I'm Mary Ann Kolbasek McGee, Executive Editor at Information Security Media Group, and today I'm speaking with Steve Cagle, CEO of Privacy and Security Consultancy Clearwater. We're going to be discussing new guidance that the Department of Health and Human Services has issued as part of the Biden Administration's strategy to shore up cybersecurity in the healthcare sector. The new HHS guidance details voluntary essential and enhanced cybersecurity performance goals, or CPGs that the healthcare sector should achieve at their organizations. Hi, Steve.
Hi, Mary Ann. So Steve, HHS says that essential cybersecurity performance goals include mitigating known vulnerabilities, implementing email security, multi-factor authentication, strong encryption, data response, and so on and so forth, while enhanced goals address certain issues such as asset inventory, third-party vulnerability disclosures and incident reporting, cybersecurity testing, mitigation, network segmentation, and a bunch of other controls and issues. Overall, what do you think of these goals, including how HHS is characterizing them as essential versus enhanced and why? First, let me say that the establishment of well-defined healthcare-specific cybersecurity performance goals, it's a great step moving forward in establishing what I would call very specific foundational outcomes for cyber hygiene and healthcare.
And I think what's really important with these goals is that they reference some very specific controls and practices that need to be implemented, at least in the view of HHS, to truly meet those goals. So why is that important? Well, when we see a clear water, when we assess and advise healthcare organizations across the industry, is that especially with smaller organizations, there's a lot of ambiguity or maybe lack of understanding of what good looks like in terms of cybersecurity. So the outcomes are great, right?
To have those goals, to have those objectives. However, the healthcare industry really needs to be more prescriptive in how it achieves those goals. So one thing I like a lot is that we do have some basic outcomes here that are defined, and they reference existing frameworks, existing control sets, and practice guides that are used in healthcare, such as the 405E Health Industry Cybersecurity Practices, and this Cybersecurity Framework, and this Special Publication 800-S53, that control set. And by defining these goals with these specific references, it might help to reduce some ambiguity.
Now, all that said is it's very important to recognize that these are very basic outcomes, and even the essential goals are very, very basic. And the enhanced goals are generally speaking things that we would recommend for all organizations. So what I think HHS is trying to do here is a bit of prioritization, right? Especially for those organizations, say, where do we start?
And what are the things that are going to potentially reduce the most risk, according to the threats that the industry is facing as a whole? What is absent, unfortunately, from these goals is the requirement to do ongoing risk analysis. So every organization, while, again, important to set up those baseline controls, those essential controls, even what HHS is calling enhanced goals, that's a great place to start. But we have to recognize, as an industry, that every organization has unique risks.
And things like acid inventory knowing where your data is, I don't look at that as being optional. You need to know where your EPHI is. That's a requirement of HIPAA's security role. And there's no way you can know if you're protecting your information and your organization, if you don't know where your data is, where your critical systems are.
So again, the essential goals, big place to start, the enhanced goals, good place to go next. And then thirdly, you need to do that ongoing risk analysis to see what level of residual risk do I have after implementing and achieving those goals. And then what next steps do I need to take to ensure I reduce that risk to an appropriate level? Steve, do these enhanced and essential goals differ much than from what HIPAA already requires?
Is this lifting the industry up at all? Or you mentioned also that, for instance, the risk analysis is not part of this, but it is part of HIPAA. Do these sets of goals do much more beyond what is already expected from these entities under HIPAA? That's a great question, right?
Because we already have the HIPAA security role. We had in place for some time. We see that many organizations, unfortunately, are not following what's intended in the HIPAA security role, and certainly not necessarily implementing some of the requirements in a way that is on par with industry best practices. So, in some ways, we're not talking about anything new, right?
And again, the control sets, the references to the outcomes in the cybersecurity framework, the health industry cybersecurity practices guide was released in 2019, enhanced last year. These are not new things, but what HHS is going to be doing here is saying, hey, look, these are going to be much more specific, right? These outcomes, we're going to define which of the controls from these different control sets, which of these specific practices we really mean. And HIPAA doesn't necessarily do that.
That's one of the challenges is that one can say, well, I'm complying with it. I'm doing something in a certain way. Well, yeah, but you're really not doing it the way you should be in terms of today's best practices. So, I think there is some benefit in doing that.
