GlobalProtect Integration with AirWatch: Solving the Mysteries of Mobile Security and BYOD

Over the ages, philosophers challenged the conventions of traditional thinking by meditating upon a “koan.” A koan is similar to a riddle, except that there is no punchline. It typically involves a paradoxical statement that is subject to a multitude of interpretations, many of which are correct in their own peculiar way. And even when analyzed with a great deal of time and deep thought, the koan defies an answer.

For security practitioners, the topic of what to do about mobile devices introduces a series of modern-day koans.

  • How could your network security policies apply to users who are not in the office?
  • How do you inspect traffic when users are not behind your firewall?
  • How can you provide security while respecting privacy?
  • How can you protect business data on a device that you don’t own?

These questions were not easily solved, primarily because conventional thinking led to more dead ends. Organizations accustomed to having total control over fairly stationary, corporate-owned devices found themselves in an entirely different world when faced with mobile devices and BYOD. And trying to apply such measures often led to stalemates or unacceptable compromises to the protection of the company’s data or user’s expectation of privacy.

In order to address concerns with mobile security, and break through the questions around past approaches, Palo Alto Networks partnered with VMware/AirWatch to bring forward fresh thinking. The Palo Alto Networks next-generation security platform provides the most comprehensive approach to stopping threats, based on prevention. AirWatch has deep expertise for managing mobile devices and applications. By providing integration points between these two sets of products, we can provide our respective customers a solution to deliver security for business assets on a device while honoring privacy for both personal data and traffic.

The first aspect of the integration is the use of AirWatch’s enrollment process to provision the GlobalProtect app. During enrollment, an unmanaged mobile device (including one that is personally owned) is loaded with the appropriate configuration and enterprise applications that prepare it for use in a business environment. The organization can manage the business assets separately from the personal apps and content on the device. The GlobalProtect app can be transparently installed during enrollment, providing the key capability of establishing an app-level VPN tunnel back to the next-generation firewall for traffic visibility, the enforcement of policy, and threat prevention. The traffic from personal apps remains untouched, thus honoring the user’s expectation for privacy with non-business-related activity.

A second aspect of the integration is the use of threat intelligence from WildFire to detect mobile devices with malware. Since AirWatch knows about the inventory of apps on a mobile device, integration with WildFire allows the organization to spot devices that are infected. AirWatch can apply a workflow to address the issue, such as alerting the user or quarantining the device until the problem has been corrected.

With these new capabilities, organizations have a more nuanced and balanced approach to mobile security, one that’s focused on the specific requirements of protecting the business apps and data without having to cross personal boundaries.  By applying an integrated approach, the mobile security koans now have answers that are readily available. The organization can move forward with the adoption of mobile computing by having the requisite security for business content while honoring their employees’ expectations of privacy for personal data.

To learn more about this integration, visit http://paloaltonetworks.com/airwatch for more information. Palo Alto Networks will also be on hand at AirWatch Connect in Atlanta this week. Watch this space for more thoughts following my time there.

[Palo Alto Networks Blog]

Health IT’s Most Pressing Issues (Part 4)

Health IT’s most pressing issues may be so prevalent that they can’t be contained to a single post, as is obvious here, the fourth installment in the series detailing some of the biggest IT issues. There are differing opinions as to what the most important issues are, but there are many clear and overwhelming problems for the sector. Data, security, interoperability and compliance are some of the more obvious, according to the following experts, but those are not all, as you likely know and we’ll continue to see.

Here, we continue to offer the perspective of some of healthcare’s insiders who offer their opinions on health IT’s greatest problems and where we should be spending a good deal, if not most, of our focus. If you’d like to read other installments in the series, go here: Health IT’s Most Pressing Issues, Health IT’s Most Pressing Issues (Part 2) and Health IT’s Most Pressing Issues (Part 3). Also, feel free to let us know if you agree with the following, or add what you think are some of the sector’s biggest boondoggles.

