Getting a Tighter Grip on Vendor Security Risk in Healthcare episode artwork

EPISODE · Nov 24, 2023

Getting a Tighter Grip on Vendor Security Risk in Healthcare

from Info Risk Today Podcast · host InfoRiskToday.com

Despite the high frequency of major health data breaches involving vendors, many healthcare sector entities remain lax in their approach to manage and reduce third-party security risk, said Glen Braden, CIO and principal of compliance auditing firm Attest Health Care Advisors.

Episode metadata supplied by the publisher feed · Published Nov 24, 2023

Embed this episode

NOW PLAYING

Getting a Tighter Grip on Vendor Security Risk in Healthcare

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary Ann Kolbasek, the executive editor at Information Security Media Group. Today I'm speaking with Glenn Braden, who is principal and CIO at compliance auditing firm, a test healthcare advisors. We're going to be discussing a recent survey and a recommended practices and implementation guide released by the Health Third Party Trust or Health 3PT initiative. So Glenn, just for starters, just briefly describe what your involvement was in the development of the Health 3PT recommended practices for the healthcare sector and for entities in dealing with the third party risk.

So I really see myself as the vendor voice on the committee. The committee is mostly covered entities and we work with covered entities. We audit covered entities. So I have a lot of experience working with third party risk assessments, third party risk assurance, and because they're coming to us, coming to me.

And I bring that voice, I guess, to the committee. So when we're looking at recommendations, when we're looking at just the things to do, like, okay, so this is kind of how I see it from the other side of the table, because really it is a competition and it's two pieces of the same work process that needs to be good in place. Glenn, please describe a little bit about what the Health 3PT survey looked at and what were some of the key findings that sort of emerged from that that might be helpful for healthcare sector entities to realize? From both sides, the question is getting to how much this process has been in the pain for both sides.

It's painful, it's expensive, and it's not working effectively. It's not working as well as we think it should be. The finding that stood out to me, I think the most was that 60% of the covered entities thought that their current process was not effective, and 72% of vendors thought it wasn't effective. So to me, and I'm the vendor side, I can see what the covered entities are doing and how they're assessing us, how they're assessing their vendors, and if not effective, whether what they asked or what they do, they're clearly not getting the best answers that they could be getting through the current process of sending these questionnaires, and a statement that says, sign this, that you're complying with the contract percent, that you assure us that you're secure.

Well, okay, I don't think that's very effective. Glenn, as you know, we see a lot of major health data breaches that are reported to the Department of Health and Human Services, and about 40% of the incidents this year alone are reported as having involved a HIPAA business associate, and that ranges from incidents involving third parties, such as law firms and practice management vendors to major hacks involving large software providers, such as Fortra and Progress software, and as we know, covered entities often have many, many business associates that handle protected health information, as well as subcontractors of those BAs. So with that said, what third party best practices are highlighted in this new guide that you think entities tend to full short on that they really need to be spending more attention on? I think the entities tend to offload the assessment of the risk to the vendor.

So I can't tell you how many questionnaires I filled out where I'm telling them what we do for them. I'm telling them the data we get and how we share it. I'm telling them how secure we are. I'm telling them how much of the risk we are.

And if you're trusting the, I don't know how to put this, if you're trusting the person who you're supposed to be hosting the risk, trust them then to tell you every about their risk, you really have no assurance that any of that is correct. Because you're the business, you're responsible for what your vendors are doing, and you need to know what that vendor is doing for you. And if you're just responding, relying on somebody in there, IT shops tell you what they're doing. It's not going to be effective or the best information.

So I think part of within the recommendation recommended practices is one for one, you have to have a way to rank your vendors and what the risk is. And then you need to know what they're doing, what they've got, what they're doing, what that data, and how to assess the risk from just the beginning start. And how often you need to assess the risk, how much risk they are to the organization. It really starts with the hiring company to assess what their vendors are doing for them.

Because pressing the vendor to tell you exactly what your risk cannot be effective. So then it goes through how you do that. So once you know your risk, you need concise language in the contract. So this is what you're going to do.

But you can't rely on that contract to do it all. Because as a vendor, when I sign a BAA, I'm at risk for a day breach regardless of what happens. So just having the language in the contract really isn't enough. There needs to be some sort of appropriate, reliable, consistent way to have an assurance about our security capability.

And that's the key, that it's consistent, that there's an industry standard for how you know if they have security assurances, if my data's safe with them. Because these questionnaires and the finding, I just got another one that they want me to sign. That's a station that says we're secure. Well, you're 100% trusting me to tell you that I'm secure with, you're not checking anything.

I don't see how that's effective. So it goes through set by set on what makes sense, because it makes sense for us as a vendor that we have, we can show that we have security, that the proper security measures in place, because I'm highly certified. I have gone through these audits. I have demonstrated that we have these security controls in place.

