Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
27
12:00 AM - Arab Health 2020
29
1
7
10
12
14
16
20
23
25
27
28
29
1
Arab Health 2020
2020-01-27 - 2020-01-30    
All Day
ABOUT ARAB HEALTH 2020 Arab Health is an industry-defining platform where the healthcare industry meets to do business with new customers and develop relationships with [...]
12th International Conference on Acute Cardiac Care
2020-01-28 - 2020-01-29    
All Day
ABOUT 12TH INTERNATIONAL CONFERENCE ON ACUTE CARDIAC CARE Acute Cardiac Care has been undergoing a substantial transformation in recent years as the population ages and [...]
30 Jan
2020-01-30 - 2020-01-31    
All Day
The ICMHS conference is an international forum for the presentation of technological advances and research results in the fields of Medical and Health Sciences. The [...]
Annual Lower and Upper Canada Anesthesia Symposium 2020 (LUCAS)
2020-01-31 - 2020-02-02    
All Day
ABOUT ANNUAL LOWER & UPPER CANADA ANESTHESIA SYMPOSIUM 2020 (LUCAS) On behalf of the Departments of Anesthesia of McGill University, Queen’s University, and the University [...]
RF - 577th International Conference On Medical & Health Science - ICMHS 2020
2020-02-02 - 2020-02-03    
All Day
577th International Conference on Medical & Health Science - ICMHS 2020. It will be held during 2nd-3rd February, 2020 at Berlin , Germany. ICMHS 2020 [...]
ISER- 747th International Conference On Science, Health And Medicine ICSHM
2020-02-02 - 2020-02-03    
All Day
ISER- 747th International Conference on Science, Health and Medicine ICSHM is a prestigious event organized with a motivation to provide an excellent international platform for [...]
International Conference On Medical And Health SciencesICMHS-2020
2020-02-03 - 2020-02-04    
All Day
The ICMHS conference is an international forum for the presentation of technological advances and research results in the fields of Medical and Health Sciences. The [...]
Medlab Middle East 2020
2020-02-03 - 2020-02-06    
All Day
ABOUT MEDLAB MIDDLE EAST 2020 Medlab Middle East is the only medical laboratory industry event that offers manufacturers the opportunity to meet a diverse audience [...]
Cloud Architecture Implementation Healthcare 2020
2020-02-04 - 2020-02-06    
All Day
This summit brings together leaders from healthcare organizations to scale up their cloud infrastructure, implement cloud technology and share use cases about the success and [...]
4th Microbiome Movement - Drug Development Summit Europe 2020 - London, UK
2020-02-04 - 2020-02-06    
All Day
A unique forum focusing on pursuing disease causation to foster the creation of targeted Microbiome-based therapeutics, biomarkers and diagnostics. Time: 8:30 am - 5:50 pm [...]
Structural Heart Intervention And Imaging Feb 2020 CME Conference-San Diego
2020-02-05 - 2020-02-07    
All Day
The Scripps Structural Heart Intervention and Imaging conference features live case demonstrations, lectures from renowned faculty, hands-on workshops, and extensive satellite symposia. Time: 7:00 am [...]
Structural Heart Intervention And Imaging Feb 2020 CME Conference-San Diego
2020-02-05 - 2020-02-07    
All Day
The Scripps Structural Heart Intervention and Imaging conference features live case demonstrations, lectures from renowned faculty, hands-on workshops, and extensive satellite symposia. Time: 7:00 am [...]
18th Annual South Beach Symposium
2020-02-06 - 2020-02-09    
All Day
ABOUT 18TH ANNUAL SOUTH BEACH SYMPOSIUM The 18th Annual South Beach Symposium will take place in Miami Beach, Florida from February 6-9, 2020 at the [...]
Primary Care CME In Clearwater Beach, Florida February 2020
2020-02-08 - 2020-02-10    
All Day
Topics include latest hypertension guidelines, cancer screening, cholesterol management, immunizations, COPD, skin and soft tissue infections, etc. Time: 08:00 - 11:00
Primary Care CME In Clearwater Beach, Florida February 2020
2020-02-08 - 2020-02-10    
All Day
Topics include latest hypertension guidelines, cancer screening, cholesterol management, immunizations, COPD, skin and soft tissue infections, etc. Time: 08:00 - 11:00  
World Congress On Medical Imaging And Clinical Research WCMICR-2020
2020-02-09 - 2020-02-10    
All Day
The WCMICR conference is an international forum for the presentation of technological advances and research results in the fields of Medical Imaging and Clinical Research. [...]
Medical Design & Manufacturing (MD&M) West
