Health IT’s Most Pressing Issues

Healthcare is not without its issues. Seemingly, for each source asked what the biggest problem the sector faces, there is a differing opinion on what’s most important. I’m often perplexed by the lack of cohesiveness shown toward the industry’s leading issues, too, and sometimes wonder how many of us could name the most pressing threats to the industry, as agreed upon by the community. There are clear problems – interoperability, lack of transparency, disparate systems working against each other — to name a few. So, in the following series, I’ve asked some insiders for their opinions on health IT’s greatest problems, and as you’ll see, they responses received vary greatly.

Scott Friedman, executive vice president, Sherpa Software

Healthcare IT struggles mightily with patient information that is not in the medical record system, but has leaked into other locations in the healthcare organization (cell phone emails, USB drives, employee desks, etc.). Healthcare organizations have moved Protected Health Information (PHI) into HIPAA compliant electronic health records (EHRs) systems, patients maintain electronic copies of their health information, which they give to their different providers as they move between appointments. This “patient distributed information” becomes PHI, with all its associated compliance and legal burdens for the health care organization.

There is liability associated with this, and information governance strategies available that reduce the associated risks. Patient distributed information is present on smartphones, tablets, laptops, and the like are not sanctioned EHR (such as email, file directories, etc.). These devices are not part of the organization’s HIPAA compliant system, and never can be. Most healthcare providers ignore the problem, which eventually leads to catastrophic security failures resulting in patient privacy breaches, and career damaging incidents for the healthcare IT department.

To eliminate the problem, IT needs to look to integrate an information governance framework that can:

  • Interview employees to understand how they deal with and understand this issue.
  • Audit, usually done with software systems, to provide objective evidence and quantification of the presence of PHI on your digital systems.
  • Set specific policies and procedures employees can follow in each and every situation when they come into contact with “patient distributed information.”
  • Provide raining and review of policies and procedures work.
  • Automate the policies and procedures with software systems to ensure compliance.
  • Surveil your digital systems is the best way to monitor and review your program, as well as seek to improve it.

Acknowledge the increasing presence of patient distributed information on your digital systems, and have a plan for how to address it. Look to information governance to establish a strategy and program to address patient distributed information. With the proper policies, procedures, training, and systems in place your organization will be able to effectively handle and mitigate the risks.

Steve Schick, senior director, education, LightCyber

Steve Schick

One of the most pressing issues facing healthcare organizations today is the threat of a targeted data breach. While data breaches are a top concern for most companies and organizations, it is even more acute for healthcare. Healthcare data is some of the most valuable in the dark web, commanding a substantial premium over credit card details. Over the past year, there have been at least 95.5 million healthcare records in the U.S. stolen through big data breaches, representing nearly 30 percent of the U.S. population.

While nearly every healthcare organization is a target, there are very few that can properly defend against a targeted data breach. Most have an excellent level of preventative security, but no amount of prevention will keep a motivated cybercriminal out of a network. Both Gartner and the FBI agree that it is no longer possible to have 100 percent effective preventive security. Even the president of RSA, Amit Yoran, concluded world’s largest security conference with the cutting observation, “Our industry has adopted a defensive mindset that mimics the dark ages … beyond this irrational obsession with perimeters, the security profession follows an equally absurd path to detecting these advanced threats.”

The shocking news is that very few companies have the means to find a post-intrusion active data breach. The traditional preventative and malware-focused approaches do not work. The industry “standard” of six months to discover a data breach is evidence enough. Only with great luck will organizations be able to find active attackers if they are still chasing signatures of known malicious software and other statically defined technical artifacts. Larger organizations find themselves drowning in security alerts, most of them false-positives.

The best way to find an active data breach quickly and accurately is to look for the operational activities they have to use once they land in a network. In particular, reconnaissance and lateral movement are two kinds of behaviors that must be done and can be spotted if you know how to look for them. The new breed of active breach detection technologies seems to be a promising new way of finding these attackers. Unfortunately most healthcare organizations don’t yet know about these.

