Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
31
12:00 AM - EXPO.health
5
6
8
9
10
11
13
15
16
18
19
20
21
22
23
24
26
27
28
30
1
32nd Annual Summer Seminar in Health Care Ethics & Surgical Ethics
2019-07-29 - 2019-08-02    
All Day
32nd Annual Summer Seminar in Health Care Ethics & Surgical Ethics is organized by University of Washington School of Medicine (UWSOM) Continuing Medical Education (CME) [...]
3-Day Physician Assistant PANCE / PANRE Board Review Course by Certified Medical Educators (CME) - Salt Lake City
2019-07-29 - 2019-07-31    
All Day
3-Day Physician Assistant PANCE / PANRE Board Review Course is organized by Certified Medical Educators (CME) and will be held from Jul 29 - 31, [...]
Four Week Radiologic Pathology Correlation Course (Jul 29 - Aug 23, 2019)
2019-07-29 - 2019-08-23    
All Day
Four Week Radiologic Pathology Correlation Course is organized by American Institute for Radiologic Pathology (AIRP) and will be held from Jul 29 - Aug 23, [...]
Third Annual Philadelphia Trauma Training Conference
2019-07-30 - 2019-08-01    
All Day
Third Annual Philadelphia Trauma Training Conference is organized by Thomas Jefferson University (TJU) and will be held from Jul 30 - Aug 01, 2019 at [...]
IDAA Annual Meeting 2019
2019-07-31 - 2019-08-04    
All Day
International Doctors in Alcoholics Anonymous (IDAA) 70th Annual Meeting 2019 is organized by International Doctors in Alcoholics Anonymous (IDAA) and will be held from Jul [...]
EXPO.health
2019-07-31 - 2019-08-02    
All Day
EXPO.health Schedule July 31 - August 2, 2019 - Location: Boston, MA Join us at EXPO.health (Formerly Healthcare IT Expo – HITExpo) 2019 happening July [...]
01 Aug
2019-08-01 - 2019-08-03    
All Day
UCSF CME: Neurosurgery Update 2019 is organized by The University of California, San Francisco (UCSF) Office of Continuing Medical Education and will be held from [...]
PBI Medical Ethics & Professionalism (ME-22) - Irvine
2019-08-02 - 2019-08-03    
All Day
PBI Medical Ethics & Professionalism (ME-22) is organized by Professional Boundaries, Inc. (PBI) and will be held from Aug 02 - 03, 2019 at Wyndham [...]
The 8th Beijing International Top Health & Medical Exhibition (BIHM)
2019-08-02 - 2019-08-04    
All Day
The 8th Beijing International Private Health and Medical Exhibition will be held at the China International Exhibition Center from August 2nd to August 4th, 2019. [...]
Angiogenesis Gordon Research Seminar (GRS) 2019
2019-08-03 - 2019-08-04    
12:00 am
Angiogenesis Gordon Research Seminar (GRS) is organized by Gordon Research Conferences (GRC) and will be held from Aug 03 - 04, 2019 at Salve Regina [...]
Lung Development, Injury and Repair Gordon Research Seminar (GRS) 2019
2019-08-03 - 2019-08-04    
All Day
Lung Development, Injury and Repair Gordon Research Seminar (GRS) is organized by Gordon Research Conferences (GRC) and will be held from Aug 03 - 04, [...]
Platelet Rich Plasma for Aesthetics Course - Miami (Aug 2019)
Platelet Rich Plasma for Aesthetics Course is organized by Empire Medical Training (EMT), Inc and will be held on Aug 04, 2019 at GALLERYone - [...]
Physician Medical Weight Loss Training (Aug 04, 2019)
2019-08-04    
All Day
Physician Medical Weight Loss Training is organized by Empire Medical Training (EMT), Inc and will be held on Aug 04, 2019 at The Platinum Hotel [...]
Grand opening for Saint Alphonsus Regional Rehabilitation Hospital
2019-08-07    
4:00 pm - 6:00 pm
Grand opening for Saint Alphonsus Regional Rehabilitation Hospital 711 North Curtis Road | Boise, Idaho Aug 7, 2019 4:00 p.m. MDT A new home for Saint Alphonsus [...]
7th International Conference on  Medical Informatics & Telemedicine
2019-08-12 - 2019-08-13    
All Day
Conference Date : August 12-13, 2019 Rome, Italy Theme: Innovative information technologies for the improvement of patient care “7th International Conference on Medical Informatics and Telemedicine” will take [...]
CMBBE 2019 - 16th International Symposium on Computer Methods in Biomechanics and Biomedical Engineering and the 4th Conference on Imaging and Visualization
2019-08-14 - 2019-08-16    
8:00 am - 6:00 pm
CMBBE 2019 - 16th International Symposium on Computer Methods in Biomechanics and Biomedical Engineering and the 4th Conference on Imaging and Visualization is organized by [...]
Joint / Extremity / Non Spinal Injection Course (Aug 17, 2019)
2019-08-17    
All Day
Joint / Extremity / Non Spinal Injection Course is organized by Empire Medical Training (EMT), Inc and will be held on Aug 17, 2019 at [...]
Wilderness Medicine Expedition Course 2019
2019-08-25 - 2019-09-02    
All Day
Wilderness Medicine Expedition Course is organized by National Outdoor Leadership School (NOLS) and will be held from Aug 25 - Sep 02, 2019 at Wyss [...]
Diabetes, Lipidology, Pulmonary Medicine, and Critical Care Conference
2019-08-25 - 2019-09-01    
All Day
Diabetes, Lipidology, Pulmonary Medicine, and Critical Care Conference is organized by Continuing Education, Inc and will be held from Aug 25 - Sep 01, 2019 [...]
Neurology Certification Review 2019
2019-08-29 - 2019-09-03    
All Day
Neurology Certification Review is organized by The Osler Institute and will be held from Aug 29 - Sep 03, 2019 at Holiday Inn Chicago Oakbrook, [...]
Ophthalmology Lecture Review Course 2019
2019-08-31 - 2019-09-05    
All Day
Ophthalmology Lecture Review Course is organized by The Osler Institute and will be held from Aug 31 - Sep 05, 2019 at Holiday Inn Chicago [...]
Emergency Medicine, Sex and Gender Based Medicine, Risk Management/Legal Medicine, and Physician Wellness
2019-09-01 - 2019-09-08    
All Day
Emergency Medicine, Sex and Gender Based Medicine, Risk Management/Legal Medicine, and Physician Wellness is organized by Continuing Education, Inc and will be held from Sep [...]
Events on 2019-07-30
Events on 2019-07-31
IDAA Annual Meeting 2019
31 Jul 19
Knoxville
EXPO.health
31 Jul 19
Boston
Events on 2019-08-01
01 Aug
Events on 2019-08-29
Events on 2019-08-31
Latest News

