Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
26
27
28
30
2
8
9
10
11
12
13
14
19
21
24
26
28
29
30
1
2
3
4
5
6
Neurology Certification Review 2019
2019-08-29 - 2019-09-03    
All Day
Neurology Certification Review is organized by The Osler Institute and will be held from Aug 29 - Sep 03, 2019 at Holiday Inn Chicago Oakbrook, [...]
Ophthalmology Lecture Review Course 2019
2019-08-31 - 2019-09-05    
All Day
Ophthalmology Lecture Review Course is organized by The Osler Institute and will be held from Aug 31 - Sep 05, 2019 at Holiday Inn Chicago [...]
Emergency Medicine, Sex and Gender Based Medicine, Risk Management/Legal Medicine, and Physician Wellness
2019-09-01 - 2019-09-08    
All Day
Emergency Medicine, Sex and Gender Based Medicine, Risk Management/Legal Medicine, and Physician Wellness is organized by Continuing Education, Inc and will be held from Sep [...]
Medical Philippines 2019
2019-09-03 - 2019-09-05    
All Day
The 4th Edition of Medical Philippines Expo 2019 is organized by Fireworks Trade Exhibitions & Conferences Philippines, Inc. and will be held from Sep 03 [...]
Grand Opening Celebration for Encompass Health Katy
2019-09-04    
4:00 pm - 7:00 pm
Grand Opening Celebration for Encompass Health Katy 23331 Grand Reserve Drive | Katy, Texas Sep 4, 2019 4:00 p.m. CDT Encompass Health will host a grand opening [...]
Galapagos & Amazon 2019 Medical Conference
2019-09-05 - 2019-09-17    
All Day
Galapagos & Amazon 2019 Medical Conference is organized by Unconventional Conventions and will be held from Sep 05 - 17, 2019 at Santa Cruz II, [...]
Mesotherapy Training (Sep 06, 2019)
2019-09-06    
All Day
Mesotherapy Training is organized by Empire Medical Training (EMT), Inc and will be held on Sep 06, 2019 at The Westin New York at Times [...]
Aesthetic Next 2019 Conference
2019-09-06 - 2019-09-08    
All Day
Aesthetic Next 2019 Conference Venue: SEPTEMBER 6-8, 2019 RENAISSANCE DALLAS HOTEL, DALLAS, TX www.AestheticNext.com On behalf Aesthetic Record EMR, we would like to invite you [...]
Anti-Aging - Modules 1 & 2 (Sep, 2019)
2019-09-07    
All Day
Anti-Aging - Modules 1 & 2 is organized by Empire Medical Training (EMT), Inc and will be held on Sep 07, 2019 at The Westin [...]
Allergy Test and Treatment (Sep, 2019)
2019-09-15    
All Day
Allergy Test and Treatment is organized by Empire Medical Training (EMT), Inc and will be held on Sep 15, 2019 at Aloft Chicago O'Hare, Chicago, [...]
Biosimilars & Biologics Summit 2019
2019-09-16 - 2019-09-17    
All Day
TBD
Biosimilars & Biologics Summit 2019 is organized by Lexis Conferences Ltd and will be held from Sep 16 - 17, 2019 at London, England, United [...]
X Anniversary International Exhibition of equipment and technologies for the pharmaceutical industry PHARMATechExpo
2019-09-17 - 2019-09-19    
All Day
X Anniversary International Exhibition of equipment and technologies for the pharmaceutical industry PHARMATechExpo is organized by Laboratory Marketing Technology (LMT) Company, Shupyk National Medical Academy [...]
2019 Physician and CIO Forum
2019-09-18 - 2019-09-19    
All Day
Event Location MEDITECH Conference Center 1 Constitution Way Foxborough, MA Date : September 18th - 19th Conference: Wednesday, September 18  8:00 AM - 5:00 PM [...]
Stress, Depression, Anxiety and Resilience Summit 2019
2019-09-20 - 2019-09-21    
All Day
Stress, Depression, Anxiety and Resilience Summit is organized by Lexis Conferences Ltd and will be held from Sep 20 - 21, 2019 at Vancouver Convention [...]
Sclerotherapy for Physicians & Nurses Course - Orlando (Sep 20, 2019)
2019-09-20    
All Day
Sclerotherapy for Physicians & Nurses Course is organized by Empire Medical Training (EMT), Inc and will be held on Sep 20, 2019 at Sheraton Orlando [...]
Complete, Hands-on Dermal Filler (Sep 22, 2019)
2019-09-22    
All Day
Complete, Hands-on Dermal Filler is organized by Empire Medical Training (EMT), Inc and will be held on Sep 22, 2019 at Sheraton Orlando Lake Buena [...]
The MedTech Conference 2019
2019-09-23 - 2019-09-25    
All Day
The MedTech Conference 2019 is organized by Advanced Medical Technology Association (AdvaMed) and will be held from Sep 23 - 25, 2019 at Boston Convention [...]
23 Sep
2019-09-23 - 2019-09-24    
All Day
ABOUT 2ND WORLD CONGRESS ON RHEUMATOLOGY & ORTHOPEDICS Scientific Federation will be hosting 2nd World Congress on Rheumatology and Orthopedics this year. This exciting event [...]
25 Sep
2019-09-25 - 2019-09-26    
All Day
ABOUT 18TH WORLD CONGRESS ON NUTRITION AND FOOD CHEMISTRY Nutrition Conferences Committee extends its welcome to 18th World Congress on Nutrition and Food Chemistry (Nutri-Food [...]
ACP & Stem Cell Therapies for Pain Management (Sep 27, 2019)
2019-09-27    
All Day
ACP & Stem Cell Therapies for Pain Management is organized by Empire Medical Training (EMT), Inc and will be held on Sep 27, 2019 at [...]
01 Oct
2019-10-01 - 2019-10-02    
All Day
The UK’s leading health technology and smart health event, bringing together a specialist audience of over 4,000 health and care professionals covering IT and clinical [...]
Events on 2019-08-29
Events on 2019-08-31
Events on 2019-09-03
Medical Philippines 2019
3 Sep 19
Pasay City
Events on 2019-09-04
Events on 2019-09-05
Galapagos & Amazon 2019 Medical Conference
5 Sep 19
Galapagos Islands
Events on 2019-09-06
Events on 2019-09-07
Events on 2019-09-15
Events on 2019-09-16
Events on 2019-09-18
2019 Physician and CIO Forum
18 Sep 19
Foxborough
Events on 2019-09-22
Events on 2019-09-23
The MedTech Conference 2019
23 Sep 19
Boston
23 Sep
Events on 2019-09-25
Events on 2019-09-27
Events on 2019-10-01
01 Oct
Latest News