2020-02-11 - 2020-02-13    
All Day
ABOUT MEDICAL DESIGN & MANUFACTURING (MD&M) WEST Medical Design & Manufacturing (MD&M) West is where serious professionals find the technologies, education, and connections to stay [...]
Third International Conference On Zika Virus And Aedes Related Infections
2020-02-13    
All Day
This Conference will bring together multidisciplinary experts aiming to tackle the challenges that Aedes related infections present including zika, dengue, yellow fever, and chikungunya. Time: [...]
The IRES - 791st International Conferences On Medical And Health Science ICMHS
2020-02-15 - 2020-02-16    
All Day
The IRES - 791st International Conferences on Medical and Health Science ICMHS aimed at presenting current research being carried out in that area and scheduled [...]
4th International Conference on Chronic Diseases
2020-02-17 - 2020-02-18    
All Day
ABOUT 4TH INTERNATIONAL CONFERENCE ON CHRONIC DISEASES It takes immense pleasure to invite you to attend the 4th International Conference on Chronic Diseases (Chronic Diseases [...]
European Gynecology and Obstetrics Congress
2020-02-17 - 2020-02-18    
All Day
ABOUT EUROPEAN GYNECOLOGY AND OBSTETRICS CONGRESS Gynecology 2020 destine to endeavor leading-edge memoranda of eminent keynote speakers, universal personalities, special sessions and poster presentations attracting [...]
18 Feb
2020-02-18 - 2020-02-20    
All Day
Technology Networks is a global online scientific publication that covers the latest research, industry news, and technologies. Our 12 online communities provide focused coverage of [...]
6th International Conference On Food And Beverages
2020-02-19 - 2020-02-20    
All Day
Meetings International Meetings Int. invites you to attend the ‘6th International Conference on Food and Beverages 2020” which is to be held on February 19-20, [...]
10th Global Summit on Neuroscience and Neuroimmunology
2020-02-19 - 2020-02-20    
All Day
ABOUT 10TH GLOBAL SUMMIT ON NEUROSCIENCE AND NEUROIMMUNOLOGY 10th Global Summit on Neuroscience and Neuroimmunology (Neuroimmunology 2020) is aimed at improving health across the globe, [...]
Mayo Clinic Nephrology And Transplantation For The Clinician 2020
2020-02-21 - 2020-02-22    
All Day
Nephrology and Transplantation for the Clinician: 18th Annual Update From Mayo Clinic is a two-day course designed to u-p-d-a-t-e participants on nephrology topics relevant to [...]
28th International Conference on Cancer Research and Pharmacology
2020-02-21 - 2020-02-22    
All Day
ABOUT 28TH INTERNATIONAL CONFERENCE ON CANCER RESEARCH AND PHARMACOLOGY PULSUS Conferences is glad to invite all the participants across the globe to attend 28th International [...]
Rocky Mountain Winter Conference On Emergency Medicine 2020
2020-02-22 - 2020-02-26    
All Day
Each day the conference starts with a hot breakfast followed by engaging, cutting edge didactics led by experts from the countrys top academic programs. Please [...]
CRT20 Conference
2020-02-22 - 2020-02-25    
All Day
ABOUT CRT20 CONFERENCE CRT, one of the world’s leading interventional cardiology conferences, is attended by more than 3,000 interventional and endovascular specialists. At the 2019 [...]
3rd International conference on  Diabetes, Hypertension and Metabolic Syndrome
2020-02-24 - 2020-02-25    
All Day
About Diabetes Meet 2020 Conference Series takes the immense Pleasure to invite participants from all over the world to attend the 3rdInternational conference on Diabetes, Hypertension and [...]
3rd International Conference on Cardiology and Heart Diseases
2020-02-24 - 2020-02-25    
All Day
ABOUT 3RD INTERNATIONAL CONFERENCE ON CARDIOLOGY AND HEART DISEASES The standard goal of Cardiology 2020 is to move the cardiology results and improvements and to [...]
Medical Device Development Expo OSAKA
2020-02-26 - 2020-02-28    
All Day
ABOUT MEDICAL DEVICE DEVELOPMENT EXPO OSAKA What is Medical Device Development Expo OSAKA (MEDIX OSAKA)? Gathers All Kinds of Technologies for Medical Device Development! This [...]
Events on 2020-01-27
Arab Health 2020
27 Jan 20
Dubai
Events on 2020-01-28
Events on 2020-01-30
Events on 2020-01-31
Events on 2020-02-03
Events on 2020-02-06
18th Annual South Beach Symposium
6 Feb 20
Miami Beach
Events on 2020-02-09
Events on 2020-02-11
Events on 2020-02-17
Events on 2020-02-18
18 Feb
Events on 2020-02-22
CRT20 Conference
22 Feb 20
National Harbor
Events on 2020-02-26
Articles