Charles A. “Drew” Settles, product analyst, TechnologyAdvice

Charles A. “Drew” Settles

First and foremost, of all the issues facing healthcare technology, I believe the top issue is the interoperability (or lack thereof) of most electronic medical records systems. Interfacing systems from disparate vendors usually takes expensive custom development, but hopefully the push for free access to EMR/EHR APIs in Stage 3 of the Meaningful Use Incentive program will finally bring semantic interoperability to health IT.

Paul Cioni, senior vice president, Healthcare & Infor Solutions Sales, Velocity Technology Solutions
The top issue facing healthcare CIOs is that there is simply too much for them to do, including major initiatives involving information security, patient confidentiality, and revenue cycle management and reimbursement. Most are focusing on what’s urgent, rather than on what’s important. All of these issues are not only competing for a CIO’s budget, but also for his/her time. With so many things on the “as soon as possible” priority list, healthcare CIOs barely have time to strategically plan. It’s difficult for CIOs to create a five-year plan for the organization’s IT when they’re trying to figure out the next five months. A disaster recovery plan, for example, may not get created when CIOs are more concerned with downtime of clinical applications or the reporting of a data breach to the regulatory authorities.

Paul Cioni

The use of the cloud — with a comprehensive but flexible portfolio of service options- helps relieve CIOs from what I call the “tyranny of the urgent.” By allowing a cloud provider to manage a variety of back-office and ERP-related functions, the CIO can shift his focus to systems that affect clinical outcomes. Extending the secure, private cloud approach to clinical systems liberates key resources — budget and people — to focus on achieving meaningful use or embracing population health initiatives. Cloud deployment options like disaster recovery as a service or desktop as a service can conserve capital dollars and speed time to outcome. It’s not one issue – it’s all of them.

Lynn O’Connor Vos, CEO, Grey Healthcare Group (ghg):
The rapid acceleration of advancements in health information technology is leading to greater efficiency and productivity in the industry. At the same time, while technology has improved healthcare delivery in certain respects, significant challenges remain, particularly in areas related to the collection and transfer of health information and the user experience of healthcare providers and patients throughout this process. A perfect example of this is EHR/e-Prescribe systems, which are being adopted to solve a number of problems, including inaccurate prescriptions and portability of patient data, but which have also introduced other issues, in that healthcare providers (HCPs) are now burdened with time-consuming data entry that may be impacting their efficiency with chart updates.

With the goal of improving outcomes, patient adherence to medication is a critical factor in achieving the outcomes needed in chronic disease. At present, paper prescriptions leave too much to chance and it is well known that a significant number of prescriptions never get filled, and about six out of 10 patients report that they do not always take their medication as directed (according to the American Academy of Family Physicians). Health IT can play a vital role in supporting the healthcare process at every stage of a patient’s journey. However, true, efficient interoperability between healthcare systems is still a goal, rather than a reality, and immediate solutions are required to meet the needs of patients, caregivers, their healthcare providers and other stakeholders. A relevant example of this is the process of filling a prescription. As payers make efforts to control costs in the marketplace, an increasing number of prescriptions now require prior authorization (PA). Incredibly, even with the latest advancements in health IT, a patient generally doesn’t learn that their prescription has been rejected because of a PA requirement until they are standing at the pharmacy attempting to pick it up. The subsequent process to obtain a completed PA and successful submission is labyrinthine, and unfortunately, a number of drop off points exist, leading to a significant gap between PAs required and PAs successfully submitted. According to market research, upwards of 40 percent of patients who receive a PA forego treatment altogether, and only 30 percent of patients receiving a PA receive the originally prescribed medication. These data indicate that significant barriers to care exist as patients denied prescriptions at the pharmacy as a result of PA requirement are less likely to get that prescription filled at all.