This year, healthcare IT must seriously look beyond just prevention to strategies and tools that will stop data breaches after an attacker has already made it into the network. Traditional approaches have proven to be immense failures for this problem. It’s time to consider a new approach to safeguard the systems and data these IT organizations are chartered to protect.

Amir Naftali, co-founder and chief technology officer, FortyCloud

Healthcare IT operations are very frequently computation and memory intensive. Operations like processing electronic personal health records, ?genetic data analysis and other healthcare related Big Data processing are all heavy CPU and memory consumers?.?

Therefore, IT are always on the lookout for a more powerful yet cost-effective solution. Today, cloud-based infrastructure services (IaaS) offer almost infinite virtual computation resources in an attractive and agile pay-per-use model.
These resources can be allocated almost anywhere around the globe.

Moving healthcare IT operations to infrastructure clouds seems, therefore, a like very natural step. An almost a perfect fit exists between the computation and business needs of Healthcare IT, and the compelling business model of IaaS.

However, the only caveat with this alliance is security. Healthcare IT operations deal with highly sensitive patient data, while public cloud infrastructure environments have security challenges that are inherent to the model itself. Furthermore, health-related security regulations, like HIPAA, make it impossible to adopt any leading public IaaS offering “as is” for healthcare IT operations. Therefore, to ensure that its data is secured in the cloud or hybrid environments, a CISO must supplement its cloud operations with an ISV solution that is not part of the initial cloud offering.?

Jonathan Kaplan MD, MPH, board certified plastic surgeon, Pacific Heights Plastic Surgery

Price transparency — patients want it, but doctors/facilities don’t want to provide it because the doctor/facility has no incentive. The pricing info that consumers do get is mostly just US averages. It’s almost impossible to get pricing for a specific service from a specific provider.

[Electronic Health Reporter]

IT and the Line of Business – Security vs Usability Survey

The undeniable benefits of the cloud – better functionality, scalability, availability, and innovation at lower cost – is driving a secular move to cloud services. These benefits have made the cloud an executive-level and board-level conversation at many companies. As a result, IT is looking to take advantage of these opportunities not only for systems of engagement but also for the systems of record that house the authoritative copy of sensitive data. At the same time, end users demand and expect the same level of usability and functionality in enterprise systems as they’ve come to expect with personal technology. As data leaves the company datacenter for the cloud, IT is caught between delivering technologies to support innovation and growth in the business and securing sensitive data against proliferating threats.

In this survey we plan to explore how these trends are reshaping the role of IT and its relationship to the line of business. After numerous high profile data breaches in recent years starting with the Target payment card theft and culminating in the Sony breach, we also seek to investigate how organizations are preparing for mega breaches. Finally, as more organizations look to migrate their systems of record to the cloud, we focus on what systems of record are being migrated first and the security challenges organizations face as sensitive data moves beyond the firewall.

You are invited to participate in the survey

IT and the Line of Business – Security vs Usability

Take the survey now

Participants will be entered to win 1 of 10 Certificate of Cloud Security Knowledge (CCSK) exam tokens and a DJI Phantom 2 quadcopter drone.

The CCSK token ($345 value) will allow the user to take the CCSK exam onhttps://ccsk.cloudsecurityalliance.org/ and earn their certificate. A link to the study material will be included. Respondents can only take the survey once but feel free to invite your qualified friends and colleagues.

Thank you for your support!

[Cloud Security Alliance]

Using Cyber Risk Intelligence to Identify the Controls You Should Focus On

With so many cyber threats out there, knowing where to focus your efforts and what controls to implement is no easy task. However, with cyber risk intelligence, you can gain an immediate understanding of the trending cyber threats to your business domain, what the bad guys are after and how they are getting in. And then you can shift your defenses and implement the appropriate controls.

