Benefits abound for healthcare organizations harnessing the Internet of Things (IoT), as do the implicit risks. After all, a dizzying array of connected devices provides more potential points of entry than ever for cybercriminals, whose thirst for sensitive patient data seems only to grow. As we have all recently experienced with the WannaCry ransomware attack, a simple virus with a potent payload, utilizing the end-users’ failure to patch older operating software, provides a fertile environment for blackhats to exploit.
Despite the growing focus on patient data security, breaches are on the rise. More HIPPA-covered healthcare organizations reported data breaches in 2016 than in any other year since the HHS began publishing its ‘Wall of Shame’ in 2009. Last year, the healthcare sector also experienced more large data breaches (those that affect 500 people at once) than ever. In fact, 2016 was the second worst year on record in terms of the sheer number of people whose records were breached.
The good news is that healthcare IT teams can take meaningful steps to turn the tide.
6 Musts for Protecting Sensitive Patient Data
Potential data breaches exist everywhere, from connected life-saving medical devices to EMRs. Below are six key strategies to consider in preventing them — and limiting damage if and when one occurs.
- Evaluate your IoT security posture regularly. The volume of mobile devices, wearables, and wireless equipment under your team’s care will only continue to grow, as technology and affordability converge to make truly connected care even more viable. To keep up with the fast-changing threat landscape, it is wise to constantly assess your program for vulnerabilities.
- Make Mobile Device Monitoring (MDM) a priority. MDM should be a priority for all mobile devices, including personal smart devices accessing Wi-Fi points within the medical institution, plus secured two-factor authentication for access externally via a virtual private network.
- Put protocols in place for device usage and monitoring. The more personal devices in use in a hospital, the more likely that essential firmware or malware updates will be neglected. It’s all too easy for an employee’s personal smartphone to become vulnerable to a data breach. Provide clear guidelines on how employees should use and update their devices.
- Monitor your wireless network airspace relentlessly. Whatever security solutions your organization adopts, one rule of thumb applies to all: monitor, monitor, monitor. Periodic airspace monitoring is not adequate for protecting patient data. Instead, implement a continuous monitoring solution so IT managers can quickly pinpoint and remediate rogue access points and unsecured WLAN connections that put your entire network at risk.
- Engage the C-suite. A strong security program doesn’t just need one champion — it needs many. You need champions in the highest levels of your organization to ensure data security is considered a core organizational objective. Personal accountability down to every end-user must be transparent, continuous, and ubiquitous.
- Understand the human element. In 2017, OCR data and other third-party studies found that insiders were the number one security threat in healthcare organizations. While some behavior is malicious, some estimates suggest that roughly two-thirds of attacks are a result of human error, such as employees falling for phishing scams, using misconfigured servers, or other unintended missteps. That’s why it’s vital to train all employees early and often in security tactics, and to provide regular check-ins and refresher security training.
From cloud security management to enterprise platform encryption and real-time backup, worthy security solutions are abundant. The patient data stream may be fraught with danger with the rise of the IoT, but with a rigorous IoT security strategy, you can keep your organization’s cyber-defenses up, and vulnerabilities down.
This piece is the second in a blog series written by Albert Villarin, MD, who serves as CMIO of Staten Island University Hospital (part of Northwell Health), and CMIO at Burwood Group. The first piece outlined the key benefits of connected care, and subsequent segments will focus on making data interoperable and facilitating adoption. To follow Burwood Group on Twitter, click here.