Adaptive Defense Model for Evolving Cybersecurity Risks
Healthcare Tech Outlook

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our Healthcare Tech Outlook Advisory Board.

Renown Health

Adaptive Defense Model for Evolving Cybersecurity Risks

Steven Ramirez is the CISO and VP of Renown Health. With more than a decade of experience in the IT security landscape, he is a seasoned leader with expertise in risk management, cybersecurity, privacy management, data confidentiality, IT regulatory compliance (HIPAA privacy/security, PCI security), data protection, IT advisory, enterprise risk management, crisis management, and many more. In his current role at Renowned Health, he is responsible for projects and priorities for all information security issues, establishing long and shortrange business plans to provide the organization with a topnotch network security infrastructure.

As per your experience, where does the healthcare security sector stand today?

The shift towards where the healthcare security space is today began when every organization started moving to Electronic Health Records (EHRs)—with the inception of the Affordable care act. But, the ultimate progress towards digital transformation came with the outbreak of COVID-19. On another note, amidst such transformation, not having a built-in framework for the sudden digital shift posed a major challenge for enabling such services.

IT in the healthcare space is also quite different from other aspects of the sector, which makes its data security needs more exclusive. Today, we have IoT-based medical devices and traditional systems, which hold tons of technical information and population health records. There is also a constant need for sharing that information to ease interoperability. This makes the surface area relatively big for cyber attacks. As a result, though the security aspects of healthcare have come a long way, there is a raising need for evolution to make the systems more breach-proof.

What are some of the best healthcare security best practices that organizations must adopt?

Doing the basics of security management is the foremost task. Before incorporating AI and other technologies, companies must focus on Security 101. Aspects like twofactor authentication, password hygiene maintenance, and privileged access management are some of the best practices that hold prime importance in maintaining data security.

Assessing the company's third-party security hygiene is another crucial function. With rapid cloud transformation, organizations must confirm their security agreements— liability and security controls—with third-party partners like Okta and Microsoft. This is because when such partners lack apt security hygiene; they are compromised, which has an upstream and downstream impact on the healthcare organization.

Finally comes the part of risk pre-assessment, where organizations must equivocate their healthcare model to cybersecurity to facilitate early risk detection. Doing so, they will have the right security tools along with a strong foundation of basic controls. This will help them build an adaptive defense model, which can assess risks and secure the system when such adversities arise.

Could you shed some light on the process of identifying the right security solution for an organization?

The present IT security landscape is massive and has new players jumping into the market daily. This makes the number of choices for a specific security solution relatively big. However, before choosing the right security solution or its provider, organizations must have a clear understanding of their own business environment, critical processes, and riskappetite. Not just that, they must strive to maintain a constant low risk-appetite so that the ultimate quality care for patients doesn't get affected.

"Before choosing the right solution or its provider, organizations must have a clear understanding of their own business environment, critical processes, and risk appetite"

Also, ensuring that the healthcare organization doesn't have any redundant tools—provided by companies like Google and Microsoft as a one-stop-shop for all security solutions—is necessary. As cloud-based systems for IT and security aspects are a major catch today, top Managed Service Providers (MSPs) like Google and AWS are absorbing a lot of security controls, and healthcare organizations are compelled to adopt them to keep their systems operational. But, such efforts alone cannot be of much help for risks particular to their organization. Healthcare firms need to build their own adaptive defense for threat detection, containment, and eradication, such that the security tool-belt helps them manage the intricate risks specific to them.

Pondering on the ever-evolving landscape of IT security threats—where a new type of malware, ransomware, or attack technique is evolving every now and then—there lies a significant need for organizations to alter their security strategy constantly. However, such is not a feasible wayout. Instead, firms need to focus on the fundamentals: understanding the common attack methodologies in every attack type and building the defense systems accordingly. To do so, they can utilize frameworks like MITRE ATT&CK and NIST CSF to understand the core components of such evolving risks, evaluate the attack surface of their own systems, and build adaptive systems to safeguard from such risks.

What are some of the healthcare security initiatives you initiated amidst COVID-19?

The onset of COVID-19 made the healthcare sector—like all other industries—enable remote working. However, when it came to providing a secure interface for smoothly running the massive regular data access and transfer, it became a major challenge. As a result, in 2019 and the coming two years, the healthcare industry witnessed a series of security breaches—700 attacks on critical infrastructure as per the FBI. Owing to such incidents, at Renown health, we have focused on managing identity access management and privileged access—both internally and externally—so that the clinical engineering servers don't get compromised. We have also sought to collaborate with peers who have worked in other organizations to exchange information on the best tools and frameworks for security management, amidst such adversities.

Integrating my experience from working in UofL Health into Renown's system to get a clear view of loopholes within our systems' periphery and inner core was another initiative. It helped us better understand the well-being of our current systems and strengthen the internal control to stop the threats from spreading when any breach happens. Moreover, we initiated funny and interactive training sessions monthly to educate the employees on cybersecurity awareness for their specific job roles.

Could you walk us through the prominent challenges in the healthcare security space?

Funding management is among the top challenges faced by healthcare firms. Presently, organizations have a lot of aging infrastructure, which needs replacement with the constant hardware and software refreshes. But such technologies are not cheap, making the healthcare sector—with relatively low funding opportunities—struggle to incorporate the latest in technological developments.

Expanding medical staff deeper into the communities for setting up vaccine and testing centers during COVID-19 was another severe challenge. As technology was the focal point of such an effort, optimizing a secure environment amidst the advancing security-risk landscape became a major concern.

Also, currently, central America has a growing talent crunch for efficient cybersecurity experts, which expands the threat vulnerabilities in healthcare IT. However, COVID-19 has been beneficial here, as organizations could hire talents from the east and west coast regions of America by providing remote working facilities.

Furthermore, the US government is also adding up legislation within HIPAA (Health Insurance Portability and Accountability Act of 1996) to strengthen and support cybersecurity components of healthcare. But, such efforts focus on data protection and not educating the organizations on the procedures of data protection.

What is your advice to your peers in the healthcare security space?

Information security officials must strive to stay a step ahead of the rogues. And the best way to do that is by developing a cybersecurity community where peers from various healthcare organizations have to be brought together. They must analyze the issues collectively from different viewpoints to get a complete picture of the pertinent risks. Also, to aid the technical training and development of the IT security professionals for best risk management, they must be taken through certified courses from CIS and NSA.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief