I'm Marianne Culbisack McGee, executive editor at Information Security Media Group. Today I'm speaking with attorney Marcus Christian, a partner in the Washington D.C. based office of law firm Mayor Brown's Cybersecurity and Data Privacy Practice and White Collar Defense and Compliance Group. So Marcus, based on what you see with clients and others, what are some of the top security vulnerabilities and most worrisome cyber threats involving health related data these days?
I think you know everyone, when they think of the threat, they think of the hackers and what hackers doing to healthcare organizations. Certainly they're a big factor and I'll talk about them in a moment. But I think it's a more common and consistent threats that face organizations. I say areas of risk.
Perhaps it's a better way to put it. And one of those would just obviously be human errors. We talk about cybersecurity in general. Human error is a topic that often comes up, a source that often comes up and just something basic.
The misrepresented communications, be they letters, statements about the older or whatnot, emails or other transmission that simply goes to the wrong recipients. Not the kind of thing you want to read about in paper or see on the news as a mega breach. But it's something that happens and something that's worth noting because it's not something that we expect is going to go away. There's another area of risk that you think about delivery of healthcare.
We think about practitioners who are many instances dealing with emergencies. And one of the things they want to do and they need to do is get access to information quickly. So oftentimes they find ways to repay to smart people with little time. They find shortcuts to speed access to patient files and records.
Some of those shortcuts include sharing passwords, using weak passwords, using emails to transmit sensitive information, when they use more secure platforms and the like. That's something else that I'd say as part of the backdrop, another would be aging operating systems. You know, many healthcare systems in general. I mean, if you get a system that seems to be working in terms of actually working, I mean, it'll allow you to do the things that you want to do.
Can you share information, you store information, can you retrieve information, but it may not be a accomplishing or allowing you to accomplish or meet your security objectives. So that's something that Contributed to the WannaCry outbreak not long ago. So those are something that I identify as part of the backdrop. I think more technological perspective.
We're looking at expanding attack service now. Consumers we have an ever expanding array of connected device and applications that allow us individuals, wealth, practitioners, health plans and others to monitor activity that is directly relevant to healthcare and health related outcomes. They could be in terms of helping to respond and treat a health condition, but also to prevent a negative healthcare additionally related activity. So that's another part of it.
But when you think about some of the incidents and types of incidents that occur attend to folks on the healthcare, on healthcare, you think about one, calculated data is something that's very attractive to cyber criminals, to hackers, among other things. One, it can be more valuable on the black market than say some types of financial data such as credit cards. Two, it's very much more sensitive in terms of individuals who have their healthcare data stolen. Healthcare records include not only data that's relevant for financial transactions such as Social Security numbers, dates of birth and other types of information, but it can be very sensitive and that can reveal some very conditions that could cause people to suffer reputational harm and other negative consequences.
So it's obviously something that threat actors can get a hold of. They can monetize it in a number of ways by selling it on the black market, by using it to commit extortion. When you look at a healthy organization, by infecting organizations with ransomware, we're using a lot and requiring them to pay to regain access to that information. So those are some of the things we see.
Also in some incidents I've dealt with, you find not only that there are vulnerability in threats just because they're hackers or just because they're workarounds, but there's a combination of factors coming together. You may have information that's shared among a large number of organizations and organization one may have very strict and robust measures for security. And then you look at the organization too and they're being a little bit more lax in terms of how they deal with the data for legitimate business purposes if they're considered inoculation, such as efficiency. But when you think about the sensitivity of that information as well as the requirements, when you think about HIPAA requirements and other information security requirements as well as privacy standards, they miss the mark.
And so where's the Nevis where we see, we see healthcare at the sector as one of the number one sectors that threat actors hit from the outside. In terms of hackers and others, we see a large number of accidental events that are or incidents that are due to human error. And it's something that when we look at these types of risks that are associated with healthcare data, there's no sense that it's completely one way out anytime in the near future. What we do hope and we do expect and we do plan for is that by taking certain measures, healthcare companies, health plans and others can actually have a higher level of cybersecurity and do a better job of protecting records.
So, Marcus, when it comes to regulatory gaps involving the privacy and security of health data, what stands out to you and what are some of the top issues? Obviously, we have HIPAA protecting protected health information related to covered entities and business associates, but there's also consumer wearable health devices and smart watches that are generating some sensitive health data. Are there gaps in that area and what other areas do you see? Regulatory gaps?
One way to describe these gaps, I would say to some extent that growing pains in technology and capabilities are advancing very quickly. And so you have HHS ocr, which deals primarily with HIPAA and privacy and security rules, but you also have the FTC which is certainly taking a look at this area in terms of devices that collect medical information. Whereas H OCR is focused on hipaa, the FTC is focused on the FTC act and they're looking for stepped acting practices. And through the FTC act, you will find the FTC is increasingly looking for ways to assert its authority to protect health data that's collected by these wearable devices.
And you also have the FDA and there's certain devices that will collect information and they call the FDA's jurisdictional medical devices. And it's worth mentioning here that we talk about cybersecurity. We're not simply talking about the confidentiality of information. We're talking also about the integrity of information as well as the availability of information.
When you think of a medical device, along with someone like me depend the cyber security. That medical device, certainly confidential information is important, but also important to the availability of that device. Or the clinician needs a certain amount, certain types of information from that device. Then it is very important for it to be accurate for us and not to be close to cybersecurity threats or to be compromised by cybersecurity events and incidents.
