I'm Mary Ann Coba, Executive Editor at Information Security Media Group. Today I'm speaking with Taylor Lehman, who is Director for the Office of the CISO at Google Cloud. Taylor, who was a longtime CISO in the healthcare sector prior to joining Google, and I will be discussing some of the latest regulatory developments involving cyber security in the healthcare sector. So Taylor, as you know, the Department of Health and Human Services recently issued guidance specifying certain voluntary cyber security performance goals that the healthcare sector should be trying to implement.
The so-called CPGs are broken into two categories, essential and enhanced. HHS also indicated that the so-called voluntary goals will inform new enforceable cybersecurity standards. The CPGs are also part of a larger strategy that the Biden administration has to improve cyber security in the healthcare sector. So Taylor, based on what you see, what do you think about HHS's plans so far to help boost the cyber security in the healthcare sector?
Is this where we need to go and why? I'm encouraged to see so much activity taking place right now. The last year with the CPGs being the latest sort of activity has been pretty productive. We started with the Omnibus Appropriations Act, which got into focus on security and medical devices, which many of us in the industry were happy to see.
Finally, something there. We've been doing more now with looking at AI and these health AI underscoring the importance of security and its relationship with safety. There, HHS last year started to allude to there be more here in terms of the CPGs. We talked also about the visual resources that were going to be put in place to incentivize and implement actually better cybersecurity in hospitals, specifically a great strategy around education, strategy around enforcement and accountability.
So there's just been so much in the last year. It's hard to be critical, especially from someone in my shoes, who has felt very strong for a long time that something needed to be done to really make this more of a priority. So I'm positive on it. I do think it doubles in the details, though.
And I'm curious and kind of holding my breath to see what is going to happen with HIPAA in particular, that's one area I'm bringing to see. And then how will we translate the law into what level of prescriptiveness will it be when whatever comes next comes next? So with that said, when you do start drilling down on the various goals that HHS has set, which goals you think entities are most likely to struggle with and why? Well, I think the work unique thing about the CPGs that wasn't immediately obvious to me, I've read them a couple of times, is they've done a job of aiming data-driven, which is to say they took a retrospective look at what didn't work or has worked in the past as protecting systems.
And the issue of guidance set was basically the answer to many of those events and have those recommendations been in place at the time the organization, where they started to experience it, that they wouldn't have them in the first place. So I think that the data-driven nature of it was really good in general. I also think by focusing on the essential and enhanced data, they did a good job of explaining what are the very, very basic things you need to do and they didn't start out with. Here's a recommendation on, for example, do an inventory of systems and software.
While that's super important, and that's been guidance that has been given to industry for years, like that particular guidance is really, really hard to actually do. So in many organizations, just because they can't do that activity, for example, they don't do anything. The CPGs did a good job of putting very reasonable and achievable goals in the essential. And I think that'll, it's a subtle thing, but I think it'll go a long way to helping organizations actually make progress.
But I think, you know, overall, it's the heavy emphasis on prevention, which I think is good, but it doesn't go far enough. I like to be focused on identity, basically making sure that the people who are in your systems are known and that they have the right levels of access. Like, there's no other more common breach that we see in cloud or anywhere that doesn't start with identity problem. And I think that was really productive.
But I would really like to have seen much more on resilience measures, specifically those things that keep systems up and running when there is a compromise of a network or a system. And that really speaks to a broader point around like availability of systems. We continue to need to make progress that availability is the goal in a healthcare setting. The systems have to keep running and working and treating people.
If they go down, bad things happen. And I'd say arguably that's much more of an important outcome we need to get to than say data privacy. Data privacy is important, but like you have to choose between privacy and getting health care. I think most people would choose getting health care.
Taylor, what kind of health or various resources do you think health care sector entities might need to achieve these various goals that HHS has set? Well, I think the first thing anybody is going to have somebody sit down and look at this and say, all right, I'm going to start. It's like what to start with. And while they are basic, in general, you know, there's 20 CDG.
