| | APRIL 20228UTLOOKHealthcare Tech IN MY OPINIONBy John Wilson, CSX, CRISC, CISSP, CISM, CCSK, Director, IT Risk Management and Assurance, Texas Health ResourcesSince the introduction of the HITECH Act, the healthcare industry has made significate changes in many areas, such as digital transformations. For example, Promoting Interoperability (formerly known as Meaningful Use) assisted with the push to move away from paper records to the digitization of health information. As this began to converge, the official start date of health care information security governance and digital healthcare began. The purpose of this article is to bring a security perspective in two critical areas in the healthcare domain, starting with medical devices and mobile applications.Medical devices have increased in many capabilities, including networking, storage, processing and computing. Many medical devices, including hospital beds, now have Bluetooth capability. Medical devices that come with these new networking capabilities introduce the concept of an "unbound medium," meaning bad actors do not have to be present or close in proximity to do harm. Security that can affect patient safety has become a concern with medical devices' enhanced capabilities. While many security capabilities should be taken into consideration, a few key areas to consider are asset management and device classification, and assessments.Medical device asset management should have a lifecycle management approach. This includes processes from new device onboarding and offboarding (e.g., destruction and disposal) as well as processes for when the devices are in production (post-onboarding and pre-offboarding). Many technologies in both active asset monitoring (RFID) and passive monitoring (networking SPAN ports) can assist with asset management. Since many medical devices can process and store sensitive data, such as Protected Health Information (PHI), the question becomes when the right time is to identify a device as being lost or, even worse, stolen. As part of the medical device onboarding process, the devices should be classified. Classification helps assist with determining risk identification, risk response and tolerance. For example, devices can be classified with labels such as "critical network-enabled" or "critical non-network enabled" (to name just a few classification examples). A medical asset classification helps enable a deep understanding of what is inventoried and knowing what the security program is trying to protect. As mobility continues to advance in many areas from cloud accessibility to smart devices, many clinical applications are How to Secure and Embrace New and Emerging Healthcare Technology Capabilities < Page 7 | Page 9 >