SlideShare a Scribd company logo
1 of 21
Download to read offline
1
Cybersecurity in Healthcare
Steven Goriah, DHA, CHCIO, FACHE, CISM
Vice President Information Technology
CISO
Westchester Medical Center Health Network
Cybersecurity in Healthcare
• 82 % of hospitals reported a significant security incidents in the
past 12 Months
• E-mail (e.g., phishing email) continues to be the most frequently
reported initial point of compromise (69%) n=166
• E-mail can contain a wealth of information, including sensitive
patient clinical and financial information
3
2019 HIMSS CYBERSECURITY SURVEY
LifeBridge Health
• The attack potentially breached the data of around 500,000 patients.
Health Management Concepts
• This ransomware attack fast became a full-blown data breach over
500,000 patients.
UnityPoint Health
• Two security breaches last year. The second compromised the data of
1.4 million patients.
4
Largest Healthcare Data Breaches of 2018
It’s all about Risk Management. Which is riskier?
“More people are killed every year by
pigs than by sharks, which shows you
how good we are at evaluating risk.”
How do we approach such a complex
situation for Healthcare?
6
What is the Role of a Framework?
• Provides a common language and systematic
methodology for managing cybersecurity risk.
• Includes activities to be incorporated in a
cybersecurity program that can be tailored to
meet any organization’s needs.
• Designed to complement, not replace, an
organization's cybersecurity program and risk
management processes.
7
• ISO 27000 Series
• CObIT 5
• NIST SP 800 Series
• HITRUST v9
Usable Cybersecurity Frameworks
(most popular of the more than 200 available)
8
HITURST
CSFcontains 149 security and privacy controls parsed
amongst 46 control objectives within 14 broad control
categories
9
Choose a Suitable Framework Wisely
Choose a Framework (one or more) –
The Only Bad Choice is No Choice!
10
High-level HITRUST and NIST CSF Comparison
HITRUST NIST
Purpose A scalable, prescriptive and certifiable
framework specific created in response to
multiple compliance requirements, many of
which are subject to interpretation
In response to the President’s Executive Order
13636, Improving Critical Infrastructure
Cybersecurity (2013). It’s a framework – based on
existing standards, guidelines, and practices - for
reducing cyber risks to critical infrastructure
Industry Healthcare-specific Applies broadly across multiple industries
Objective A framework that can be leveraged to
communicate, compare and benchmark
cybersecurity AND can be used for
certification
A framework that can be leveraged to
communicate, compare, and benchmark cyber
security
Illustrative
Sources
ISO, HIPAA, NIST, CMS, MARS-E, IRS, PCI,
CSA-CCM, state laws, etc.
COBIT, NIST, ISA, CCS, ISO, HIPAA (new)
11
HITRUST CSF and NIST CsF
• HITRUST CSF and NIST CsF
are complementary
frameworks
• While an organization can
leverage either frameworks
on its own, there is value in
• Leveraging HITRUST as the HPH
standard and
• Using the NIST CsF being the
mechanism to communicate
maturity and comparison
between industries
12
13
Comparison of ISO, NIST, and HITRUST
Footnotes on next page (published by HITRUST in 2014)
Implementation Advice
• Allow for flexibility in implementation and bring in concepts of
maturity models
• Reflect how your organization will implement core functions and
manage its risk
• Be progressive, building on previous tiers
• Define the characteristics at the organization level and determine
how a category will be implemented
14
Get the Board Involved
• Audit and Compliance Committee
• IT Subcommittee of the Board
• Finance Committee
15
but not too involved…
Keep the Reporting Simple But Consistent…
• Use terms that Board members can understand
• Should be easy enough to understand without explanations
• Provide the explanations
• Propose a model and get the Chair’s endorsement
• Use terms broad enough to accommodate evolving needs
• Avoid the temptation to change
• Use graphs and iconography that work in color and black & white
16
• Communicate, but test for comprehension at every step with every
stakeholder group
• Plan and ADJUST
• Clarify Roles and ADJUST
• Eliminate Ambiguity and ADJUST
• Embrace Accountability
• Execute and ADJUST
• Continue Praying
Be Deliberate
17
and ADJUST
Individual/Body CIO CMIO ISGC
Task
Support Implementation of EHR R A I
Engage physicians in information system selection/development A R C
Manage vendors R C I
Negotiate contracts R C I
Design clinical systems/review clinical processes C R I
Build clinical systems/change workflow processes R C I
Test clinical systems/workflow changes R C I
Validate (testing with users) clinical systems/workflow changes C R I
Develop training curriculum (design education tools and content) I R I
Deploy training (deliver education) R C I
Select end-user devices C R I
Govern Information Management activities A C R
Participate in Executive Leadership R I C
Report to the Institutional Board R C I
Participate in HIE activities C C R
Responsible for performance of task
Assists responsible person, may do bulk of work
Consulted - opinions are sought
Informed - kept up-to-date on progress
RACI Matrix for CIO, CMIO, and IS Governance Council (ISGC)
mm/dd/yyyy
Role Clarification and Responsibility is
Essential – RACI Diagram
18
• Many positive advances are occurring in healthcare cybersecurity
practices.
• Cybersecurity professionals have more resources and budget
available to help ensure that their organizations stay ahead of the
threats.
• Cybersecurity professionals feel empowered to drive change in
healthcare organizations
19
2019 HIMSS CYBERSECURITY SURVEY
20
It’s critical to create a culture of privacy and security.
Thank You!
21

