I'm Marianne Culbasek McGee, executive editor at Information Security Media Group. Today I'm speaking with Robert Booker, Chief Strategy Officer for hitrust. Robert recently retired as a longtime CISO of the Fortune 100 health insurer. Hitrust, formerly called the Health Information Trust alliance, is best known for its common security framework for health and financial information.
Robert will be speaking to me about how the HITRUST CSF meshes with recent guidance from the Department of Health and Human Services regarding how the Office for Civil Rights will consider in its HIPAA enforcement determinations the recognized security practices that covered entities and business associates have implemented in the 12 months prior to a HIPAA breach or violation. HHS OCR says that among the recognized security practices that it will consider are those pertaining to the National Institute of Standards and Technologies cybersecurity framework practices of section 400 of the Cybersecurity act of 2015 and other so Robert, how does the high trust CSF align with the recognized security practices that HHS OCR says it will consider and does the high trust CSF fit into that so called other category of RSPs that HHS OCR said it would consider? I think to start out we're really grateful for the leadership from Congress and the OCR around this topic. We as an industry have relied on HIPAA HIPAA security rule for now over a decade in terms of looking at security expectations for healthcare and I think, I think steps such as this that in my organizations to look at more modern contemporary security frameworks are really helpful.
So you know when we think about NIST cybersecurity framework we think about the 405D opportunities, specifically hippie as it's sometimes referred to or the other category. I think we the fact that organizations will likely address one of those paths that most preface to how they've designed their program so hydros that they can support NIST csf. In fact that's how we see the opportunity near future well recognized. There's good sector guidance in how to implement and moreover it's something that we've already provided and have available within our framework of tooling.
So I think I look at that as a near term opportunity and organizations are really asked to look at their previous 12 months of sustaining practices. You know we're looking for organizations who have already done something. So I think this is a good approach. It's a good start.
I think organizations will consider different options in the future with regard to other OCR SSRIs taking a very narrow interpretation of the statute there is focus specifically where there is legislative regulatory citation. We see a lot of the feedback that has been offered by commentaries to the RFI that OCR issued last spring as other things such as HITRUST CSF as opposed to NIST csf. So we're hopeful that as OCR understands the true alignment of these frameworks, that they will in fact recognize the tooling such as high trust as an opportunity as well. And it's in sort of natural state.
But we don't think that in any way impedes an organization's opportunity to start and work with it today because we have for a long time had a very significant focus on NIST csf. We're very fond of it, we think it provides a great framework for organizations to work within. And we're not really that concerned about it. In fact, we were endorsing it in our remarks when the guidance came out is that we would encourage those people working with us to use NCSF in the near term.
One point I think is really interesting as well around this is what we really mean by the opportunity for organizations. And so the guidance that was issued by OCR was very clear on the opportunity to mitigate potential enforcement or audit activities and to use use these frameworks as a incentive to mitigate that risk. I actually like the word mitigation a lot as a long standing security executive because ultimately the goal really is to mitigate security risk and to reduce the threats to entities of achieving or sustaining a cyber event. So if you will, a breach.
So, you know, I think a mitigation is often offered the context of recognizing security practices as mitigating enforcement. I actually think organizations I hope will think that it's an opportunity to mitigate the threats that they face and the risk that they face and to implement these more contemporary security frameworks as a method of knowing that their security is mature and it's sustainable and it's continuing to operate as they expect. So Robert, based on what you see in all the years you spent as being a healthcare sector cisa, where do you think many healthcare entities and their business associates have the most trouble in terms of embracing what recognize security practices and what sorts of practices are often weak or fall to the wayside? The thing that's interesting I think about healthcare broadly is it's such a diverse community.
And my reading of what OCR is doing and looking at it I think is really respectful of the fact that healthcare session versus portfolio companies, we have large payers, hospital systems, organizations like the organization I had the privilege of serving all the way down to regional systems and even small. I've heard the term two doctor practice. Often there's these small groups of physicians and healthcare providers out there, all focusing on the same threats and the same risks. They're all Internet, they all use technology, they're all relying on the benefit that technology brings them and serving their patient population.
So they're all exposed. And so the largest organizations will have more resource and more synergies to try to do very comprehensive programs while the smaller entities are focused on just how do we do the basics, do the basics acceptable way, you know, meet the HIPAA obligations and potentially do other things. So I think that diversity and that variety between healthcare providers and healthcare industry participants is a true challenge. And so I think where, you know, without drawing broad generalizations, I think, you know, you have the big guys and big gals and little guys and little gals out there, they're all, you know, focused on these problems.
And so I think where smaller entities may feel like they're having to perhaps go it alone, or perhaps they don't have access to the same level of expertise and experience that maybe large companies can hire, that might be seen by them as a, as a challenge. And I think the opportunity for us as an industry, for high trust and others as participants in the industry is to encourage those small entities not to go it alone. Tools and frameworks like hitrust CSF can chart a path towards them. Knowing where to start in implementing, evaluating and sustaining your security programs, how to focus on the security essentials, maybe to start and step into the other over time.
