I'm Mary Ann Kolbasek McGee, Executive Editor at Information Security Media Group. Today I'm speaking with Mike Hamilton, SISO, and Co-Founder of Security Firm Critical Insight, and John Delano, a former healthcare CIO, and a current VP at Christus Health. We're going to be discussing a new critical insight report examining health data breach trends so far in 2023, as well as some other emerging healthcare security issues. So, Mike, for starters, please describe what your study examined involving health data breaches, and what were the biggest surprises or changes that you saw so far in 2023?
The study is conducted by going through all of the public reports of unauthorized disclosure of protected health information, and it's all public, and we have data analysts that get on this, and they tease out the trends. I think a lot of it is obvious to us that health institutions are getting knocked over at a furious pace, that records are being stolen, that the knock-on effects have become more severe. I think that the biggest surprise to me was the entry point in the organization, what leads to one of these data breaches. Network server breaches are responsible for 97% of the records disclosed, where only 2% can be attributed to email action.
That surprises me, and it's probably shouldn't surprise me because the trend that we have seen is when there is a vulnerability announced, the scanning to find vulnerable systems starts within five minutes, and criminals and nation states both go to work right away, reverse engineering a patch to find out how to create the exploit, and they've gotten real good at it. So, I think that really constitutes a bit of a wake-up call for me. I know that for you, John. I think to maybe add on to what Mike said, it doesn't surprise me just because we've run so many legacy systems within health care, and so we're still trying to get into-life operating systems and equipment out of our environment, and as Mike mentioned, we can certainly reverse engineer patches, but when we're talking about into-life systems, the vendors are no longer writing patches for those exploits, and so server 2008, 2012, some of these older in-life operating systems, we still have running in our environment, which nationally opened those doors to risk.
The second thing I would add that it kind of stood out to me as it relates to the breach report is while we certainly see the number of breaches slightly decline, I won't say it was a big decline, but it did go down, which is always a positive, we actually continue to see the number of records that were breached to go up, and so what that's saying is while we have less breaches, they're much bigger in nature, and so that actually constitutes to be a bigger problem, it would be easy to rest on our laurels and say, well, the number of breaches is going down, so we're making headway, we're doing something right, but in reality, the number of records that were breached continues to go up, which is the problem. So I understand that a lot of the uptake in terms of the number of records that were compromised in these breaches, even though there's been fewer breaches, we see more patients or individuals affected, and a big part of that appears to be the business associates, and we often hear about business associate breaches that affect dozens of covered entity clients and many of their patients. What sorts of BA incidents that we're seeing are most concerning to you and why? John?
Business associates have been around for a long time, it's a requirement from a HIPAA perspective, but we're becoming more interconnected. Every system is interconnected, where in years past, we had a lot of standalone pockets of data, but now we're sharing more and more data, we're more interconnected, and so to me, that's more of the reason why we see business associates being a big portion of those that are compromised, just to me more of the interconnected nature of where we stand from data exchanges and other types of interoperability. And Mike, how about for you? I know we see a lot of vendor, third party sort of incidents, major software vendors having vulnerabilities that get exploited, that affect health sector entities, but also entities and other sectors.
What's most concerning? Well, I think it shows that the criminals are doing research and targeting to a greater degree than they did before. If someone can affect a service provider that, for example, provides online access to protected health information, online records, electronic health records, and that service provider serves a dozen 2,600 institutions, it becomes a one-stop shop. So I think that, as I say, this is not only targeting by criminals, but it's an attempt to lower their own risk and maximize their own return on investment of the resources that go into these things.
So these are criminal corporations, and they're trying to maximize ROI here, and the best way to do that is to go to the one institution that has records that apply to many and do one smash and grab instead of a hundred. Any predictions for what we might see for the remaining months of 2023, perhaps into 2024, in terms of evolving health data breach trends, Mike? I think that with an election coming up and the geopolitical situation the way it is, and the fact that there is a regional impact from rendering a hospital unable to operate, of course, just pure records disclosure doesn't do that. It's frequently accompanied with ransomware.
That really has a psychological impact on a region, and our adversaries know this, and so I think that this is going to continue a pace until we get a whole lot more serious about the involvement of the federal government to make it stop. It's the responsibility of every institution to do this, and these are these are apples, oranges, and golf clubs. One size does not fit all. So help needs to be extended, I think, from a national level in such a way that they stop picking these hospitals out of the herd.
So now when we talk about 2023, if there's been a top buzzword this year, it has to be generative AI. What sort of use cases are you hearing most about involving generative AI in healthcare right now, John? And what are some of your concerns potentially from the security and privacy front? Yeah, good timing, because it just got out of an hour-long conversation around standing up governance to address AI.
And certainly the term AI to me is like the word cloud. It means a lot of different things, but particularly where everybody's interested right now is in the capabilities around generative AI. And so we do have solutions that we are piloting. Nuance has a product called DAX that we're piloting that is aimed at helping reduce the amount of documentation that our positions have to do.
So they bring their cell phone into the room of the patient, it listens to the conversation, and then creates a visit summary based off of the conversation, which produces a lot of the time that physician has to take to type up that note. So there's a lot of positive opportunities there. It gets mixed in with a lot of noise. So in our organization, we have currently requests around two or three different chatbots that people want to deploy for various reasons.
So there's a lot of noise out there. In addition, I just captured a list of 27 of our current vendors that are working to begin AI capabilities into their solutions. And so we're wrestling with how we get ahead of that to evaluate what those capabilities are. Do we want to take that upgrade or do we want to turn those features on?
What would be the benefit our environment if we did so? And then most importantly, what would be the risk? So we certainly, in the case of DAX, where we're creating patient data, how do we keep that data from getting outside our four walls? How do we protect that?
How does it not get baked into the generative capabilities where it gets absorbed and then maybe it gets spit out in somebody else's output from generative AI? So we really know the genie's out of the bottle, but we're just trying to build a fence around it so that we can ensure from a legal and compliance perspective and from a data perspective that we're able to protect any of that content that is either created or reviewed as part of an AI search. And Mike, from your perspective, what's most concerning, potentially regarding security and privacy and potential breaches involving generative AI and healthcare? Are there certain applications, certain uses that are most worrisome to you?
Well, just the privacy information that's going to be aggregated in that way. How do you train the AI? What's the data set that you use for it? You know, that's all got to be stored somewhere.
I mean, to John's point, there are risks around using these things. But you know, remember, I'm on the other side of this. I'm on the, let's kick the bad guys out of the network side. And as we are evaluating uses of generative AI, it is to, for lack of a better term, to augment slash replace a tier one analyst to speed and investigation when an event occurs and it goes in front of an analyst, there's a period of time when that needs to be examined, investigated.
And there are a series of steps that are fairly common there. Go find me the provenance of these domain names and the reputations of these IP addresses. That can all be done with generative AI to color the ticket and pass it along to the next tier of analysts and take something that would ordinarily take 15 or 20 minutes and turn that into a minute. So, you know, we're, we're looking at uses of generative AI to speed the investigation.
On the other side of that, I think there are implications of how you train AI, how you use third party AI services, what the agreements are with those organizations as to what they're going to do with your data. And a lot of this has to get sussed out in national policy and in corporate policy and in litigation before we really know how it's going to land. Well, thank you very much, Mike and John. I've been speaking to Mike Hamilton and John Delano.
I'm Mary Ann Coba-Seck McGee of Information Security Media Group. Thanks for joining us.