Will “Digital Fingerprint” Forensics Thwart the Data Thieves Lurking in Hospital EHR Corridors?

AI Image

Exclusive article at EMRIndustry.com

By Santosh Varughese, president, Cognetyx, delivering ‘Ambient Cognitive Cyber Surveillance’ to protect information assets against cyber security threats, data breaches & privacy violations.

 

As Halloween approaches, the usual spate of horror movies will intrigue audiences across the US, replete with slashers named Jason or Freddie running amuck in the corridors of all too easily accessible hospitals. They grab a hospital gown and the zombies fit right in.  While this is just a movie you can turn off, the real horror of patient data theft can follow you.

(I know how terrible this type of crime can be. I myself have been the victim of a data theft by hackers who stole my deceased father’s medical files, running up more than $300,000 in false charges. I am still disputing on-going bills that have been accruing for the last 15 years).

Unfortunately, this horror movie scenario is similar to how data thefts often occur at medical facilities. In 2015, the healthcare industry was one of the top three hardest hit industries with serious data breaches and major attacks, along with government and manufacturers. Packed with a wealth of exploitable information such as credit card data, email addresses, Social Security numbers, employment information and medical history records, much of which will remain valid for years, if not decades and fetch a high price on the black market.

Who Are The Hackers?

It is commonly believed attacks are from outside intruders looking to steal valuable patient data and 45 percent of the hacks are external. However, “phantom” hackers are also often your colleagues, employees and business associates who are unwittingly careless in the use of passwords or lured by phishing schemes that open the door for data thieves. Not only is data stolen, but privacy violations are insidious.

The problem is not only high-tech, but also low-tech, requiring that providers across the continuum simply become smarter about data protection and privacy issues. Medical facilities are finding they must teach doctors and nurses not to click on suspicious links.

 

To thwart accidental and purposeful hackers, organizations should implement physical security procedures to secure network hardware and storage media through measures like maintaining a visitor log and installing security cameras. Also limiting physical access to server rooms and restricting the ability to remove devices from secure areas. Yes, humans are the weakest link.

