Zero Trust in Healthcare - A Cure for Identity and Access Management episode artwork

EPISODE · Aug 22, 2019

Zero Trust in Healthcare - A Cure for Identity and Access Management

from Info Risk Today Podcast · host InfoRiskToday.com

As the healthcare industry undergoes its own digital transformation, security is more important than ever. Okta's Nick Fisher says a zero trust model can keep hospitals and patients healthy when it comes to protecting their data.

Episode metadata supplied by the publisher feed · Published Aug 22, 2019

Embed this episode

NOW PLAYING

Zero Trust in Healthcare - A Cure for Identity and Access Management

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Hi, I'm Scott Ferguson, managing editor with Information Security Media Group. And I'm speaking today with Nick Fisher. He is the director of Product Marketing at Okta. Nick, thanks for speaking with us today.

Great, thanks Scott, happy to be here. Before we begin, Nick, could you tell me a little bit about Okta itself and what role you play at the company? Sure, yeah, so Okta is a cloud-based identity and access management provider. And we provide solutions across both what we call workforce identity and customer identity, helping organizations enable their workforce to be more productive and secure the business while also helping them build seamless customer experiences for their end-facing customers.

And I'm here based in our HQ in San Francisco, and I focus on what's called Solutions Marketing, here in the Product Marketing Organization. And in this role, I cover all of our entire Solutions Suite. I talk to a lot of large organizations across the variety of industries, about a lot of business challenges with their legacy identity solutions and how modern I think you can help that. And if you talk about Zero Trust and how that around healthcare space.

Great, well, thank you for that, Nick. And as you know, Information Security Media Group and Okta held a round table, executive round table in New York City a couple of weeks ago. We were talking about the issues of healthcare, and it was kind of interesting to kind of talk about when we're talking with CISOs, and they are helping out their companies with their digital transformation journeys. What's it like when you talk to these folks about when it comes down to cloud adoption?

What are some of their pain points and where are they in this part of their journey? Sure, yeah, so every organization is different in either where they are in their cloud journey or what business problems they're trying to solve, but there are definitely some trends we see in healthcare space, largely in increasing pressure, we see to move to the cloud in order to stay competitive. But there are some broad-based trends. When I talk to our healthcare customers, we see commonalities around a move towards providing things like value-based care or over sort of a fee-for-service-based care where providers are paid and rewarded for quality of care and patient health outcomes, right?

So this means providers are increasingly focused on providing a great patient experience, using patient portals to drive ongoing engagement after that patient leaves the facilities, trying to develop sort of an omni-channel view to deliver better patient care. So that's one big challenge we see them trying to address as they move into the cloud. We see a lot of UIOD for doctors and staff that's becoming more prevalent, and that plays very heavily into their digital transformation efforts. This is replacing often pagers that can issue to them.

Doctors can also exert a lot of influence and don't necessarily want to be prevented from doing their job, and so we see organizations trying to move towards more digitizing information from a history of maintaining paper records and something doctors and staff are really clamoring for. And while this is happening, the CSOs are trying to be business enablers for their organization, but especially in healthcare, we're dealing with incredibly sensitive data and PII, so balancing the needs to enable the business to embrace the cloud, to be more competitive, while securing that sensitive data is sort of a pervasive challenge. And when hospitals and healthcare organizations are transforming their infrastructure, moving towards the cloud, what issues are they confronting when it comes to issues such as identity and access management? Yeah, good question.

So there are issues both on how they try to engage better with their patients and customers, and then there are issues around their workforce that maybe it's the doctors, maybe it's their staff members, nurses, et cetera. And depending on the type of healthcare organization, those user groups vary. But as I alluded to earlier, a lot of healthcare providers are looking to portals as a way to provide better care, increase and trap patient engagement, adopt that value-based care we talked about earlier. And then by allowing those patients to interact directly with the healthcare providers, get access to their own health records, your patient portals, the organizations that need to ensure patients only have access to their records, so identity becomes critical there.

And organizations also have a vested interest in securing patient access to portals to prevent against data breaches. Also, most healthcare organizations that we work with, they also have many business partners to provide these services. So for example, a hospital might work with a separate ambulatory service for their emergency department, their food services may be separate, et cetera. And these business partners have users that require different levels of access to applications or other resources, and those might have PHI.

So those need to be secured, managed, and the life cycle of that partner access is being managed. Also, hospital might not have visibility when one of these users or partners leaves the organization. So the off-boarding and life cycle management becomes an identity challenge there. Other trends we see, so healthcare workers, they're using a lot of M&A as a growth strategy, right?

So integrating disparate systems when an M&A event occurs, trying to reduce redundancy across the systems and providing new employees day when access to apps can be a big challenge. And so that becomes a big compelling event to look to modernize your identity stack into a way that allows you to increase your agility when it comes to M&A activity. There's definitely a lot more challenges I can go into here, but pause there and see if you have any questions on any of what I talked about so far. No, I think that's interesting.

