Please summarize this into one paragraph: The number one priority…

Question Answered step-by-step Please summarize this into one paragraph: The number one priority… Please summarize this into one paragraph: The number one priority for health care providers, by definition of the industry name, is to provide quality care to improve patient health. However, with the rise of cyberattacks and the exponential growth of technology and mobile/medical devices, health care providers also must focus on cybersecurity compliance, protection, and prevention. The health care industry has been the most highly targeted industry within the past several years, with more than 110 million health data records breached in 2015 alone. One may ask, why? The simple truth is that this industry is teeming with personally identifiable information (PII) embedded in protected health information (PHI), such as personal data and health records, and is increasingly integrating new technologies that cybercriminals can exploit with ease. The health care industry also has traditionally been behind the cybersecurity curve and focused on meeting compliance laws — electing to focus resources on patient care rather than taking the extra steps for implementing enterprise risk management strategies focused on proactive prevention and protection measures. Although this has been the trend, we are beginning to see a shift in focus from an operational standpoint as health care providers recognize the inevitability of cyber threats while adapting changes in technology and consumer expectations. MODERN CYBERSECURITY THREATS Due to the nature of the health care industry, cybercriminals can find new personal data targets and health records on a daily basis and attack them from multiple angles. This allows cybercriminals to have a full toolkit of resources at their disposal to infiltrate their targets. These tools include ransomware infections, business email compromise (BEC) scams, phishing and spearfishing attacks, and medical device contamination, just to name a few. Ed Cabrera is the Chief Cybersecurity Officer at Trend Micro. Journal of Health Care Compliance — September-October 2016 Health Care: Cyberattacks and How to Fight Back 28 Recent attacks on Hollywood Presbyterian Medical Center,1 Kentucky Methodist Hospital,2 and MedStar3 highlight what cybercriminals are capable of when infiltrating the operational side of health care institutions. These attacks utilized ransomware infections to extort organizations for monetary gains while others focus on gaining access to information through phishing and BEC attacks by targeting individual employees. In some extreme cases, cybercriminals also can use these threats to entirely stop operations and halt services for patients. Not as common, but just as feasible, are secondary attacks through mobile/medical devices. Though it may sound like science fiction, cybercriminals are capable of infiltrating wearables like step trackers to leapfrog into organizations’ networks. Taking the concept even further, some cybercriminals claim they can directly access pacemakers or morphine drips, which can result in dire health consequences or even fatalities. HEALTH CARE CYBERSECURITY SHIFT Cyber threats are no longer a small issue for health care providers like they have been in the past. More recently, threats have evolved into a major problem that unfortunately is seen as a common occurrence. Because of the growth, evolution, and almost routine occurrence of cyber threats, health care executives and organizations have acknowledged there needs to be a shift in how they deal with cybersecurity. Toward the end of 2015, we began to see this shift in cybersecurity protocols from simply meeting regulatory compliances to focusing on risk management via prevention and protection measures. Executives and organizations are putting more emphasis on organizational aspects, such as improvements in risk management, threat responses, and allocating additional budgetary funds for cybersecurity. This is not only to protect the company as a whole but also to protect patient privacy and PHI/PII data. This shift appears to be a holistic approach on behalf of organizations — tackling all the issues at hand during a cyberattack, from prevention and protection to containment and recovery. This is essential for combating cyber threats in the health care industry due to the vast range of threats as well as the increasing attack surface due to growing technology and integrating devices. CYBERSECURITY PRIORITIES Cybersecurity as a whole is an undertaking in and of itself, generally requiring substantial budgetary allocations or entire departments dedicated to maintain security. To tackle the initial stages of cybersecurity, it is best to develop a strategic plan and highlight the priorities organizations should focus on to achieve security success. According to the Healthcare Provider Breaches and Risk Management Road Maps survey conducted by the SANS Institute, the following are what health care providers and executives felt were the most important priorities when dealing with threats at an organizational infrastructure level, in descending order: 1. Respond quickly and efficiently to new threats: Health care providers desire agility when dealing with cyber threats. On average it takes minutes for most compromises, but it takes months or years to detect them. Improved response times through breach detection technology and procedures will cut down on cybercriminal dwell times and will allow security teams to manage and contain the threats they face. 2. Protect patient data: Health care providers hold patient PHI/PII data in high regard, as it is a primary target for criminals to steal and sell online for profit, or use for further financial exploitation. Therefore, they need to adapt security strategies from the inside that bring technical and operational security Journal of Health Care Compliance — September-October 2016 29 Health Care: Cyberattacks and How to Fight Back controls as close to the data as possible throughout its entire lifecycle. 