More Related Content

What's hot

Information Security Awareness Training
Information Security Awareness TrainingInformation Security Awareness Training
Information Security Awareness Training
Randy Bowman
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
PECB
 

What's hot (20)

Information Security Awareness
Information Security Awareness Information Security Awareness
Information Security Awareness
 
Information Security Awareness Training
Information Security Awareness TrainingInformation Security Awareness Training
Information Security Awareness Training
 
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
 
Introduction to Cybersecurity
Introduction to CybersecurityIntroduction to Cybersecurity
Introduction to Cybersecurity
 
Tcs cybersecurity for healthcare
Tcs cybersecurity for healthcareTcs cybersecurity for healthcare
Tcs cybersecurity for healthcare
 
Cyber Security and Healthcare
Cyber Security and HealthcareCyber Security and Healthcare
Cyber Security and Healthcare
 
SOC presentation- Building a Security Operations Center
SOC presentation- Building a Security Operations CenterSOC presentation- Building a Security Operations Center
SOC presentation- Building a Security Operations Center
 
Cybersecurity Employee Training
Cybersecurity Employee TrainingCybersecurity Employee Training
Cybersecurity Employee Training
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
 
Security operation center (SOC)
Security operation center (SOC)Security operation center (SOC)
Security operation center (SOC)
 
How to assess and manage cyber risk
How to assess and manage cyber riskHow to assess and manage cyber risk
How to assess and manage cyber risk
 
Cybersecurity: Cyber Risk Management for Banks & Financial Institutions
Cybersecurity: Cyber Risk Management for Banks & Financial InstitutionsCybersecurity: Cyber Risk Management for Banks & Financial Institutions
Cybersecurity: Cyber Risk Management for Banks & Financial Institutions
 
Cyber Security Awareness
Cyber Security AwarenessCyber Security Awareness
Cyber Security Awareness
 
IT Security Awareness-v1.7.ppt
IT Security Awareness-v1.7.pptIT Security Awareness-v1.7.ppt
IT Security Awareness-v1.7.ppt
 
End User Security Awareness Presentation
End User Security Awareness PresentationEnd User Security Awareness Presentation
End User Security Awareness Presentation
 
IT Infrastrucutre Security
IT Infrastrucutre SecurityIT Infrastrucutre Security
IT Infrastrucutre Security
 
ISO 27001
ISO 27001ISO 27001
ISO 27001
 
What is cyber security
What is cyber securityWhat is cyber security
What is cyber security
 
SOC Cyber Security
SOC Cyber SecuritySOC Cyber Security
SOC Cyber Security
 
Security Awareness Training
Security Awareness TrainingSecurity Awareness Training
Security Awareness Training
 

Similar to Tech Refresh - Cybersecurity in Healthcare

UoF - HITRUST & Risk Analysis v1
UoF - HITRUST & Risk Analysis v1UoF - HITRUST & Risk Analysis v1
UoF - HITRUST & Risk Analysis v1
Bryan Cline, Ph.D.
 
PSQH July-Aug 2015 Simplified ST Model - Woods-Pestotnik
PSQH July-Aug 2015 Simplified ST Model - Woods-PestotnikPSQH July-Aug 2015 Simplified ST Model - Woods-Pestotnik
PSQH July-Aug 2015 Simplified ST Model - Woods-Pestotnik
Michael Woods, MD, MMM
 
BME 307 - HMIS - Data Management Systems 24112021 Final.pdf
BME 307 - HMIS - Data Management Systems 24112021 Final.pdfBME 307 - HMIS - Data Management Systems 24112021 Final.pdf
BME 307 - HMIS - Data Management Systems 24112021 Final.pdf
edwardlowassa1
 
Direct Project HIT Standards 10.27
Direct Project HIT Standards 10.27Direct Project HIT Standards 10.27
Direct Project HIT Standards 10.27
Brian Ahier
 
Choosing an Analytics Solution in Healthcare
Choosing an Analytics Solution in HealthcareChoosing an Analytics Solution in Healthcare
Choosing an Analytics Solution in Healthcare
Dale Sanders
 