And I think you hit upon a lot of really interesting points there. One other issue, and this came up to in our round table in New York is that there's also this issue of zero trust when it comes to security, but it's kind of defined a little differently in healthcare. How do you define zero trust in the healthcare space? Yeah, so I talk a lot about zero trust with our customers and with CISOs in the market.

And I think one thing just to start off when I acknowledge is that zero trust is becoming a bit of a buzzword these days. It's right up there with next gen digital transformation in terms of buzzword status. I would say if you go to a security conference, you'll see a lot of vendors latching onto this term of zero trust because it's gotten a bit of a brand associated with it rounds with a modern way to do security. But really for many healthcare organizations, the challenges that their business model is now outpacing their security model, that business model of digital transformation, bracing cloud and mobile to better do the job, means that they need to rethink what security means and what trust really means.

I think many of this audience is probably aware of the origins of this term where we used to have a trusted perimeter often secured by a firewall and then everything outside of that perimeter was considered untrusted by default. And this term actually originated back in 2010. But since then cloud and mobile have really changed the game. And what we see, especially in healthcare organizations, is that you can no longer rely on that trusted network perimeter, especially as you have people working from any device, any network, any location.

And really what we see is the need for a strong control point to be the foundation of your security strategy. And identity often becomes that unified control point. It is the single point across users, across devices, across networks, no matter where they work. And so for healthcare in particular, this means securely enabling the organization to adopt those modern technologies for the workforce and for patient experiences, rooted in strong authentication and authorization for that workforce and using intelligent context to ensure that that user is who they say they are and that they have the right access controls.

But there really is no silver bullet for zero trust by what vendors might say on their marketing materials. This is really an entire ecosystem of technologies that provide better context for making access decisions, detecting risk, responding to threats quickly, but we're increasingly seeing modern identity solutions as the foundation of the zero trust security model in healthcare organizations to enable that digital transformation to talk about it. That's so true. And I guess that leads me to the next question because then you have identity and access management and you have this concept of zero trust.

What are the challenges that healthcare and hospitals have when it comes to actually implementing the technologies themselves? What's so unique about this market and being able to use these as part of your security toolbox? There are some unique things happening in this space that are really exciting I think for this space and for patients as well, but it does present some distinct challenges for identity and access management and zero trust. I was recently reading a piece that came out from in recent Horowitz where they discussed how software is eating care delivery in the healthcare industry.

I think they're sort of just a bit, but they talk about how the use of electronic records in the provider market along with many core systems on the payer side that are creating systems with record. They're very good at storing data right now. We're starting to solve that problem around storing data, but these systems are not great at enabling interoperability and data liquidity between the systems. And zero trust and identity and access management really benefit from a strong API ecosystem of interoperable systems that can ensure that the right users are accessing the right data and the right context that can't be done in a vacuum.

So that is a challenge that we're seeing around. They can show that these healthcare systems can properly interact with each other. We also see the emergence of new access points for care. So when I talk to our healthcare customers, a lot of them are moving into spaces like virtual care and bringing in the retail clinics as a part of that community-based services home care as well.

And so these are omni-channel experiences that create a strong need for centralized identity and access management, but many healthcare companies are often building these in-house and it's a monumental challenge to tie together these different patient properties regardless of where the patient is. And doing this for how to unify patient experience. And it also introduces a lot of security risks when you try to build some of these identity platforms and how oftentimes developers we see in healthcare organizations are not. That experience in building identity, but they want to be focused more on building great omni-channel experiences.

So you can have that unified view of the patient. I would say the other big challenge we see is that there's just a lot of legacy technology to deal with which slows down the process and slows down the business goals of improving patient experiences and better enabling their workforce. VPNs we still see as running rampant in that. And the BYO mobile business goals is really not compatible.

Legacy identity platforms are also being used alongside these new modern cloud-based business tools and healthcare organizations are running into big challenges and you have things like requirements, like EPCS, I talked to a lot of customers about this, this requires integrations with EHR solutions to deploy tools like multi-factor authentication and critical infrastructure is a big risk as well. We see a lot of companies, they're still using static SSH keys and password vaulting to manage access to servers and these critical resources. And many of these companies, they're trying to move their workloads to the clouds using infrastructure as a service, like AWS and GCP and Microsoft Azure and that presents unique access identity and access management challenges as just the number of servers grows exponentially. And there's so much sensitive data in those servers that it's just a risk that builds up.

So I'll say those are some of the common challenges I'm seeing when I talk to our healthcare customers and then CISOs. And you touched upon it there a little bit. I want to dig down into this just a little bit more. It's a regulated industry.

