I'm Mary Ann Kolbasak-McGeek, executive editor at Information Security Media Group. Today I'm speaking with Keith Fricki, who is partner and principal consultant at TW Security. Hi, Keith. Hi, Mary Ann, how are you today?
Good. So Keith, what are you keeping your eye on most closely these days when it comes to the state of cybersecurity in the healthcare sector? Well, I think there's a couple of things. You know, we're always keeping our eye on how the vendors are responding to any question errors that are being sent out by potential purchasers of their products and services.
Because if you look at the Office for Civil Rights breach metrics that are published on a quarterly basis, somewhere between 24 and 40 percent of the breaches that are reported in a given quarter are due to vendors. And it's very revealing at times when you look at these question errors and see the answers that are being provided. In one case, I remember the question was very simply, have you had a breach that was reportable in the last two years? In one case, the vendor chose not to answer the question, but the comment was, we complied with all federal, state, and local requirements regarding breach notification.
So we took that as a yes and went and investigated, and sure enough, six months prior they had a breach that involved over 54,000 patient records. So it's really important that covered entities make sure that they're doing their diligence to the extent that they can to make sure that their vendors are honest about what they're saying. I also think that there's a lot of challenge with how technology is moving at such a rapid pace, and the healthcare organizations continue to struggle with just keeping up with what they have. And so the challenge from a budget perspective becomes, do I make investments in new technology to provide better patient care, or do I try to invest in upgrading my aging infrastructure, and that's always a tough balancing act for organizations to maintain.
So I think those are probably two of the biggest ones that I would come to mind for me. You mentioned vendors, and as you know, change healthcare provider of IT services and products to the healthcare ecosystem recently suffered a cyber attack that seems to be causing a lot of disruption throughout the industry, doctor offices, hospitals, pharmacies, so on and so forth. Some of them are unable to do some of their key business processes, submit claims, do patient authorizations, and some of these entities are saying that this is going to affect their cash flow. Now, we know it's early in the investigation, but what are some of the early lessons that you think seem to be emerging from the change healthcare attacks so far that healthcare and data should be taking notice of?
Yeah, that's a great question. And I think as an industry, sometimes we look at the services that vendors provide to us the same way we do an outlet in our house. You plug an appliance into it and you expect the electricity to be there. And so I think one of the lessons learned is that we really need to take the time to do some kind of a business impact analysis and understand just how dependent we are on vendors for certain products and services, and how we would navigate being without them for an extended period of time.
And you'd be surprised at the number of organizations that have not conducted a business impact analysis, which is actually a requirement in the HIPAA security rule. And once they have their arms around what that business impact analysis looks like, I think the next step then is to move into tabletop exercises where they're leveraging what they've learned about the business impact analysis and run through some scenarios where they have extended downtime, so that if something like what's happening, a change, healthcare happens to them, they're a little bit more prepared and aware of some of the things they need to be thinking about. Now, do you think that entities kind of underestimate the impact that, you know, an attack on one of their vendors might have on them, not really realizing the extent to how much they depend on them, or even for that matter, you know, IT market consolidation, perhaps not realizing that, you know, a vendor that they dealt with before is now part of another bigger vendor that might pose another wave of risk that they're not quite aware of? Yes, I would definitely agree with that.
I really think that one of the possible outcomes of this whole event is that we might see a divestiture of an organization the size that we're talking about here at the United Healthcare Group level like we did in 1982 with AT&T, and the divestiture into all the baby bells, because we essentially had too many eggs in one basket here, and with those roll-ups of the conglomerations, that does cause a single point of failure, and I think when we have to scramble to find alternative ways of conducting business and there aren't many choices left, that makes it difficult for us to have a backup plan, or a plan B. I guess it also makes those large organizations bigger targets for the bad guys? It definitely does, because, you know, the old adages, why do bank robbers rob banks, because that's where the money is? So the criminals are going after the large organizations, and, you know, we continually hear, unfortunately, that if you're a target of intent by a criminal group, they're likely going to compromise your network and get in, and because the trend these days is for the criminal element to steal data first, because organizations have done a better job of being able to restore data from backups, they want to steal the data to extort money so that you can't rely on the backups because they'll threaten to post your data out on the internet.
So I think all these factors are really a wake-up call for all industries, but healthcare in particular, just about what a bad situation we're in right now, and the recovery time is a lot longer, I think, than anybody expected. So when it comes to artificial intelligence, we hear a lot about AI and healthcare, machine learning, enabled sort of healthcare developments, what are you most optimistic about in terms of AI helping healthcare, but then what are your top concerns in terms of the risks? I think the optimistic part that I have is twofold. First, there are capabilities that machines will bring to healthcare delivery that will supersede what humans are capable of, just sifting through terabytes of data and helping make some very eye-opening or cutting-edge innovations in diagnosis and treatment, and I think that even AI itself might help us understand different ways that we could approach using today's technology as a way to move us into future use, and also I think where it lends itself well is we always here, especially in healthcare, that people resources are spread so thin, and AI is a good opportunity for us to automate some of the mundane processes that free up people's time to focus on the things that are most important.
The areas of concern that I have include, you know, I advise people that AI creeping into the business world isn't a whole lot different than social media when it crept in, but there's a much bigger leap in using it appropriately because we really, really need the governance and focus on the ethics of using AI, and I think we're running before we crawl and it's going to come back to haunt us because the AI technology is, it's kind of like letting the horses out of the barn and trying to corral them, I don't think we fully understand what we've unleashed, and organizations need to get their arms around how they're going to best use AI, but to do it in a manner where the system has integrity because if you're not focused on building a platform that, you know, the whole garbage and garbage outage is really important here because you have to be able to trust that the output is valid, and unfortunately I think that today's generation has been conditioned to take everything at face value, and one of my favorite sayings of late is common sense isn't a flower that grows in everybody's garden, and we really need to question the output of AI and make sure that we're validating it because if we don't, now we're talking about patients' lives in making decisions, so I think these are some of the really key aspects of using AI so that we're using it with respect. Thank you so much, Keith. I've been speaking to Keith Fricki of TW Security. I'm Mary Ann Cobisak-Bagie of Information Security Media Group.
Thanks for joining us.