web analytics

Cybersecurity Support for Rural Hospitals – Source: www.databreachtoday.com

Rate this post

Source: www.databreachtoday.com – Author: 1

Governance & Risk Management
,
Healthcare
,
Healthcare Information Exchange (HIE)

A Former CISO’s Perspective on What Is Needed

Jackie Mattingly, CHPS, HCISPP, CHISL, CISSP, Senior Director of Consulting Services, Clearwater


July 16, 2024    

Cybersecurity Support for Rural Hospitals

Like many across the healthcare industry, I found that the recent announcement of Microsoft and Google’s new cybersecurity initiatives for rural hospitals raised more questions than it answers. While the White House coordinated with the American Hospital Association on this initiative, they did not consult with the Health Sector Coordinating Council, which represents the entire healthcare industry. Many in the community feel this is another example of allowing the tech giants to drive the conversation, rather than listening to the recommendations of healthcare security leaders and addressing the actual issues.

See Also: Identity Security Clinic

With over 12 years of experience dedicated to healthcare cybersecurity, including several years as the chief information security officer for Owensboro Health in Kentucky, as well as experience working across the industry as a board member of the Association for Executives in Healthcare Information Security, I know very well the challenges that smaller, resource-constrained hospitals face in working to protect themselves from the onslaught of cyberattacks that plague the industry. These challenges include limited financial resources, a shortage of skilled cybersecurity professionals, and the constant evolution of cyberthreats that require continuous monitoring and updating of security measures.

These are just some of the questions that came to mind as I reviewed the announcement:

  • Can resource-strapped hospitals engage effectively with these programs?
  • Are the financial supports sustainable beyond the first year?
  • What does “training” truly encompass, and how practical is it for minimal IT staff?
  • Will these assessments lead to actionable support or just highlight known issues without real solutions? What practical support is available post-assessment to address identified issues?
  • How will resources be allocated to ensure even the smallest hospitals benefit?
  • How will this initiative differ from existing CISA and 405(d) HICP resources that hospitals already struggle to use due to lack of bandwidth?

Tools Are Not Enough

The Microsoft-Google initiative does not do much at all to truly address the cybersecurity challenges that rural and critical access hospitals are facing, nor does it address any of the pressing third-party vulnerabilities that have resulted in numerous breaches.

Providing tools alone will not solve the problem. Rural and critical access hospitals lack the people, bandwidth and expertise to build and execute effective cybersecurity programs, encompassing both long-term strategic planning and immediate tactical needs.

During my tenure at Owensboro, we engaged outside experts focused on cybersecurity in healthcare and met weekly with them to assess cyber risk across the organization. That type of dedicated effort is required to keep a hospital secure within a rapidly changing threat environment. Engaging with experts provided us with tailored strategies and actionable insights – something that generic tools and guidelines often fail to offer.

Government Support

Congress must act to provide similar resources to smaller healthcare providers, including funding through grants and rebates, to address cybersecurity risks at a level that is appropriate to protect the safety of patients. Robust security practices based on industry standards, including ongoing risk management, must be implemented at all healthcare organizations. This is the only path forward to win the war against cybercriminals, and accomplishing this is only realistic with real support from our government.

There should be a structured approach for post-assessment support, ensuring that identified risks are not just documented but actively mitigated through comprehensive action plans and remediation efforts, with the necessary resources and expertise provided to hospitals.

While the Biden administration claims to be working “relentlessly to improve the resilience of the healthcare sector to cyberattacks,” we continue to see record breaches in healthcare and increases in ransomware attacks, and research shows that these are resulting in higher mortality rates.

Initiatives such as the Microsoft-Google announcement are unlikely to drive meaningful improvement in protecting our most vulnerable hospitals and the patients they serve. It is essential to focus on solutions that lead to substantial, lasting enhancements in cybersecurity.

Original Post url: https://www.databreachtoday.com/blogs/cybersecurity-support-for-rural-hospitals-p-3669

Category & Tags: –

Views: 1

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post