HIPAA Compliance: Simple Steps to the Healthcare Cloud
HIPAA Compliance: Simple Steps to the Healthcare CloudHIPAA Compliance: Simple Steps to the Healthcare Cloud
HIPAA Compliance: Simple Steps to the Healthcare Cloud
Hostway|HOSTING
 

Similar to Tech Refresh - Cybersecurity in Healthcare (20)

UoF - HITRUST & Risk Analysis v1
UoF - HITRUST & Risk Analysis v1UoF - HITRUST & Risk Analysis v1
UoF - HITRUST & Risk Analysis v1
 
City of hope research informatics common data elements
City of hope research informatics common data elementsCity of hope research informatics common data elements
City of hope research informatics common data elements
 
The Data Operating System: Changing the Digital Trajectory of Healthcare
The Data Operating System: Changing the Digital Trajectory of HealthcareThe Data Operating System: Changing the Digital Trajectory of Healthcare
The Data Operating System: Changing the Digital Trajectory of Healthcare
 
The Data Operating System: Changing the Digital Trajectory of Healthcare
The Data Operating System: Changing the Digital Trajectory of HealthcareThe Data Operating System: Changing the Digital Trajectory of Healthcare
The Data Operating System: Changing the Digital Trajectory of Healthcare
 
Data Is the New Strategic Asset in M&As: Is Ripping and Replacing EHRs Really...
Data Is the New Strategic Asset in M&As: Is Ripping and Replacing EHRs Really...Data Is the New Strategic Asset in M&As: Is Ripping and Replacing EHRs Really...
Data Is the New Strategic Asset in M&As: Is Ripping and Replacing EHRs Really...
 
PSQH July-Aug 2015 Simplified ST Model - Woods-Pestotnik
PSQH July-Aug 2015 Simplified ST Model - Woods-PestotnikPSQH July-Aug 2015 Simplified ST Model - Woods-Pestotnik
PSQH July-Aug 2015 Simplified ST Model - Woods-Pestotnik
 
AI and the Future of Clinical Research - CDISC 2020 US Interchange
AI and the Future of Clinical Research - CDISC 2020 US InterchangeAI and the Future of Clinical Research - CDISC 2020 US Interchange
AI and the Future of Clinical Research - CDISC 2020 US Interchange
 
BME 307 - HMIS - Data Management Systems 24112021 Final.pdf
BME 307 - HMIS - Data Management Systems 24112021 Final.pdfBME 307 - HMIS - Data Management Systems 24112021 Final.pdf
BME 307 - HMIS - Data Management Systems 24112021 Final.pdf
 
Microsoft: A Waking Giant in Healthcare Analytics and Big Data
Microsoft: A Waking Giant in Healthcare Analytics and Big DataMicrosoft: A Waking Giant in Healthcare Analytics and Big Data
Microsoft: A Waking Giant in Healthcare Analytics and Big Data
 
Moving to the Cloud: Modernizing Data Architecture in Healthcare
Moving to the Cloud: Modernizing Data Architecture in HealthcareMoving to the Cloud: Modernizing Data Architecture in Healthcare
Moving to the Cloud: Modernizing Data Architecture in Healthcare
 
Direct Project HIT Standards 10.27
Direct Project HIT Standards 10.27Direct Project HIT Standards 10.27
Direct Project HIT Standards 10.27
 
Meet Your Interoperability Goals and Realize Your Vision
Meet Your Interoperability Goals and Realize Your VisionMeet Your Interoperability Goals and Realize Your Vision
Meet Your Interoperability Goals and Realize Your Vision
 
CHIME LEAD Fourm Houston - "Case Studies from the Field: Putting Cyber Securi...
CHIME LEAD Fourm Houston - "Case Studies from the Field: Putting Cyber Securi...CHIME LEAD Fourm Houston - "Case Studies from the Field: Putting Cyber Securi...
CHIME LEAD Fourm Houston - "Case Studies from the Field: Putting Cyber Securi...
 
Mergers, acquisitions, and partnerships dramatically reducing it consolidati...
Mergers, acquisitions, and partnerships  dramatically reducing it consolidati...Mergers, acquisitions, and partnerships  dramatically reducing it consolidati...
Mergers, acquisitions, and partnerships dramatically reducing it consolidati...
 
Cyb 690 cybersecurity program template directions the foll
Cyb 690 cybersecurity program template directions the follCyb 690 cybersecurity program template directions the foll
Cyb 690 cybersecurity program template directions the foll
 
Closing-the-gap-meeting-acute-workforce-needs-in-healthcare-cyber security-an...
Closing-the-gap-meeting-acute-workforce-needs-in-healthcare-cyber security-an...Closing-the-gap-meeting-acute-workforce-needs-in-healthcare-cyber security-an...
Closing-the-gap-meeting-acute-workforce-needs-in-healthcare-cyber security-an...
 
