Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
29
1
2
3
4
6
7
8
9
10
11
13
14
15
16
17
7:30 AM - HLTH 2025
18
19
20
22
23
24
25
26
27
28
29
30
31
1
2
12:00 AM - NextGen UGM 2025
TigerConnect + eVideon Unite Healthcare Communications
2025-09-30    
10:00 am
TigerConnect’s acquisition of eVideon represents a significant step forward in our mission to unify healthcare communications. By combining smart room technology with advanced clinical collaboration [...]
Pathology Visions 2025
2025-10-05 - 2025-10-07    
8:00 am - 5:00 pm
Elevate Patient Care: Discover the Power of DP & AI Pathology Visions unites 800+ digital pathology experts and peers tackling today's challenges and shaping tomorrow's [...]
AHIMA25  Conference
2025-10-12 - 2025-10-14    
9:00 am - 10:00 pm
Register for AHIMA25  Conference Today! HI professionals—Minneapolis is calling! Join us October 12-14 for AHIMA25 Conference, the must-attend HI event of the year. In a city known for its booming [...]
HLTH 2025
2025-10-17 - 2025-10-22    
7:30 am - 12:00 pm
One of the top healthcare innovation events that brings together healthcare startups, investors, and other healthcare innovators. This is comparable to say an investor and [...]
Federal EHR Annual Summit
2025-10-21 - 2025-10-23    
9:00 am - 10:00 pm
The Federal Electronic Health Record Modernization (FEHRM) office brings together clinical staff from the Department of Defense, Department of Veterans Affairs, Department of Homeland Security’s [...]
NextGen UGM 2025
2025-11-02 - 2025-11-05    
12:00 am
NextGen UGM 2025 is set to take place in Nashville, TN, from November 2 to 5 at the Gaylord Opryland Resort & Convention Center. This [...]
Events on 2025-10-05
Events on 2025-10-12
AHIMA25  Conference
12 Oct 25
Minnesota
Events on 2025-10-17
HLTH 2025
17 Oct 25
Nevada
Events on 2025-10-21
Events on 2025-11-02
NextGen UGM 2025
2 Nov 25
TN
Latest News

Balancing cybersecurity concerns with patient needs in an era of increased risk

cybersecurity in business

Significant security incidents are common occurrences in healthcare organizations worldwide. In fact, 82% of hospitals reported they had experienced a significant security incident in the past 12 months, according to the 2019 HIMSS Cybersecurity Survey.1

“Today, information security is a top C-suite priority in the healthcare industry,” said Paul McRae, senior director of global healthcare programs at ServiceNow, as he kicked off a panel discussion on cybersecurity at the ServiceNow Knowledge 2019 Conference in Las Vegas. “Patient care, safety, and privacy are at risk. Healthcare as an industry has responded by creating a culture of governance, risk management, and compliance.”

The challenge for healthcare organizations, then, is to optimally communicate necessary information to patients while also managing compliance with regulations such as HIPAA.

To address this challenge, an important first step is to identify all the critical systems and their business owners. Healthcare organizations should consider their business partners’ systems, as well, said Fausto Grelli, Head of Digital Services Enablement at Novartis. “We have a significant number of third-party vendors in every area of the organization. Tracking the risk with our vendors is crucial for us.”

Achieving the balance between optimal communication and regulatory compliance is a sticky wicket for healthcare, said Claude Council, senior manager of cybersecurity at Shriners Hospitals for Children. “The problem is that we could quickly bankrupt the organization if we provide absolute security with zero risk. There has to be a balance between risk and providing patient care, which is the organization’s main mission.”

Of course, not providing enough security can result in dire consequences, said Michael Parisi, vice president of assurance strategy and community development at HITRUST. “At the end of the day, if there is a medical device that could be compromised, if there’s information that is incorrectly input into a EHR or into a medical record, if a prescription is incorrectly administered, all of that can ultimately result in the loss of human life. It doesn’t get any more real than that.”

IT leaders also should perform risk assessments based on HITRUST and then notify business owners of where they need to increase security. To accomplish this, IT leaders can use an algorithm to calculate risk in each system and then let business leaders decide if the level of risk is acceptable. This approach makes it possible for organizations to balance between providing security and allowing internal customers to provide patient care.

Communicating risk to leaders, however, can be labor-intensive. Doing so can involve scouring through spreadsheets, sending control leaders emails pointing out where security weaknesses exist and asking for updates to their systems — and then repeating the same thing two weeks later with the business leaders.

The ServiceNow platform provides timely and consolidated summaries of healthcare system weaknesses to all business owners and leaders. “What we’re finding is that the business owners are becoming more engaged because they’re seeing it,” Council said. “It’s in front of them.” Because of this automated communication, in fact, Shriners has reduced control weakness by a significant percentage.

Source: https://www.healthcareitnews.com/news/balancing-cybersecurity-concerns-patient-needs-era-increased-risk