Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
27
12:00 AM - Arab Health 2020
29
1
7
10
12
14
16
20
23
25
27
28
29
1
Arab Health 2020
2020-01-27 - 2020-01-30    
All Day
ABOUT ARAB HEALTH 2020 Arab Health is an industry-defining platform where the healthcare industry meets to do business with new customers and develop relationships with [...]
12th International Conference on Acute Cardiac Care
2020-01-28 - 2020-01-29    
All Day
ABOUT 12TH INTERNATIONAL CONFERENCE ON ACUTE CARDIAC CARE Acute Cardiac Care has been undergoing a substantial transformation in recent years as the population ages and [...]
30 Jan
2020-01-30 - 2020-01-31    
All Day
The ICMHS conference is an international forum for the presentation of technological advances and research results in the fields of Medical and Health Sciences. The [...]
Annual Lower and Upper Canada Anesthesia Symposium 2020 (LUCAS)
2020-01-31 - 2020-02-02    
All Day
ABOUT ANNUAL LOWER & UPPER CANADA ANESTHESIA SYMPOSIUM 2020 (LUCAS) On behalf of the Departments of Anesthesia of McGill University, Queen’s University, and the University [...]
RF - 577th International Conference On Medical & Health Science - ICMHS 2020
2020-02-02 - 2020-02-03    
All Day
577th International Conference on Medical & Health Science - ICMHS 2020. It will be held during 2nd-3rd February, 2020 at Berlin , Germany. ICMHS 2020 [...]
ISER- 747th International Conference On Science, Health And Medicine ICSHM
2020-02-02 - 2020-02-03    
All Day
ISER- 747th International Conference on Science, Health and Medicine ICSHM is a prestigious event organized with a motivation to provide an excellent international platform for [...]
International Conference On Medical And Health SciencesICMHS-2020
2020-02-03 - 2020-02-04    
All Day
The ICMHS conference is an international forum for the presentation of technological advances and research results in the fields of Medical and Health Sciences. The [...]
Medlab Middle East 2020
2020-02-03 - 2020-02-06    
All Day
ABOUT MEDLAB MIDDLE EAST 2020 Medlab Middle East is the only medical laboratory industry event that offers manufacturers the opportunity to meet a diverse audience [...]
Cloud Architecture Implementation Healthcare 2020
2020-02-04 - 2020-02-06    
All Day
This summit brings together leaders from healthcare organizations to scale up their cloud infrastructure, implement cloud technology and share use cases about the success and [...]
4th Microbiome Movement - Drug Development Summit Europe 2020 - London, UK
2020-02-04 - 2020-02-06    
All Day
A unique forum focusing on pursuing disease causation to foster the creation of targeted Microbiome-based therapeutics, biomarkers and diagnostics. Time: 8:30 am - 5:50 pm [...]
Structural Heart Intervention And Imaging Feb 2020 CME Conference-San Diego
2020-02-05 - 2020-02-07    
All Day
The Scripps Structural Heart Intervention and Imaging conference features live case demonstrations, lectures from renowned faculty, hands-on workshops, and extensive satellite symposia. Time: 7:00 am [...]
Structural Heart Intervention And Imaging Feb 2020 CME Conference-San Diego
2020-02-05 - 2020-02-07    
All Day
The Scripps Structural Heart Intervention and Imaging conference features live case demonstrations, lectures from renowned faculty, hands-on workshops, and extensive satellite symposia. Time: 7:00 am [...]
18th Annual South Beach Symposium
2020-02-06 - 2020-02-09    
All Day
ABOUT 18TH ANNUAL SOUTH BEACH SYMPOSIUM The 18th Annual South Beach Symposium will take place in Miami Beach, Florida from February 6-9, 2020 at the [...]
Primary Care CME In Clearwater Beach, Florida February 2020
2020-02-08 - 2020-02-10    
All Day
Topics include latest hypertension guidelines, cancer screening, cholesterol management, immunizations, COPD, skin and soft tissue infections, etc. Time: 08:00 - 11:00
Primary Care CME In Clearwater Beach, Florida February 2020
2020-02-08 - 2020-02-10    
All Day
Topics include latest hypertension guidelines, cancer screening, cholesterol management, immunizations, COPD, skin and soft tissue infections, etc. Time: 08:00 - 11:00  
World Congress On Medical Imaging And Clinical Research WCMICR-2020
2020-02-09 - 2020-02-10    
All Day
The WCMICR conference is an international forum for the presentation of technological advances and research results in the fields of Medical Imaging and Clinical Research. [...]
Medical Design & Manufacturing (MD&M) West