Choosing an Analytics Solution in Healthcare
Choosing an Analytics Solution in HealthcareChoosing an Analytics Solution in Healthcare
Choosing an Analytics Solution in Healthcare
 
Health IT Summit Beverly Hills 2014 – “A Use Case…Thoughts on How to Leverage...
Health IT Summit Beverly Hills 2014 – “A Use Case…Thoughts on How to Leverage...Health IT Summit Beverly Hills 2014 – “A Use Case…Thoughts on How to Leverage...
Health IT Summit Beverly Hills 2014 – “A Use Case…Thoughts on How to Leverage...
 
Cloud Cybersecurity: Strategies for Managing Vendor Risk
Cloud Cybersecurity: Strategies for Managing Vendor RiskCloud Cybersecurity: Strategies for Managing Vendor Risk
Cloud Cybersecurity: Strategies for Managing Vendor Risk
 
HIPAA Compliance: Simple Steps to the Healthcare Cloud
HIPAA Compliance: Simple Steps to the Healthcare CloudHIPAA Compliance: Simple Steps to the Healthcare Cloud
HIPAA Compliance: Simple Steps to the Healthcare Cloud
 

More from CompTIA

More from CompTIA (20)

CompTIA IT Employment Tracker – December 2021
CompTIA IT Employment Tracker –  December 2021CompTIA IT Employment Tracker –  December 2021
CompTIA IT Employment Tracker – December 2021
 
CompTIA IT Employment Tracker – November 2021
CompTIA IT Employment Tracker –  November 2021CompTIA IT Employment Tracker –  November 2021
CompTIA IT Employment Tracker – November 2021
 
CompTIA IT Employment Tracker – October 2021
CompTIA IT Employment Tracker –  October 2021CompTIA IT Employment Tracker –  October 2021
CompTIA IT Employment Tracker – October 2021
 
CompTIA IT Employment Tracker – September 2021
CompTIA IT Employment Tracker –  September 2021CompTIA IT Employment Tracker –  September 2021
CompTIA IT Employment Tracker – September 2021
 
CompTIA IT Employment Tracker – July 2021
CompTIA IT Employment Tracker –  July 2021CompTIA IT Employment Tracker –  July 2021
CompTIA IT Employment Tracker – July 2021
 
CompTIA IT Employment Tracker – June 2021
CompTIA IT Employment Tracker –  June 2021CompTIA IT Employment Tracker –  June 2021
CompTIA IT Employment Tracker – June 2021
 
Trends in Automation 2021
Trends in Automation 2021Trends in Automation 2021
Trends in Automation 2021
 
CompTIA IT Employment Tracker – May 2021
CompTIA IT Employment Tracker –  May 2021CompTIA IT Employment Tracker –  May 2021
CompTIA IT Employment Tracker – May 2021
 
CompTIA IT Employment Tracker – April 2021
CompTIA IT Employment Tracker –  April 2021CompTIA IT Employment Tracker –  April 2021
CompTIA IT Employment Tracker – April 2021
 
IT Operations and Emerging Technology
IT Operations and Emerging TechnologyIT Operations and Emerging Technology
IT Operations and Emerging Technology
 
CompTIA IT Employment Tracker – March 2021
CompTIA IT Employment Tracker – March 2021CompTIA IT Employment Tracker – March 2021
CompTIA IT Employment Tracker – March 2021
 
Help Desk Trends
Help Desk TrendsHelp Desk Trends
Help Desk Trends
 
CompTIA IT Employment Tracker – February 2021
CompTIA IT Employment Tracker –  February 2021CompTIA IT Employment Tracker –  February 2021
CompTIA IT Employment Tracker – February 2021
 
CompTIA 2021 IT Industry Outlook
CompTIA 2021 IT Industry OutlookCompTIA 2021 IT Industry Outlook
CompTIA 2021 IT Industry Outlook
 
CompTIA IT Employment Tracker - January 2021
CompTIA IT Employment Tracker - January 2021CompTIA IT Employment Tracker - January 2021
CompTIA IT Employment Tracker - January 2021
 
CompTIA IT Employment Tracker – November 2020
CompTIA IT Employment Tracker –  November 2020CompTIA IT Employment Tracker –  November 2020
CompTIA IT Employment Tracker – November 2020
 
CompTIA IT Employment Tracker – October 2020
CompTIA IT Employment Tracker – October 2020CompTIA IT Employment Tracker – October 2020
CompTIA IT Employment Tracker – October 2020
 
CompTIA IT Employment Tracker – September 2020
CompTIA IT Employment Tracker –  September 2020CompTIA IT Employment Tracker –  September 2020
CompTIA IT Employment Tracker – September 2020
 
