Hi, I'm Mary Ann Cobus, Executive Editor at Information Security Media Group. I'm here speaking with Bob Bastani, who is Senior Cyber Security Advisor at the Department of Health and Human Services Administration for Strategic Preparedness and Response. Hi, Bob. Good afternoon.
Thank you for the opportunity. I'm really glad to be here. Thank you for joining us, Bob. So, Bob, being part of HHS's ASPR, you must see and hear a lot about cyber attacks and other related issues that the sector has been dealing with.
Overall, what are some of the top cyber challenges and cyber threats you see the healthcare sector struggling with most of these days? Yeah, thank you. The National Security Council considers healthcare and public health sector to be one of the top three sectors that are prioritized for additional attention. This is among the 16 sectors.
Some statistics, a lot of statistics, but just to throw a few, according to OCR, more than 509 organizations reported healthcare data breaches to HHS in 2022, impacting up for the 48 million individuals. And there are several independent reports that illustrate the threat to the sector, such as the 2022 Verizon Data Beach Report, Crowded Strikes 2023 Global Threat Reports, and that they all indicate that health sector was the top frequently targeted sector in the country. Now, here's some of the ongoing cyber threats against healthcare and public health. We have threats that are financially motivated.
We see a lot of financially motivated criminal, criminally originated threats, and these are coming in forms of ransomware and theft of electronic records. Historically, health sector industry has faced some of the most severe cyber threats because they handle the vast amount of sensitive patient data, they handle delivery of care, and they have money. And because of that, they are the top target. In 2022, we saw significant increase in ransomware attack against healthcare and public health by cyber criminal in form of ransomware.
Particularly concerning is that they are directly targeting attack against hospitals, and they aim to disrupt clinical operations more and more. We also see more and more we see a state sponsored espionage type attacks that they're with the whole purpose of impacting the critical infrastructure of the nation. And there is an area, there are some areas where it's difficult, there's a marriage of between cyber criminals and nation states, and nation states use cyber criminals to get money. And you see more and more, for example, from North Korea, those type of attacks.
And then we see a number of activism that are that attack the health sector for various reasons. And we see they're very disruptive. You see the serial denial of attack mostly from the actors. So Bob, you're here with him speaking about the steps that health care sector entities might take to improve their security posture, including adopting a cyber security framework.
Why is it so important for health care sector entities to adopt a standards based framework such as the National Institute for Standards and Technologies CSF? Yeah, so we in March, HHS, an Aspir, we, along with our partners in the private sector, we released an implementation guard, CSF implementation guard for health care and public health. And we are trying more and more to encourage the health sector to use the CSF framework. Now, the benefit of using a framework in general is that it allows, creates a strategic view of managing risk.
And so that provides organizations with opportunity to identify areas where existing processes may be a strength or where processes, a new processes can be implemented. Really important frameworks provide a common language taxonomy and systematic methodology for communicating risks both internally and externally to, for example, to the partner partners and even patients. And frameworks provide a context of two organizations, how to view risk. And that contextual view of risk management is really important.
Now, why CSF? Why is it that there are many frameworks? Well, CSF is developed by National Institute of Standards in very close collaboration with private sector. It is mandatory for federal entities.
So it's very much used in federal space. It's used and used and corrected. And also you have a, NIST has a very long view of frameworks. So there's always going to be updated.
More importantly, it's vendor agnostic. So regardless, you will not be taught to a vendor. The methodology that it uses also, and there are a lot of resources that NIST makes available for free. And that will allow you to map to NIST frameworks very easily.
Now, very recently, there was a change. There was an update that was done to the Hitek Act that made it even more attractive to use the CSF framework. So that update, the 2021 amendment to the Hitek Act added a requirement to HHS Office of Civil Rights to consider regular entities implementation of recognized security practices, specifically NIST cybersecurity framework, in certain OCR HIPAA compliance enforcement activities. And that is really important.
That provides additional incentive. So Bob, with that said, what are the benefits for using the NIST CSF when it comes to the health care entities themselves? What do they get out of it? Yeah.
So we talked about the fact that it directs the OCR to take into consideration the use of CSF framework in an organization. There are requirements. For example, the CSF framework should be in use for 12 months. And OCR has some requirements in terms of proving that CSF is being implemented across the organization.
But although that the use of CSF alone does not provide a blanket, it's not a blanket for forgiveness for HIPAA violations, it does give OCR an opportunity to consider that when they levy fines or enforcement actions. That is very important. And but even outside of that, by just using the CSF framework, without a doubt, the risk and the cyber-risk environment will go down. And the entities are able to identify and react.
And they become more resilient. So I really suggest the CSF framework implementation like that they put together is very detailed, very prescriptive, how to a step-by-step makes it easy to do it. So it sounds like that would be a lot of help to help care entities that might be struggling with how to implement if they use that resource to help. Yeah, absolutely.
And as I said, NIST provides a ton of free resources, which are documented in that implementation guide that they provide. One of the most important help that NIST provides is this library that maps almost any framework to the NIST CSF framework. So entities don't have to go and invest a ton re-establishing a new framework. They can map the existing framework to CSF very easily using the NIST documents.
So besides adopting a framework, any other suggestions or steps that you think health care sector entities should be considering to take to improve their preparedness to deal with the kinds of cyber challenges and threats that we see? There are a lot of things that entities should do just at a very high level. It's important for entities to look at risk managing risk holistically in their environment. And so the risk is something that is managed from top down from bottom up all across the organization.
And that is a culture that has to be changed. So there are a lot of how to document and you can implement these procedures or that procedures and make sure you have to factor authentication. And a lot of things you can do, but ultimately it's about a mindset change in terms of looking at risk and managing risk holistically across the environment. But there are clearly other things that education and training of users are really, really important.
We see more and more that the first line of exposure are users by clicking on the wrong link. There are still people that get tricked into links and those links are getting more and more complex and customized. So training is really important as well. And finally, a couple of months ago, the Biden Administration introduced their National Cyber Security Strategy focused on 16 critical infrastructure sectors.
What do you think the health care sector should learn from what the strategy says? Is there something that stands out to you that the private sector health care organizations should be paying close attention to? So there's a shift in mindset where responsibility now, that strategy looks at the responsibility of operators and developers and manufacturers, service providers, their responsibility and their role in cyber incidents. And it's starting to shift a little bit from, I wouldn't say they're still mandate, they're shifting into mandates, they're soft mandates right now, but that shift is happening.
So that there's a shared responsibility for making sure that the critical infrastructure of the nation is safe from cyber attacks and that strategy you can see that shift in that strategy. Well, thank you so much Bob. I've been speaking to Bob Estani of HHS Asper. I'm Mary Ann Kolbasak-McGhee of Information Security Media Group.
Thanks for joining us.