But I think the other thing that's really out there is also the opportunity to invite collaboration with people like cloud service providers. Most small entities are no longer hosting their technology in house. They're using well trusted suppliers in the market, cloud service providers to provide the fundamentals they need to just keep their systems online and operating and the opportunity to inherit security from those systems and actually take advantage of the opportunities that the bigger cloud service providers have to provide good security as part of the framework is something that's out there. So I would actually encourage the entities that are less complete in their approach to think about frameworks like high trust csf, but also think about inheritance from their supply chain to see where they can actually help them do those basics.
Well, I think if you take that as the small end of the market and combine that with entities that just by size and scale are doing a lot of work in this area, I think together we have a better representation as an industry. And we would hope that would continue to help drive the risk down for all healthcare companies. So Robert, you talked about a lot of the issues that smaller entities have when it comes to the more cyber mature healthcare entities. Where are they struggling the most do you think?
When it comes to cybersecurity issues these days over WAL and why? I think of it as maybe less of a struggle and more of a opportunity to be completed the program. So you know, if I think about the types of things that you have to do to just make sure your program is operating and it's sustainable, I think about the ability to validate your system continuously is really important. Thinking about how you report on what your validation looks like is important.
So I think, I think that's, that's very, very clearly aligned with the RSPs that were just announced. You have to demonstrate, you know, that you're aligned with framework. You have to show evidence and I think very precisely defined expectations on evidence that those RSPs have been active and consistently in use for 12 months or across the entire scale of the company. It's more than just policy and procedures and even more than just saying, you know, I've got an audit program that annually sort of checks my system or biannually depending on the level of certification and assurance you're seeking.
So you got a good validation reporting system. And I think it has to be built into the culture of management for that organization. So the second thing I think is also interesting is assurance and transparency. If you think about assurance maybe set in a way as proof or validation that the practices and controls are implementing and operating just as the OCR has asked for, look at tools that build that framework and drive validation capabilities.
So that's why trust just having been around for more than a decade, we've thought a lot about maintaining, evolving this framework and the assurance system around the framework. So it's the entity that is making sure the programs are mature. So that would be, if you will, a large healthcare company. It's the entities that rely on the evidence that companies produce to make sure that they need to obligations.
So that would be the relying parties in this case ocr, but also the other companies that partner with the entity. And then really the assurance system would be the auditors, the assurance partners, the certifications or validation frameworks that people use. So I think the large organizations, you know, there's an opportunity to really think about that validation, that reporting that assurance and transparency as sort of the outcomes that are produced. And you know, really all that's for the purpose in my mind of making sure that there's strong evidence that the program operates and that organizations can know they're always close to their peak readiness to deal with today's threat, whatever it may be.
We can't really unfortunately predict when an attack or when an event may try to try to hit us or hit one of our trading partners. So we look at that one point, maybe a third party risk. I think it's a bigger ecosystem than just the indicator their supply chain and others I think, especially in the last 18, 24 months have been implicated. So I'd say supply chain risk and third party risk is also really important.
So Robert, talking about predictions, any predictions that you have for cybersecurity in the healthcare sector in the months to come, any emerging threats or risks that seem to provide the most worry right now, I think the challenge for the years ahead is the it's a combination of many threats. You know, we used to think about leaving all companies. Used to think about things like phishing, or we think about things like malware credential attacks. Now we think about supply chain attacks, software poisoning.
One thing I think we can be really clear on is that the criminal entities that want to take advantage of companies are creative, will continue to focus on new and interesting challenges. So the ability to have a risk management framework that's adaptive to the new threats and new attack profiles is continually self tuning and self updating is really important. We spend a lot of time on threat adaptive analysis. So just asking ourselves in the last quarter, what has changed?
You know, now we see more attacks of this nature and so perhaps that indicates more prioritization of certain controls or certain safeguards. And so I think organizations that look at that as a continuous improvement opportunity will be better served. But I also think we'll see a lot of, a lot of interesting activity with regard to public and private sector partnership. I think just the last four to six weeks of updates in the federal government about, you know, critical infrastructure protection, about, you know, recognized practices which we're talking about today, security approaches, you know, I think you're going to see a lot more of that.
And so I think companies that care about this, and I think most all do, will have a lot of opportunity to look at these problems and sort of reflect on how they might want to evolve their programs. And so I think while the threats are challenging and continue to face all companies, the opportunities to have resource and potential investment of new capabilities defined by the public private sector to support these things is pretty strong. So I think high risk, but also high salts for those risks, I think is one way to think about. Well, thank you so much, Robert.
I've been speaking to Robert Booker. I'm Marianne Coldis at thee of Information Security Media Group. Thanks for joining us.