CompTIA IT Employment Tracker – August 2020
CompTIA IT Employment Tracker –  August 2020CompTIA IT Employment Tracker –  August 2020
CompTIA IT Employment Tracker – August 2020
 
CompTIA IT Employment Tracker – July 2020
CompTIA IT Employment Tracker –  July 2020CompTIA IT Employment Tracker –  July 2020
CompTIA IT Employment Tracker – July 2020
 

Recently uploaded

Low Rate Call Girls Nagpur {9xx000xx09} ❤️VVIP NISHA Call Girls in Nagpur Mah...
Low Rate Call Girls Nagpur {9xx000xx09} ❤️VVIP NISHA Call Girls in Nagpur Mah...Low Rate Call Girls Nagpur {9xx000xx09} ❤️VVIP NISHA Call Girls in Nagpur Mah...
Low Rate Call Girls Nagpur {9xx000xx09} ❤️VVIP NISHA Call Girls in Nagpur Mah...
Sheetaleventcompany
 
Call Girl Service In Mumbai ❤️🍑 9xx000xx09 👄🫦Independent Escort Service Mumba...
Call Girl Service In Mumbai ❤️🍑 9xx000xx09 👄🫦Independent Escort Service Mumba...Call Girl Service In Mumbai ❤️🍑 9xx000xx09 👄🫦Independent Escort Service Mumba...
Call Girl Service In Mumbai ❤️🍑 9xx000xx09 👄🫦Independent Escort Service Mumba...
Sheetaleventcompany
 
Call Girls In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indo...
Call Girls In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indo...Call Girls In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indo...
Call Girls In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indo...
Sheetaleventcompany
 
Independent Call Girls Bangalore {7304373326} ❤️VVIP POOJA Call Girls in Bang...
Independent Call Girls Bangalore {7304373326} ❤️VVIP POOJA Call Girls in Bang...Independent Call Girls Bangalore {7304373326} ❤️VVIP POOJA Call Girls in Bang...
Independent Call Girls Bangalore {7304373326} ❤️VVIP POOJA Call Girls in Bang...
Sheetaleventcompany
 
Low Rate Call Girls Udaipur {9xx000xx09} ❤️VVIP NISHA CCall Girls in Udaipur ...
Low Rate Call Girls Udaipur {9xx000xx09} ❤️VVIP NISHA CCall Girls in Udaipur ...Low Rate Call Girls Udaipur {9xx000xx09} ❤️VVIP NISHA CCall Girls in Udaipur ...
Low Rate Call Girls Udaipur {9xx000xx09} ❤️VVIP NISHA CCall Girls in Udaipur ...
Sheetaleventcompany
 
🍑👄Ludhiana Escorts Service☎️98157-77685🍑👄 Call Girl service in Ludhiana☎️Ludh...
🍑👄Ludhiana Escorts Service☎️98157-77685🍑👄 Call Girl service in Ludhiana☎️Ludh...🍑👄Ludhiana Escorts Service☎️98157-77685🍑👄 Call Girl service in Ludhiana☎️Ludh...
🍑👄Ludhiana Escorts Service☎️98157-77685🍑👄 Call Girl service in Ludhiana☎️Ludh...
dilpreetentertainmen
 
Delhi Call Girl Service 📞8650700400📞Just Call Divya📲 Call Girl In Delhi No💰Ad...
Delhi Call Girl Service 📞8650700400📞Just Call Divya📲 Call Girl In Delhi No💰Ad...Delhi Call Girl Service 📞8650700400📞Just Call Divya📲 Call Girl In Delhi No💰Ad...
Delhi Call Girl Service 📞8650700400📞Just Call Divya📲 Call Girl In Delhi No💰Ad...
Sheetaleventcompany
 
❤️ Zirakpur Call Girl Service ☎️9878799926☎️ Call Girl service in Zirakpur ☎...
❤️ Zirakpur Call Girl Service  ☎️9878799926☎️ Call Girl service in Zirakpur ☎...❤️ Zirakpur Call Girl Service  ☎️9878799926☎️ Call Girl service in Zirakpur ☎...
❤️ Zirakpur Call Girl Service ☎️9878799926☎️ Call Girl service in Zirakpur ☎...
daljeetkaur2026
 
Premium Call Girls Bangalore {9179660964} ❤️VVIP POOJA Call Girls in Bangalor...
Premium Call Girls Bangalore {9179660964} ❤️VVIP POOJA Call Girls in Bangalor...Premium Call Girls Bangalore {9179660964} ❤️VVIP POOJA Call Girls in Bangalor...
Premium Call Girls Bangalore {9179660964} ❤️VVIP POOJA Call Girls in Bangalor...
Sheetaleventcompany
 
Call Girl In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indor...
Call Girl In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indor...Call Girl In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indor...
Call Girl In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indor...
Sheetaleventcompany
 