Growing Nightmare

Medical data theft is a growing national nightmare.  IDC’s Health Insights group predicts that 1 in 3 healthcare recipients will be the victim of a medical data breach in 2016.  Other surveys found that in the last two years, 89% of healthcare organizations reported at least one data breach, with 79% reporting two or more breaches. The most commonly compromised data are medical records, followed by billing and insurance records. The average cost of a healthcare data breach is about $2.2 million.

At health insurer Anthem, Inc., foreign hackers stole up to 80 million records using social engineering to dig their way into the company’s network using the credentials of five tech workers. The hackers stole names, Social Security numbers and other sensitive information, but were thwarted when an Anthem computer system administrator discovered outsiders were using his own security credentials to log into the company system and to hack databases.

Investigators believe the hackers somehow compromised the tech worker’s security through a phishing scheme that tricked the employee into unknowingly revealing a password or downloading malicious software. Using this login information, they were able to access the company’s database and steal files.

Healthcare Hacks Spread Hospital Mayhem in Diabolical Ways

Not only is current patient data security an issue, but thieves can also drain the electronic economic blood from hospitals’ jugular vein—its IT systems. Hospitals increasingly rely on cloud delivery of big enterprise data from start-ups like iCare that can predict epidemics, cure disease, and avoid preventable deaths. They also add Personal Health Record apps to the system from fitness apps like FitBit and Jawbone.

Banner Health, operating 29 hospitals in Arizona, had to notify millions of individuals that their data was exposed. The breach began when hackers gained access to payment card processing systems at some of its food and beverage outlets. That apparently also opened the door to the attackers accessing a variety of healthcare-related information.

Because Banner Health says its breach began with an attack on payment systems, it differentiates from other recent hacker breaches. While payment system attacks have plagued the retail sector, they are almost unheard of by healthcare entities.

What also makes this breach more concerning is the question of how did hackers access healthcare systems after breaching payment systems at food/beverage facilities, when these networks should be completely separated from one another? Healthcare system networks are very complex and become more complicated as other business functions are added to the infrastructure – even those that don’t necessarily have anything to do with systems handling and protected health information.

Who hasn’t heard of “ransomeware”? The first reported attack was Hollywood Presbyterian Medical Center which had its EHR and clinical information systems shut down for more than week. The systems were restored after the hospital paid $17,000 in Bitcoins.

 

Will Data Thieves Also Rob Us of Advances in Healthcare Technology?

Is the data theft at MedStar Health, a major healthcare system in the DC region, a foreboding sign that an industry racing to digitize and interoperate EHRs is facing a new kind of security threat that it is ill-equipped to handle? Hospitals are focused on keeping patient data from falling into the wrong hands, but attacks at MedStar and other hospitals highlight an even more frightening downside of security breaches—as hospitals strive for IT interoperability. Is this goal now a concern?

As hospitals increasingly depend on EHRs and other IT systems to coordinate care, communicate critical health data and avoid medication errors, they could also be risking patients’ well-being when hackers strike. While chasing the latest medical innovations, healthcare facilities are rapidly learning that caring for patients also means protecting their medical records and technology systems against theft and privacy violations.

“We continue the struggle to integrate EHR systems,” says anesthesiologist Dr. Donald M. Voltz, Medical Director of the Main Operating Room at Aultman Hospital in Canton, OH, and an advocate and expert on EHR interoperability. “We can’t allow patient data theft and privacy violations to become an insurmountable problem and curtail the critical technology initiative of resolving health system interoperability. Billions have been pumped into this initiative and it can’t be risked.”

Taking Healthcare Security Seriously

Healthcare is an easy target. Its security systems tend to be less mature than those of other industries, such as finance and tech. Its doctors and nurses depend on data to perform time-sensitive and life-saving work.

Where a financial-services firm might spend a third of its budget on information technology, hospitals spend only about 2% to 3%. Healthcare providers are averaging less than 6% of their information technology budget expenditures on security, according to a recent HIMSS survey. In contrast, the federal government spends 16% of its IT budget on security, while financial and banking institutions spend 12% to 15%.