HHS also has said in their concept paper, their strategy document released in December that they intend to update the HIPAA security role and to begin that process in the spring, and that they also intend for these cybersecurity performance goals to serve as the basis for additional regulation, potentially implemented through the HIPAA security role, potentially used in conjunction with CMS in terms of Medicare, Medicaid reimbursements. So, I think what we're going to see here is again, a more well-defined way of implementing some of the existing requirements that we have, and again, focus and prioritization on some of the things that HHS feels are absolutely the minimum that we need to start with and then go from there. Based on what you see with your own clients in the healthcare sector overall, are there certain goals that were sort of spotlighted either in essential or enhanced that generally give healthcare organizations the most trouble and why? I mean, look, we see a variety of issues across the industry, but there definitely did some common themes if you look either at the breaches that occurred last year and where they were sourced from or other resources.
So, I'll give you some examples of vulnerability management, which was cited right at the top of the essential goals. You can look at the healthcare resilience landscape paper that the healthcare and public health sector coordinating council released last year. In that paper, they found, or in that study, they found that 89% of hospitals surveyed indicated they were conducting regular vulnerability scanning, at least on a quarterly basis, which we don't believe is frequent enough considering how quickly we're seeing zero-day and other vulnerabilities coming out and being exploited by threat actors. But what was even more alarming in that study was that 47% of the hospitals only have a plan to remediate those vulnerabilities.
So, half of our hospital systems, actually more than half the hospital systems, don't have a plan to remediate these vulnerabilities. And that's really concerning. So, why is that happening? Well, it's resources.
It's the need to do vulnerability management and remediate things very, very quickly in an environment where the hospital just doesn't have the people or the systems in place to do that on a continuous basis to respond quickly. We're also seeing many breaches stemming from phishing attacks, from social engineering, those social engineering and other types of not just phishing but phishing smishing. They're becoming much more sophisticated attacks. Threat actors are using AI-enabled techniques and tactics to gain credentials.
Once they have those credentials, they can easily move through a network because many organizations don't have the controls in place to deal with privilege access management or to deal with dormant accounts. They have too many people with too much permission. So, once those credentials are exposed and they're compromised, the threat actor can escalate and move laterally through the network. So, those types of controls, again, they're not easy to implement.
And you have to remember that even when you have really good preventative security controls in place, which we don't have in healthcare, generally speaking, you still have risk. And you still need to be in a position where you can detect whether a threat actor has exploited a vulnerability, is in your network, is in one of your systems. Regardless of how much security we're in is training to, regardless of how many vulnerabilities you're meeting, there's always that risk. And in the past 12 months, the median dwell time for ransomware has fallen from five and a half days to less than one day.
So, just think about how much more quickly an organization has to respond after they detect something little undetected in the first place. And that's really, really hard. It's going to continue to be hard for hospitals, health systems, other healthcare organizations because the complexity is becoming much, much more every day. It's not like we implement all these controls, achieve all these outcomes, and we're done.
Cybersecurity is becoming much, much more complex. So, you have to really establish the cyber security as a core competency. And for larger organizations, their challenges are different than smaller organizations. Small organizations are just trying to get the basics in.
The larger organizations think they've deployed these controls, but they're very large. They've done acquisitions. They have hundreds and hundreds of different information systems, and they have pockets of risk. And their challenges, they don't know where their data is.
They don't do risk analysis on an ongoing basis, many of them. And they have areas where they're vulnerable. And that's what they used, so different types of organizations really have different challenges. But in all, they really need to get these basic controls in place.
And then once again, do that risk analysis to understand where they have additional exposures to the organization. So, Steve, as you know, many of the large data breaches that we see in healthcare, especially last year or the year before, the cyber attacks, many of these incidents affected carbon entities, but they were actually incidents that happened at their business associates or other third-party vendors. The enhanced goals include issues such as third-party vulnerability disclosures and incident reporting. But do you think there's enough attention on these goals as they pertain to third parties that might also be responsible for some of these disturbing trends that we're seeing in the healthcare sector?
And is there anything that HHS could do about that? I think absolutely we need to be going beyond hospitals, beyond poverty entities, other providers. We need to recognize that healthcare is an ecosystem, and it is made up of service providers, of digital health companies, health IT providers, connected medical devices, information is not only being stored on their devices, it's being stored in the cloud. And these vendors, these third parties, fourth parties, and their technologies are becoming essential in terms of delivering care.
And as you said, many of the breaches over the past few years have been third-party breaches, and the industry has struggled to want to assess risk, but beyond assessing risk, you know, we really need to ensure that the vendors are doing something to reduce it to a reasonable level. And my view on this is if you're in the business of healthcare, and I think this is how our clients feel as well, by the way, if you create received transmit EPHI, you are absolutely a target of a third actor, and you have responsibility as an organization to protect that data and to protect those systems. And those organizations need to be accountable to the same standards that a provider is. If they're going to have EPHI, now they are covered in the HIPAA security.
