Healthcare industry group builds cybersecurity threat center
Network World - Looking to address growing cybersecurity threats in the healthcare industry the Health Information Trust Alliance today said it has established a centralized Cybersecurity Incident Response and Coordination Center where organizations can report incidents and get help remediating electronic medical security problems.
The 5-year-old HITRUST group -- which is led by an amalgamation of healthcare and computing industry giants such as WellPoint, Kaiser Permanente and Cisco -- said it created the center with an eye toward helping the U.S. healthcare industry battle cyberattacks with timely alerts and by sharing of relevant cybersecurity threat and event information.
IN PICTURES: High-tech healthcare technology gone wild
"The group will focus on cybersecurity threats and events targeted at healthcare organizations in areas, including, but not limited to, networks, mobile devices, workstations, servers and medical devices. This sharing of information is crucial for organizations' preparedness, protection and crisis management," the group stated.
"The center is working initially with 14 leading industry organizations, representing health plans and health systems, and the U.S. Department of Health and Human Services to share various security incident information. The center will collaborate with HITRUST and others to identify and remediate incidents, and will also obtain and synthesize cyber threat and response information from numerous other sources to make the information more readily available to center participants. HITRUST will also lead the center's participants in evaluating appropriate tools and related security mechanisms to support the center's efforts," the group stated.
The HITRUST organization has already established what it calls a Common Security Framework that can be used by any and all organizations that create, access, store or exchange personal health and financial information.
"As the healthcare industry continues its conversion process to full patient electronic medical records, it will most certainly become a more frequent target of cybersecurity attacks, and having such a system in place in the near future will be key to collaboratively responding and preventing such attacks," said Jorge DeCesare, chief data security administrator of Dignity Health, in a statement.
A recent Network World story helps define the cybersecurity problems healthcare organizations are facing. The article noted that a biannual survey of 250 healthcare organizations shows the percentage experiencing a patient data breach is up. And with the growth in electronic records-keeping, more of those problems are originating from laptops and mobile devices rather than a human slip-up in handling paper documents.
"Use of new technologies, in particular mobile devices in the workplace, has skyrocketed, creating new operational efficiencies and security vulnerabilities," noted the survey report, entitled the "2012 HIMSS Analytics Report: Security of Patient Data." The organization Healthcare Information and Management Systems Society also pointed out, "As mobile devices proliferate in exam rooms and administrative areas, so do the associated vectors of potential attack. Adding to this are the risks from employee negligence and organizational policies that have not kept pace with ever-changing technology."
Apple continues work on iOS 8, but its latest developer release underlines the importance of new sensor technologies as it pulls together a private and secure mobile foundation to support the digital health industry.
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- 2014 Healthcare Data Management Survey Summary
- This report provides insights into how much information Healthcare IT organizations are managing, the rate of data growth they are experiencing and which...
- Selecting Foundational Controls Makes HIPAA Compliance Easier
- In this Dell Software white paper, learn more about HIPAA and IT security compliance - straight from an auditor - and discover how...
- Security, Privacy and Trust in Email Management
- This white paper discusses a SaaS-based email management solution that delivers the security, continuity and archiving capabilities your organization demands.
- The Total Cost of Email
- In this white paper, we'll explore the true costs of fragmented email management and uncover how to reduce those costs with a cloud-based...
- Balancing Security, Compliance and Cost: the Prescription for Healthcare Email Management: Move to the Cloud
- Learn how cloud-based technologies for core productivity tools such as email and collaboration can help healthcare organizations be more efficient with IT dollars... All Healthcare IT White Papers
- API Management: The Key to Improving the Consumer Travel Experience Join PhoCusWright's Senior Technology Analyst, Norm Rose, as he shares his insights on how travel suppliers and intermediaries can improve industry data flow...
- Tips to Simplify Database Administration and Development Make your job easier while getting the most from the leading productivity tool for database professionals. Learn tips from Dell Software's Oracle® ACE,...
- E-Signature RFP Checklist Webcast If your organization is looking to adopt e-signatures, you may be overwhelmed by the number of providers that offer seemingly similar solutions. How...
- On-Demand Webinar: Transform Your Datacenter with Cisco ACI and Citrix NetScaler Learn how Citrix NetScaler -- the leader in public clouds, integrates with Cisco ACI to enable the enterprise network transition to a new...
- Cloud and Collaboration: Driving Your Business Value Mission Critical Cloud from Peer 1 Hosting is enterprise-grade.
- All Healthcare IT Webcasts