💚 Low Rate Call Girls In Chandigarh 💯Lucky 📲🔝8868886958🔝Call Girl In Chandig...
💚 Low Rate  Call Girls In Chandigarh 💯Lucky 📲🔝8868886958🔝Call Girl In Chandig...💚 Low Rate  Call Girls In Chandigarh 💯Lucky 📲🔝8868886958🔝Call Girl In Chandig...
💚 Low Rate Call Girls In Chandigarh 💯Lucky 📲🔝8868886958🔝Call Girl In Chandig...
Sheetaleventcompany
 

Recently uploaded (20)

Low Rate Call Girls Nagpur {9xx000xx09} ❤️VVIP NISHA Call Girls in Nagpur Mah...
Low Rate Call Girls Nagpur {9xx000xx09} ❤️VVIP NISHA Call Girls in Nagpur Mah...Low Rate Call Girls Nagpur {9xx000xx09} ❤️VVIP NISHA Call Girls in Nagpur Mah...
Low Rate Call Girls Nagpur {9xx000xx09} ❤️VVIP NISHA Call Girls in Nagpur Mah...
 
Ulhasnagar Call girl escort *88638//40496* Call me monika call girls 24*
Ulhasnagar Call girl escort *88638//40496* Call me monika call girls 24*Ulhasnagar Call girl escort *88638//40496* Call me monika call girls 24*
Ulhasnagar Call girl escort *88638//40496* Call me monika call girls 24*
 
Independent Call Girls Service Chandigarh | 8868886958 | Call Girl Service Nu...
Independent Call Girls Service Chandigarh | 8868886958 | Call Girl Service Nu...Independent Call Girls Service Chandigarh | 8868886958 | Call Girl Service Nu...
Independent Call Girls Service Chandigarh | 8868886958 | Call Girl Service Nu...
 
Call Girl Service In Mumbai ❤️🍑 9xx000xx09 👄🫦Independent Escort Service Mumba...
Call Girl Service In Mumbai ❤️🍑 9xx000xx09 👄🫦Independent Escort Service Mumba...Call Girl Service In Mumbai ❤️🍑 9xx000xx09 👄🫦Independent Escort Service Mumba...
Call Girl Service In Mumbai ❤️🍑 9xx000xx09 👄🫦Independent Escort Service Mumba...
 
Call Girls In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indo...
Call Girls In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indo...Call Girls In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indo...
Call Girls In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indo...
 
💸Cash Payment No Advance Call Girls Kanpur 🧿 9332606886 🧿 High Class Call Gir...
💸Cash Payment No Advance Call Girls Kanpur 🧿 9332606886 🧿 High Class Call Gir...💸Cash Payment No Advance Call Girls Kanpur 🧿 9332606886 🧿 High Class Call Gir...
💸Cash Payment No Advance Call Girls Kanpur 🧿 9332606886 🧿 High Class Call Gir...
 
Independent Call Girls Bangalore {7304373326} ❤️VVIP POOJA Call Girls in Bang...
Independent Call Girls Bangalore {7304373326} ❤️VVIP POOJA Call Girls in Bang...Independent Call Girls Bangalore {7304373326} ❤️VVIP POOJA Call Girls in Bang...
Independent Call Girls Bangalore {7304373326} ❤️VVIP POOJA Call Girls in Bang...
 
Low Rate Call Girls Udaipur {9xx000xx09} ❤️VVIP NISHA CCall Girls in Udaipur ...
Low Rate Call Girls Udaipur {9xx000xx09} ❤️VVIP NISHA CCall Girls in Udaipur ...Low Rate Call Girls Udaipur {9xx000xx09} ❤️VVIP NISHA CCall Girls in Udaipur ...
Low Rate Call Girls Udaipur {9xx000xx09} ❤️VVIP NISHA CCall Girls in Udaipur ...
 
❤️Amritsar Escort Service☎️9815674956☎️ Call Girl service in Amritsar☎️ Amrit...
❤️Amritsar Escort Service☎️9815674956☎️ Call Girl service in Amritsar☎️ Amrit...❤️Amritsar Escort Service☎️9815674956☎️ Call Girl service in Amritsar☎️ Amrit...
❤️Amritsar Escort Service☎️9815674956☎️ Call Girl service in Amritsar☎️ Amrit...
 
2024 PCP #IMPerative Updates in Rheumatology
2024 PCP #IMPerative Updates in Rheumatology2024 PCP #IMPerative Updates in Rheumatology
2024 PCP #IMPerative Updates in Rheumatology
 
❤️Amritsar Call Girls Service☎️98151-129OO☎️ Call Girl service in Amritsar☎️ ...
❤️Amritsar Call Girls Service☎️98151-129OO☎️ Call Girl service in Amritsar☎️ ...❤️Amritsar Call Girls Service☎️98151-129OO☎️ Call Girl service in Amritsar☎️ ...
❤️Amritsar Call Girls Service☎️98151-129OO☎️ Call Girl service in Amritsar☎️ ...
 
