HHS Resources, Funding to Bolster Healthcare Cyber Efforts episode artwork

EPISODE · Mar 12, 2024

HHS Resources, Funding to Bolster Healthcare Cyber Efforts

from Info Risk Today Podcast · host InfoRiskToday.com

The Department of Health and Human Services is working on grant programs and other financial programs to help under-resourced healthcare organizations deal with the cybersecurity challenges they're facing, said La Monte Yarborough, CISO and acting deputy CIO at HHS.

Episode metadata supplied by the publisher feed · Published Mar 12, 2024

Embed this episode

NOW PLAYING

HHS Resources, Funding to Bolster Healthcare Cyber Efforts

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary Ann Kolbasach-McGee, Executive Editor at Information Security Media Group. I'm here at HIMSS speaking with Lamont Yarbrough, who is CISO and acting Deputy CIO of the U.S. Department of Health and Human Services. Welcome.

Hi, happy to be here. Thank you so much for joining us here. So over the last year or so, what have been some of the most concerning developing trends that we've been seeing involving cyber threats facing the healthcare sector from your perspective? Okay, well from our perspective, of course, overarching, I think that the health and public health care sector is a target-rich environment, right?

So there will be no shortage of actors taking the opportunity to do what they do in that space. So from that perspective, I, along with my colleagues within HHS and throughout the federal sector and external partners, are always working diligently to ensure that we can do all that we can to kind of mitigate the risks within that environment. So now the Biden administration has been focused on strategies for strengthening cybersecurity in critical infrastructure sectors, including the healthcare sector. What are the most important aspects of this strategy that you think healthcare sector entities should be paying more attention to and be focused on right now at their organizations?

I think organizations, by and large, irrespective of whether they're in the health and public health care sector, they should be ensuring that they have some type of paradigm of some organization maturity as it regards cybersecurity practices, right? And appreciating that a lot of the folks within said sector are not necessarily cyber experts, that they are relying on perhaps those who are, that they are building the capability within their environments to the extent that they are able, and they're leaning in and leaning on those who can help advise them on ways to be better in that space. And as we know, the healthcare sector has sort of been rocked recently with the change healthcare Optum cyber attack. I know you can't really go into details, but any emerging lessons that are coming out of this incident so far that entities really should be paying close attention to because you never know if this could happen again to a large player?

Yes, it's really unfortunate what's happening right now, but what I will say, and again, it's not just unique to this particular space, but you know, cybersecurity is important on a variety of levels. Specifically, we tend to say at HHS that, you know, cybersecurity is patient safety ultimately, right? And that's the whole ecosystem that supports health and public health care. All of the players within that space.

But I think if anything, what it goes to show is, for one, there are no absolutes when it comes to cybersecurity. You can do everything that you're supposed to be doing and still suffer from a cyber attack. So that being said, you have to be ever so mindful and ever so committed to ensuring that you're doing all that you can to protect your environment. A big good point that a lot of entities, they do what they think is right and they still wind up getting hit somehow, even if it's not done directly.

It might be a vendor or whatever. The government too has had their share of attacks. HHS has had incidents. Any lessons that the government is learning from what it's dealt with in terms of being a target for some of these things?

Well, again, and I say this a lot actually, there are perhaps leaders in government and out and everywhere who thinks that because perhaps that they have a robust cybersecurity team, or maybe perhaps they have the latest and greatest cybersecurity tools, and they have robust and mature processes, again, we can do everything that we're supposed to do, but a savvy threat, a bad actor, can find ways to overcome your perimeter in all manner of things. So I guess what this demonstrates is that constant vigilance, that whack-a-mole scenario, if you will, that it's never ending. You can never plant a flag and say, we are 100% secure, because that's just an impossible goal and an impossible task. So with that said, where should organizations be focusing their attention?

If they know that there is no 100% way that they can be completely safe from an attack, how to be better prepared to deal with something when it happens? Well, if we're speaking specifically to the health and public health care sector, there's a number of things that we do at HHS. One of the things that I literally spoke to just a few moments ago here at HIMSS, we were actually announcing through our 405B program. For those who may not be familiar with what 405B is, it's an outcome of the cybersecurity act of 2015, chapter and verse 405B within that language, within that law, says that HHS, so partners, so it's a public-private partnership with the sector, to build ways and mechanisms by which they should be considering with respect to their cybersecurity posture.