Lynn O’Connor Vos

Given the barriers with PAs, services have emerged to facilitate the process and attempt to improve the outcome. The challenge is that the complexity of forms and information required and the submission process itself present obstacles that are often difficult for busy healthcare providers to overcome. Administrative and logistical barriers include failure to notify the HCP about the PA requirement, incorrect form submission, submission of incomplete or inaccurate information, and confusion in completing a non-standard form. Numerous handoffs along the way also increase the likelihood that the form may never be successfully completed or submitted. To date, Health IT has not provided a seamless solution to these challenges.

The administrative onus for PAs falls heavily on physicians and pharmacies, and can bring significant effort and frustration for them. It can take an average of 30 to 45 minutes to complete a prior authorization, while denial rates can be high, often because of minor errors and omissions, and appeal processes can be cumbersome. In an environment that increasingly aligns health outcomes to reimbursement rates, unsuccessful prior authorization submissions can result in fewer patients receiving the medicine they need, poor outcomes and lost revenue. Fortunately, the prior authorization process does not have to rely solely on technology and automation. PARx Solutions provides a concierge approach to the problem, engaging clinical staff to work one-on-one with physician offices and pharmacies to help streamline prior authorization processes and improve success rates. The company’s holistic solution, which combines automated software systems with clinical staff attention and follow through, ensures a higher success rate of submission than wholly automated solutions.

Health IT has come a long way in automating many important healthcare processes; however, instant data exchange and true interoperability are still future goals, and meeting the user experience needs of healthcare constituents is still a significant challenge. Healthcare stakeholders must focus on providing immediate solutions to bridge these gaps, and some of these may require a combination of technology and human attention. To become a true service industry, healthcare must provide patients with personalized care, not systematic care. For some, this may include tangible incentives to keep to care plans, such as reduced monthly contributions to individual’s health plans by agreeing to certain commitments. For others, it may be decision-making support. Regardless of the approach, the challenge for health IT is to better support physicians and patients in more personalized ways that allow them the flexibility to drive the health care needs of each patient effectively.

Eric Rice

Eric Rice, chief technology officer, Mach7 Technologies
Many of the current Health IT issues are around interoperability and the ability to provide a “complete” patient record. The majority of HIT systems don’t communicate with one another effectively, if at all. A single unified platform upon which to plug in best-of-breed or specialty/departmental solutions can enable communication across an enterprise, IDN or region, consolidating storage of the data.

Key issues:

— Achieving MU 2 and 3, image enabling the EMR
— Providing access and sharing of patient imaging data across the enterprise, IDN, region
— Ability for providers and clinicians to select their best-of-breed visualization solutions
— Consolidating storage / controlling storage cost
— No system in place to effectively and efficiently manage growth (i.e. organic, M&A…); need a scalable, highly-available platform

John Matthews, CIO, ExtraHop

John Matthews

Healthcare IT organizations are being bombarded from all sides. Not only are they tasked with managing complex, diverse and disparate IT environments of any industry, they must often do so on a budget and with limited human capital. Compounding these pressures is the fact that clinicians and business stakeholders rely heavily on IT systems to manage patient care and outcomes.

Take the ICD-10 migration, for example. Working with our customers, we’ve realized that one of the foundational challenges of this migration has simply been the ability to quickly and easily identify the components in their environment that interact with ICD codes. HDOs need this information in order to understand how these codes flow through the organization, and to develop a roadmap for migration. Incomplete migration when the new standards go into effect on October 1 of this year will have a major impact on the business side of healthcare, impacting billing and reimbursement. It will also impact patient care if patient conditions are improperly coded, making it more difficult to provide proper care and deliver good outcomes.

[Electronic Health Reporter]

Health IT’s Most Pressing Issues (Part 3)

Health IT’s most pressing issues may be so prevalent that they can’t be contained to a single post, as is obvious here, the third installment in the series detailing some of the biggest IT issues. There are differing opinions as to what the most important issues are, but there are many clear and overwhelming problems for the sector. Data, security, interoperability and compliance are some of the more obvious, according to the following experts, but those are not all, as you likely know and we’ll continue to see.

