Welcome!

Machine Learning Authors: Yeshim Deniz, Zakia Bouachraoui, Elizabeth White, Liz McMillan, Carmen Gonzalez

Related Topics: @CloudExpo, Cloud Security, @DXWorldExpo

@CloudExpo: Blog Post

Keeping Digital Health Organizations Safe from Cyber Attack | @CloudExpo #DX #Cloud #Security

We are learning that cybercrime isn’t always focused on economic gain

For health organizations, breaches are a constant threat, due to the high value of healthcare data - Social Security Numbers, treatment records, credit information, and other sensitive personally identifiable information (PII). And the cost of a breach to a health system or hospital can be devastating.

And the health care industry has seen its share of breaches in the past quarter alone. For example, the National Health Service in England and Scotland was hit by a Wanna Decryptor ransomware attack affecting at least 16 of its organizations. Within two days 150 countries were affected. Also last quarter, up to millions of patient records at Bronx-Lebanon Hospital Center in New York stored on a backup system managed by iHealth Innovations were exposed to a data breach.

Despite all the focus on preventing protected health information (PHI) theft and thwarting the next ransomware attack on a health organization, we are learning that cybercrime isn't always focused on economic gain. Some attacks have the goal of bringing critical infrastructure to its knees, as was likely the case of the recent Petya "ransomware" attack in Ukraine. Clearly bad actors and nation states have interests beyond ransom collection and PHI theft. This is beyond what we've seen for traditional cyberattacks, and these attacks can originate beyond a nation's borders.

These days it feels like health organizations are almost under constant attack, especially for ill-equipped, overworked IT staff suffering from the shortfall of qualified security staff. Fewer young people are interested in careers in cyber security (just as their Russian counterparts are attracted to hacking). This trend puts even more pressure on health security teams for innovation and automation for securing their organizations. Otherwise, they won't be able to keep up as their organizations digitalize and ride the Electronic Health Record (EHR) and mobile waves, all which expose more health information systems (HIS) to more attack surfaces.

Health organizations today are also challenged at times with the difficulty of finding the originators of an attack. Offshore state actors have resources available to conceal their identities. They can remain anonymous if desired, which makes the risk/reward ratio for hackers even more attractive. It may be matter of which health organizations are safest vs which are the best in determining the most successful organizations over the next five years.

Look at Ukraine to See the Future
The line between hackonomics and nation-sponsored cyberattacks gets blurred even further as nation states get more active in cybercrime. For those attackers funded by foreign benefactors, attribution of the attack can become even more complex. Yet these attacks, as has been shown, can propagate quickly beyond the attacked nation or organization.

Ukraine has witnessed infrastructure hacks and other cyberattacks resulting in infrastructure blackouts. More about this was written in the recent Wired article How an Entire Nation became Russia's Test Lab for Cyberwar.

Trusted Access Needed in the Medical Field
Just like trust is needed between patient and doctor, trust is the critical foundation for survival in the digital healthcare age. Without trust, the health industry cannot function effectively.

Health organizations need to rethink access control if they are to survive in the new digital world because the traditional security perimeter is helpless in defending against these new attacks. Health security teams need to adopt Zero Trust models of security, which limit connectivity to health systems based on device and user trust.

Trusted Access Control is a Zero Trust approach which leverages application-layer tunneling with software-defined perimeter technology (SDP) with advanced trust assessment that protects data far beyond traditional access control solutions. These new solutions assess trust of devices and users, and grant access to only specific applications and services based on granular trust-based decisions, instead of providing simple posture checking.

This new approach greatly reduces attack surfaces by isolating target health assets, such as HIS servers, from all devices and users, including potential attackers as well as legitimate users with possibly compromised devices. Health information can be seen by only those authorized users who have been authenticated, and whose devices have been verified as trusted and safe in their current context.

These new technologies and capabilities available to health organizations offer a considerable increase in security with less complexity and cost. As the shortage of health security experts increases, more powerful and easier to manage solutions that reduce capital and operating costs are needed. Along with effective security practices and operating discipline, these new solutions will help health organizations preserve trust and grow their practices without having to overspend on security to meet growing cyberattacks, especially since healthcare remains one of the biggest targets for attackers and threats to sensitive healthcare data.

More Stories By Greg Ness

Gregory Ness is the VP of Marketing of Vidder and has over 30 years of experience in marketing technology, B2B and consumer products and services. Prior to Vidder, he was VP of Marketing at cloud migration pioneer CloudVelox. Before CloudVelox he held marketing leadership positions at Vantage Data Centers, Infoblox (BLOX), BlueLane Technologies (VMW), Redline Networks (JNPR), IntruVert (INTC) and ShoreTel (SHOR). He has a BA from Reed College and an MA from The University of Texas at Austin. He has spoken on virtualization, networking, security and cloud computing topics at numerous conferences including CiscoLive, Interop and Future in Review.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


CloudEXPO Stories
Cloud is the motor for innovation and digital transformation. CIOs will run 25% of total application workloads in the cloud by the end of 2018, based on recent Morgan Stanley report. Having the right enterprise cloud strategy in place, often in a multi cloud environment, also helps companies become a more intelligent business. Companies that master this path have something in common: they create a culture of continuous innovation. In his presentation, Dilipkumar Khandelwal outlined the latest research and steps companies can take to make innovation a daily work habit by using enterprise cloud computing. He shared examples from companies that have benefited from enterprise cloud computing and took a look into the future of how the cloud helps companies become a more intelligent business.
Never mind that we might not know what the future holds for cryptocurrencies and how much values will fluctuate or even how the process of mining a coin could cost as much as the value of the coin itself - cryptocurrency mining is a hot industry and shows no signs of slowing down. However, energy consumption to mine cryptocurrency is one of the biggest issues facing this industry. Burning huge amounts of electricity isn't incidental to cryptocurrency, it's basically embedded in the core of "mining." In this winner-takes-all game, burning the most electricity increases the chances of winning. The Bitcoin Energy Consumption Index states that the global energy usage of all bitcoin mining already is equivalent to the power uptake of the country of the Czech Republic. Mining equipment for a larger operation can exceed 100 megawatts (MWs) - similar to what a 1 million-square-foot Google ...
CloudEXPO has been the M&A capital for Cloud companies for more than a decade with memorable acquisition news stories which came out of CloudEXPO expo floor. DevOpsSUMMIT New York faculty member Greg Bledsoe shared his views on IBM's Red Hat acquisition live from NASDAQ floor. Acquisition news was announced during CloudEXPO New York which took place November 12-13, 2019 in New York City. Our Silicon Valley 2019 schedule will showcase 200 keynotes, sessions, general sessions, power panels, and hands on tutorials presented by 150 rockstar speakers in 10 hottest conference tracks of 2019:
The dream is universal: heuristic driven, global business operations without interruption so that nobody has to wake up at 4am to solve a problem. Building upon Nutanix Acropolis software defined storage, virtualization, and networking platform, Mark will demonstrate business lifecycle automation with freedom of choice and consumption models. Hybrid cloud applications and operations are controllable by the Nutanix Prism control plane with Calm automation, which can weave together the following: database as a service with Era, micro segmentation with Flow, event driven lifecycle operations with Epoch monitoring, and both financial and cloud governance with Beam. Combined together, the Nutanix Enterprise Cloud OS democratizes and accelerates every aspect of your business with simplicity, security, and scalability.
Andrew Keys is co-founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life settlement products to hedge funds and investment banks. After, he co-founded a revenue cycle management company where he learned about Bitcoin and eventually Ethereum.