| | October 202019UTLOOKHealthcare Tech As evidenced by the malware-induced breach at Banner Health and the ransomware attack at Hollywood Presbyterian earlier this year, cybercriminals are continually targeting healthcare organizations. The financial and reputational costs of a breach can be immense and often those costs aren't fully realized for several years after the event as regulatory findings and fines are rarely immediate. The cost of a breach has significant impact on the cost, access, and safety of care. I see four areas where we in the industry should be increasingly vigilant--unchecked adoption, implementation of consumer tools, Internet of Things (IoT) leakage, and government involvement.Unchecked AdoptionAs more and more apps and tools for caregivers' smartphones become available, organizations must enforce policies and standards to avoid possible data loss. Caregivers are necessarily innovative and, if a tool will make their jobs easier, they are likely to use it. A good example is cloud storage it's entirely convenient for accessing files, but the ramifications of commingling personal and care related information is not inherently addressed in these applications and tools. Unchecked adoption of shadow apps and systems as well as BYOD issues are common causes of data loss. Helping caregivers understand that implementing new tools has potential risks for your organization and for them personally is difficult. However, organizations must have mechanisms in place so that clinicians can make recommendations for the tools and systems they want (and often need) and an efficient vetting process that seriously considers the recommendation and "closes the loop" with the clinician. It's not enough to just say no; you've got to work with the business to address the needs.Implementing Consumer ToolsSmartphones aren't only in the hands of clinicians. Patients are also eager to connect with healthcare through taps and swipes. However, safely and securely implementing consumer facing apps that touch vast amounts of healthcare data and actually provide value to the patient presents its own set of concerns. The increased traffic and access to data increases the likelihood of a breach if sufficient controls are not in place on the device or within the app. Connecting apps together and sharing data between them also presents many security issues that must be resolved in the development process. A strong expectation of vendors to uphold your security requirements as well as reviews of their Secure Software Development Life Cycle (SSDLC) programs are important parts of making application purchase decisions.Internet of Things (IoT) LeakageIoT devices are entering healthcare at an increasing rate. Many of these devices lack needed encryption or have potential fail points that can be exploited by crafty cybercriminals. In order to make certain that patients' data (and the patients 4 Cybersecurity Weak Spots You Should Care About When Others Don'tCIO INSIGHTSBy Marc Probst, CIO & VP, Intermountain Healthcare < Page 9 | Page 11 >