Ways in which to mitigate the risks within their environment. So we've operated this program for a number of years, and again today we kind of announced that we had released some education, our cyber education through the 405B program, in Spanish language. And we feel that targeting the healthcare and public healthcare sector in regions across the country with large Spanish-speaking populations. So by and large, in a lot of ways though, that's an underserved community.

So we want to ensure that to the extent that we are providing this information throughout the entire community, that the Spanish-speaking community and others, as we review, as we target the Spanish-speaking community, we also want to consider other underrepresented communities. That's kind of a tongue twister. Moving forward. So we announced that today.

We want to ensure that with that capability of the Spanish-language content, that you can train all your staff in healthcare facilities because it's paramount to, again, ensuring patient safety and the availability of materials in Spanish enhances accessibility and effectiveness. Now, what about the under-resourced organizations out there in the healthcare sector? You have a lot of smaller clinics. You have rural hospitals.

You know, a lot of these entities sort of complain that we know that we might be targeted, but we don't know what to do. We don't even have the staff that would be able to handle this. Are there any sort of incentives or funding or other sorts of programs that might be available or might be in the pipeline? We actually are working, you know, to demonstrate our commitment that we are working to provide some types of resources by way of grants and other incentives for implementing cybersecurity practices specifically to those communities and sectors, or rather practitioners, that don't have the resources for themselves.

So we are continually working that so that hospitals and healthcare providers can explore those opportunities for financial assistance and other support incentives to bolster their cybersecurity capabilities. And as we look into the year here, anything else that we should be keeping our eye on in terms of HHS and programs or regulatory sort of work? I know that HHS OCR is working on an updated security rule for HIPAA. There's a bunch of other things that they're working on.

Anything that you can tell us that we should be kind of watching for right now? Well, we are considering implementing some enforceable cybersecurity standards within the HPH cybersecurity goals that have far-reaching implications because industries play an important role in the development of these standards and actually participating and shaping them. But once we do that, we want to hopefully put some teeth behind them so that, you know, folks can kind of use it as an authoritative source in informing their overall cybersecurity posture. And finally, as you work with other leaders within the government, whether it's CISA or other parts of HHS, what is your assessment in terms of the way that healthcare is sort of seen as a critical infrastructure sector in terms of its preparedness compared to other industries?

Does it have a lot of work to catch up on? Are there any industries that are worse? Well, I'm probably not the authority to speak from that perspective. But let me say this, okay?

So when you talk about, just for your audience who may not be aware, when you talk about critical infrastructure, overarchingly there are 16 sectors, right? And critical infrastructure, by definition, are those capabilities that shape or inform the American way of life. Be it communications, our military, our ability to have communications, chemical, water, a number of things that informs those sectors. And take away any one of those should pretty much be impactful to practically every American.

So that's by and large what that means. And with respect to this particular sector, of which the United States Department of Health and Human Services is the sector risk management agency for the health and public healthcare sector, we are fully committed to working with said sector through a number of programs, 405D and others within HHS, to bolster their ability to not only defend themselves, but to be able to respond in an effective way when calamity occurs. So, yes, always mindful to all of us at HHS that we do whatever we can for the sector to ensure that, you know, everyone is protected because, again, and we will probably say this 5 million times, cybersecurity is patient safety. One last question.

When you look at some of the major attacks that we've seen in healthcare and other sectors, what are the most concerning vulnerabilities that you think the nation states and other bad actors are exploiting the most that these healthcare entities should really be focused on, you know, doing this? I know we always talk about patching, but what else? Well, patching is critical. And that's just goes down to what I would characterize as good cybersecurity hygiene.

There's a number of other things that go along with that beyond just patching. The most prominent threats of the day, and they can vary on any given day and any given month and any given year, you know, of course malware is going to be probably within the top three, right? Malware in the form of malware is ransomware, which, of course, if you turn your TV on any given day, someone is being overcome by a ransomware attack

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on March 12, 2024.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!