🍑👄Ludhiana Escorts Service☎️98157-77685🍑👄 Call Girl service in Ludhiana☎️Ludh...
🍑👄Ludhiana Escorts Service☎️98157-77685🍑👄 Call Girl service in Ludhiana☎️Ludh...🍑👄Ludhiana Escorts Service☎️98157-77685🍑👄 Call Girl service in Ludhiana☎️Ludh...
🍑👄Ludhiana Escorts Service☎️98157-77685🍑👄 Call Girl service in Ludhiana☎️Ludh...
 
Delhi Call Girl Service 📞8650700400📞Just Call Divya📲 Call Girl In Delhi No💰Ad...
Delhi Call Girl Service 📞8650700400📞Just Call Divya📲 Call Girl In Delhi No💰Ad...Delhi Call Girl Service 📞8650700400📞Just Call Divya📲 Call Girl In Delhi No💰Ad...
Delhi Call Girl Service 📞8650700400📞Just Call Divya📲 Call Girl In Delhi No💰Ad...
 
❤️Call Girl In Chandigarh☎️9814379184☎️ Call Girl service in Chandigarh☎️ Cha...
❤️Call Girl In Chandigarh☎️9814379184☎️ Call Girl service in Chandigarh☎️ Cha...❤️Call Girl In Chandigarh☎️9814379184☎️ Call Girl service in Chandigarh☎️ Cha...
❤️Call Girl In Chandigarh☎️9814379184☎️ Call Girl service in Chandigarh☎️ Cha...
 
❤️ Zirakpur Call Girl Service ☎️9878799926☎️ Call Girl service in Zirakpur ☎...
❤️ Zirakpur Call Girl Service  ☎️9878799926☎️ Call Girl service in Zirakpur ☎...❤️ Zirakpur Call Girl Service  ☎️9878799926☎️ Call Girl service in Zirakpur ☎...
❤️ Zirakpur Call Girl Service ☎️9878799926☎️ Call Girl service in Zirakpur ☎...
 
Premium Call Girls Bangalore {9179660964} ❤️VVIP POOJA Call Girls in Bangalor...
Premium Call Girls Bangalore {9179660964} ❤️VVIP POOJA Call Girls in Bangalor...Premium Call Girls Bangalore {9179660964} ❤️VVIP POOJA Call Girls in Bangalor...
Premium Call Girls Bangalore {9179660964} ❤️VVIP POOJA Call Girls in Bangalor...
 
Call Girl In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indor...
Call Girl In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indor...Call Girl In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indor...
Call Girl In Indore 📞9235973566📞Just Call Inaaya📲 Call Girls Service In Indor...
 
❤️ Call Girls service In Panchkula☎️9815457724☎️ Call Girl service in Panchku...
❤️ Call Girls service In Panchkula☎️9815457724☎️ Call Girl service in Panchku...❤️ Call Girls service In Panchkula☎️9815457724☎️ Call Girl service in Panchku...
❤️ Call Girls service In Panchkula☎️9815457724☎️ Call Girl service in Panchku...
 
💚 Low Rate Call Girls In Chandigarh 💯Lucky 📲🔝8868886958🔝Call Girl In Chandig...
💚 Low Rate  Call Girls In Chandigarh 💯Lucky 📲🔝8868886958🔝Call Girl In Chandig...💚 Low Rate  Call Girls In Chandigarh 💯Lucky 📲🔝8868886958🔝Call Girl In Chandig...
💚 Low Rate Call Girls In Chandigarh 💯Lucky 📲🔝8868886958🔝Call Girl In Chandig...
 
Call Now ☎ 8868886958 || Call Girls in Chandigarh Escort Service Chandigarh
Call Now ☎ 8868886958 || Call Girls in Chandigarh Escort Service ChandigarhCall Now ☎ 8868886958 || Call Girls in Chandigarh Escort Service Chandigarh
Call Now ☎ 8868886958 || Call Girls in Chandigarh Escort Service Chandigarh
 

