I'm Marianne Kolbasac-McGee, Executive Editor at Information Security Media Group. I'm here at HIMSS24 speaking with Lee Kim, who is Senior Principal of Cybersecurity and Privacy at HIMSS. Hi, Lee. Hi, Marianne.
So, Lee, we're here at HIMSS now for a few days. What are you hearing from healthcare security leaders, such as CISOs, in terms of their biggest concerns these days? Their biggest concerns include everything from their own liability to AI, of course. How do we secure in light of AI and everything fueled by AI?
I think also they're concerned about, of course, the increasing mountain of regulations as well. And in terms of regulation, what are they worried about? I know there is some talk about the HIPAA security rule being updated, perhaps potential enforcement of not meeting certain requirements when it comes to cybersecurity, even though the cybersecurity performance goals are voluntary right now. What are they worried about?
I think that's a great lead-in because the cybersecurity performance goals, which, as you know, are a derivative of the DHS CISA cross-sector cybersecurity performance goals, are sector-specific ones. They're voluntary for now, much like the electrical sector has sector-specific goals. But I predict if I had a crystal ball that they would definitely be mandated. And I think that it's a great time for healthcare organizations to get on board before maybe they're running out of time.
So now what are some of the lessons that you see emerging from some of the major cyberattacks we've been seeing lately, including the Change Healthcare attack, which has certainly had a significant widespread impact on the healthcare sector? What lessons are emerging in terms of vendors, business continuity, emergency preparedness, and all of that? Oh, absolutely. So first of all, I would say the greater need for information sharing.
I think that in terms of cyber threats, we finally realized it could be really vast and far-reaching. So the ability to share threat information with other providers and even vendors in the space is very important. So that's why it's highly important to get on board with H-ISAC and partake of things like 405d resources. I think just as well, we need to look at our business continuity and disaster recovery plans and even look at NIST cybersecurity framework 2.0 and look at those implementation examples, right?
Like how can we do better in terms of ensuring that our business and our clinical operations are still running? What can we do in case the internet or something electronic is not working? Do we have paper backups? Do we have other backups in case one thing fails?
It's really, I think, a signal to say, look at everything that could potentially be critical and that could potentially be a cascade of failures. How can we safeguard against that? And we could do that by revising policies, procedures, and training people on the new way. So now what are you keeping your eyes on when it comes to artificial intelligence, machine learning-enabled healthcare?
What's changed the most since last year from a regulatory standpoint, from a legislative standpoint? What are you watching? I am watching the development of the European Union AI Act and the fact that for certain technologies that are very, very, very risky at the extreme end, those are banned. Those with high risk, there are some limitations as to those systems, et cetera, et cetera.
And I think it's very important because we're starting to see that there's a link between artificial intelligence and safety. For example, in the military context, I don't think that necessarily we wanted to even fathom AI systems or other things being automated in that sense, but AI is being embedded into everything, and that's something that we need to keep an eye on. So one thing that I'm really fascinated by, though, in terms of whether you're on ChatGPT or using Gemini or something else, is these models, of course, take an educated guess and, of course, sometimes certain specific statistical calculations to determine, okay, this is the knowledge that you need. But really what is happening is that you always have to review your output and the day and age of social media and TikTok and everything else.
I just simply have to ask, do we still have the discernment skills where we can review something and see, okay, there is an error, there is an omission? Because I build GPT models sometimes every day, personally, sometimes professionally, and what I've seen is sometimes what GPT and other things will do is that it might sometimes drop some things from an answer or analysis. Sometimes it might pull something from another totally different and irrelevant domain and suddenly it gets into my answer. And sometimes it'll do things like it will, of course, as we know, hallucinate on occasion in terms of something that might not be true at all, something that might sound very authoritative but is actually made up.
So this whole business of, dare I say, fake news and everything else that we've heard in the news, I think we need to have an eye out for fake information and what do we do about it. And I would say the most powerful weapon we have is cognitive tools, is the ability to deeply think and sometimes creatively think because at least right now, these AIs cannot create as humans do and they certainly don't have creativity capabilities. So I would say the next time you're concerned about a deep fake or something else, maybe throw a zinger and create something and sing, write a poem, do something that'll fool the AI and maybe it'll say, okay, as a deep fake, I give up and I can't simulate it. So now you mentioned deep fakes.
What are some of your security and privacy concerns when it comes to the use of AI in healthcare and how are those concerns changing? Sure. From the AI perspective, this is, number one, I think that it's fundamental, right? I mean, I think that in terms of AI and attacks, it's not like the attacks will necessarily get more sophisticated because that's not where large language models and other generative AIs is at.
It's very superficial but extremely quick, quote-unquote, thinking and processing of things. So I think we need to be aware of AI-fueled attacks that have just much greater velocity. And if you think about the world's fastest volleyball game, well, you've got to have an automated tool to match that automated volleyball server that's serving at 100 miles per hour, maybe 1,000 miles a second. We need to leverage AI tools to defend against AI tools.
It'll truly be more machine-to-machine. I anticipate in terms of threat intelligence and defenses that we will get much more automated as it relates to defense. I think that also as to the vulnerabilities that we see and screen-connect vulnerabilities as we saw in connection with certain cyber attacks, instead of the manual process of actually patching when we get around to it or when we can or when the doctors will allow us, I think that we will deal with more systems that are automatically analyzing for vulnerabilities and that can self-heal. And not naming names, but I think that there was a DARPA competition in about 2016 where there was an AI system that already demonstrated that, the ability to find vulnerabilities and self-heal.
So I really do believe systems like that are the future of our technology. And a year from now, where do you hope we're at when it comes to the use of AI in healthcare and organizations kind of vetting out the concerns that they need to be focused on? What would you like to see in terms of advancement, in terms of handling AI? Absolutely.
I think that across all healthcare organizations, I really think that within a year they should stand up some kind of central AI committee that's made up of the major stakeholders like legal, like the head of clinical, like accounting, all the major things that make your organization work so that for anything significant where AI might change the way you do business or do decisions or make business decisions, that people are on board and that there's consensus so that it's controlled because otherwise uncontrolled growth can lead to what? Cars wrecking on the road, essentially. So I think that's where we need to go with that. I also believe that in terms of ethics and workforce, those are two issues that I'm not actually hearing enough of.
How do we responsibly deploy AI at our organization but still keep that human element, still keep that human touch and consideration as to what we are doing and what we are seeing just simply to preserve the human in the loop and ensure that our workforce still operates as a workforce and not just simply a money-making machine in light of profit. Well, thank you so much, Lee. Always a pleasure. I've been speaking to Lee Kim of HIMSS.
I'm Marianne Kolbesak-McGee of Information Security Media Group. Thanks for joining us.