I'm Mary Ann Kolbasek McKee, executive editor at Information Security Media Group. I'm here at HIMS 24 speaking with Margie Zook, who is senior principal health cybersecurity engineer at MITRE. Hi, Margie. Hi.
It's great to be with you today. Thanks so much for joining me. So Margie, as you know, health care sector entities are falling victim to ransomware attacks and other disruptive cyber incidents that force them to take their IT systems offline sometimes for days or weeks. What should health care entities, hospitals, and others in the medical profession be thinking about in advance when it comes to these incidents and especially the impact of their connected medical devices and other IoT or OT that might get impacted?
I think it's very important for hospitals today to prepare for a cyber attack. Preparedness is really the key involving all aspects of the hospital in those preparedness exercises involving the cyber and IT people, the biomedical, clinical emergency preparedness side. And to really walk through realistic scenarios, many hospitals have had to disconnect from the internet when these events happen. So understanding the clinical impacts of that.
How would those disconnect from the internet impact their ability to provide clinical services for their patients? And so I think preparedness is really the key to this in addition to doing what you can to raise the bar to prevent attacks but knowing that they may happen and really focusing on the clinical resiliency and being ready to operate under those conditions. So now what about the regional impact on services that are provided by medical devices, imaging systems and other critical gear when a health system in the community is hit with a ransomware or other attack. How should those other entities in the community be prepared to deal with some negative impact for instance or patients being diverted, anything that might impact their institutions?
I think that's really a big focus today is thinking about regional resiliency in addition to resiliency for your own hospital. Recently UC San Diego published a paper talking about the impacts that their hospital had due to a ransomware attack in the region where patients were unexpectedly diverted to their facilities and there were patient safety impacts there and that's one of the first research articles we've seen with actual data for regional impacts. So I think it's very important that these relationships are established in a region that when a cyber attack happens regional partners are informed so that they know what to expect and also to try to build up more of regional partnerships around these attacks. And should they practice or do they even have the bandwidth to kind of rehearse these things in advance being that people are just so busy with their day-to-day operations?
How realistic is that? I think they are extremely busy and we recognize that but I think that this should have a high priority. Regional resiliency exercises are just as important as hospital system exercises so that the partners know each other before it happens and with all of the third parties involved on both ends right of the upstream and downstream from the hospital operations it's important to involve everybody in the regional preparedness exercises. So now what other types of cyber emergency should healthcare sector entities be prepared to respond to?
We hear so much about ransomware, are there other incidents that are sort of in the cyber realm that they should also be thinking about? Any cyber attack is going to cause an impact on the hospital system. There is a lot of focus on ransomware recently because of all the recent attacks but I think that really all other types of attacks need to be prepared for as well. Understanding the interconnections between the systems in the hospital, the reliance on cloud, I think all of that really needs to be understood.
So when we think about attacks we often think about the disruption to patient care but as we've seen in the recent attack for instance on change healthcare which is a key IT services vendor from many many medical and healthcare organizations and pharmacies, that attack was very disruptive for some of their clinical processes but also their business sort of processes, claim processing, those sorts of things. How can entities be better prepared for those sorts of incidents that affect supply chain or pharmaceutical suppliers, equipment manufacturers and other IT vendors that might provide really critical services to them? How do we best prepare for that? I think there needs to be an understanding of the whole end to end ecosystem for these hospitals which involves that front end with the payers.
I often think too of the public safety side, the ambulance is 911. There's so much involved in the operation of the hospitals that you really need to think about all of those aspects of it and think about how can you have resiliency in each of those processes because they are going back to paper within the hospital setting due to the ransomware so hospitals are becoming more prepared for that for longer down times but there's a lot of this processing that has become automated in addition to that and we need to think about what is resiliency there, what does down time mean, how can we be better prepared for it? There's probably a lot of work that goes into one system's over store, they have all that piles of paper that they've been using here in the meantime, getting everything entered into the system, making sure there's a record of everything, is there some way to prepare for that or is it kind of just winging it when this happens? I think realizing that that is a part of recovery and allowing for it because we have heard from hospitals that it takes a long time to actually recover from these incidents in addition to getting the systems back up, they do have to follow up and get everything that was done on paper back into the system so it unfortunately just comes down to preparing for it and preparing for the time it will take to actually recover.
And finally, anything else that you're keeping your eyes on these days when it comes to medical device, cybersecurity or other medical IOT or OT and top concerns? Well we're always seeing new technologies introduced and with new technologies and also with legacy technologies, you know there are opportunities for attacks. One thing that we've been looking into further is regional organization, we're seeing some states including Massachusetts running regular meetings for hospital systems to discuss the latest threats, the Massachusetts cyber center runs monthly meetings for hospitals. So regional preparedness I think is really critical for the future and we are seeing some good things happening across the states and also all of the free services that CISO offers that people can take advantage of, you know they do offer free scanning services, they help with tabletop exercises so you can go to the CISO website and look at what might be reasonable for you to integrate into your hospital setting.
It's also a number of great resources, best practice documents being published by the health sector coordinating council cybersecurity working group so that's a great resource, HHS 405D which is available under that but they have published cybersecurity practices in volumes one for small and one for medium and large which is important depending on the size of organizations. So there really are a lot of resources out there to help that have been developed by communities of manufacturers and hospitals alike. So some focus on the medical device side, some focus more on the hospital cyber practices. So I think there is, we do hear some of some really good things happening to help but it is a, it's a daunting problem.
Well thank you so much Margie, I've been speaking to Margie Zuck, I'm Mary Ann Kolbasakmiki of Information Security Media Group, thanks for joining us. Thank you, it's been great.