So you can't do them all at once. I usually try to steer people towards the first second of these really get information about your environment. And if you can do that with like a focus on what are the things that are going to fail first and hurt the most, you will practically speaking, you're going to make more progress in a short amount of time focusing on those things. So we talk about, you know, don't get a red team.
You'll get a purple team assessment and build you some technical analysis of your network to show you where the weak parts are in it in particular, you know, the highest priority ones. And then overlay the results of that activity with the CPGs and or other guidance, like this is got some really great guidance on security and cloud security, on princess and security and local devices, but really use the actual information about your environment to drive what you go do from a goal pursuit perspective. Taylor, you've spent many years as a CISO in health care at a large health care organization. You see much overlap between the CPGs, the essential and the enhanced goals and what entities should be doing under HIPAA already, or is there much new material here that, you know, kind of drives things forward?
There's nothing new here. This is guidance that's been given in different flavors for the better part of the last two decades. You know, it stands out to me that it's still the prevailing guidance, which really should make you wonder why haven't we been able to get to this yet? If we've been talking about the two decades, what applies to CISO is from.
And I think a lot of this stuff is so a challenge because of factors really unrelated to cyber security, organizational politics, bureaucracy, the stacking of, you know, particular things, any organization that has on flavor, those things do get in the way. One unique thing about how there's just this tremendous amount of legacy technology that exists, you know, all that old snowflakes, things that exist on a network that are really hard to secure because they require a pretty specific approach to do it. And, you know, one of the things that I thought was interesting is, you know, really thinking about the technical debt, probably the thing that makes any of these goals exponentially hard is when you compare that to like modern computing platforms like cloud, and I went through this, you know, with Google cloud, it's just an example that I work here. But like at least eight of these goals, of the 20 goals, eight of the goals, are turned on by default on the cloud.
Meaning if you took a server and deployed it on-premise, you'd have say 20 of these things to do. You took that same server and you deployed it in Google cloud, you only have 12 things to do because eight of the 20 things are just done automatically turned on for you. And so like just there, right, like if we agree that, you know, the technology, that's a problem and the way out of technology that is to upgrade modern systems, just like generally, like there's a data point here that says like, it's true, right? Like almost half of your security burden goes away just by leveraging new technology platforms.
I thought that was really powerful. Until you're sort of talking about security by default, as you know, we do see a lot of incidents in the healthcare sector, but also other sectors that involve vendors. Do you think that the, you know, the vendor community overall needs to sort of look at things in that, you know, security by default sort of manner, so that, you know, these mistakes that sometimes happen are less frequent, and that, you know, fewer organizations that use various products are victims of something that, oh, we've got to set something. Oh, I didn't know we were supposed to do this.
Yeah, I think the more people who pick up on this idea and censorship products where security is turned on and all the way up, almost the point where the product itself is unusable and requires you to turn some of it off, like, starting, if we were to start with technology that showed up on our loading docks or showed up on our internet browsers, like, that worked that way and did require someone to go get a PhD in securing the device if it was shipped with nothing on. I think we wouldn't see many of the problems we see today. Like, entire classes of threats would just not exist, because, like, in many respects, like, you know, the secure option is also the only option. And we could do that if more people started really thinking about how to make their products designed for security and secure by default.
Taylor, as you know, the overall strategy, local calls for an update of the HIPAA security rule. They're talking also about potential kind of sticks and carrots to get entities to adopt, you know, some of these goals, even though they're being called voluntary. What do you think needs to be done to kind of push things forward? When it comes to either new requirements or new incentives or, you know, sticks and carrots, what do you think might make a difference?
I'm a little torn on this one. I think cyber security is a requirement. It's not an optional thing. And I think, especially, you know, in any business you're in, really, you know, it's not necessarily the mission of many of these organizations to be great at cyber security, but, you know, hospitals to treat patients and make people healthy.
That's the idea. You know, drug manufacturers make drugs to keep people healthy. That's their goal. Nowhere in there is cyber security.