Penn Medicine CISO offers tips for COVID-19 cybersecurity response

As hospitals and health systems nationwide grapple with the fast-moving demands of the coronavirus crisis, they’re also faced with an added challenge: fending off a sustained upswell in cybersecurity threats, perpetrated by bad actors taking advantage of the pandemic’s chaos.

Healthcare IT News spoke recently with Dan Costantino, Chief Information Security Officer at Penn Medicine, who offered some insights into how his infosec staff has adjusted its strategies to support the health system during the public health emergency.

He described new efforts to thwart COVID-19 themed phishing attempts, efforts to securely roll out new telehealth offerings and the ongoing need to be nimble and accommodating to the needs of clinical staff on the front lines.

Q. Generally speaking, have you made changes to your security posture in light of these new opportunistic cyber threats? Or is it a matter of ensuring you maintain the strategies you’ve always had in place?

A. We’re continuing to push along on many of the previous projects that we had underway. We’re continuing to focus on a lot of our former strategic objectives that we already had in place, in as many ways as we can.

However, obviously, in light of what’s happening there, there has been a need to make some small adjustments. That’s just the new threat landscape that we’re faced with, and some of the new demands from the clinical and operations perspective.

We’ve started to increase our own levels of awareness and threat modeling around things like COVID-19-themed phishing emails, and some of the specific attacks that the industry in general may be seeing during a time like this.

By doing that, we’ve implemented a heightened level of awareness within our security operations center. We have a full security operations center on-site at Penn Medicine, and we also outsource a portion of security operations as well. And so we’ve increased our level of vigilance, high level of vigilance, within that security operations center.

And we’ve done that with the understanding that cyber criminals will use a time of crisis to cover some of their actions in a very opportunistic way. And so we try to track and match our operations and vigilance to that.

Secondly, the health system has needed to adjust their approach to clinical care. And with that, we’ve had to adjust ours to remain aligned in certain ways.

They’re starting to introduce a lot of new workflows and technologies in a really short period of time. And in order to keep pace with that, we’ve needed to build somewhat of a rapid-response risk-analysis capability.

And this allows us to continue evaluating the security and the architecture of new solutions at a high level, while not slowing down the development and deployment of said technologies and new workflows and business processes.

That’s been an adjustment for our team. It puts us in a position where we are still able to align and keep pace with the business to provide them that level of support from a security perspective, and that level of analysis and review that we need. But also, you know, I’m not slowing things down to normal lead times and service level agreements that we would have in place for something like that.

