Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
30
2
3
4
5
6
7
9
12
13
14
15
17
19
22
25
27
12:00 AM - HLTH 2019
28
29
30
31
1
2
3
01 Oct
2019-10-01 - 2019-10-02    
All Day
The UK’s leading health technology and smart health event, bringing together a specialist audience of over 4,000 health and care professionals covering IT and clinical [...]
08 Oct
2019-10-08 - 2019-10-09    
12:00 am
Looking to maximize the efficiency of your current Revenue Cycle solution? Join us as we present strategies for analyzing your MEDITECH Revenue Cycle, and learn from other [...]
2019 Southwest Dental Conference
2019-10-10 - 2019-10-11    
All Day
ABOUT 2019 SOUTHWEST DENTAL CONFERENCE For 91 years, the Southwest Dental Conference has been the meeting of choice for quality professional development and innovative educational [...]
Annual Conference & Exhibition Lyotalk USA 2019
2019-10-10 - 2019-10-11    
All Day
ABOUT ANNUAL CONFERENCE & EXHIBITION LYOTALK USA 2019 Lyotalk is USA’s largest annual conference on Lyophilization/Freeze Drying. Lyotalk attracts gathering from of 150+ experts from [...]
Lab Indonesia 2019
2019-10-10 - 2019-10-12    
All Day
ABOUT LAB INDONESIA 2019 LabAsia is Southeast Asia’s leading laboratory exhibition, serving as the region’s trade platform for laboratory equipment & services suppliers to engage [...]
30th International Conference on Clinical and Experimental Ophthalmology
2019-10-11 - 2019-10-12    
All Day
ABOUT 30TH INTERNATIONAL CONFERENCE ON CLINICAL AND EXPERIMENTAL OPHTHALMOLOGY The 30th International Conference on Clinical and Experimental Ophthalmology is going to be held during October [...]
7th International Conference on Cosmetology & Beauty 2019
Cosmetology and Beauty 2019 passionately welcomes each one of you to attend a global conference in the field of cosmetology which is held on October [...]
16 Oct
2019-10-16 - 2019-10-17    
All Day
ABOUT 17TH INTERNATIONAL CONFERENCE ON CANCER RESEARCH AND THERAPY Cancer Research Conference 2019 coordinates addressing the principal themes and in addition inevitable methodologies of oncology. [...]
Global Cardio Diabetes Conclave 2019
2019-10-18 - 2019-10-20    
All Day
ABOUT GLOBAL CARDIO DIABETES CONCLAVE 2019 A strong correlation between cardiovascular diseases and diabetes is now well established. The American Heart Association considers that individuals [...]
2019 Rehabilitation Medicine Society of Australia and New Zealand
2019-10-20 - 2019-10-23    
All Day
ABOUT 2019 REHABILITATION MEDICINE SOCIETY OF AUSTRALIA AND NEW ZEALAND On behalf of Rehabilitation Medicine Society of Australia and New Zealand (RMSANZ) and the organising [...]
21 Oct
2019-10-21 - 2019-10-23    
All Day
ABOUT GLOBAL CONFERENCE ON SURGERY AND ANESTHESIA (GCSA 2019) Global Conference on Surgery and Anesthesia (GCSA 2019) scheduled on October 21-23 2019 in Dubai, UAE [...]
21 Oct
2019-10-21 - 2019-10-22    
All Day
ABOUT 10TH INTERNATIONAL CONFERENCE ON MASS SPECTROMETRY AND CHROMATOGRAPHY ME Conferences is excited to announce the “10th International Conference on Mass Spectrometry and Chromatography” that [...]
MEDICAL JAPAN 2019 TOKYO
2019-10-23 - 2019-10-25    
All Day
ABOUT MEDICAL JAPAN 2019 TOKYO B to B Trade Show Covering All the Products/Services/Technologies in the Healthcare Industry! MEDICAL JAPAN TOKYO, a sister show of [...]
15th ACAM Laser and Cosmetic Medicine Conference 2019
2019-10-23 - 2019-10-25    
All Day
ABOUT 15TH ACAM LASER AND COSMETIC MEDICINE CONFERENCE 2019 As the new president of ACAM, I am delighted to welcome you all to the 15th [...]
23rd European Nephrology Conference
2019-10-24 - 2019-10-25    
All Day
ABOUT 23RD EUROPEAN NEPHROLOGY CONFERENCE Theme: The Imminent of Nephrology: Current & Advance Approaches to treat Kidney Diseases 23rd European Nephrology Conference is the world’s [...]
FNCE 2019 Food & Nutrition Conference & Expo
2019-10-26 - 2019-10-29    
All Day
ABOUT FNCE 2019 – FOOD & NUTRITION CONFERENCE & EXPO Experience dynamic educational opportunities not available elsewhere. Gain access to new trends, perspectives from expert [...]
HLTH 2019
2019-10-27 - 2019-10-30    
All Day
ABOUT HLTH 2019 HLTH is the largest and most important conference for health innovation. It’s an unprecedented, large-scale forum for collaboration across senior leaders from [...]
Events on 2019-10-01
01 Oct
Events on 2019-10-08
08 Oct
8 Oct 19
Massachusetts
Events on 2019-10-10
Events on 2019-10-18
Global Cardio Diabetes Conclave 2019
18 Oct 19
Bidhannagar
Events on 2019-10-23
Events on 2019-10-24
Events on 2019-10-26
Events on 2019-10-27
HLTH 2019
27 Oct 19
Las Vegas
Latest News