That's how we tell them, yes, we are a secure shop. And it really goes through the other piece where they will, where government agencies can fall to the side as they do their risk assessment, or their insurance, or whatever their questionnaires, they do them every once in a while. And then if there is something that's not up to par, then they may work on a tech correction planner. They may say you need to expect this, but then there's no follow-up.

So it just kind of follows by a wayside. And then, you know, two or three years later, oh, well, we had this problem with a vendor and they never fix it. With high trust, that's part of the process is you go through the validation. If there's something's not appropriate, there's a current evacuation plan.

And then it's checked for the next year. And it follows through, so there's follow-up. And I think because Kubernetes have so many vendors, and they have so much to take in, I guess, and to review, that a lot of that follow-up just doesn't happen. If there is a risk or something that needs to be corrected.

So does the best practices implementation guide focus on, for instance, getting high trust certified? Are there other certifications that entities can seek from their vendors that would give them this extra sense of assurance that, you know, their third parties are actually doing what they say they're doing and, you know, checking up on them every so often to make sure that everything is secure in terms of their practices and everything else they're doing with the PHI that they're handling? There are multiple levels, I guess, of high trust assurance available now. So, yes, that's exactly what we're proposing and suggesting is that the coverage needs to be assessed with that vendor.

And then based on the risk of their data with the vendor, the risk of their vendor, the vendor, you know, having a breach, that kind of helps drive the level of high trust assurance you would want, whether it's a place like us, which is R2 certified, so it's a two-year certification that we've had for a number of years that assures, yes, they have the highest level that you can get the assurance. And it's consistent. It's a consistent process. It's a consistent rating scoring methodology.

So, you know, this vendor meets these standards. And that's really what it is. I think we recognize that there's some limitations with other certifications or other audits, with an ISO, the entity kind of determines the appropriate control they want to have in place, kind of the support center with the SOC. You decide a little bit about which controls you want in and how you're going to control things with high trust.

It's very set. And if you have this, then you need to have the control in place. So, I think that's where the consistency comes in. So, Glenn, as you know, we have seen quite a few large breaches being reported in the healthcare sector, but also other industries involving third party software.

And this year, there's been a lot of breaches involving fortress, move product for advantage or secure file transfer. We have had lots of breaches being reported involving progress softwares, move it software. And these incidents have involved, for instance, exploitation of zero day vulnerabilities and things like that. So, when it comes to like, you know, large software vendors, such as those and others that are also sometimes used by a carbon entity's vendors, so there may be subcontractors.

When this guy sort of applied to that, when high trust, you know, certification applied to those sorts of companies, or is that one of those sort of those, you know, black holes where, well, you know, maybe you have other third party risk management under control, but there's certain things that are harder to control. A lot of that comes in to the scoping of the high trust certification on what all is included. So, I do, I do believe, and one of the most important questions that the vendor covered in speaking asked is, are all of the systems or all of the processes that use to deliver the service to us included in your high trust report? So, is it properly scoped?

And I think that that is a legitimate question, and that is an appropriate question, for anyone who's relying on the high trust report for the vendor, is it appropriately scoped? And everything included. So, that's one thing, because scoping does matter. I think we're all kind of at a little bit of the mercy of some of these huge software companies with breaches and with being breached and zero day vulnerabilities, the best kind of response, the best example that I see from my clients or clients who reach out and ask, okay, move it, it has a problem, do you use move it, do your subcontractors use move it?

And then within the first week that's going to be out, they're assessing whether that's a problem with us as a vendor. And we can answer that no, or yes, or whatever, and it's what we're doing about it. I think the high trust certification definitely sets a bar on a floor, maybe, but yes, because the nature of the beast and the nature of these exploits, nothing is going to be able to say there's no way that someone does have a problem, because the software is because none of us can test that software is secure. Glenn, based on the work you do with health care sector entities overall, are there some top mistakes that you see organizations making with the third party risk management programs that if they were to address that ASAP, it would greatly reduce the risk of their third parties?

One of the comments I made when we had a webinar was that many of my covered entity clients don't even ask about security at all. And if each and every one of them came with a security questionnaire, there's no way we could even respond to that because there would be too many. So I think everyone needs to be looking at their vendors and their risk, and I don't think everyone is looking at it at this point. So that's a place to start.

I do think hearing your risk with vendors and then looking for vendors who have the appropriate risk assurances, like a hydro certification, is a good set to go because my understanding is there's not that many of us. For some of my clients, I know I've talked to clients and talked to the ones where we're like 5% or 10% of their vendors are hydro certified. So they're much more concerned with those un certified vendors than they are with us. But it gets to me where I can't imagine that the clients who literally are not asking, who never asked anything.

Thank you, Glenn. I've been speaking to Glenn Braden. I'm Mary-Ann Colbizak McGee, Information Security Media Group. Thanks for joining us.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on November 24, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!