sample
Running head: CYBER ATTACK ISSUES IN THE HEALTH CARE INDUSTRY 1
CYBER ATTACK ISSUES IN THE HEALTH CARE INDUSTRY 2
Cyber Attack Issues in the Health Care Industry
Student’s Name
Institutional Affiliation
Cyber Attack Issues in the Health Care Industry
*Step 1: Selection of Industry and Cyber Issues
In the industry of focus here is health care. There are many cybersecurity issues in the health care industry. According to KPMG (2018), the healthcare industry is faced by cyber threats such as loss or theft of data or equipment, ransomware attacks, accidental, insider, and intentional loss of data, attacks against connected medical devices which might affect patient safety, as well as e-mail phishing attacks. Email phishing occurs when individuals within the hospital or outside yet familiar to the hospital staff trick one another and get information through the e-mail and once a given link is opened it becomes malicious to the computer within the health care network. In this case the fraudulent email from the attacker pretends to be an IT support person from the health care patient billing organization and instructs the physician to click the link so as to change the billing software passwords only for that to be malicious and once information is accessed, the identity is used to steal for the patients.
When it comes to ransomware a hacker denies access to important data for the healthcare after installing ransomware. After such a program is installed it becomes difficult for a physician to view patient charts rendering the system inaccessible, since 2015, Coventry & Branley-Bell (2018) asserts that is a lot of hacking which is a leading health data breach. Besides, there is malware and ransomware with hackers stealing medical health records, denying access to health service provision, and enhancing intentional harm. When equipment or data is stolen, the physician might have lost the computer while on a journey or in a coffee place. The stolen gadget or data can then be misused. Such a rise has resulted in a lot of financial, reputation loss and how patient safety. With the breaches, there is stigmatization especially for patients who have mental or sexual health conditions. Considering the UK, in 2017 alone resulted in infection of over 300,000 computers globally and lockout of 50 hospitals where patients had to be delayed in receiving services and many devices could not function as the hackers demanded ransom payments from the health center. Malware has also been injected in unprotected medical devices hence resulting in weak links in hospital networks. When there is data loss, the attacker impersonates as a member of the health care staff then contacts the employee of the center and askes for verification of patient data. In such an imposter situation, the entire patient record is acquired and compromised.
Step 2, 3, 4: Project Practice - SIM TRAY
On the first day, my score was 6/12 in the first topic 5/16 in topic 2, 8 in topic three, and 8 in topic four. On the second the score improved to 9/12 the first topic, 9/16 in the second topic, 10 in the third topic, and 14 in the fourth topic. Finally, on the third day, I scored 12/12, 10/12 in the second topic, 11 in the third topic, and 15 in the fourth topic. Thus, my best score was 12 in topic 1 10/16 in topic 2, 11 in topic 3, and 15 in topic 4.
The health care cybersecurity-related policies include US Health Insurance Portability and Accountability Act of 1996 that was introduced to make sure that some electronic health information is safeguarded. The rule demands that health care entities have a reasonable and suitable administrative, physical, and technical security to afford integrity, confidentiality, and availability of EHRs which they develop, receive, sustain, or share the data.
Among the countermeasures of cyber threats in the healthcare industry are an evaluation of the organizations and benchmarking cybersecurity capabilities reliably and effectively. Besides, the health care organizations need to share knowledge, common procedures, and suitable references across the industry to better the cybersecurity competencies. To protect the email phishing attacks, it is suitable for the health care industries to have protection controls, encryption, multifactor authentication, and workforce education (KPMG, 2018). This means that no stranger should manage to send a mail to any stakeholder attached to the health care firm, diverse proof for remote e-mail access by anyone else, offering certification before an e-mail is logged into, and ensuring all the workers in the healthcare firm understand what cyber-attacks are, necessary steps to take to prevent it, and how it happens.
