, you're going to have infoxipation things like that, putting additional stresses on the system, so it's definitely a good idea to test and verify the whole stuff works ahead of them. Now, Chris, you mentioned uptick in telecommuting, but the federal government is also easing up on restrictions for telemedicine in light of the coronavirus outbreak.
What about security and privacy considerations involving expanded telehealth services? What should information security teams be doing right now with this? There are definitely requirements for doing telehealth securely. You have to make sure a lot of the messages are encrypted and transitive data flows back and forth.
Encryption at the endpoints, typically. You don't want to make sure it's compatible. There are issues around consent for ensuring that the patients that are participating in telehealth sessions have consented to participate that way, so there's a lot to do there. Yes, telehealth is a potentially great technology for addressing this pandemic because it allows people who are sick to actually stay at home but still receive medical care in many cases.
That's to their benefit, because if you're not presenting symptoms of the coronavirus right now, it's probably not the best idea to go to the doctor, because you don't want to expose yourself to other people. So there's many, many advantages there, but at the same time, I think hospitals that don't already have telehealth systems in place, you have to really evaluate whether it's in their interest to go out quickly or to take their time and go without quarantine at the original time frame because they may be introducing risks if they rush to do things. So yes, it's important to do a lot of this stuff at the same time. You need to wait the risks and factor them into your time frame.
And Chris, with all that said, are there any other top tips for healthcare information security teams as well as healthcare CISOs in terms of their organizations being prepared to deal with this outbreak? And what about shifting priorities? Do you see a lot of shifting priorities now for security? Because now we have the pandemic, so now that's on the front burner, now we have to put stuff on the back burner.
What's at risk in doing that? It definitely does cause a shift in priorities, and that's part of why you want to stick to the risk assessment process. You don't want to rush into things too quickly without thinking what the consequences of that particular action may be. Whether it's rolling out telehealth, increasing remote access, you really want to think to ensure that what you're doing is going to benefit the organization and not benefit the organization in some ways, but increase risk dramatically in other ways.
You want to make sure you're striking an appropriate balance. Because at the end of the day, patient safety is what's most important. So maybe a little bit of increased risk if it provides huge gains in patient safety is worthwhile. If it provides a little bit of increase towards patient safety, but huge risks in other ways, it may not be as worthwhile.
And it's important organizations really go through that process as they think about rolling out these technologies right into this Russian together in place without thinking about the potential consequences. Top of that, some of the other stuff that we didn't touch on yet is, I think, employee education is also particularly important in terms of information security. We're seeing a huge uptick right now in phishing campaigns related to coronavirus. There's been some fake coronavirus maps circling around, which is very malware.
So once again, reminding them of employees of the risks of things like phishing, those just links, things like that are definitely very beneficial as well. And finally, Chris, how about when it comes to any sort of critical security technologies that might otherwise get overlooked or maybe under implemented in times that are more normal? Any of those technologies that you think need more consideration or a sort of a re-look in light of everything that we're dealing with, but it comes to coronavirus and information securities, many challenges in dealing with this? I don't know if new technologies in particular necessarily to address this issue.
I think the standard good information security practices still apply and will still go a very long way towards solving a lot of the security issues presented by the coronavirus. One of the things that worries me though, is that if you have a lot of confusion, you have a lot of staff calling out sick, it also kind of makes an ideal time for somebody to attack your organization. Because it's very easy to pass off problems to temporary workers or confusion or other stuff that's happening. And you may not notice that the attackers going through your system, particularly if you have information security staff that would normally be there to detect the attack out of the sick leaves, things like that.
So I think it's the time for information security to actually be increasingly careful to look at their logs and other stuff increasingly closely to ensure that there's no nefarious activity that's going to be passed off as a confusion occurring to the pandemic and all the changes occurring as a result of the pandemic. Thanks Chris. I've been speaking with Chris Friends. I'm Mary Ann Cobusak-Migee of Information Security Media Group.
Thanks for listening.