Why Healthcare Organizations Are at Increased Risk of Attack
A cyberattack on any industry can be detrimental, but in healthcare, patients’ lives could be at stake. Unfortunately, research shows that hospitals and health systems are among the most targeted. Hospitals are keepers of sensitive data: protected health information, personally identifiable information, financial information and payment methods, insurance data, research, and intellectual property, explains Jeff Sturman, managing partner at WittKieffer and former senior vice president and chief digital information officer for Memorial Healthcare System in Hollywood, Fla.
Health systems also operate across multiple devices, platforms and medical equipment types, which means a greater surface area for attack. “Healthcare organizations often have a broader technology footprint than many other industries — electronic health record, radiology, laboratory, etc.,” explains Sturman. “Many of these systems were never designed with modern cybersecurity principles in mind.”
Hospitals may fall victim to ransomware, credentialing compromises, third-party threats, data or privacy breaches, medical device tampering, and further vulnerabilities from internet-facing systems, explains Sturman. In addition, health systems must comply with laws and regulations, such as HIPAA, which adds another layer of complexity for a SOC analyst.
“Some systems are unique only to the healthcare environment, and that’s where vulnerabilities and threats get a little more focused,” says Alexandria Donathan, executive director of the Institute for Cybersecurity at Marshall University.
In cybersecurity, the confidentiality, integrity and availability of data are paramount, explains Donathan. In healthcare specifically, the emphasis must be on patient care and maintaining operations, even during an incident.
“Attackers know hospitals often have a low tolerance for downtime, making ransomware particularly effective,” says Sturman. “The patient safety dimension is what makes healthcare SOCs fundamentally different.”
RELATED: Remedy alert fatigue for healthcare security operations centers.
The Pros and Cons of Outsourcing the SOC in Healthcare
Generally speaking, opting for a third-party vendor for a SOC is common, says Donathan. Health systems often lack specialized, trained analysts or 24/7 cybersecurity coverage.
Major benefits of outsourcing the SOC include:
- 24/7 coverage by specialized staff
- Access to technology and software that might be too expensive to own
- Improved retention of cybersecurity staff due to more focused work
If a specialized internal person is hired but they leave for another job, they take with them their knowledge — and coverage, Donathan points out. “If you’re outsourcing to a third party, you have that backup.”
Outsourcing allows internal IT staff to focus on clinical workflows and risks, compliance and larger strategic improvements, says Donathan, who was previously the senior technical adviser at the U.S. Cyber Command’s Joint Force Headquarters - Department of Defense Information Network.
As for the negative consequences of outsourcing, the biggest potential issue is partnering with a vendor that does not fully understand the complexity and ramifications of the healthcare industry. “If not addressed properly, external analysts may not initially understand health systems’ clinical workflows, critical applications and normal operating patterns,” says Donathan. “A provider may identify a technical threat without understanding the patient care consequence of isolating a device or shutting something down.”
In addition to careful vendor selection, ensuring that final decisions remain in-house can also prevent any devastating patient care consequences. Donathan encourages leadership to clearly outline the responsibilities of each party in their service agreements.
“Poorly defined responsibilities can create delays during an incident,” says Donathan — and in healthcare, those delays could cost lives.
Click the banner below to sign up for HealthTech’s weekly newsletter.