Penn Medicine CISO offers tips for COVID-19 cybersecurity response

As hospitals and health systems nationwide grapple with the fast-moving demands of the coronavirus crisis, they’re also faced with an added challenge: fending off a sustained upswell in cybersecurity threats, perpetrated by bad actors taking advantage of the pandemic’s chaos.

Healthcare IT News spoke recently with Dan Costantino, Chief Information Security Officer at Penn Medicine, who offered some insights into how his infosec staff has adjusted its strategies to support the health system during the public health emergency.

He described new efforts to thwart COVID-19 themed phishing attempts, efforts to securely roll out new telehealth offerings and the ongoing need to be nimble and accommodating to the needs of clinical staff on the front lines.

Q. Generally speaking, have you made changes to your security posture in light of these new opportunistic cyber threats? Or is it a matter of ensuring you maintain the strategies you’ve always had in place?

A. We’re continuing to push along on many of the previous projects that we had underway. We’re continuing to focus on a lot of our former strategic objectives that we already had in place, in as many ways as we can.

However, obviously, in light of what’s happening there, there has been a need to make some small adjustments. That’s just the new threat landscape that we’re faced with, and some of the new demands from the clinical and operations perspective.

We’ve started to increase our own levels of awareness and threat modeling around things like COVID-19-themed phishing emails, and some of the specific attacks that the industry in general may be seeing during a time like this.

By doing that, we’ve implemented a heightened level of awareness within our security operations center. We have a full security operations center on-site at Penn Medicine, and we also outsource a portion of security operations as well. And so we’ve increased our level of vigilance, high level of vigilance, within that security operations center.

And we’ve done that with the understanding that cyber criminals will use a time of crisis to cover some of their actions in a very opportunistic way. And so we try to track and match our operations and vigilance to that.

Secondly, the health system has needed to adjust their approach to clinical care. And with that, we’ve had to adjust ours to remain aligned in certain ways.

They’re starting to introduce a lot of new workflows and technologies in a really short period of time. And in order to keep pace with that, we’ve needed to build somewhat of a rapid-response risk-analysis capability.

And this allows us to continue evaluating the security and the architecture of new solutions at a high level, while not slowing down the development and deployment of said technologies and new workflows and business processes.

That’s been an adjustment for our team. It puts us in a position where we are still able to align and keep pace with the business to provide them that level of support from a security perspective, and that level of analysis and review that we need. But also, you know, I’m not slowing things down to normal lead times and service level agreements that we would have in place for something like that.

We’re able to turn them around rather quickly, which is which is needed in the health system.

And I think, frankly, with the security team, it’s been beneficial for us to align in that way. Historically, security teams have found that if you don’t align yourself well, and if you don’t support clinical operations, eventually, you know, some of these technologies will find their ways through the cracks.

And so we’ve tried to align ourselves to be a strong business partner in a way that the clinical operations and, in general, health system leadership teams will want to come to us for consultation on those things.

