How New Federal Cyber Resources Can Help Healthcare Entities episode artwork

EPISODE · Apr 17, 2023

How New Federal Cyber Resources Can Help Healthcare Entities

from Info Risk Today Podcast · host InfoRiskToday.com

New resources released Monday from a high-profile federal advisory group provide insights into the state of healthcare sector preparedness and best practices for dealing with evolving cyberthreats, according to Erik Decker, CISO of Intermountain Healthcare and co-chair of the task force.

Episode metadata supplied by the publisher feed · Published Apr 17, 2023

Embed this episode

NOW PLAYING

How New Federal Cyber Resources Can Help Healthcare Entities

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Hi, I'm Marianne Kolbesak-McGee, Executive Editor at Information Security Media Group. I'm here at HIMSS speaking with Erica Decker, who is CISO of Intermountain Health. Eric is also co-chair of the 405D Cybersecurity Task Group that advises the U.S. Department of Health and Human Services.

Hi, Eric. Hey, Marianne. How are you doing? Good.

So, Eric, there's a new update to the Health Industry Cybersecurity Practices document that was first issued in 2019. What will we find in this new updated document that is most significant? Yeah, so it is for sure a, I would call it a 0.5 level update. We updated one of the threats from phishing to social engineering, and then we did some significant rewrite of practices.

So the medical device practices has, it's much more robust than it was before. We've updated and added risk analysis and risk management into practice 10. Really turned that whole thing into oversight and governance from a cybersecurity perspective. And then just peppered throughout, you know, the rest of the practices, there's just a bunch of extra added help for folks to understand how to actually implement some of these practices that are down at that level.

So it's really just about modernizing, you know, keeping current. I think it's actually a good thing to know that we didn't have to do a significant like 2.0 version update because what we're really trying to make sure is that HIPAA is analogous to hygiene, and hygiene should just be the same, you know, no matter, you know, look at the Spanish flu from a hundred years ago. They're masking up, they're washing their hands. What did we do with COVID?

We masked up, we washed our hands. That's hygiene. And so a lot of these practices are going to be fairly consistent, but hopefully the readers will find a lot of value in them. So with that said, what does the new document address that wasn't addressed before?

Are there, is there new advice? Is there new threats that are now highlighted or things that are highlighted in a way that it weren't before because it wasn't as much of a problem? Yeah, from a threat perspective, the main update was moving from phishing to social engineering and really looking at social engineering from the perspective of it's going to come in through email for sure. But there's also, you know, business email compromises.

It's not just about credential access and malware dropping. There's smishing that's going on. This is the text message phishing attacks, you know, that happen. And, you know, keeping the reader current on those types of attacks.

And then I think the biggest update from a practice perspective was that risk, the practice 10, which is the, used to be policies and procedures, and now it's cybersecurity oversight and governance. And it really gets into what a risk assessment program looks like, what risk management program looks like, how to work with cyber insurance and what are the kinds of coverages, you know, to consider as part of all that. And then of course, as well, the policies and procedures that was in there before. And now there were also other documents that were released today, one on resiliency.

What can you tell us about this? Yes. So that is, that was a study that was sponsored, co-sponsored by HHS and the industry. So this was a, we call the hospital cybersecurity resiliency landscape analysis.

And what we were looking at was, why is it, how are hospitals getting beat today? What are the, what are the means and methods by which the adversaries are taking to actually break in and cause disruptive damage? So we're not necessarily looking at the data security, data confidentiality, privacy issues, which we all know are certainly issues. But we're looking at more from a public health perspective.

When our hospitals are not up and operational for 30 to 45 days because of a ransomware outbreak, that has, can cause harm. You know, so, so the landscape analysis looked at both that adversarial mindset, how are we breaking in? How are they beating us? And then resiliency to that.

You know, so where are the areas that were strong from a hygiene perspective? Again, this goes back to hiccup. Hiccup is that resiliency standard. And, you know, where, what elements of that, when you marry the two things together, are we weaker on and where do we need to bolster?