Here, we continue to offer the perspective of some of healthcare’s insiders who offer their opinions on health IT’s greatest problems and where we should be spending a good deal, if not most, of our focus. If you’d like to read the first installment in the series, go here: Health IT’s Most Pressing Issues and Health IT’s Most Pressing Issues (Part 2). Also, feel free to let us know if you agree with the following, or add what you think are some of the sector’s biggest boondoggles.

Reuven Harrison, CTO and co-founder, Tufin

Reuven Harrison

The healthcare industry has undoubtedly become a bigger target for security threats and data breaches in recent years and in my opinion that can be attributed in large part to the industry’s movement to virtualization and the cloud. By adopting these agile, effective and cost-effective modern technological trends, it also widens the network’s attack surface area, and in turn, raises the potential risk for security threats.

We actually conducted some research recently that addresses evolving security challenges, including those impacting the healthcare industry, with the introduction of cloud infrastructures. The issue is highlighted by the fact that the growing popularity of cloud adoption has been identified as one of the key reasons IT and security professionals (57 percent) find securing their networks more difficult today than two years ago.

Paul Brient

Paul Brient, CEO, PatientKeeper, Inc.
No industry on Earth has computerized its operations with a goal to reduce productivity and efficiency. That would be absurd. Yet we see countless articles and complaints by physicians about the fact that computerization of their workflows has made them less productive, less efficient and potentially less effective. An EHR is supposed to “automate and streamline the clinician’s workflow.” But does it really? Unfortunately, no. At least not yet. Impediments to using hospital EHRs demand attention because physicians are by far the most expensive and limited resource in the healthcare system. Hopefully, the next few years will bring about the innovation and new approaches necessary to make EHRs truly work for physicians. Otherwise, the $36 billion and the countless hours hospitals across the country have spent implementing electronic systems will have been squandered.

Mounil Patel, strategic technology consultant, Mimecast

Email security is one of healthcare’s top IT issues, thanks, in part, to budget constraints. Many healthcare organizations have already allocated the majority of IT dollars to improving systems that manage electronic patient records in order to meet HIPAA compliance. As such, data security may fall to the wayside, leaving sensitive customer information vulnerable to sophisticated cyber-attacks that combine social engineering and spear-phishing to penetrate organizations’ networks and steal critical data. Most of the major data breaches that have occurred over the past year have been initiated by this type of email-based threat. The only defense against this level of attack is a layered approach to security, which has evolved beyond traditional email security solutions that may have been adequate a few years ago, but are no longer a match for highly-targeted spear-phishing attacks.

Dr. Rae Hayward, HCISPP, director of education and training at (ISC)²

Dr. Rae Hayward

According to the 2015 (ISC)² Global Information Security Workforce Study, global healthcare industry professionals identified the following top security threats as the most concerning: malware (77 percent), application vulnerabilities (74 percent), configuration mistakes/oversights (70 percent), mobile devices (69 percent) and faulty network/system configuration (65 percent). Also, customer privacy violations, damage to the organization’s reputation and breach of laws and regulations were ranked equally as top priorities for healthcare IT security professionals.

So what do these professionals believe will help to resolve these issues? Healthcare respondents believe that network monitoring and intelligence (76 percent), along with improved intrusion detection and prevention technologies (73 percent) are security technologies that will provide significant improvements to the security posture of their organizations. Other research shows that having a business continuity management plan involved in remediation efforts will help to reduce the costs associated with a breach. Having a formal incident response plan in place prior to any incident decreases the average cost of the data breach. A strong security posture decreases not only incidents, but also the loss of data when a breach occurs.

Terry Edwards, CEO, PerfectServe

Terry Edwards

One of the major challenges the healthcare industry is navigating is how to enable more effective communication and collaboration across care teams, while also being HIPAA compliant. Physicians, nurses and all care team members need to be able to send and receive information on a patient’s condition in real-time, without compromising protected health information.

