As the coronavirus outbreak grows, many businesses are requesting that their employees work from home. That includes health care sector organizations and workers that are not on the front lines in patient care. I'm Mary Ann Cobusak-McGee, Executive Editor at Information Security Media Group. Today I'm speaking with former health care CIO, Drex DeFord, about how mandatory work from home potentially impacts data security in the health care sector and what do entities need to be thinking about and doing to address these new challenges.
So, Drex, for starters, when we think about the health care sector, we tend to think about those on the front lines, and clinical workers who are working directly with patients. But what other kinds of health care sector employees are candidates for work at home and telecommuting? There are actually quite a number of health care teammates that can work from home. When you think about much of the information technology team, while there are things that they have to do maybe hands-on inside the organization at a data center or something like that, a lot of them can do most of their work from home.
Supply chain people may very well, especially if they're just doing payments, things like that, may be able to work from home. The chief financial officers team, the treasurer, all of those folks have real opportunities to work from home because most of their work is administrative. If you think about it as a sphere, the health care workers, the people who touch you, are on the point into the sphere that they're supported by a lot of other folks who can certainly work from home. And what about clinicians that are providing telehealth to patients?
That's being expanded by many organizations. And what about clinicians that are providing these telehealth services to patients, but the clinicians might be at home? Is that also something that we're seeing a higher demand for? I think you see a higher demand for that now.
There are a lot of organizations who, as you said, are expanding their telehealth. But during this time, certainly has a way to pre-screen potential patients who may have COVID-19 wanting to check them out before they come in. Some of those physicians are working from offices that are either on campus on the hospital or in the office, but some of them are working from home and there are opportunities for that. And certainly, if that requirement expands, you'll see more physicians working from home, especially if they're fully dedicated to the telemedicine side of the house.
So, Drex, is it safe to say that security teams within health care organizations typically don't deal with situations like we're dealing with right now where there are sudden great spikes in demands for enabling and supporting work at home? And with that said, what are the challenges that these security teams are facing, especially in light of this fast turnaround in terms of fulfilling these requests for people to be able to work at home and access corporate networks and maybe patient data securely while still running business as usual? That's a really great question. I mean, I think I would start off with sort of this idea that being in a hurry is a recipe for cybersecurity problems either now or in the future.
Now, certainly I'm a big fan of cutting through red tape and if we can cut through it, let's cut through it, let's reduce the cycles that takes to get things done. But a lot of the red tape, especially in the world of cybersecurity, is there for specific purpose and we need to pay attention to it. We're onboarding temporary staff, for example. There are a lot of organizations that are bringing on nurses that are temporary, all of that onboarding and off boarding of those folks when they're done, making sure they have proper access to systems.
All of those are incredibly important when it comes to their work from home staff. While we've always had individuals who work from home that sort of sheer increase in this crisis driven remote work demand, maybe enough to overwhelm some of the remote work infrastructure that health systems have, it may cause them to do things like go out and purchase emergency equipment, have emergency installation of new hardware or software to support that demand. And the punch line and all of that is be really thoughtful during this crisis. This sense of urgency sometimes creates a potential for openings that can be exploited by cyber criminals or landmines that you may just step on later, even though you had really great intentions to go back and fix some of the things that you did, some of the shortcuts that you may have taken to get the mission accomplished.
So just be thoughtful and be careful. So drugs, we're seeing a demand for telecommuting in many industries as well. Are there any special security or privacy challenges for entities in the health care sector that are not necessarily being faced by organizations and other sectors at this point? Health care definitely has some real specific requirements when it comes to health, patient privacy and security.
We see that through HIPAA and other state regulations that have promulgated over time. Certainly when you're working from home and when you have employees working from home and health care, you want to be very thoughtful about how they secure their workplace and do they have a place to secure documents that they may have at home, especially that has really proprietary business information or more patient, clinical information. You want to do all the normal things that you would do, make sure that the PC that they're using has a screen saver, that it has full disk encryption in case somebody breaks into the house and steals the machine. If you're using your personal Wi-Fi and you will be at home, make sure that you have a desk Wi-Fi enabled and that they have a separate network from the words, change your network password words, change your router passwords, make sure that all the things that you're doing are secure as possible.
You know, some organizations are leveraging virtual desktop infrastructure, which allows them to sort of expand this capacity for remote work pretty quickly. Unfortunately, if you're an organization that hasn't already gone down the VDI path, trying to stand up now may be a bit of a challenge. Always make sure that you use multi-factor authorization tools, so two-factor authentication kinds of tools to make sure that you're double checking that the person logging in is the person that's logging in. Some organizations that I've talked to you in the past few days have actually created sort of work-from-home kits that includes both the equipment and sort of a how-to process of the things that you need to do.
That may include things like reviewing the home environment before approving work-from-home. And that everything in the process gets documented because undoubtedly at the end of all of this, there's going to be some audits to make sure that all the equipment comes back, that we didn't get breached, that all those sorts of things are resolved. And then I think you look at tools too, like Slack or Microsoft Teams or Zoom or WebEx. You always need to make sure you have a backup plan.