HIPAA being of course the number one issue that you hear over and over again, protecting patient data. What are sort of the challenges with that amid all the other issues that you kind of also had brought up just now? Yeah, I think when I talk to customers, they often see HIPAA as ultimately an access management problem. You don't want employees to leave and still have access to patient data.

Also, we talked about just now access to that critical infrastructure needs to be rethought. You lose SSH and RDP keys and then entire databases full of that patient data can be leaked and that poses a HIPAA compliance risk. But I think whenever I talk to customers across any regulated industry about compliance, they'll acknowledge, especially CISOs will acknowledge that compliance doesn't make security. It's not the same thing.

But taking a zero-trust approach to access management, often with identity as that foundation of the security model, is increasingly the approach we're seeing from the healthcare market. And HIPAA compliance is a natural outcome of a security model that focuses largely on securing access management without interrupting the business. Interesting. And so as we're talking here, if you were to look into the future, whether it's 18 months down the road, five years down the road, 10 years down the road, what does the future of security, cybersecurity in healthcare look like?

Is zero trust in identity and access management building that foundation? Or is it gonna be undergoing even greater changes as we move forward and hospitals and healthcare organizations bring more of their business into the cloud? So I like this question. We do get to have the privilege of spending a lot of time with our customers, thinking about what does the 10-year vision for what does healthcare look like and what role does identity play in that?

I would say, especially when it comes to zero trust, this is definitely a journey for a lot of our customers. So we often, in the next couple of years, are meeting organizations where they are today and helping them move securely to the cloud. And so many organizations have a lot of that hairy legacy technology that they're not really gonna be getting rid of, maybe even within the next five to 10 years. But the hybrid cloud is gonna be a reality for a lot of healthcare works over the next decade.

But as they've big trends in security, we've seen the challenges around managing passwords, especially in the healthcare space with the need to secure access to all that personal information. Identity attacks are just exploding right now as more companies look to the cloud. You really don't need to break into a system anymore. You simply need to log in.

You can compromise the user name of password. You don't have the appropriate controls around it. And so focusing on killing the password and replacing that with stronger factors is definitely a three to five year initiative, I would say, for a lot of our customers. We've been some exciting development around new protocols that are gonna speed this along in the last year.

So the W3C, the World Wide Web Consortium, they recently approved for use what we call FIDO2 or WebAuthn, which is a standard for passwordless primary authentication. And so the vision here is that cloud-based service providers are gonna allow you to securely use a biometric based authenticators, say on your laptop or on your mobile device as for that primary authenticator. And we're sort of rallying around these standards now for doing that. And that is all rooted in strong identity insurance there.

And so that's really exciting because that removes a lot of risk around making sure that the right person has access to the right data and starts to eliminate some of that hit a compliance risk around patient data leakage. Now it's not a silver bullet, but it is something that a lot of our customers are really excited about because it also introduces a good user experience who likes remembering passwords, right? And forgetting your passwords, all your systems and going through password resets. So can we eventually start to remove that from the experience or kill the password overall?

I would say, with identity really being that new perimeter like we talked about earlier, I think we're gonna start to think more about what a universal identity looks like for patients in particular. So this is not just, you know, your doctor is moving from hospital to hospital your patients as they move throughout their different healthcare providers in their life. Having that unified identity to tie back to the electronic health records we talked about earlier. There's a lot of challenges and complications that come with that.

There's some interesting technology around blockchain-based universal identities that we're seeing. But I'd say that this is something that there's clearly a market demand for, there's clearly a security need for and most importantly a health benefit for providing universal and transparent communication of health risk between patients and doctors. So universal identity is something that I'm excited to see how that plays out. And I'd say the final thing I'll talk about when we're hearing more customers increasingly in the healthcare space thing about this is focusing on the identity of the machines.

So a lot of sensitive medical equipment that need to communicate with each other as we move in further into this era of the internet of things and connected devices, you know, medical devices have a lot of promise in terms of interrupting with the data sources to improve healthcare or do readouts of healthcare and things like Apple Watch, for example. But like, how do we start to secure and provide sort of zero trust access controls to those machines? Especially often when an operating system is not consistent across them. And so focusing on the identity of those machines and how that plays into providing secure as your trust access is increasing going to be a topic.

And I think over the next 10 years, we're going to see some big sea change movements in how we provided an access management to connected devices. So I think those are some of the key ones that have come up. So big changes, nonetheless, coming down the road in healthcare. Nick, thank you so much for speaking with us today and giving us some guidance on what the future of healthcare looks like.

We appreciate it. Yeah, happy to go. Thank you. And we were speaking with Nick Fisher.

He is the Director of Product Marketing at Octa. I'm Scott Ferguson, managing editor with Information Security Media Group. Thanks for listening.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on August 22, 2019.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!