In the end protection of systems, the health care organizations could place the primary endpoint protection regulation, identity provision, transfers, and de-provisioning processes. Often, this process should be enhanced by healthcare management so that no one accesses the health care data or shares out information anyhow. Moreover, access management, asset management, and network management call for adapt securities, secure storage of inactive gadgets, network firewalls and profiles, data classification, backup strategies, and recommissioning assets (Healthcare & Public Health Sector Coordinating Councils, n.d.). All these processes ensure that gadgets alert on attacks, put away data based on who is managing it, have specific people who manage such data, and data be kept in various gadgets of that it is not lost through one gadget. Another strategy is data protection and loss prevention through backups, inventory of servers and endpoints as well as intrusion prevention so that data is asset secure and is in various places. The cybersecurity policies, vulnerability management, and medical device security too are essential (Jalali & Kaiser, 2018). The three could be offered when a health care institution establishes a robust IT policy, manages medical devices well under particular people, enhance configuration, patch, and change management, as well as scanning of the web application to eliminate any threats. It is also the best practice for the health care firms to prioritize actions and investments which will improve cybersecurity.
Currently, the following mobile technologies applicable in the healthcare industry are being used. First, there is m-health in which smartphones, personal data assistant, wireless devices, and monitoring devices serve in giving the patient information and health services. Through, its patients have disease surveillance, integrated illness management among children, routine immunization, and child and maternal health. There has been Information technology Aided relapse preventing program in Schizophrenia telemonitored on the phone (Kalem & Turhan, 2015). Then there is the Few Touch Application serving diabetic patients.
Gramm-Leach-Bliley Act (GLBA) application in the healthcare industry. Comes with the imposition of various data protection obligations. For example, except where there are exemptions, there should be no sharing of information from a financial institution with non-affiliated 3rd parties apart from when the give the clients a notice or a chance to ‘opt-out’ (Congressional Research Service, 2019). Moreover, the account numbers r credit card numbers should not be sharing in direct marketing and the clients should receive ‘clear and conspicuous’ initial and yearly notices to the clients describing the privacy ‘practices and policies’ such notices must have classes of NPI collected and disclosed, the classifications of the 3rd parties that the information is being shared with. In addition, there should be a maintained ‘administrative, physical, and technical protection’ ensuring the safety and confidentiality’ of the customers with reference to the anticipated threats.
From this lesson I have learned that , cyber threat is a complex scenario, it comes in various formats and through various parties. I have also realized that everyone can expose the health care industry to cyber-attacks. Patients, physicians, the other integrating parties to health care, and the institution itself can render it risky. A standard is essential to ensure that cybersecurity is installed in any health care firms the customer, the organization, and reputation of the managers should be safe.
*Step 4: Project Practice - SIMTRAY Adios: Day 3
The proposed regulation from the above analysis is diverse including use of codes, controls, management, backups, education, among others. To influence the agencies into implementing the proposals made in the act, I will have to start with the harm the industry faces at the moment. I will exhaustively cover the critical risks and show the causes of that, particularly negligence and ignoring of the acts that are present. I will have to show the connection between the two and give a list of some organizations that have already gone at a loss because of failure to adhere to the standards or policies. I will then ask the team to ask questions about the two areas so that if there is anything, they have no disillusioned they learn about it. This will follow after I have posted information on cyber-attacks and cybersecurity to them as well as links which they can read more and understand the level of insecurity in data and IT areas of health care, possible risk factors, countermeasures, policies, and a way forward.
*Step 5: Cyber Posture and Create a Relevant Standard
Relevant Standard
To address the cybercrime issue of a data breach in the health care industry, it is fundamental for all the firms to adhere to both HIPAA and Gramm-Leach-Bliley Act. Besides, access, asset, and network management are necessary with a CIO consistently supervising movements of the staffs so that none uses the chance given to them to serve the clients to share out data to the third party. The allocation of specific people to data management, provision of authentication processes and security safeguards are necessary too. It is necessary that the health care industry educates not only its workforce but also the clients and other attached stakeholders on relevant and suitable protection mechanisms that will ensure they safeguarded from the prevailing attacks.