Providers often try to address secure communication with point solutions (secure texting), yet these tools are incomplete and the kind of collaboration that needs to occur doesn’t happen. In many cases, it’s just too hard for one clinician to connect with other care team members because the initiator needs to know the workflow of the person they need to reach.

For example, a physician who admits a patient into a hospitalist service may be listed in the EHR as the attending doctor. However, the patient is likely to be reassigned to a different hospitalist, say one of seven in the group, within a few hours. In the EHR, the name of the admitting doctor does not change. So, the question becomes, “Who is the hospitalist covering the patient right now?” An effective communication solution will address this variable as part of the communications process. Building on this, rotating schedules and multiple communication modalities creates uncertainty for how to reach a clinician at any given point. All of this contributes to delays in patient care.

As an industry, we’re making strides to facilitate more efficient and secure communication and collaboration, but the challenge needs to be addressed at the root – which is about process and workflow.

Dwain Wright, senior security consultant, ControlScan
From an IT security standpoint, poorly managed third-party relationships continue to create multiple points of vulnerability for healthcare organizations. These relationships include application management, installation of services and the management of security infrastructure (firewalls, malware systems, etc.).

There are three primary reasons today’s third-party relationships are unnecessarily risky:

Lack of due diligence in up-front discussions — When purchasing a piece of software or a service, many HIT professionals are walking away from the table without a clear understanding of what’s required to maintain the security posture of the product once it’s installed in their environment. Similarly, while the third-party may be providing a service, you still have to be knowledgeable on how that service will be performed such that it won’t impact the security posture or practices of your organization. It’s also essential to properly vet the service provider based upon their own security posture and credentials.

Lack of oversight during implementation — All software is “customizable” to some extent. At best, the third-party provider will establish initial settings that conform to their understanding of your IT organization. Unfortunately, we see many instances where settings have been incorrectly configured or left at their defaults. It is the HIT professional’s responsibility to ensure that all software, apps and services are implemented in accordance with data security and privacy best practices and standards.

Lack of formal, defined processes for maintenance and updates – As mentioned in #1 above, many HIT professionals are behind from the very beginning because they don’t ask important security-related questions early in the relationship. Consequently, we see many instances where patches and updates aren’t applied in a timely manner, or even at all. This is especially prevalent when internal and external roles and responsibilities aren’t pre-defined.

Recently I was on-site with an organization that manages a network of hospitals and clinics. We were discussing the settings of a specific application and determined that it was necessary to contact the third-party vendor for clarification. While we were talking with the vendor, they remotely accessed the application before our very eyes-without any granting of access on the client side! The client was completely unaware that the vendor had this capability.

Third-party relationships are not bad in and of themselves; in fact, they are essential to organizational growth. The key is to build those relationships on strong communication and knowledge sharing so that your organization and the information it works with remain secure.

Dr. Donald Donahue, Lieutenant Colonel, U.S. Army (Ret.)

Dr. Donald Donahue JR.

The single greatest issue facing health IT is interoperability. When health systems cannot share data — or worse, when functions within a healthcare facility cannot share information — the promise of improved outcomes and lower costs evaporates.

 [Electronic Health Report]

 

Health IT’s Most Pressing Issues (Part 2)

Health IT’s most pressing issues may be so prevalent that they can’t be contained to a single post, as is obvious here, the second installment in the series detailing some of the biggest IT issues. There are differing opinions as to what the most important issues are, but there are many clear and overwhelming problems for the sector. Data, security, interoperability and compliance are some of the more obvious, according to the following experts, but those are not all, as you likely know and we’ll continue to see.

Here, we continue to offer the perspective of some of healthcare’s insiders who offer their opinions on health IT’s greatest problems and where we should be spending a good deal, if not most, of our focus. If you’d like to read the first installment in the series, go here: Health IT’s Most Pressing Issues. Also, feel free to let us know if you agree with the following, or add what you think are some of the sector’s biggest boondoggles.