2020-02-11 - 2020-02-13    
All Day
ABOUT MEDICAL DESIGN & MANUFACTURING (MD&M) WEST Medical Design & Manufacturing (MD&M) West is where serious professionals find the technologies, education, and connections to stay [...]
Third International Conference On Zika Virus And Aedes Related Infections
2020-02-13    
All Day
This Conference will bring together multidisciplinary experts aiming to tackle the challenges that Aedes related infections present including zika, dengue, yellow fever, and chikungunya. Time: [...]
The IRES - 791st International Conferences On Medical And Health Science ICMHS
2020-02-15 - 2020-02-16    
All Day
The IRES - 791st International Conferences on Medical and Health Science ICMHS aimed at presenting current research being carried out in that area and scheduled [...]
4th International Conference on Chronic Diseases
2020-02-17 - 2020-02-18    
All Day
ABOUT 4TH INTERNATIONAL CONFERENCE ON CHRONIC DISEASES It takes immense pleasure to invite you to attend the 4th International Conference on Chronic Diseases (Chronic Diseases [...]
European Gynecology and Obstetrics Congress
2020-02-17 - 2020-02-18    
All Day
ABOUT EUROPEAN GYNECOLOGY AND OBSTETRICS CONGRESS Gynecology 2020 destine to endeavor leading-edge memoranda of eminent keynote speakers, universal personalities, special sessions and poster presentations attracting [...]
18 Feb
2020-02-18 - 2020-02-20    
All Day
Technology Networks is a global online scientific publication that covers the latest research, industry news, and technologies. Our 12 online communities provide focused coverage of [...]
6th International Conference On Food And Beverages
2020-02-19 - 2020-02-20    
All Day
Meetings International Meetings Int. invites you to attend the ‘6th International Conference on Food and Beverages 2020” which is to be held on February 19-20, [...]
10th Global Summit on Neuroscience and Neuroimmunology
2020-02-19 - 2020-02-20    
All Day
ABOUT 10TH GLOBAL SUMMIT ON NEUROSCIENCE AND NEUROIMMUNOLOGY 10th Global Summit on Neuroscience and Neuroimmunology (Neuroimmunology 2020) is aimed at improving health across the globe, [...]
Mayo Clinic Nephrology And Transplantation For The Clinician 2020
2020-02-21 - 2020-02-22    
All Day
Nephrology and Transplantation for the Clinician: 18th Annual Update From Mayo Clinic is a two-day course designed to u-p-d-a-t-e participants on nephrology topics relevant to [...]
28th International Conference on Cancer Research and Pharmacology
2020-02-21 - 2020-02-22    
All Day
ABOUT 28TH INTERNATIONAL CONFERENCE ON CANCER RESEARCH AND PHARMACOLOGY PULSUS Conferences is glad to invite all the participants across the globe to attend 28th International [...]
Rocky Mountain Winter Conference On Emergency Medicine 2020
2020-02-22 - 2020-02-26    
All Day
Each day the conference starts with a hot breakfast followed by engaging, cutting edge didactics led by experts from the countrys top academic programs. Please [...]
CRT20 Conference
2020-02-22 - 2020-02-25    
All Day
ABOUT CRT20 CONFERENCE CRT, one of the world’s leading interventional cardiology conferences, is attended by more than 3,000 interventional and endovascular specialists. At the 2019 [...]
3rd International conference on  Diabetes, Hypertension and Metabolic Syndrome
2020-02-24 - 2020-02-25    
All Day
About Diabetes Meet 2020 Conference Series takes the immense Pleasure to invite participants from all over the world to attend the 3rdInternational conference on Diabetes, Hypertension and [...]
3rd International Conference on Cardiology and Heart Diseases
2020-02-24 - 2020-02-25    
All Day
ABOUT 3RD INTERNATIONAL CONFERENCE ON CARDIOLOGY AND HEART DISEASES The standard goal of Cardiology 2020 is to move the cardiology results and improvements and to [...]
Medical Device Development Expo OSAKA
2020-02-26 - 2020-02-28    
All Day
ABOUT MEDICAL DEVICE DEVELOPMENT EXPO OSAKA What is Medical Device Development Expo OSAKA (MEDIX OSAKA)? Gathers All Kinds of Technologies for Medical Device Development! This [...]
Events on 2020-01-27
Arab Health 2020
27 Jan 20
Dubai
Events on 2020-01-28
Events on 2020-01-30
Events on 2020-01-31
Events on 2020-02-03
Events on 2020-02-06
18th Annual South Beach Symposium
6 Feb 20
Miami Beach
Events on 2020-02-09
Events on 2020-02-11
Events on 2020-02-17
Events on 2020-02-18
18 Feb
Events on 2020-02-22
CRT20 Conference
22 Feb 20
National Harbor
Events on 2020-02-26
Articles