Well, but again, generally, we see most many organizations don't necessarily comply, or they're not necessarily implementing the requirements to the level that they should based on the level of risk potentially to the data for the patient or the patient themselves. So, you know, we have seen additional regulation in medical device security, with FDA this in 2023. Additional regulation, I think, will continue to need to see that type of approach when it comes to other types of technology providers or service providers that are really essential to the industry. So, certainly, I think that's much needed, and it should be an area that the HHS devoted some focus to.
And Steve, you mentioned this as well, that the Biden administration's cyber strategy document in December floated potential rulemaking, including possible sticks and carrots for healthcare sector entities to achieve the various goals. What do you think we'll see in terms of incentives, whether sticks and carrots? And what do you think could work to actually push the healthcare sector forward in this area in terms of meeting these goals? It's a combination of things.
Just publishing the goals, it'll help, but it's not really going to be enough to change behavior. That was also noted in HHS's cyber security strategy concept paper. If we really want to see change across the industry, and by real change, what I mean is, we're not seeing ransomware attacks at hospitals with ambulances being diverted from emergency rooms, we're not seeing megabreeches leading to north of 100 million records, 120 million records like we had last year. Real change.
We need to motivate healthcare organizations and the third parties to change behavior. And I'd like to see HHS communicating, as I said before, that these goals extend beyond just the providers, but also if they're not voluntary. And they're required, they should be required. And we will need to see that, I believe, manifests itself in regulation, perhaps in the update to the security role.
I also think we need some way of validating that these controls are in place, and that, again, organizations are conducting risk analysis on an ongoing basis, and they're doing it in a way that's comprehensive. So we have to have both. We have to have the baseline, because there needs to be some minimum standard that we have in healthcare, but we also need to understand that that's probably not going to be enough, or that there's going to be some unique risks that exist for certain organizations. And without validation, I don't think there's necessarily going to be compliance on the whole.
I think a lot of organizations will comply a lot already doing these things. But if you look at other industries out there, you do see things like auditing programs in the DOD, they've launched the CMMC program to ensure that the defense supply chain is actually implementing many of the requirements that have been voluntary for a long time that haven't been met. That said, I also think we need to be very practical and reasonable about how that's done, because there are many healthcare providers today that cannot afford to fund their security programs. And some of them can't.
Some of the wells are passed to this basic level of maturity. They've got great programs in place. They have great risk management in place. It's not an issue for them.
There are others that cannot. And we need to think about those smaller rural hospitals, nonprofit organizations that never plan for this. And how we solve that, it could be in a number of ways. I think it can't just be punishing those that are really already being punished by things like inflation and resource shortages and so on and so forth.
You can look at what New York State of New York has proposed. They proposed new regulations that would require things like annual risk assessment and having a CSO as a position in the organization, but they also proposed $500 million of grants to those healthcare organizations. And I think some sort of combination of those things is really important. We have to have a solution here and the solution is probably going to be multifaceted.
And finally, Steve, what else are you keeping your eyes on these days concerning healthcare sector cybersecurity issues and why? I think a big thing that we all need to think about as an industry is how do we enact a change here? And I think we really need to have some accountability coming from or at the level of the board and at the C-suites. One of the things that we're doing a lot at Clearwater and we've had a lot of requests for that is continued education.
Education at that level, the organization really understanding, helping us understand what does it mean to assess risk and to manage risk and to make risk determination? Where do we draw the line? I think with the SEC regulations that came into effect at the December 18th of last year, where now SEC regulated companies have to report security incidents within four days. If they're deemed of material impact, they have to report annually on their risk management program, how the board ensures that risk is assessed, what resources they provide.
Many are looking to those types of organizations and what the SEC has done as a framework that potentially should apply to other industries. We have C-suite coming up with critical infrastructure that will need to report ransomware payments that are made within 24 hours, security incidents within 72 hours. So I think that type of accountability at the board level, you have continued to educate those at the board level and really ensuring that organizations have a longer term roadmap to not just address what we're seeing today, but what we're expecting over the next few years, which is going to be a more sophisticated AI-enabled attack by threat actors and greater impact to the organization, as we see larger breaches and more serious impact into ongoing operations. Well, thank you so much, Steve.
I've been speaking to Steve Kegel. I'm Mary-Ann Kobasek McGee of Information Security Media Group. Thanks for joining us.