Michael Fimin

Michael Fimin, CEO and co-founder, Netwrix
The largest concern of any healthcare organization is protecting patient personal data. Every year healthcare entities of all sizes become victims of data leaks, fresh examples are both Anthem and Premera Blue Cross, and lose thousands of dollars mainly because of employee misbehave or human error. Being not an easy one to prevent, human factor sets IT pros a number of challenges to cope with:

1. Insider threat. Unfortunately, privilege abuse is a primary root cause for many data breaches. No matter if an employee is breaking bad or his credentials were stolen, sensitive data is put at risk. The only way to prevent insider threats is to have visibility into the IT infrastructure and be able to track any changes made to both security configurations and data. Monitor user activity and establish rigorous control over accounts with extended privileges. Regularly review all access rights to ensure that permissions are granted adequately to employees’ business needs.

2. Security of devices. In 2014 healthcare organizations suffered from physical theft or loss of electronic devices more than any other industry, said the Verizon 2014 DBIR. Without proper identity and authentication management personal data stored on these devices can be easily accessed by adversaries, leading to financial and reputational losses. If your employees’ laptop or tablets end up in the wrong hands, encryption, two-factor authentication and ability to manage the device remotely will protect your data, or at least will make hacker’s job much harder.

3. Employees’ negligence. Deliberate or accidental mistakes pose more danger to data integrity than you might think. A simple email with confidential data sent to the wrong address may lead to a huge data leak. Make sure that your employees are familiar with the company’s security policy and are aware of what they should do to maintain security each person in the company should clearly understand that integrity of information assets is their personal responsibility.

Barry Chaiken

Dr. Barry Chaiken, chief medical information officer,Infor
Healthcare providers organizations invested billions of dollars purchasing and implementing electronic medical records with this investment driven by the economic incentives provided by the HITECH Act. Now that these systems are installed an up and running, organizations struggle to obtain real value from these investments. These systems were implemented with speed in mind rather than clinical transformation that improved quality and reduced costs. Now, organizations must embrace clinical transformation and change management to redo workflows and processes to effectively impact care. Organizations cannot justify their investment in EMRs unless they rework their EMR implementations to obtain true value from their deployment.”

Matthew Fisher, co-chair, health law group, Mirick O’Connell

Matthew Fisher

One of the top health IT issues that I encounter is meeting compliance requirements with the HIPAA Security Rule. Security is a hot issue for health IT in light of the numerous breaches and other attacks that have occurred in order to gain access to protected health information. Health IT is at the forefront of these issues because the conversion to predominantly electronic data formats has created a number of vulnerabilities. Foremost among the vulnerabilities is the often outdated security systems or measures that may be in place. From a regulatory compliance perspective, particularly HIPAA, organizations must perform a comprehensive risk analysis of their operations. The results of the risk analysis, which should include identification, likelihood and threat level associated with each issue, form the backbone of an organization’s security policies. Under HIPAA, the Security Rule is designed to be somewhat flexible and scalable to each organization’s needs. As the brief description of the risk analysis shows, the results help an organization to determine how to meet the addressable elements of the Security Rule.

All of this places a lot of pressure on health IT to meet demands and protect organizations. As can be seen from breach fallouts, health IT can be at the top of the blame list. However, proactive attention to these issues can help alleviate the pain and put a organization ahead.

Dr. David Kibbe, president and CEO, DirectTrust

For me, the top issue for health IT is interoperability of information exchange: It should be very easy for health care professionals to move data and information across organizational boundaries and IT platforms, without extra effort, and in a manner that is electronic, secure, and identity-validated. Data exchange has to be vendor agnostic. That we don’t have this capability deployed everywhere in health care is less a problem of standards than a problem of business models and culture.

