Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
1
2
6
7
9
10
11
12
13
14
18
19
20
21
23
27
28
30
12:00 AM - Hepatology 2021
31
1
2
3
4
Heart Care and Diseases 2021
2021-03-03    
All Day
Euro Heart Conference 2020 will join world-class professors, scientists, researchers, students, Perfusionists, cardiologists to discuss methodology for ailment remediation for heart diseases, Electrocardiography, Heart Failure, [...]
Gastroenterology and Digestive Disorders
2021-03-04 - 2021-03-05    
All Day
Gastroenterology Diseases is clearing a worldwide stage by drawing in 2500+ Gastroenterologists, Hepatologists, Surgeons going from Researchers, Academicians and Business experts, who are working in [...]
Environmental Toxicology and Ecological Risk Assessment
2021-03-04 - 2021-03-05    
All Day
Environmental Toxicology 2021 you can meet the world leading toxicologists, biochemists, pharmacologists, and also the industry giants who will provide you with the modern inventions [...]
Dermatology, Cosmetology and Plastic Surgery
2021-03-05 - 2021-03-06    
All Day
Market Analysis Speaking Opportunities Speaking Opportunities: We are constantly intrigued by hearing from professionals/practitioners who want to share their direct encounters and contextual investigations with [...]
World Dental Science and Oral Health Congress
2021-03-08 - 2021-03-09    
All Day
About The Webinar Conference Series LLC Ltd invites you to attend the 42nd World Dental Science and Oral Health Congress to be held in March 08-09, 2021 with the [...]
Euro Metabolomics & Systems Biology
2021-03-08 - 2021-03-09    
All Day
Euro Metabolomics 2021 will be a platform to investigate recent research and advancements that can be useful to the researchers. Metabolomics is a rapidly emerging [...]
International Summit on Industrial Engineering
2021-03-15 - 2021-03-16    
All Day
Industrial Engineering conference invites all the participants to attend International summit on Industrial Engineering during March15-16, 2021 Webinar. This has prompt keynotes, Oral talks, Poster [...]
Digital Health 2021
2021-03-15 - 2021-03-16    
All Day
The use of modern technologies and digital services is not only changing the way we communicate, they also offer us innovative ways for monitoring our [...]
Genetics and Molecular biology 2021
2021-03-15    
All Day
Human genetics is study of the inheritance of characteristics by children from parents. Inheritance in humans does not differ in any fundamental way from that [...]
Food Science and Food Safety
2021-03-16 - 2021-03-17    
All Day
Food Safety. It also provides the premier multidisciplinary forum for researchers, professors and educators to present and discuss the most recent innovations, trends, and concerns, [...]
Traditional and Alternative Medicine
2021-03-16 - 2021-03-17    
All Day
Traditional Medicine 2021 welcomes attendees, presenters, and exhibitors from all over the world. We are glad to invite you all to attend and register for [...]
Carbon and Advanced Energy Materials
2021-03-16 - 2021-03-17    
All Day
Materials Science 2021 was an enchanted achievement. We give incredible credits to the Organizing Committee and participants of Materials Science 2021 Conference. Numerous tributes from [...]
Advancements in Tuberculosis and Lung Diseases
2021-03-17 - 2021-03-18    
All Day
Tuberculosis is a communicable disease, caused by the infectious bacterium Mycobacterium tuberculosis. It affects the lungs and other parts of the body (brain, spine). People [...]
Herbal Medicine and Acupuncture 2021
2021-03-22 - 2021-03-23    
All Day
The event offers a best platform with its well organized scientific program to the audience which includes interactive panel discussions, keynote lectures, plenary talks and [...]
Hospital Management and Health Care
2021-03-22 - 2021-03-23    
All Day
Healthcare system refers to the totality of resource that a society distributes with in organization and health facilities delivery for the aim of upholding or [...]
Hematology and Infectious Diseases
2021-03-22 - 2021-03-23    
All Day
Hematology is the discipline concerned with the production, functions, bone marrow, and diseases which are related to blood, blood proteins. The main aim of this [...]
Aquaculture & Marine Biology
2021-03-24 - 2021-03-25    
All Day
The 15th International Conference on Aquaculture & Marine Biology is delighted to welcome the participants from everywhere the planet to attend the distinguished conference scheduled [...]
Artificial Intelligence & Robotics 2021
2021-03-24 - 2021-03-25    
All Day
The Conference Series LLC Ltd organizes conferences around the world on all computer science subjects including Robotics and its related fields. Here we are happy [...]
Tissue Engineering & Regenerative Medicine
2021-03-24 - 2021-03-25    
All Day
Tissue Engineering & Regenerative Medicine mainly focuses on Stem Cell Research and Tissue Engineering. Stem cell Research includes stem cell treatment for various disease and [...]
Nursing Research and Evidence Based Practice
2021-03-25 - 2021-03-26    
12:00 am
Global Nursing Practice 2021 has been circumspectly organized with various multi and interdisciplinary tracks to accomplish the middle objective of the gathering that is to [...]
Earth & Environmental Science 2021
2021-03-26 - 2021-03-27    
All Day
Earth Science 2021 is the integration of new technologies in the field of environmental science to help Environmental Professionals harness the full potential of their [...]
Earth & Environmental Science 2021
2021-03-26 - 2021-03-27    
All Day
Earth Science 2021 is the integration of new technologies in the field of environmental science to help Environmental Professionals harness the full potential of their [...]
Nanomaterials and Nanotechnology
2021-03-26 - 2021-03-27    
All Day
Nanomaterials are the elements which have at least one spatial measurement in the size range of 1 to 100 nanometre. Nanomaterials can be produced with [...]
Smart Materials and Nanotechnology
2021-03-29 - 2021-03-30    
All Day
Smart Material 2021 clears a stage to globalize the examination by introducing an exchange amongst ventures and scholarly associations and information exchange from research to [...]
World Nanotechnology Congress 2021
2021-03-29    
All Day
Nano Technology Congress 2021 provides you with a unique opportunity to meet up with peers from both academic circle and industries level belonging to Recent [...]
Nanomedicine and Nanomaterials 2021
2021-03-29    
All Day
NanoMed 2021 conference provides the best platform of networking and connectivity with scientist, YRF (Young Research Forum) & delegates who are active in the field [...]
Hepatology 2021
2021-03-30 - 2021-03-31    
All Day
Hepatology 2021 provides a great platform by gathering eminent professors, Researchers, Students and delegates to exchange new ideas. The conference will cover a wide range [...]
Events on 2021-03-03
Events on 2021-03-05
Events on 2021-03-17
Events on 2021-03-25
Events on 2021-03-30
Hepatology 2021
30 Mar 21
Articles