In a new mid-year cybercrime report by SurfWatch Labs, our data analysts looked at all of the CyberFacts, or evaluated cyber intelligence, collected from 1 January to 30 June 2015. A CyberFact consists of an actor—who conducted the attack; target—what information/systems were targeted; effect—what was the impact of the attack; and practice—what method was used, along with other key metadata and information such as the target industry sector.

A common theme we found was that cybercriminals are targeting personally identifiable information (PII). The top breach targets of the first half of 2015 (Anthem, OPM, etc.) show an important shift when compared to the second half of 2014 when point of sale (POS) breaches at Home Depot, Staples, Dairy Queen and others took up seven of the top 10 slots. In those instances, cybercriminals were going after credit card information, which is very different from the personal information of patients, employees, partners and other individuals associated with the breached organization.

The reason for the cybercrime shift to focus on PII is that this kind of information allows cybercriminals to gain a greater fraud footprint—much more beyond simply selling credit card numbers on the Dark Web. If your organization has personal data, it is time to pay close attention and implement the proper controls.

We found that 77 percent of all cyberattacks in the first half of 2015 started at user interaction points with web sites, applications, accounts and/or endpoints. While the mid-year report outlines differing avenues of approach for different industries, cybercriminals are first targeting users for entry.

Knowing the user environment is the most targeted, you will want to implement the proper controls to ensure you can answer these questions:

  • Are your users effectively trained?
  • Are you proactively monitoring the user environment?

It is certainly not an easy feat, but it’s critically important to the overall security posture of your organization.

Another key point to highlight is that since last year when POS equipment was the leading avenue of approach, retail vendors have been upgrading their equipment for chip and PIN, adding tokenization and more, which is creating a harder target for actors to penetrate. As such, cybercriminals have shifted to other “softer” targets.

You cannot just implement controls to address an exploitable surface and then think you are covered, as it is a constantly moving target. As targets begin to harden their environment, the cybercriminals will shift to softer targets to continue their business—and right now they have chosen your users or, in some cases, the users of your partners.

Adam Meyer
Chief Security Strategist at SurfWatch Labs

[ISACA Now Blog]

Customized Malware—The Game Changer

“How secure is our network from unauthorized access?”

If you are an information security or risk management professional, you have undoubtedly become accustomed to having this question asked of you, likely with increased frequency. Those posing this question, whether a senior manager or an individual serving on your board of directors, are acutely aware of the dramatic increase in cyber attacks and the consequences associated with the unauthorized access of customer information, proprietary corporate data or intellectual property. Given your respective role, it is, therefore, logical that individuals turn to you for reassurance that the organization’s confidential information is adequately protected from the rapidly evolving array of external threats.

The next time that you are asked this question, I urge you to reflect on this article. Before you launch into your practiced response of describing the myriad technical controls you have deployed to secure your network perimeter, a best-in-class firewall, robust anti-virus software and a data loss prevention solution, it is advisable to remember this indisputable fact: customized malware has rendered these technologies increasingly ineffective. If you are performing an information security or risk role, you must recognize that a new generation of prolific hackers are routinely deploying customized malware to successfully penetrate the networks of sophisticated, multinational corporations. Therefore, the traditional approach of combating this threat through a technology centric strategy is obsolete.

Organizations that fail to acknowledge this dynamic, and adjust their approach accordingly, will remain at the imminent risk of a data breach and be exposed to the consequences that accompany these events. This article will discuss and define the evolving threat posed by customized malware and provide a multifaceted approach to mitigate this risk.

Customized malware is malicious software that has been modified, reengineered or altered to evade the detection capabilities of traditional security technologies. Customized malware may be presented as any of the commonly known forms of malicious software, including viruses, worms, Trojan horses, rootkits and ransomware. The most common customized malware delivery method is inbound email, normally by a phishing or spear phishing attack. Given that anti-virus products provide “signature-based detection,” only malware variants whose algorithms have been previously identified are prevented from compromising the intended victim. Whenever a new malware variant is identified, a “patch” that addresses this specific threat is created, distributed and installed. In an enterprise environment, conscientious security administrators ensure that all new patches are installed immediately upon receiving the update from their anti-virus provider. Unfortunately, the period that elapses between identification, analysis and distribution of a security patch is 30 to 90 days. In the interim, organizations are significantly exposed to the risk of a customized malware attack.