The reason this one issue is on the top of my list is because the lack of interoperable exchange of health information is a by-product of fee-for-service payment to doctors and hospitals; payment for volume not payment for quality. If you get paid by insurers even when tests and procedures need to be duplicated, because the data aren’t readily available to your “silo” of information from someone else’s “silo” of information, why bother to change? But health care payers are moving toward “value-based care” in which quality and efficiency are rewarded, providers are put at some level of risk for the costs of the care they deliver, and those who do poorly on such metrics as readmissions to hospital and patient satisfaction are penalized and paid less.

Value-based payment success requires that providers communicate with one another in a distinctly multi-vendor environment, one in which doctors and hospitals use EHRs from over 300 vendors. Yet many members of care coordination teams, such as those in long-term post-acute care and home health, don’t use EHRs at all.

Providers engaged in value-based payment simply can’t fumble the transitions of care made by their patients as they did under fee-for-service; if they do they’ll fail financially. The challenge they are facing is how to move data and information wherever and to whomever the patient goes to next, and regardless of which vendor’s EHR the next provider organization is using, so that care becomes much more coordinated and outcomes more predictable.

Direct exchange is an example of a standard that is open and available for use in over 40,000 health care organizations that use EHRs certified by ONC; that certification includes that the EHRs are Direct-enabled to both send and receive messages, and file attachments of any kind, and to and from any other certified EHR user. Direct messages are sent encrypted end-to-end, and the relying parties know precisely the identity of one another even before the message is transmitted. Attachments can be in any type of file format, including structured XML, Word, PDF, and in common file image file formats like .jpg and DICOM.

Why don’t we hear more about direct exchange in the media and press? Well, that’s because new technologies take time to become adopted, even when there are federal standards built into certifications. And, as the recent ONC report to Congress on Information Blocking pointed out, “… some [provider and EHR] business practices, though they may arguably advance legitimate individual economic interests, interfere with the exchange of electronic health information in ways that raise serious information blocking concerns.” Put even more simply, there still exist business and cultural incentives in health care to restrict information flows to protect private economic gain, even at the expense of the patients and the public at large.

As the incentives change because of value-based purchasing contracts becoming more widespread, we will see more and more health care providers and hospitals choosing to use interoperable health IT tools.

[Electronic Health Report]

Health IT’s Most Pressing Issues

Healthcare is not without its issues. Seemingly, for each source asked what the biggest problem the sector faces, there is a differing opinion on what’s most important. I’m often perplexed by the lack of cohesiveness shown toward the industry’s leading issues, too, and sometimes wonder how many of us could name the most pressing threats to the industry, as agreed upon by the community. There are clear problems – interoperability, lack of transparency, disparate systems working against each other — to name a few. So, in the following series, I’ve asked some insiders for their opinions on health IT’s greatest problems, and as you’ll see, they responses received vary greatly.

Scott Friedman, executive vice president, Sherpa Software

Healthcare IT struggles mightily with patient information that is not in the medical record system, but has leaked into other locations in the healthcare organization (cell phone emails, USB drives, employee desks, etc.). Healthcare organizations have moved Protected Health Information (PHI) into HIPAA compliant electronic health records (EHRs) systems, patients maintain electronic copies of their health information, which they give to their different providers as they move between appointments. This “patient distributed information” becomes PHI, with all its associated compliance and legal burdens for the health care organization.

There is liability associated with this, and information governance strategies available that reduce the associated risks. Patient distributed information is present on smartphones, tablets, laptops, and the like are not sanctioned EHR (such as email, file directories, etc.). These devices are not part of the organization’s HIPAA compliant system, and never can be. Most healthcare providers ignore the problem, which eventually leads to catastrophic security failures resulting in patient privacy breaches, and career damaging incidents for the healthcare IT department.

To eliminate the problem, IT needs to look to integrate an information governance framework that can:

  • Interview employees to understand how they deal with and understand this issue.
  • Audit, usually done with software systems, to provide objective evidence and quantification of the presence of PHI on your digital systems.
  • Set specific policies and procedures employees can follow in each and every situation when they come into contact with “patient distributed information.”
  • Provide raining and review of policies and procedures work.
  • Automate the policies and procedures with software systems to ensure compliance.
  • Surveil your digital systems is the best way to monitor and review your program, as well as seek to improve it.