You’re not investing enough in IT security, healthcare

IT security, healthcare

Mathematically, the gap between $3.6 million and $17,000 is a chasm.

This is something you know well if you’re Hollywood Presbyterian Hospital, which paid the latter number to unlock patient data held hostage by malicious hackers using ransomware when the former number is what the hackers initially asked for.

While the dramatic reduction in ransom may have caused Hollywood Presbyterian to breathe a sigh of relief, there is no reason they or you should feel comforted. Consider this an initial shot across the bow of what promises to be a lengthy and spirited battle between wired healthcare and cybercriminals.

The fact is, most of healthcare simply doesn’t spend enough on data security. In a study conducted by HIMSS Analytics and Symantec that polled 115 IT and security professionals in hospitals with more than 100 beds, more than half (52 percent) said their organization dedicated between zero and 3 percent of the IT budget to security. Just 28 percent said they spent between 3 and 6 percent of IT budget on security.

“All of this makes healthcare organizations rich targets for cybercriminals,” reads the study summary. “Stolen patient data fetches up to 50 times more than a Social Security or credit card number, because a patient’s EHR contains data that can be used for medical or identity theft, or other fraud. As a result, criminal attacks on healthcare information systems have increased 125 percent in the past five years.”

Smaller IT budgets mean fewer resources for security personnel. Among respondents to the HIMSS Analytics/Symantec poll, 72 percent employed five or fewer people dedicated to security; 10 percent of respondents have 21 or more on the IT security staff. When adjusted to include employees with data security responsibility outside of IT, the average among respondents was 10 people.

So, how many data security pros is enough? How much of the IT budget should hospitals spend on security, adjusting for size? The report offers no specifics. Right now, faced with a growing security concern in hospitals, the answer seems to be “more.”

“The irony is that information technology and data in healthcare are clearly critical to the mission of providing care, yet data security is an afterthought,” said Mac McMillan, chair of the HIMSS Privacy & Security Policy Task Force and CEO of information security and privacy consulting firm CynergisTek. “We don’t have enough” data security specialists, McMillan added, “and we don’t have enough who are qualified to do their job.”