Meanwhile, the number of healthcare attacks over the last five years has increased 125%, as the industry has become an easy target. Personal health information is 50 times more valuable on the black market than financial information. Stolen patient health records can fetch as much as $363 per record.

“If you’re a hacker… would you go to Fidelity or an underfunded hospital?” says John Halamka, the chief information officer of Beth Israel Deaconess Medical Center in Boston. “You’re going to go where the money is and the safe is the easiest to open.”

Many healthcare executives believe that the healthcare industry is at greater risk of breaches than other industries. Despite these concerns, many organizations have either decreased their cyber security budgets or kept them the same. While the healthcare industry has traditionally spent a small fraction of its budget on cyber defense, it has also not shored up its technical systems against hackers.

Disrupting the Healthcare Security Industry with Behavior Analysis   

Common defenses in trying to keep patient data safe have included firewalls and keeping the organization’s operating systems, software, anti-virus packages and other protective solutions up-to-date.  This task of constantly updating and patching security gaps or holes is ongoing and will invariably be less than 100% functional at any given time.  However, with only about 10% of healthcare organizations not having experienced a data breach, sophisticated hackers are clearly penetrating through these perimeter defenses and winning the healthcare data security war. So it’s time for a disruption.

Many organizations employ network surveillance tactics to prevent the misuse of login credentials. These involve the use of behavior analysis, a technique that the financial industry uses to detect credit card fraud. By adding some leading innovation, behavior analysis can offer C-suite healthcare executives a cutting-edge, game-changing innovation.

The technology relies on the proven power of cloud technology to combine artificial intelligence with machine learning algorithms to create and deploy “digital fingerprints” using ambient cognitive cyber surveillance to cast a net over EHRs and other hospital data sanctuaries. It exposes user behavior deviations while accessing  EHRs and other applications with PHI that humans would miss and can not only augment current defenses against outside hackers and malicious insiders, but also flag problem employees who continually violate cyber security policy.

“Hospitals have been hit hard by data theft,” said Doug Brown, CEO, Black Book Research. “It is time for them to consider new IT security initiatives. Harnessing machine learning artificial intelligence is a smart way to sort through large amounts of data. When you unleash that technology collaboration, combined with existing cloud resources, the security parameters you build for detecting user pattern anomalies will be difficult to defeat.”

While the technology is advanced, the concept is simple. A pattern of user behavior is established and any actions that deviate from that behavior, such as logging in from a new location or accessing a part of the system the user normally doesn’t access are flagged.  Depending on the deviation, the user may be required to provide further authentication to continue or may be forbidden from proceeding until a system administrator can investigate the issue.

Some of those leading this effort include Cognetyx which delivers ‘Ambient Cognitive Cyber Surveillance’ to protect healthcare information assets against cyber security threats, data breaches & privacy violations. The Houston-based firm provides a Virtual Intelligent Eye that combines artificial intelligence with advanced machine learning algorithms to provide real-time behavior analysis and anomalous user access monitoring.

The Virtual Intelligent Eye works by generating a digital “fingerprint” based on behavior for every single login, by every single user, in every single application and database across the organization.
This information is a recording of the “who, what, when, where, why, and how” data is being accessed within an organization. Once a baseline for behavior is established, the system can easily identify anomalies in user activity, and send out the appropriate alerts immediately when there are deviations from normal behavior.

The cost of this technology will be positively impacted by the continuing decline in the cost of storage and processing power from cloud computing giants such as Amazon Web Services, Microsoft and Alphabet.

The healthcare data security war can be won, but it will require action and commitment from the industry. In addition to allocating adequate human and monetary resources to information security and training employees on best practices, the industry would do well to implement network surveillance that includes behavior analysis. It is the single best technological defense against the misuse of medical facility systems and the most powerful weapon the healthcare industry has in its war against cyber criminals.