So what I would say is when you talk about HHS ocr, we talk about FTC and the fda, I think we have spaces between their general areas in which they act that they're looking at negotiating how they're going to fill that space. And I think that that space is not necessarily created by these organizations, but it's created by a growth over time in terms of the attack space, in terms of the types of devices the places where healthcare information, where medical information happens to reside and other factors. And as always, in the cybersecurity area and in the privacy area, for that matter, it seems as though the risk and the threats grow and move faster than regulators can grow and change. And beyond, say, the regulatory regulations and statutes on the book, you also have the fact that the hhs, ocr, the FTC, and the FDA faced the reality that they have finite resources and finite budgets where you have, you know, you look at the world of innovation out there, innovation in terms of new devices and innovation, if you want to call it that, in terms of what threat actors are doing.
It's really busy, the pace of which that's occurring. And so it's a tough job for the regulators, but it's something that they'll have to be vigilant about. They're going to have to figure out ways in which they can kind of COVID that space that falls between their various organizations and their areas of focus. So looking ahead to 2020, what trends do you expect to play out when it comes to the respective roles of federal agencies and maybe perhaps even Congress in terms of new legislation or perhaps new laws or even the state lab for that matter, in terms of protecting sensitive medical data?
So I turn first back to the federal agencies. One, I would say that I think probably one debating on which organization hhs, ocr, FTC or FDA may be moving the most quickly to focus on this. First of all, I wanted to disparate any organization, but historically, if you look at the ftc, it tended to be a little bit more energetic in terms of asserting itself in the privacy and cybersecurity area. That's not to say that the other two agencies haven't been aggressive.
It's just that in many ways HHS that is handsful when you look at the organizations, covered entities and business associates that have incidents, and when you look at how long some of the investigations take for hhs, you understand that it has a fairly full docket. Sometimes it takes years before some of these major breaches we hear about are actually resolved. So it's quite a busy organization. So I would say among those, you may see the most movement in this space for the ftc.
Now let's turn to Congress generally. I think the conviction wisdom is in a election year, you're not going to see a lot in terms of lawmaking on critical issues by Congress. And one might also say, and if you add to that Congress taking laws that deal with cybersecurity or data privacy, many people have Laws hope that that's going to happen. I do believe based upon what I've seen, that this is the major issues that Congress is taking very seriously.
However, the prospects of significant legislation next year are probably pretty slim. I will add one factor that perhaps is worthy of taking consideration. That's there's a lot of activity on the state level, which I'll talk about in a moment, that may be creating a certain amount of pressure and a certain amount of urgency on the part of Congress in that you have the California Consumer Privacy act and many other bills. The CDPA California Consumer Privacy act was passed last year and it's really sweeping legislation that creates privacy rights on behalf of individuals that have never before existed in the United States.
And so as other states look to California and consider what type of legislation they may pass and I wanted to add there's an exception for HIPAA data, but it certainly does not completely exempt health care organizations. It's that Congress is going to take a look because it needs to consider the fact that you can wind up with 50 states with 50 different types of very restrictive and very business perspective burdensome laws on the books. Whereas Congress could, through its powers, pension powers, create one law that could apply across 50 states. So that's something that I think will be effective for Congress.
If you look forward to 2020. Whether that makes a difference, I think remains to be seen. Now, getting back to the states and you do that about the states, I think clearly the states are where the most activity is taking place. Even before the California Consumer Privacy act, there I would say has been a fair amount of activity in terms of a state not only passing data breach notification laws.
In 2018, the 50th state actually passed its data breach notification law, but also strengthening their laws. If you look several years ago, many of these laws didn't cover breaches that involve medical data. Now increasing numbers are and not only are states including medical information in their laws for data breach notification, they're also passing laws that include cyber security requirements, minimum cybersecurity requirements for organizations. So that's something I think is just an indicator of the level of activity we're seeing on a state basis.
And I think that will, if it is seen to be there seem to be a need in the healthcare area. I think you want to see more of that. Another thing I would say is that whereas on the national level one may say the politics are against legislation passing next year for health care for a number of reasons, for healthcare cybersecurity for a number reason on a state level, there are other factors that also increase the likelihood of activity. So on a state agency basis, many state attorneys general are elected and privacy and security are issues that tend to resonate with the electorates in various states.
So constituents want to see their AGs being aggressive in these states. And if the AGs get that message, they're going to be aggressive and it's something that they see the benefit of them. So we've seen increasing number of fairly active CAGs and other agencies for that matter. We're seeing more laws that are requiring notification of state AGs and other agencies when there is a cybersecurity incident.
So that's something that I would say summary, I would say for Congress next year, probably not going to see a lot of or any legislation specifically for the healthcare sector for the agencies. I think you'll see HHS hard at work dealing with cybersecurity issues, making sure when they have an examination organizations have administrative, physical and technical controls. You're going to see the FTC and the fda, but particularly ftc, very interested in devices that collect personal data and the claims about cybersecurity that their manufacturers make. That's going to be a very specific, very focused area for the ftc, and it's growing.
And so on the state level, there's going to be a lot of activity. So that's pretty much at least my outlook and my thought about what we'll see in 2020 in terms of legislative regulatory space. Thanks, Marcus. I've been speaking to attorney Marcus Christian.
I'm Marianne Kobisak McGee of Information Security Media Group. Thanks for listening.