Cloud Apps in hospitals are a Pandora’s Box for hackers

By D’Arcy Guerin Gue, Vice President Industry Relations,  Phoenix Health Systems a division of Medsphere Systems

Cloud apps….Everyone uses them, and the best are remarkable productivity enhancers.  Your IT Department knows about some of them, but research says hospital employees are using hundreds more. Data security is at risk. 

Most hospitals have officially embraced at least some cloud services, such as Microsoft 365, and been diligent in determining that vendors can be signed and sealed Business Associates under HIPAA.  Microsoft has provided BA agreements for years that outline its security responsibilities.

But the big picture of healthcare’s cloud app usage includes widespread unmonitored employee and departmental adoption of popular commercial apps like Dropbox, Evernote and Smartsheet. And these are the tip of the iceberg. The average healthcare organization uses an astounding 928 cloud services, according to a mid-2015 Skyhigh study. In case you’re stunned, IT departments must feel the same, since they estimated only 60 services. What is going on here?

As a quick preamble, while HIT surveys normally rely on self-reporting, Skyhigh, a top cloud security broker and research organization, used actual usage data  for over 1.6 million employees of healthcare providers and payers. The bottom line is that employees bring cloud services into their work places for increased productivity and sometimes personal enjoyment without the knowledge of IT. Services vary from collaboration tools such as Gmail and Evernote, to development tools like SourceForge and Github, to content sharing services like YouTube and LiveLeak, to social media (Facebook, Twitter, LinkedIn) and file sharing such as Google Drive and Dropbox.

Are we really surprised? It’s time to acknowledge the extraordinary level of immersion in online resources of our healthcare employees — not unlike our entire population.  Says Skyhigh: “The average healthcare employee uses 26 distinct cloud services including  8 collaboration services, 4 file-sharing services, 4 social media services and 4 content sharing services.” Many of these services promote work quality productivity, though other apps do not.

In either case, how is your hospital’s security at risk when an employee uses them? Cyber criminals monitor cloud services to determine what sites healthcare employees like to frequent. Criminals compromise the sites if they can in order to ultimately compromise a targeted healthcare organization in what is known as a “watering hole attack.”

Here’s just one way this works, and it’s so simple that it is humbling. When a data-heavy cloud-based organization experiences a data breach, user passwords are among the first casualties. For example, eBay had to prompt 145 million users in 2014 to change their passwords after account credentials were compromised. University of Cambridge research by Joseph Bonneau shows that at least 31% of passwords are reused in multiple places. When the average healthcare employee is using 26 different cloud services, chances are good that one overused password could put a criminal in the driver’s seat — inside the hospital and, perhaps, inside a system containing PHI.

Unconvinced? Another potential source of cloud-based data access is APIs, software building blocks that are used to connect to other software. An example is that an employee may connect his or her Facebook account to Dropbox, so it can automatically save the most recent content posted. If the Facebook account gets compromised, the same will happen to the Dropbox account, which may well contain private information — hopefully not PHI.

Do these dangers indicate your organization should flatly outlaw adoption of cloud services by employees? Probably not, unless you plan to spend millions to enforce it. Your employees are using these applications and services in the often justifiable belief that they support better job performance. Your staff will continue to find applications that work for them: task management, team collaboration, automated spreadsheets, and much more. This kind of unauthorized but often harmless and productive  activity is so common that security experts have given it a name: “shadow IT.”

The control that IT organizations once had over enterprise IT is gone; I would argue that it never existed. Regardless, this puts your IT and security team in a difficult position. IT’s job isn’t to hold your organization back from being able to quickly adapt and innovate, but it must ensure security across the enterprise. What should you do? Establish a cloud application strategy, including policies and procedures:

  1. Learn what applications are being used.

Knowledge is the beginning; monitor network traffic and identify what cloud applications are in use and how prevalent they are. If you don’t have software that will accomplish this, you should.

  1. Assess the security positions and overall risk that different services pose.

Many cloud services meet HIPAA requirements, but many have unacceptable levels of risk. Dropbox, as an example of the former, announced in November 2015 that it is HIPAA-compliant. Salesforce’s Health Cloud patient relationship tool “has built-in tools to facilitate adherence to HIPAA Requirements.” Other tools may meet your hospital’s risk threshold  but cannot prevent your staff from populating them with PHI.  For example, the popular Evernote appears to have strong security backbones, but you will have to establish strong guidelines prohibiting employees from posting PHI. Other tools may be high-risk cloud applications that your IT department can block and notify employees of their prohibition.

  1. Understand users and proactively work with them

Even the riskiest applications are often used by well-meaning employees. Few employees knowingly move sensitive data to their own devices or cloud-based tools for criminal purposes. If your IT staff watches and analyzes cloud activity for naively risky activities as well as suspicious movements, the results will be critical to developing a strategy for migrating toward sanctioned cloud apps and providing employee-friendly training.

  1. Proactively respond

Your IT / security team can eliminate unsafe apps, and still enable employees to utilize safe and productive cloud-based tools. Review, assess, and approve/disapprove your employees’ most commonly used cloud-based apps in a measured, security-focused manner. Because technologies and applications are constantly increasing, provide a documented process for employees to request approval to use new cloud services, and create a track record of fast review and approval. If that effort is transparent, your users will recognize that IT’s motives are aligned with organizational objectives and concerned with empowering employees while minimizing security risks.

IT should be able to to identify approved cloud services and communicate its list to employees, based on their roles. It should periodically update the list, and provide usage standards like not recording PHI and proprietary business information, and provide associated training. A big benefit to absorbing this responsibility is that users will have no excuse to circumvent the rules, thereby lowering your organization’s overall security risks.

From our experience, most hospitals don’t have the kind of cloud app risk mitigation program described above. Instead, they are doing little or nothing to understand and address what has become a ubiquitous reality. We need to establish a middle ground that allows employees to take advantage of valuable popular services while maintaining our hospitals’ data security.

Source Medsphere