Smart buildings present a unique healthcare cybersecurity threat

businessman touching Cloud with Padlock icon on network connection, digital background. Cloud computing and network security concept (businessman touching Cloud with Padlock icon on network connection, digital background. Cloud computing and network s

The virtual and physical realms are becoming increasingly enmeshed through the world of the Internet of Things. The rate of Internet connections is outpacing companies’ abilities to secure them.

As a result, a large driver of cybercrime is the least-protected networks and systems found in the healthcare information technology world – building automation, or smart building technology.

For example, hackers stole 40 million credit card numbers from Target by getting into the retailer’s internet-connected HVAC systems. And in another example, hackers got access to a North American database by way of a web-connected fish tank.

These scenarios shed light on the ways that operational tech, such as signage, elevators, AV conferencing, HVAC, etc., can pose serious security risks for healthcare organizations.

Uniquely valuable data

“Information available in healthcare provider organizations – patient health information (PHI), payment card information (PCI), intellectual property (IP) and more – is uniquely valuable to hackers in comparison to other industries, which is why we’ve seen such a dramatic focus on cybersecurity in healthcare to date,” said Matthew Ehrlich, executive director, TEKsystems Global Services, digital technology builders whose specialties include cybersecurity.

“The problem we see, however, is that most of the efforts to protect healthcare providers fall under the IT policy umbrella,” he continued. “By limiting cyber threats to just IT policy, organizations are missing key vulnerabilities and risk exposure for their company. Building systems are not traditionally in scope for IT, yet they have a vast ecosystem of technology that must be assessed and governed.”

These technology systems, referred to as operational technology, are primitive and generally poorly governed, making them ripe targets for the infiltration of the main network of a hospital, he added.

There are many different building systems in healthcare that present cybersecurity vulnerabilities. Traditional commercial buildings have vulnerabilities rooted in operational technology in places such as HVACs, fire alarm systems, digital signage, elevators, water or electric meters, lighting, and many more. All of those vulnerabilities apply to healthcare organizations, as well.

Nontraditional technologies

“However, healthcare providers also have such unique real estate types, ranging from small ambulatory facilities to complex 1,000-plus bed hospitals ,to laboratories, to parking garages, to pharmacies and more,” Ehrlich explained. “Each of these types bring in a whole host of nontraditional-technology enablement and separate vendor ecosystems.”

Take for example the laboratory: Beyond ordering systems, one has secure rooms/doors, temperature-controlled rooms, blood banks, special lighting etc. This concept lays the foundation for the Internet of Medical Things (IoMT), which is an emerging area that healthcare organizations need to be aware of.

So what are the steps healthcare CIOs and CISOs can take to analyze, design, evaluate and implement smart building solution plans to protect themselves from hackers getting to more important things like the main network or the electronic health records system?

“First and foremost, healthcare providers should be taking a collaborative approach to solving this problem – IT cannot own this alone,” Ehrlich said. “Similarly, the risk organization cannot own this either. A coordinated effort between risk, real estate, finance, operations, IT and clinical needs to exist to ensure implementation of end-to-end policy.”

An initial assessment is the first step, and educating and understanding risk exposure can generate tremendous ROI, Ehrlich noted. After any vulnerabilities are remediated and policies are built, healthcare providers need a way to monitor and manage ongoing operations as the technology and vendor landscape is changing constantly, he said.

An extreme lack of awareness

“Most healthcare leaders are aware of the benefits an organization can achieve from a ‘smart building,’” he said. “But there is an extreme lack of awareness in healthcare today on the rising risk that exists in the current building infrastructure with very simple things like elevators or HVACs, let alone more innovative topics like ‘smart rooms.’ We fear that due to the lack of education and urgency, this problem will likely get worse before it gets better.”

With advanced analytics generated from developments/implementations of consolidated EHR, ERP and CRM over the last decade, the amount of data is hard to imagine. With that, the access to that data is increasing, and through one key area: building-system vulnerabilities, Ehrlich said.

“Building vulnerabilities will become a leading entry point or cause of breaches and incidents across the healthcare ecosystem,” he concluded.