Rethinking culture in healthcare cybersecurity strategy

Data privacy is about more than keeping personal information safe and secure, says Dr. Eric Liederman, Kaiser Permanente’s director of medical informatics – it’s an essential component for establishing trust with patients that healthcare organizations take personal safety seriously.

At the HIMSS 2023 Healthcare Cybersecurity Forum, scheduled for September 7 and 8 in Boston, Liederman will highlight his experiences implementing systems and procedures that foster a culture of privacy and security.

“Patients really do say in polls and interviews that they really care about the safety of their information and the protection of their information,” he told Healthcare IT News in a preview of his presentation.

“If people don’t feel safe getting care, they won’t get it or they’ll do things to try to mitigate their sense of the unsafe,” such as withholding information from their physicians, Liederman explained. And they “vote with their feet,” he said. 

At one health system, Liederman worked for, he said it was not unusual that employees and their families would travel more than 100 miles to get care elsewhere because the culture was so “insidious” and it was clear that privacy and safety were not priorities and that any staff member could access patient data. 

Today privacy and security represent a twofold challenge.

Insider threats go beyond the risks of staff that may take patient data for personal gain or former employees’ credentials that are compromised by bad actors. There are also well-meaning employees that do not have any criminal intent but may go looking for patient information out of concern or to share information with a patient’s concerned family or friends. 

Liederman has been in the trenches working to figure out how to set up network gates so skilled clinicians and other valuable healthcare staff – employees who may have simply lapsed in judgment – are helped to stop themselves from breaching HIPAA.

There are also outside attacks that go beyond ransomware that destroy critical trust in a healthcare organization’s ability to keep patient data safe.

Some cybercriminals seek to steal personal data to extort individuals, Liederman said, monetizing their attacks by going after high-profile patients directly. An example was the late 2022 breach of Medibank, Australia’s largest private health insurer, which included the Prime Minister’s data. 

Nation-states that support cybergangs or have cyber espionage programs will also go after other government’s data, like the U.S. Federal Office of Personnel Management’s, to learn who can be compromised, Liederman said.

He said his presentation in Boston will cover the implementation of broader insider threat programs, offering tactics to prevent external threats that seek to extort individual patients and tips for how to work closely with the communications team to develop messaging about what your organization is doing for privacy and patient data protection. 

“Those kinds of privacy action communications are not done often,” Liederman noted. “Typically the only thing that we ever get is a notice of privacy practices, which is full of impenetrable boilerplate”

Liederman’s session, “Personal Safety: How cybersecurity and privacy protection generate trust in the healthcare system,” is scheduled for 10:55 a.m. on Friday, September 8, at the HIMSS Healthcare Cybersecurity Forum in Boston.

Andrea Fox is senior editor of Healthcare IT News.
Email: afox@himss.org

Healthcare IT News is a HIMSS Media publication.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Hairstyles That Could Trigger Migraines thumbnail

Hairstyles That Could Trigger Migraines

A bad hair day can be such a headache. But if you’re among the 1 in 4 American women who have migraines, your hair can actually be a real headache. Everything from the shampoo you use to the way you cut your hair could trigger a migraine.We asked Steve Waldman, a 30-year hair industry veteran…
Read More
Timely Cervical Cancer Screening Took a Dive in Recent Years thumbnail

Timely Cervical Cancer Screening Took a Dive in Recent Years

More and more U.S. women were behind on guideline-recommended cervical cancer screening in recent years, with lack of knowledge about needing screening cited as the primary reason for not being up to date, researchers reported. In a pooled, population-based, cross-sectional study, the percentage of women not up to date on their screening increased from 14.4%…
Read More
Early versus late dialysis: ELAIN, AKIKI, STARRT and current practice in intensive nephrology thumbnail

Early versus late dialysis: ELAIN, AKIKI, STARRT and current practice in intensive nephrology

Avalie o nosso conteúdo: Houve um erro fazendo sua requisição, por favor tente novamente! Obrigado!Sua avaliação é fundamental para que a gente continue melhorando o Portal Pebmed O Portal PEBMED é destinado para médicos e demais profissionais de saúde. Nossos conteúdos informam panoramas recentes da medicina. Caso tenha interesse em divulgar seu currículo na internet,…
Read More
Samsung Galaxy A52S 5G – Review thumbnail

Samsung Galaxy A52S 5G – Review

Not long ago, OnePlus almost owned the flagship killer moniker. The brand’s smartphones dominated the Rs 30,000 to 40,000 price band with devices that delivered key flagship level features at a price tag that didn’t require you to break the bank. The last two years have seen multiple brands make a play for this price…
Read More
Index Of News
Total
0
Share