We’re able to turn them around rather quickly, which is which is needed in the health system.

And I think, frankly, with the security team, it’s been beneficial for us to align in that way. Historically, security teams have found that if you don’t align yourself well, and if you don’t support clinical operations, eventually, you know, some of these technologies will find their ways through the cracks.

And so we’ve tried to align ourselves to be a strong business partner in a way that the clinical operations and, in general, health system leadership teams will want to come to us for consultation on those things.

Q. What sort of coordination do you have with other clinical and operational IT leaders across Penn Medicine as this public health emergency unfolds?

A. Our level of coordination with the clinical-operations-center teams has always been strong. We pride ourselves as a program, and always, in our ability to align extremely well with the business and operations and always remain highly collaborative with the health system leadership.

But these times have certainly put us in more regular contact with leaders through the rapid evolution of how we’re currently providing care right now. And so, while they’re not necessarily scheduled meetings, we find ourselves in contact with clinical and operations, individuals and leaders pretty regularly.

Oftentimes what that looks like is, is some type of new clinical workflow or new clinical technology that’s being either developed, implemented or simply just designed and thought about. A lot of clinical leaders are coming to our security program for assistance, to understand what it looks like in order to secure a technology or a process.

What would it look like to secure something that they’re looking at? What kind of turnaround time would it need? Is it worth going after? A lot of times we’re being asked, you know, “We have an opportunity here. We have a need, and we may have a technology, but does the benefit outweigh the risk?” And they’re trying to understand in a really short period of time, what could the risk [be] or like from something like this, and we’re trying to match that demand the best we can.

There have been a lot of cases where we’ve been able to accommodate those requests very quickly. I’d say in most cases being able to do that, and then in some cases, we have needed to slow things down just a bit in order to fully understand the scope of it, and clinical leadership has been very understanding of that.

During the early stages of Penn Medicine’s response to COVID-19, as the non-essential personnel were starting to be sent home, we had to make sure that there were still support roles for the frontline staff. And so, as a security team, we stood up a completely off-site remote-access command center, capable of assisting over 20,000 remote employees to get connected to our network through a secure conduit, and be able to assist the frontline staff – whether that be through charting, project management, data analytics, you name it.

We’ve had more than 29,000 unique employees connect to our network remotely and securely since we started our own response.

Q. Hospitals all over the country are embracing telehealth to a scale that many are not used to. And remote care presents another whole set of security challenges. I presume Penn Medicine has expanded its telehealth offerings?

A. We have. Penn Medicine already had a pretty strong telehealth offering, but your point, this crisis has certainly put telehealth right in the spotlight due to its unique capabilities [as] well. We’ve mostly bulked up our current telehealth offerings and technologies, which we had previously vetted and previously reviewed, and ensured that we were doing things the right way and getting the most secure way possible.

But then we’ve also to think about some backstops. If the infrastructure of our current offering can’t handle the demand, what do we do? That’s where things have become, I think, a little bit more fluid for us as a security team, as we’ve had to evaluate and begin the implementation of a completely different telehealth solution that can act as a secondary solution or a backstop to what we already had in place. That’s been a pretty fluid situation.

We’ve been highly engaged and involved in that. And in reviewing the technologies and working pretty closely with the vendor to make sure that they can meet some of our workflows, we can keep things within our security standards. But so far, I would say things have gone extremely well.

Q. Do you have any advice or perspective for smaller hospitals and health systems as they seek to manage safety and security during these challenging times?

A. One of the key things for smaller hospitals to keep in mind – and maybe all hospitals should keep in mind – is that during a time like this, there’s really a need to be accommodating but not reckless. Clinical operations are moving so quickly that there really may not be time to slow things down like there were in the past, from a security perspective.

But that said, if you are a security professional, it’s your job to shine a light on potentially risky technologies and workflows. If they’re identified, then you need to make sure the right people are aware of it, as unpopular as it may be to do something like that during a crisis.

I’m not saying to put a stop to things, but it’s still the job of information security to keep the health system aware when things may look risky, and to provide the right level of consultation and insight into the best way to secure them.

But it’s important to understand that health systems’ cyber-risk tolerance may need to change in order to accommodate a crisis like this. It’s not permanent, and the risk should still be limited. However, security teams need to be prepared to make certain exceptions. And they need to find alternative ways to mitigate the risks that may be introduced during a time like this. Lastly, they need to remain aligned with business and the pace of work that that’s needed in order to get through these trying times.

Source: https://www.healthcareitnews.com/news/penn-medicine-ciso-offers-tips-covid-19-cybersecurity-response