Digital Edition

SYS-CON.TV
Healthcare Industry and Data Security By @CipherCloud | @CloudExpo [#Cloud]
Healthcare organizations must see the CHS breach as a wake-up call to reevaluate and strengthen their data security measures

The Healthcare Industry Must Address Data Security Threats

Despite the data privacy protections supposedly conferred by regulations like HIPAA and HITECH, consumers' confidential health and personal information is still not safe enough. That's the lesson to be learned from Franklin, TN-based Community Health Systems' (CHS) August 18 regulatory filing. In the filing, CHS disclosed that the names, SSNs, addresses, birth dates, and phone numbers of approximately 4.5 million people across 28 states have been stolen, according to Computerworld. Those 4.5 million victims, whom Computerworld reported had either received or been referred for services to CHS-affiliated physicians, are now at risk of identity theft, thanks to the security weaknesses of their healthcare provider. This latest large-scale data breach serves to highlight just how critical data security is in today's connected age.

Computerworld reported that the breach is being investigated by Mandiant, which "believes that a known Advanced Persistent Threat (APT) group, based in China, is responsible for the breach." Computerworld further notes that "since the breach was discovered, CHS is working with Mandiant to clean out its systems and implement new remediation measures" as well as cooperating with federal investigators. These post-incident measures come a bit too late to protect those 4.5 million victims, or CHS's reputation itself, but provide a fresh reminder to other healthcare organizations that data security matters.

HIPAA and HITECH aren't the end-all, be-all of healthcare data security. As CIO.com pointed out after the CHS breach was disclosed, "many organizations pay little more than glancing attention to the rules because of the relatively lax enforcement of the standards." Even though regulations are growing stricter and penalties stiffer, auditing requirements still fall behind those of other regulated industries, such as financial services. Healthcare organizations see little incentive to beef up their data security. Then a breach happens, and both patient trust and public reputation suffer.

What's the Solution?
Healthcare organizations must see the CHS breach as a wake-up call to reevaluate and strengthen their data security measures. This process must go all the way to the top of the organization. Security leadership is absolutely essential at any security-conscious enterprise. Having data security leadership that's independent of the IT department and able to communicate and work effectively with the business, legal, and financial leadership of the organization will go a long way toward making sure that patient data gets the attention and protection it needs. Risk assessments, data classification, strict access controls, and data encryption are all critical components. So is a change in culture to one that values data privacy and data security enough to invest in it.

The consequences of this lack of security leadership and prioritization may not always be apparent when regulatory bodies are lax in enforcing their own rules, but they will become all too apparent to any healthcare provider that suffers a breach like CHS did. If you want to prevent your organization from becoming the next CHS, you must act while you have a chance. Protect your data before it comes under attack so that you won't have to suffer the aftermath of one for which you weren't prepared. The alternative is to lose control of millions of patients' data-and millions of patients' trust.

What lessons have you learned from the CHS data breach? Tell us what you think in the comments.

About Paige Leidig
Paige Leidig is SVP at CipherCloud. He has 20 years of experience in technology, marketing, and selling enterprise application solutions and managing trusted customer relationships. As SVP of Marketing, he is responsible for all aspects of marketing at CipherCloud. Paige was previously in the Office of the CEO at SAP, where he was responsible for leading and coordinating SAP’s acquisition and integration activities on a global basis. He has managed a number of marketing initiatives at SAP, including responsibility for all go-to-market activities for SAP’s Cloud applications portfolio. Preceding his SAP career, Paige held senior management positions with Ariba, Elance, and E*Trade.

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1

Healthcare Cloud Computing Market worth $5.4 Billion by 2017, Please speak to analyst on @ http://bit.ly/1yi0B3R




ADS BY GOOGLE
Subscribe to the World's Most Powerful Newsletters

ADS BY GOOGLE

Atmosera delivers modern cloud services that maximize the advantages of cloud-based infrastructures....
In today's always-on world, customer expectations have changed. Competitive differentiation is deliv...
Artifex Software began 25-years ago with Ghostscript, a page description language (PDL) interpreter ...
In an age of borderless networks, security for the cloud and security for the corporate network can ...
Isomorphic Software is the global leader in high-end, web-based business applications. We develop, m...
Cloud Storage 2.0 has brought many innovations, including the availability of cloud storage services...
In very short order, the term "Blockchain" has lost an incredible amount of meaning. With too many j...
For enterprises to maintain business competitiveness in the digital economy, IT modernization is req...
At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with exp...
Cloud-Native thinking and Serverless Computing are now the norm in financial services, manufacturing...
Most modern computer languages embed a lot of metadata in their application. We show how this goldmi...
On-premise or off, you have powerful tools available to maximize the value of your infrastructure an...
Public clouds dominate IT conversations but the next phase of cloud evolutions are "multi" hybrid cl...
At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with exp...
Every organization is facing their own Digital Transformation as they attempt to stay ahead of the c...
Data center, on-premise, public-cloud, private-cloud, multi-cloud, hybrid-cloud, IoT, AI, edge, SaaS...
DevOps has long focused on reinventing the SDLC (e.g. with CI/CD, ARA, pipeline automation etc.), wh...
Now is the time for a truly global DX event, to bring together the leading minds from the technology...
In a recent survey, Sumo Logic surveyed 1,500 customers who employ cloud services such as Amazon Web...
Moving to Azure is the path to digital transformation, but not every journey is effective. Organizat...