Although this form of undetectable threat has been active for several years, the widely publicized attack on Target provided the public with unprecedented clarity regarding how customized malware is used. In the Target breach, the malware that was installed within the company’s network permitted a group of hackers, to perform extensive system reconnaissance and, ultimately, the theft of more than 40 million credit and debit card numbers. In addition to the cardholder data, 70 million customer email addresses, home addresses and telephone numbers were stolen. Finally, in mid-December 2013, an external party informed Target management that the retailer had been hacked and the attack eventually was disrupted.

Upon analysis of the malware used against the retailer, it was determined that this variant had a zero percent anti-virus detection rate. Simply put, this form or malware was undetectable.

Although I use the Target breach to demonstrate the characteristics, capabilities and availability of customized malware, similar attacks are commonplace throughout all sectors and industries. If your executive management team was aware that your current security approach would, at best, prevent only one in 20 attempts to penetrate your network, I suspect that you would be reevaluating your system defense strategy.

The persistent and evasive nature of customized malware requires the implementation of a multi-layered approach to data protection and network security. Given the irrefutable evidence that anti-virus products have become increasingly ineffective in preventing this form of malware from compromising global networks, enterprises can no longer rely solely on security technologies. An approach that combines employee education, threat containment and network monitoring will reduce the risk of a customized malware penetration.

I’ll be discussing this issue, including the mitigation strategy we use with our clients, during the session I am presenting at CSX 2015 in Washington DC, 19-21 October titled, “Customized Malware—Address This Threat.” I hope to see you there.

John Moynihan, CGEIT, CRISC
President and Founder of Minuteman Governance

[ISACA Now Blog]

How to Battle Hackers on an Even Plane

In the movie The Untouchables, a hit man pulls a knife to stab Sean Connery, then Connery pulls a shotgun on the hit man. The lesson from this scene is do not bring a knife to a gunfight.

A lot of corporate IT security staff must not have seen this movie. They are bringing knives to the data security fight while hackers bring guns, cannons, tanks and jet fighters.

With increasingly clever malware and phishing tactics, hackers are snagging users login credentials at a frightening pace and gaining access to networks. It can be as easy as exploiting a security hole in a web browser while the user is surfing the web to seize credentials and access privileged services.

While hackers poke, prod and probe networks every hour of the day looking for weaknesses, most corporate IT staff only review access privileges semiannually, quarterly or, if they are particularly diligent, monthly. The reviews are often perfunctory affairs that do not offer much in the way of detection or prevention.

That is not even bringing a knife to a gun fight; that is like remaining at the scene of the crime until the police arrive. Hackers have little fear of getting caught. The hacker who infiltrated Anthem’s customer database was not caught at all; Anthem did not detect the theft until 7 months later.

All of this responsibility does not necessarily have to fall to the corporate IT function. They are doing the best they can with what they have. If IT had to constantly examine and recertify user access with their current access management systems, they would not have time to do anything else. Their systems are typically a patchwork of manual or minimally automated security functions native to individual applications and databases. They do not exist in an integrated data security framework that enables IT to monitor usage of all key resources.

IT does not stand a chance of preventing more Anthem-level data losses until companies automate and analyze. Automating data extraction and cleansing provides a constant stream of user data. Analytical applications spot orphan accounts and irregular usage as they occur, not 7 or more months later. Arming IT with this kind of access management systems mean they are not going into the gunfight with a knife. It means they are ending the fight because the other side knows it cannot win.

Read Chris Sullivan’s recent ISACA Journal article:
Accelerating Access Management to the Speed of Hacks,” ISACA Journal, volume 5, 2015.

[ISACA Journal Blog]

English
Exit mobile version