The annual reporting on the state of security provision, assessment of possible situations and preventive measures should be clear, relevant, logical, and practical in the industry. It is inevitable that the health care industry should come up with an overarching, overall statement which particularizes the vision, philosophy, and mission of the industry in the principal aspects of strategic management, structural organization, information security, and what strategies will serve in the achievement of the entire policy. Having a local focus spelling out what needs to be done for policy implementation is highly recommendable for it will give a clear picture of what the industry needs to pay attention to and who should be considered. There will be an imperative need for the creation of a policy which limits the permission of the network resource, physical elements, and applications, administrators while making sure that other individuals in the IT department have particular administrative roles, distinct from the duties of the system administrator. In the end, the policy must be posted to the web page of the IT security department with links to all appropriate training materials that should be distributed to the managers of the department before redistribution to the teams.
*Step 6: Written Comments
Some of my comments will no doubt be easily received, yet there are those that are difficult to receive in health care. The standards established in the report requires that knowledge be fundamental in guiding the health care industry. The health care industry is prone to so many attacks which cannot be neglected especially due to the usage of mobile phones, enhancement gadgets and handling of patient’s records. The awareness of the kind of attacks, the risks of such attacks, losses the industry can face, countermeasures, policies that enhance compliance, and preventive measures are essential for involved stakeholders. It might be shocking to learn of some of the attacks, yet standards require that suitable controls be taken after awareness. While come of the organizations might claim to lack direct responsibility to issues of mobile phone or loss of gadgets, there are all reasons to ensure that there are controls for each of the risks established. Some workforce might feel that they are being monitored too much and controlled especially when gadgets are given to particular individuals while they are denied. They will believe that health care is up to no good and might want to resist that is why education should be the first thing to offer all stakeholders. For some of the comments they will take, they might not want to put into practice easily unless followed up or offered a reward.
I am sure that each of the important security policy forming personnel will be eager to engage in the cybersecurity, yet none will want to be on the leading front of the narrative. The CISO, IT staff members in the department, CIO, and managers will want any of them to willingly offer a way forward.
It might be inevitable to accept that the industry will comply with the policies and laws arguing for security, yet they might want exposure to the details of the law and elaboration of what each demand spells so that the correct process is done. In some cases, the claim on resources and efficient checks will be said to be a hitch for clients and community might be too hard to engage in the hundred percent security.
Ultimately, the suggestion that the organization should make a systematic organization of priorities within policies and ensure that everyone accesses them and understands them so that they own up and practice what is necessary.
References
Congressional Research Service. (2019). Data protection law: an overview. 1-79. Retrieved from https://fas.org/sgp/crs/misc/R45631.pdf
Coventry, L. & Branley-Bell, D.B. (2018). Cybersecurity in healthcare: A narrative review of trends, threats, and ways. Maturias, 113, 48-52. doi:https://doi.org/10.1016/j.maturitas.2018.04.008
Healthcare & Public Health Sector Coordinating Councils. (n.d.). Health industry cybersecurity practices: managing threats and protecting patients. 1-36. Retrieved from https://www.phe.gov/Preparedness/planning/405d/Documents/HICP-Main-508.pdf
Jalali, M. & Kaiser, J.P.. (2018). Cybersecurity in hospitals: a systematic, organizational perspective. J Med Internet Res., 20(5). doi: 10.2196/10059
Kalem, G. & Turhan, C.. (2015). Mobile technology applications in the healthcare industry for disease management and wellness. Procedia - Social and Behavioral Sciences, 2015-2018. doi: 10.1016/j.sbspro.2015.06.216
KPMG. (2018). Healthcare and cybersecurity: increasing threats require increased capabilities. 1-8. Retrieved from https://assets.kpmg/content/dam/kpmg/pdf/2015/09/cyber-health-care-survey-kpmg-2015.pdf