And so the, there's a risk analysis component of that landscape analysis that really broke everything up to the 10 practices of hiccup and dug in deep. So there, there were two quantitative studies that we leveraged the chimes, most wired survey data that it was about 377 hospital systems submitted data into. And that one was, is really about like, there's about 80 questions in that most wired survey that gets into cybersecurity stuff. It's kind of yes, no, or, you know, how often those are kind of how the questions are asked.

And the AHA sponsored another study this year as well, sponsored by Sensenet and class. And that study was really focused in on what's the coverage of hiccup look like. What's the coverage of the NIST cybersecurity framework look like and what are some of the demographic information about these hospital systems? And there were 60 hospital systems that participated in that.

And, you know, from there we can make all kinds of interesting inferences about, you know, what coverage is because in, in cyber things are not on or off. They're grades of shade, sorry, shades of gray. And so, you know, how far into adoption you are is actually super important. And that's what that study dove into.

Then after all of that was said and done, we actually sat down with 20 hospitals themselves and did a, had a conversation with them about, you know, what are they seeing boots on the ground? What does their world look like? How does it relate to HICUP? What, how does this relate to the real world?

What are some of the things that they would like to see sort of action on? And what were some of the top action sort of items that those 20 hospitals sorted out? Yeah. So, for sure, the ecosystem is, is one of the major things that we have to consider.

We are not a health system of, you know, four walls and we control everything that goes in through the gates of the four walls. We are a connected system with hundreds of vendors that are, you know, coming in and out of our organization. So that is a challenge that the complexity of the technology stack is a challenge, which is why it's hard to do hygiene at cyber hygiene in this space because it's always fluctuating and always changing. So, and we saw from the studies as well, like, you know, the, the area of that of least coverage was third-party supply chain risk management, you know, from the, from the cybersecurity framework.

So I think that's interesting. We also saw the area of least coverage in the HICUP was medical device security and, and the delivery of medical device security practices. And those two things are actually compounded together because our MDMs are connected into our environment as part of that ecosystem. And then the way we secure all of that is in there.

So that was, that was one thing. You know, I think as well, we saw various degrees of, you know, a test of coverage on 24 seven response. It was something like 88% or 87% of the hospitals said that they have a 24 seven eyes on glass, you know, shop like looking at, at these threats. And 73% aren't.

And, you know, same thing with two-factor authentication. We saw really high coverage on email, 91% saying they've got two factor around email, but that means 9% are not. And then when you start looking at, you know, lower beyond that into like VPNs and so forth, I think the numbers were around in the 80 percentile or 80, 80% coverage on that with two-factor authentication. Again, these are, these are the ways that the, the adversaries are breaking in.

They, they steal credentials or they buy credentials through an access broker and they use those credentials either to get into the front door or when they're inside your network, they move. And through the cross-strike data that we got from the threat report there within an hour and 24 minutes, I think is what their study says, they're moving laterally. They're already pivoting inside your environment using those credentials that they got through access brokers and so forth. So, you know, there's just a lot of, you know, core things that are necessary.

Two-factor coverage on your stock EDR and, you know, third-party, you know, risk management, you know, are, are top, top items. So what's your advice in terms of how healthcare sector entities can use these documents for improving their own security? Yeah, for sure. You know, I think first and foremost, the landscape analysis gives you a state of play where things are right now.

There's really interesting information in there as well on how the investment into cyber looks. So we, we looked at investment as a cyber expense to revenue, and you can, you can take that data and then look at your own organization. So I believe the, the number was 0.38% of revenue on average is being invested into cybersecurity. So go back to your own organization and see where your investment is.

Are you a below or above that? If you're below, you know, maybe you have an opportunity here to shore up some of that coverage and you've got some good industry benchmarks to show you, like what, where things should be. That's also not to suggest, by the way, that that investment is that, that, that we're in a happy place, you know, with that investment, you

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on April 17, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!