Q. What sort of coordination do you have with other clinical and operational IT leaders across Penn Medicine as this public health emergency unfolds?

A. Our level of coordination with the clinical-operations-center teams has always been strong. We pride ourselves as a program, and always, in our ability to align extremely well with the business and operations and always remain highly collaborative with the health system leadership.

But these times have certainly put us in more regular contact with leaders through the rapid evolution of how we’re currently providing care right now. And so, while they’re not necessarily scheduled meetings, we find ourselves in contact with clinical and operations, individuals and leaders pretty regularly.

Oftentimes what that looks like is, is some type of new clinical workflow or new clinical technology that’s being either developed, implemented or simply just designed and thought about. A lot of clinical leaders are coming to our security program for assistance, to understand what it looks like in order to secure a technology or a process.

What would it look like to secure something that they’re looking at? What kind of turnaround time would it need? Is it worth going after? A lot of times we’re being asked, you know, “We have an opportunity here. We have a need, and we may have a technology, but does the benefit outweigh the risk?” And they’re trying to understand in a really short period of time, what could the risk [be] or like from something like this, and we’re trying to match that demand the best we can.

There have been a lot of cases where we’ve been able to accommodate those requests very quickly. I’d say in most cases being able to do that, and then in some cases, we have needed to slow things down just a bit in order to fully understand the scope of it, and clinical leadership has been very understanding of that.

During the early stages of Penn Medicine’s response to COVID-19, as the non-essential personnel were starting to be sent home, we had to make sure that there were still support roles for the frontline staff. And so, as a security team, we stood up a completely off-site remote-access command center, capable of assisting over 20,000 remote employees to get connected to our network through a secure conduit, and be able to assist the frontline staff – whether that be through charting, project management, data analytics, you name it.

We’ve had more than 29,000 unique employees connect to our network remotely and securely since we started our own response.

Q. Hospitals all over the country are embracing telehealth to a scale that many are not used to. And remote care presents another whole set of security challenges. I presume Penn Medicine has expanded its telehealth offerings?

A. We have. Penn Medicine already had a pretty strong telehealth offering, but your point, this crisis has certainly put telehealth right in the spotlight due to its unique capabilities [as] well. We’ve mostly bulked up our current telehealth offerings and technologies, which we had previously vetted and previously reviewed, and ensured that we were doing things the right way and getting the most secure way possible.

But then we’ve also to think about some backstops. If the infrastructure of our current offering can’t handle the demand, what do we do? That’s where things have become, I think, a little bit more fluid for us as a security team, as we’ve had to evaluate and begin the implementation of a completely different telehealth solution that can act as a secondary solution or a backstop to what we already had in place. That’s been a pretty fluid situation.

We’ve been highly engaged and involved in that. And in reviewing the technologies and working pretty closely with the vendor to make sure that they can meet some of our workflows, we can keep things within our security standards. But so far, I would say things have gone extremely well.

Q. Do you have any advice or perspective for smaller hospitals and health systems as they seek to manage safety and security during these challenging times?

A. One of the key things for smaller hospitals to keep in mind – and maybe all hospitals should keep in mind – is that during a time like this, there’s really a need to be accommodating but not reckless. Clinical operations are moving so quickly that there really may not be time to slow things down like there were in the past, from a security perspective.

But that said, if you are a security professional, it’s your job to shine a light on potentially risky technologies and workflows. If they’re identified, then you need to make sure the right people are aware of it, as unpopular as it may be to do something like that during a crisis.

I’m not saying to put a stop to things, but it’s still the job of information security to keep the health system aware when things may look risky, and to provide the right level of consultation and insight into the best way to secure them.

But it’s important to understand that health systems’ cyber-risk tolerance may need to change in order to accommodate a crisis like this. It’s not permanent, and the risk should still be limited. However, security teams need to be prepared to make certain exceptions. And they need to find alternative ways to mitigate the risks that may be introduced during a time like this. Lastly, they need to remain aligned with business and the pace of work that that’s needed in order to get through these trying times.

Source: https://www.healthcareitnews.com/news/penn-medicine-ciso-offers-tips-covid-19-cybersecurity-response