Acknowledge the increasing presence of patient distributed information on your digital systems, and have a plan for how to address it. Look to information governance to establish a strategy and program to address patient distributed information. With the proper policies, procedures, training, and systems in place your organization will be able to effectively handle and mitigate the risks.

Steve Schick, senior director, education, LightCyber

Steve Schick

One of the most pressing issues facing healthcare organizations today is the threat of a targeted data breach. While data breaches are a top concern for most companies and organizations, it is even more acute for healthcare. Healthcare data is some of the most valuable in the dark web, commanding a substantial premium over credit card details. Over the past year, there have been at least 95.5 million healthcare records in the U.S. stolen through big data breaches, representing nearly 30 percent of the U.S. population.

While nearly every healthcare organization is a target, there are very few that can properly defend against a targeted data breach. Most have an excellent level of preventative security, but no amount of prevention will keep a motivated cybercriminal out of a network. Both Gartner and the FBI agree that it is no longer possible to have 100 percent effective preventive security. Even the president of RSA, Amit Yoran, concluded world’s largest security conference with the cutting observation, “Our industry has adopted a defensive mindset that mimics the dark ages … beyond this irrational obsession with perimeters, the security profession follows an equally absurd path to detecting these advanced threats.”

The shocking news is that very few companies have the means to find a post-intrusion active data breach. The traditional preventative and malware-focused approaches do not work. The industry “standard” of six months to discover a data breach is evidence enough. Only with great luck will organizations be able to find active attackers if they are still chasing signatures of known malicious software and other statically defined technical artifacts. Larger organizations find themselves drowning in security alerts, most of them false-positives.

The best way to find an active data breach quickly and accurately is to look for the operational activities they have to use once they land in a network. In particular, reconnaissance and lateral movement are two kinds of behaviors that must be done and can be spotted if you know how to look for them. The new breed of active breach detection technologies seems to be a promising new way of finding these attackers. Unfortunately most healthcare organizations don’t yet know about these.

This year, healthcare IT must seriously look beyond just prevention to strategies and tools that will stop data breaches after an attacker has already made it into the network. Traditional approaches have proven to be immense failures for this problem. It’s time to consider a new approach to safeguard the systems and data these IT organizations are chartered to protect.

Amir Naftali, co-founder and chief technology officer, FortyCloud

Healthcare IT operations are very frequently computation and memory intensive. Operations like processing electronic personal health records, ?genetic data analysis and other healthcare related Big Data processing are all heavy CPU and memory consumers?.?

Therefore, IT are always on the lookout for a more powerful yet cost-effective solution. Today, cloud-based infrastructure services (IaaS) offer almost infinite virtual computation resources in an attractive and agile pay-per-use model.
These resources can be allocated almost anywhere around the globe.

Moving healthcare IT operations to infrastructure clouds seems, therefore, a like very natural step. An almost a perfect fit exists between the computation and business needs of Healthcare IT, and the compelling business model of IaaS.

However, the only caveat with this alliance is security. Healthcare IT operations deal with highly sensitive patient data, while public cloud infrastructure environments have security challenges that are inherent to the model itself. Furthermore, health-related security regulations, like HIPAA, make it impossible to adopt any leading public IaaS offering “as is” for healthcare IT operations. Therefore, to ensure that its data is secured in the cloud or hybrid environments, a CISO must supplement its cloud operations with an ISV solution that is not part of the initial cloud offering.?

Jonathan Kaplan MD, MPH, board certified plastic surgeon, Pacific Heights Plastic Surgery

Price transparency — patients want it, but doctors/facilities don’t want to provide it because the doctor/facility has no incentive. The pricing info that consumers do get is mostly just US averages. It’s almost impossible to get pricing for a specific service from a specific provider.

[Electronic Health Reporter]

English
Exit mobile version