3. Secure supporting infrastructure: Depending on how an organization’s system structure is set up will dictate the amount of security necessary for protection. Supporting infrastructure for information supply chains from third-party vendors provides additional avenues for cybercriminals to infiltrate and access information or infect the network. (i.e., application vulnerabilities, third-party network programs, customer service portals, et cetera). Establishing and adopting a cybersecurity framework internally that speeds up vulnerability and patch management is critical but even more so for third-party vendors. 4. Meet regulatory compliance standards: Compliance regulations have always been at the forefront for health care providers. Failing to meet regulation standards results in governmental fines and consequences, not to mention leaving systems open to attack due to inadequate security. While compliance is only the starting line in the race to secure data and critical systems, utilizing advanced security solutions that not only protect and prevent attacks but also generate real-time audit logs will get you closer to the finish line. 5. Classify sensitive data and create information defense strategies: Health care providers receive vast amounts of data and information that need to be sorted and stored correctly on internal systems. Cybercriminals are incredibly effective in mapping victim data and actively seek this concentrated information, so establishing defensive strategies to protect the data is essential for prevention and protection against threats. 6. Prevent and defend against ransomware, denial of service, and other commoditized attacks: Instituting preventative measures such as establishing a robust backup strategy greatly reduces the risk of extortion attacks. Additionally, adopting a connected threat defense strategy enables organizations to automate and orchestrate their layered defenses to protect critical data and operations. 7. Manage access authorization: Controlling who accesses an organization’s network is key to maintaining security. Implementing a robust role-based identity access management strategy that includes password admittance procedures, user access trackers, network segmentation, and encrypting network systems provides extra layers of security while also adding additional barriers for external malicious threats. Regulating access also helps prevent insider threats targeting intellectual property theft and/or destruction. 8. React to a data breach cycle, from initial breach to post-breach recovery: Health care providers need to have a full-length crisis management plan to deal with each stage of a data breach. This plan should have threat-driven playbooks that lay out the necessary steps to contain the threat, procedures for recovery, and alerting the victimized parties. 9. Attract, retain, and maintain skilled information security staff: Possibly the most important part of a connected threat defense strategy is having a skilled and trained information security staff. The vulnerabilities and threats that organizations face are far too dynamic and destructive not to invest heavily in recruiting, training, and maintaining top-tier cyber security professionals to secure health care providers’ networks. 10. Educate end-users on cyber threat awareness and prevention: Employees, vendors, and patients can all serve as gateways for cybercriminals when interacting with networks. Educating them on organizational procedures and personal initiatives for Journal of Health Care Compliance — September-October 2016 Health Care: Cyberattacks and How to Fight Back 30 security will benefit both the individual and the health care organization by limiting cybercriminal access. 11. Protect endpoints from unauthorized access: Endpoints on network systems are the preferred point of entry for all attackers as they are the main access point where users interact with critical data and systems. They are easily targeted through infected emails with malicious attachments or links and attacks from compromised Web servers serving up the latest exploit kit. Health care providers should install extra security measures on company endpoints and around user activity to prevent and protect against cyber threats. 12. Defend against medical device and Internet of Things risks and threats: Medical and mobile devices also can succumb to cyber threats, allowing criminals to leapfrog, or island-hop, into an organization’s network. Securing these devices is important but a much larger challenge as they often do not have security baked into their design. Instead, health care providers should strengthen their focus on network and cloud security, making it harder for cybercriminals to access systems using these indirect routes. 13. Improve application security: Program applications, third-party applications, and mobile device applications can give way to vulnerabilities exploited by cyber threats. To fight these vulnerabilities, health care providers should consistently update these applications with the latest manufacturer updates and security patches. While reports and news stories on data breaches continue to highlight the negative sides of health care cybersecurity, we are seeing that this internal industry shift shows promise of improvement. As health care providers pivot from meeting compliance to making risk prevention their priority, the subsequent results will lead to improvements in threat response, integrated technologies, onsite and digital networks, as well as patient PII and overall quality health care.  Arts & Humanities Writing ENGL/WRTG 112 Share QuestionEmailCopy link Comments (0)