Rethinking culture in healthcare cybersecurity strategy

Data privacy is about more than keeping personal information safe and secure, says Dr. Eric Liederman, Kaiser Permanente’s director of medical informatics – it’s an essential component for establishing trust with patients that healthcare organizations take personal safety seriously.

At the HIMSS 2023 Healthcare Cybersecurity Forum, scheduled for September 7 and 8 in Boston, Liederman will highlight his experiences implementing systems and procedures that foster a culture of privacy and security.

“Patients really do say in polls and interviews that they really care about the safety of their information and the protection of their information,” he told Healthcare IT News in a preview of his presentation.

“If people don’t feel safe getting care, they won’t get it or they’ll do things to try to mitigate their sense of the unsafe,” such as withholding information from their physicians, Liederman explained. And they “vote with their feet,” he said. 

At one health system, Liederman worked for, he said it was not unusual that employees and their families would travel more than 100 miles to get care elsewhere because the culture was so “insidious” and it was clear that privacy and safety were not priorities and that any staff member could access patient data. 

Today privacy and security represent a twofold challenge.

Insider threats go beyond the risks of staff that may take patient data for personal gain or former employees’ credentials that are compromised by bad actors. There are also well-meaning employees that do not have any criminal intent but may go looking for patient information out of concern or to share information with a patient’s concerned family or friends. 

Liederman has been in the trenches working to figure out how to set up network gates so skilled clinicians and other valuable healthcare staff – employees who may have simply lapsed in judgment – are helped to stop themselves from breaching HIPAA.

There are also outside attacks that go beyond ransomware that destroy critical trust in a healthcare organization’s ability to keep patient data safe.

Some cybercriminals seek to steal personal data to extort individuals, Liederman said, monetizing their attacks by going after high-profile patients directly. An example was the late 2022 breach of Medibank, Australia’s largest private health insurer, which included the Prime Minister’s data. 

Nation-states that support cybergangs or have cyber espionage programs will also go after other government’s data, like the U.S. Federal Office of Personnel Management’s, to learn who can be compromised, Liederman said.

He said his presentation in Boston will cover the implementation of broader insider threat programs, offering tactics to prevent external threats that seek to extort individual patients and tips for how to work closely with the communications team to develop messaging about what your organization is doing for privacy and patient data protection. 

“Those kinds of privacy action communications are not done often,” Liederman noted. “Typically the only thing that we ever get is a notice of privacy practices, which is full of impenetrable boilerplate”

Liederman’s session, “Personal Safety: How cybersecurity and privacy protection generate trust in the healthcare system,” is scheduled for 10:55 a.m. on Friday, September 8, at the HIMSS Healthcare Cybersecurity Forum in Boston.

Andrea Fox is senior editor of Healthcare IT News.
Email: afox@himss.org

Healthcare IT News is a HIMSS Media publication.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Few Medicaid-participating primary care physicians providing longer-acting birth control methods, finds study thumbnail

Few Medicaid-participating primary care physicians providing longer-acting birth control methods, finds study

Credit: Unsplash/CC0 Public Domain Medicaid beneficiaries face barriers in accessing medical care—and that includes contraceptive care. A new study finds that despite birth control being an essential health service, all primary care physicians that see them may not be offering Medicaid patients some of the most effective, longer-acting birth control methods. While nearly half (48%)
Read More
Audio-only telehealth benefits patients in need, study finds thumbnail

Audio-only telehealth benefits patients in need, study finds

A recent University of California study of telehealth implementation at community health centers found that although phone visits were beneficial to historically marginalized patients, continued virtual care use depends on increased technological resources.   The study, published in SSM - Qualitative Research in Health, took a closer look at the rollout of telemedicine at two…
Read More
Men's Health Six Pack: Stefanos Tsitsipas's Essential Gear thumbnail

Men’s Health Six Pack: Stefanos Tsitsipas’s Essential Gear

Prime Day Grooming DealsBest Slides for MenSummer Bodyweight WorkoutOlympian Fitness HacksGuide to Split SquatsOur product picks are editor-tested, expert-approved. We may earn a commission through links on our site. Why Trust Us?Getty ImagesWilson Blade 98 V9 Tennis RacketObviously my racket is my most important item,” Tsitsipas says. “I love this Wilson V9 because it’s stylish
Read More
The food industry, especially meat producers, appears to be at the center of stepped-up child labor enforcement thumbnail

The food industry, especially meat producers, appears to be at the center of stepped-up child labor enforcement

Ever since federal penalties totaling $1.5 million were imposed earlier this year on 13 meat plants contracting in eight states with Packers Sanitation Services Inc. for employing children in critical food safety jobs, the story has not gone away. Child labor restrictions typically fall under federal or state Labor Departments. Still, there’s now been confirmation
Read More
Index Of News