Tech Refresh - Cybersecurity in Healthcare

  • 1. 1 Cybersecurity in Healthcare Steven Goriah, DHA, CHCIO, FACHE, CISM Vice President Information Technology CISO Westchester Medical Center Health Network
  • 3. • 82 % of hospitals reported a significant security incidents in the past 12 Months • E-mail (e.g., phishing email) continues to be the most frequently reported initial point of compromise (69%) n=166 • E-mail can contain a wealth of information, including sensitive patient clinical and financial information 3 2019 HIMSS CYBERSECURITY SURVEY
  • 4. LifeBridge Health • The attack potentially breached the data of around 500,000 patients. Health Management Concepts • This ransomware attack fast became a full-blown data breach over 500,000 patients. UnityPoint Health • Two security breaches last year. The second compromised the data of 1.4 million patients. 4 Largest Healthcare Data Breaches of 2018
  • 5. It’s all about Risk Management. Which is riskier? “More people are killed every year by pigs than by sharks, which shows you how good we are at evaluating risk.”
  • 6. How do we approach such a complex situation for Healthcare? 6
  • 7. What is the Role of a Framework? • Provides a common language and systematic methodology for managing cybersecurity risk. • Includes activities to be incorporated in a cybersecurity program that can be tailored to meet any organization’s needs. • Designed to complement, not replace, an organization's cybersecurity program and risk management processes. 7
  • 8. • ISO 27000 Series • CObIT 5 • NIST SP 800 Series • HITRUST v9 Usable Cybersecurity Frameworks (most popular of the more than 200 available) 8 HITURST CSFcontains 149 security and privacy controls parsed amongst 46 control objectives within 14 broad control categories
  • 9. 9 Choose a Suitable Framework Wisely
  • 10. Choose a Framework (one or more) – The Only Bad Choice is No Choice! 10
  • 11. High-level HITRUST and NIST CSF Comparison HITRUST NIST Purpose A scalable, prescriptive and certifiable framework specific created in response to multiple compliance requirements, many of which are subject to interpretation In response to the President’s Executive Order 13636, Improving Critical Infrastructure Cybersecurity (2013). It’s a framework – based on existing standards, guidelines, and practices - for reducing cyber risks to critical infrastructure Industry Healthcare-specific Applies broadly across multiple industries Objective A framework that can be leveraged to communicate, compare and benchmark cybersecurity AND can be used for certification A framework that can be leveraged to communicate, compare, and benchmark cyber security Illustrative Sources ISO, HIPAA, NIST, CMS, MARS-E, IRS, PCI, CSA-CCM, state laws, etc. COBIT, NIST, ISA, CCS, ISO, HIPAA (new) 11
  • 12. HITRUST CSF and NIST CsF • HITRUST CSF and NIST CsF are complementary frameworks • While an organization can leverage either frameworks on its own, there is value in • Leveraging HITRUST as the HPH standard and • Using the NIST CsF being the mechanism to communicate maturity and comparison between industries 12
  • 13. 13 Comparison of ISO, NIST, and HITRUST Footnotes on next page (published by HITRUST in 2014)
  • 14. Implementation Advice • Allow for flexibility in implementation and bring in concepts of maturity models • Reflect how your organization will implement core functions and manage its risk • Be progressive, building on previous tiers • Define the characteristics at the organization level and determine how a category will be implemented 14
  • 15. Get the Board Involved • Audit and Compliance Committee • IT Subcommittee of the Board • Finance Committee 15 but not too involved…
  • 16. Keep the Reporting Simple But Consistent… • Use terms that Board members can understand • Should be easy enough to understand without explanations • Provide the explanations • Propose a model and get the Chair’s endorsement • Use terms broad enough to accommodate evolving needs • Avoid the temptation to change • Use graphs and iconography that work in color and black & white 16
  • 17. • Communicate, but test for comprehension at every step with every stakeholder group • Plan and ADJUST • Clarify Roles and ADJUST • Eliminate Ambiguity and ADJUST • Embrace Accountability • Execute and ADJUST • Continue Praying Be Deliberate 17 and ADJUST
  • 18. Individual/Body CIO CMIO ISGC Task Support Implementation of EHR R A I Engage physicians in information system selection/development A R C Manage vendors R C I Negotiate contracts R C I Design clinical systems/review clinical processes C R I Build clinical systems/change workflow processes R C I Test clinical systems/workflow changes R C I Validate (testing with users) clinical systems/workflow changes C R I Develop training curriculum (design education tools and content) I R I Deploy training (deliver education) R C I Select end-user devices C R I Govern Information Management activities A C R Participate in Executive Leadership R I C Report to the Institutional Board R C I Participate in HIE activities C C R Responsible for performance of task Assists responsible person, may do bulk of work Consulted - opinions are sought Informed - kept up-to-date on progress RACI Matrix for CIO, CMIO, and IS Governance Council (ISGC) mm/dd/yyyy Role Clarification and Responsibility is Essential – RACI Diagram 18
  • 19. • Many positive advances are occurring in healthcare cybersecurity practices. • Cybersecurity professionals have more resources and budget available to help ensure that their organizations stay ahead of the threats. • Cybersecurity professionals feel empowered to drive change in healthcare organizations 19 2019 HIMSS CYBERSECURITY SURVEY
  • 20. 20 It’s critical to create a culture of privacy and security.