One interpretation of the HIMSS Analytics/Symantec report is that we’ll have a much better idea of how much and how many is enough once we know most healthcare facilities are following proper protocols and successful hacker intrusions level off or decline.

Organizational structure and reporting, for example, is one protocol that deserves attention. It turns out most chief information security officers (CISOs) report to a chief information officer (CIO), effectively making the person primarily responsible for security also in charge of monitoring their superior’s work. Among respondents, 54 percent said security reports to the board don’t happen regularly and 8 percent said they never happen.

The reality is that hospitals need to spend what it requires to avoid the Hollywood Presbyterian scenario. Sure, it was only $17,000 this time, but it will be more next time, and perhaps it will be a lot more than one organization can afford.

The initial investment in sound security will require more dollars, physical and technical protections, and people, but it doesn’t have to stay that way after a solid, sustainable security program is in place. Witness recent examples in Ottawa, Canada, and Henderson, Kentucky, in which hospitals were hit with ransomware attacks and were prepared to weather the assault.

Proper security. No assault. No ransom paid. No data lost. No patient data compromised.

In the real world, there are critical access hospitals that don’t have 21 doctors and nurses combined, let alone 21 employees focused on IT security. Fewer security personnel reliably correlates with vulnerable technical infrastructure and an inability to keep up with essential IT changes and upgrades.

So what can hospitals that lack money and a current security plan do to avoid the same fate as Hollywood Presbyterian? For starters, line up the ducks. The organization of waterfowl, according to HIMSS Analytics and Symantec, requires establishing priorities and inculcating organizational practices.

  • Make the CISO and CIO parallel positions to maintain separate spheres.
  • Include security updates in regularly scheduled reports to the board.
  • Establish an ongoing, consistent risk-management program.
  • Prioritize and reach a consensus on data-security measures.
  • Make medical device security and the Internet of Things part of the security plan.

“Healthcare is a very open, caring and trusting business,” said McMillan. “They [hospitals] don’t understand that you cannot have privacy without good data security.”

Okay, maybe some in healthcare don’t fully grasp the dangers of the brave new IT world their hospital or clinic is moving into. However, I think that, after years of internalizing HIPAA, clinicians and other healthcare workers understand privacy and security just fine. It’s not like healthcare is the only industry to be successfully hacked, after all.

My question is not so much about understanding as it is about investing in safety. How are hospitals already close to the financial margin going to pay for additional security protections, including needed staff, to keep the bad guys out of the (data) bank vault?

We won’t arrive at the solution simply or quickly and it will require extensive collaboration similar to creative broad-based initiatives currently underway.

To date, the ONC-initiated Interoperability Pledge, for example, has garnered written commitments from healthcare organizations of all stripes across the nation. These include the five largest health systems and providers in 46 states, as well as companies that provide 90 percent of the EHRs used by hospitals nationwide. No, a pledge is not binding, but it is indicative of a serious appreciation of the need to ensure easy, secure access to health information for patients and the providers serving them. It may also pave the way for more substantive collaboration around future nationwide interoperability.

Perhaps the CHIME National Patient ID Challenge, which focuses on the challenge of accurately matching patients with records and offers $1 million for the best solution, can serve as a model. Like security breaches, inaccurate matching annually creates millions of dollars in additional costs and harms patient safety. A patchwork of identification solutions have yielded at most 80 percent matching accuracy, even in our most sophisticated hospitals. Aiming for 100 percent accuracy, the CHIME challenge has lit a fire under at least 80 entrants across seven countries ranging from startups to large corporations to clinicians and even including credit bureaus.

Both the CHIME and Interoperability Pledge initiatives strive to harness the collective wisdom of a diverse community and maximize limited resources, including people, in a way that produces broadly beneficial results.

At some point in the near future, this kind of cross-industry collaboration on effective security systems, standards and strategies could be shared affordably with smaller hospitals and other providers that face ongoing resource challenges. In that aspect of dealing with burgeoning security threats, there is probably a role to play for everyone from the federal government to private industry to healthcare providers right down to the smallest critical access hospital in rural New Mexico.

That hackers are increasingly targeting healthcare clearly says something about the newfound maturity of the industry. That they are lured by the prospect of easy pickins says something as well. We can take a moment to dwell on the former, after which the latter demands all the energy we can spare.

Irv Lichtenwald is president and CEO of Medsphere Systems Corporation, the solution provider for the OpenVista electronic health record.