Be great at cyber security. But, you know, it is a requirement to do business. And, well, my slittness on this is, you know, I personally feel like cyber security has been and should always be core to any business decision, any funding, any investment that's being made, because it contributes directly to the mission. If you can't do those, you can't treat patients and manufacture drug systems or no.
And yet, like, that has not, I think, been something that's been prioritized highly enough for years. Organizations, generally speaking at all, there's some great examples of people who really got this, have not done enough to maintain security protections commensurate with the risks that they face, the reality of the world. You know, so the bittersweet side is like, you know, I'm glad to see we got this carrot and carrot approach. I'm calling it a carrot and carrot approach, because I don't know if there's a stick yet.
But there's a carrot and carrot approach that they suggested promoting or suggesting will be coming where, you know, there will be certain reward and or penalty for being good or bad at us. But I don't love to see the fact that it had to come through a government. I feel like we should have been able to figure this ourselves and having the government do it while it is very necessary at this point in different history. It still strikes me as like, we and security need to do a better and better job of articulating the value that security returns to the business, so that it is captured and funded like any other mission-oriented activity the business does.
So, you know, I don't want us to lose focus that security has value, and we need to keep driving towards that. But I do think in this case, given the state of things, having additional funding mechanisms available to organizations that simply can't get there is something that's going to, you know, keep Americans safe and stable. You know, in certain organizations near where I live up and running because we need all of the hospitals we have. And finally, Taylor, are there other sorts of challenges that you see right now in the healthcare sector where it relates to cybersecurity that are to being addressed by this, you know, strategy that's being laid out and what keeps you up at night?
You know, I think we're in the early days of the medical device security rollout. I still am very concerned that medical device manufacturers haven't really left the FDA's new guidance sink in and are actually doing what the guidance requires. I think there's, you know, I think it's still early days, which might explain a lot of that. But I do think that there's still a lot of work left to be done and a lot of follow up that we're going to be more about around how medical devices are doing with respect to the new guidelines that were put out and enforced last year.
So that's one area that I'm interested in seeing and hearing about in like, you know, if you just put this in the context, you know, medical devices, you're listening to this podcast. You might be thinking of talking about like a pair of scissors or a scalpel or something. It's like, no, I'm talking about software enabled equipment that's being used to diagnose, treat, you know, a patient. And many of those come with very complicated software, including AI.
And it's probably the one, the one function of procurement, procurement of these devices is where almost all of the new technology that is entering a hospital comes through these devices. So it's a big deal to think about it. You know, a lot of what was entering the ecosystem and being attacked is are these things. And they're also things that are used to keep people alive and healthy.
So like, you know, making sure that we're doing enough there couldn't have come soon enough. I'm glad to see it coming. But I'm really interested in seeing what's next. I'm also interested in seeing like, like how is going to evolve if it doesn't get into prioritizing availability and integrity of data.
Now, we're still going to, you know, have to deal with mitigating, you know, these, these, you know, direct risks to human safety. I think the integrity piece is really important because almost all of this data that's being collected by these healthcare systems, you know, we're in the age of AI now. So all of these organizations are looking to use AI, which means the accuracy of the data that's really important. We don't have really strong controls over the data coming in, how it's being used, how it's being maintained and managed.
You know, the next round of medical innovations being built on the back of this data is going to be inherently flawed. And so I'm a little worried about that. I'm really curious how things like consent, meaning like a patient consent to their data being used for a certain area might also get in the way of medical innovation. And what I need to say is, you know, if AI isn't trained with enough data on a particular problem, because people have said, don't use this to train your AI model.
I feel like there's going to be, you know, technology that's built that isn't, you know, trained effectively and could, you know, end up doing something other than what it's for. So I'm also thinking about medical data integrity and then the downstream use of it and what are the second order effects are. So all fun Friday night activities at the Lehman household. This is what I talk about with my kids.
Well, lots to think about, certainly, Taylor. Thank you so much. I've been speaking to Taylor Lehman. I'm Mary Ann Cobissak McGee of Information Security Media Group.
Thanks for joining us.