Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Monday, February 5, 2018

Healthcare Industry Cybersecurity Task Force report- June 2017

Recently a report came out from the "Health Care Industry Cybersecurity Task Force".  This group was formed by Congress as part of the Cybersecurity Act of 2015.  The task force is made up of a diverse group from the healthcare industry, taking a look at the state of cybersecurity and how it can be improved.

You can read the report HERE.

At nearly 100 pages, it's a bit much to slog thru.  At a minimum, read over the executive summary.  As someone who works with healthcare clients, their findings are not a surprise to me.  They have a figure:


which points out some of this issues.  Lack of talent- yes.  Not that there is no talent, but that many orgs don't have enough people on board.  Smaller orgs can't afford to, sometimes outsourcing their IT to vendors who themselves may not have the right skills.  (it's one thing to go with a managed security service provider who hopefully knows healthcare, it's another to go with some local IT guys who has no idea of security or the issues facing healthcare)
Legacy equipment- wow.  yes.  Big problem as the vendors aren't supporting or updating these systems, and the orgs can't.  Most orgs don't understand that there are some solutions (isolated networks and the like) for this.  Over-connectivity ties back to lack of talent.  When you don't have people on board who can properly set things up, problems will arise.  Vulnerabilities impact- this is stuff like ransomware and the like hitting groups, which often was caused by not have the right talent in place to get things in a good shape.

Some of these actually interconnect.  Healthcare IT is behind everyone else.  Too many organizations have, for various reasons, not invested in IT.  This means they have not worked to get enough people on board with the right skills and given them the budget to setup things up well.

They define 6 imperatives:

  1. Define and streamline leadership, governance, and expectations for health care industry cybersecurity.
  2. Increase the security and resilience of medical devices and health IT.
  3. Develop the health care workforce capacity necessary to prioritize and ensure cybersecurity awareness and technical capabilities.
  4. Increase health care industry readiness through improved cybersecurity awareness and education.
  5. Identify mechanisms to protect research and development efforts and intellectual property from attacks or exposure.
  6. Improve information sharing of industry threats, weaknesses, and mitigations.
The report spends quite a bit of time on a variety of recommendations and action items off of these imperatives.

Check it out and add your comments.










Wednesday, February 22, 2017

Memorial Healthcare pays $5.5 million HIPAA settlement

Well, at this point hopefully those in the infosec field, especially in the healthcare arena, are aware of the recent settlement by Memorial Healthcare (Hollywood, Florida) for $5.5 million.  This was for violations of HIPAA that resulted in the protected health information (PHI) of over 100,000 individuals being potentially exposed.  While not the highest penalty, certainly up there.

You can read the whole press release HERE.  As well as the settlement agreement HERE which includes the corrective measures they must take.

For me, this is notable as Memorial Healthcare is one of the local hospital groups in my area.  Now, I have no connection with Memorial, I do NOT have any inside information on them.  All I know is what I have read in the above articles.

Friday, January 13, 2017

BSides Tampa 2017

I will be speaking at BSides Tampa 2017 this February.

The topic will be on "HIPAA for Security Professionals".  My aim is to introduce to security professionals what HIPAA is and what they need to know about it.  With the increased pressure on healthcare organizations and their third party vendors for information security, this is important.  Especially with HHS doing random audits going forward.

Hope to see many of you there.



Sunday, March 13, 2016

Resources for workshop on security standards/frameworks/regulations for information security professionals

At the 2016 Security BSides Orlando conference, I gave a workshop on security standards, frameworks, regulations for information security professionals.  While not an exhaustive survey of such, I focused on the ones that seem the most known, and which I typically see on job descriptions.

Not covered were enterprise architecture models like Zachman or TOGAF.  Left out are other security frameworks like SABSA or things like RESILIA, FedRAMP or Cloud Control Matrix, SSAE 16/SOC, Secure DevOps, or Maturity Models for security.

Covered were:
  • CIS CSC
  • NIST CSF (plus FFIEC CAT)
  • ISO/IEC 27001
  • FISMA
  • HIPAA
  • GLBA 
  • SOX (plus COSO)
  • PCI-DSS
  • COBIT 5
  • ITIL

Wednesday, June 26, 2013

SL Powers IT Security Lunch & Learn event

Tying in with my recent posting on getting involved with local security events, today I attending a "lunch and learn" event organized by one of our local IT services companies, SL Powers.   They apparently do these events in our local area about once a month, in different locations.  This one had two presentations, both were pretty good.

First up, we had Silka Gonzalez, President & CEO of Enterprise Risk Management, a local company focused on helping their clients with risk management and assessments.  She gave a good overview of some of the various regulatory compliance standards out there that many of us have to deal with:  GLBA, FACTA, SoX, HIPAA/HITECH, FERPA, FISMA, and PCI-DSS.  What I particularly liked was how she pointed out the similarities among many of these, and what are the basic underlining concepts that are common in all of them.

The second talk was by Tom Leffingwell of Juniper Networks.  Now, I have known Juniper as a competitor to Cisco in terms of networking equipment.  What I wasn't aware of was their work in the area of network security.  So it was good to learn more about what they do in this area.  As with these kinds of presentations, you run the risk of being more a sales pitch then a technical overview, and I think he did a good job of staying more technical then sales.

I will keep my eye out for further sessions like these.  SL Powers also has a series of sessions called "Tech on Tap", which also sounds interesting.

I found out about this event via Eventbrite.  If you aren't familiar with this site, check it out.  Great way to find out about events in your area, both free and fee.  As IT people, we need to keep up our skills, so attending these events have multiple benefits.