There's been some outages and some of these tools from time to time, so you need to have a backup plan for staying connected and being in meetings. And then certainly, I've even had this experience in the last couple of days, home networks and neighborhood ISPs that you buy your internet services from are feeling pretty overwhelmed right now too, and they have a challenge processing all of that web traffic. So it's all of that. And I think when you take that and sort of combine it with the reality that inappropriate access may be a little harder to determine with somebody teammates working remotely, chief information security officers are going to be working overtime and their teams are going to be working overtime.
And especially when you look at small hospitals, which is most of the country, small and rural hospitals, that's where most of the scale are healthier from. Those teams are very small and very challenged when it comes to all of this work. I recommend that they seriously consider getting some outside help during the stressors of all the work that's going on right now. So, direct with that said, what are the new challenges that health security teams are facing with coronavirus on top of these potential cyber attacks that we are seeing, or phishing and other sort of attacks sort of linked to coronavirus in such a hot topic, and then the remote working?
When you put all this together, right, it creates sort of an interesting compound challenge. When you're at work, hopefully you would have a better opportunity to focus. Now that you're working from home, sometimes you have the challenge of kids are home and you're trying to homeschool them or your significant other is homeschooling them. The dog is barking, there's music playing, there's lots of other stuff going on.
So, it's much easier to be distracted. And in fact, when you sort of add in this other part about coronavirus and phishing, the clickbait is super attractive. I mean, if somebody sends you an email that says, turns out the president has coronavirus, that's something I'm going to want to click on. That's not true, by the way, but that's the kind of thing I'm really going to want to click on.
I'm going to be really interested in that. A lot of the emails that we're seeing out there are being targeted specifically to stuff that's interesting to the victim. So, if you had planned to go to a conference in the next couple of weeks and the bad guys somehow got their hands on the attendee list and they spooked the conference with something that says, click here to clean your refund since we're canceling a conference, you might do that because it seems like a real thing and you might get sucked in into that phishing scheme. That's not good.
I would say the other thing is to a lot of this is general hygiene stuff. Don't click on attachments. We already know there are emails out there with coronavirus safety measures that PDF as an attachment, teaching people, allegedly teaching people what to do to be safe in these trying times. That's a piece of malware, so don't click on it.
Be thoughtful about all the apps that you download. We know that we want Android app that's advertising itself as sort of the latest greatest corona 19 update, but it's really just a way to get malware on your phone. So, there's a lot of challenges that kind of go into this work from home environment, compounded with corona, and people being distracted and being in a hurry. And then I think you add on to that sort of the reality that people in healthcare love what they do.
They are here to support patients and families. And during a time like this, the mission really is pulled out of them. They've been over backwards to do things to help patients and families. And sometimes that means they make mistakes.
Somebody sends them an email scooping the CEO asking them to transfer money to pay for some equipment that you know that the organization needs right now. If you were in the office, this would be as easy as sort of sliding your chair back and walking down the hallway and double checking with the boss to make sure that they really wanted that to happen. And it worked on home environment. That's not as easy.
And again, with the sort of pressure of let's get things done and make the mission move, the tendency might be that they skip a step. And that could be disastrous for small hospitals. Now, Director mentioned skipping a step. And as we know, IT and security departments in stressed out, stretched thin, healthcare organizations are facing short turnarounds in terms of the IT requirements to support the added burdens on their entities, including the telecommutors, but all the other burdens.
What's the potential impact of all this pressure that these IT and security departments are under? And any advice on coping with that without making the sorts of mistakes that could end up in bad situations when it comes to data privacy and security? I think the advice that I would give would be to stay calm and try not to panic and everything that's going on. For the leaders of the organization, there's a lot of prioritization and reprioritization for you to do.
This is a time to really lean into it and lead, be decisive, show your frontline troops that you're there with them and that you're there to help them not be on roadblocks to get the mission done, but don't give them the sort of authority to overreach because that can be a situation where you get into trouble. Hopefully they built teams that have the authority to do a lot of great work without being centrally command and controlled. And if they take in time to do that, they're better off. Certainly healthcare has the opportunity to do a lot of these kinds of exercises and a lot of these kinds of practices to be certified by the Joint Commission and hospitals have to do regular exercises.
A lot of those are around disaster scenarios and standing up command centers and being able to work the issues and work the problems that come up from those situations. This one's a little bit different. This isn't like a plane crash or this isn't like maybe an earthquake that has a very short time frame and then everything is going to be over and we can go back to normal. Certainly feeling like this is going to be a long-term event that's going to be going on for a while and we're going to have to continue to build and renovate and revise our current systems of operations to be able to accommodate this new reality for a while I think.
Thanks, Drex. I've been speaking to Drex Daford. I'm Mary Ann Kobusak-McGhee of Information Security Media Group. Thanks for listening.