Thursday, September 24 | Thought Leadership, Human Services, Post-Acute Care

5 Strategies to Increase Cybersecurity at Your Healthcare Organization

By Bob Bowes, Director, Enterprise Security

With a 3,987%1 increase in COVID-19-related phishing attempts reported since March 1 of 2020, prioritizing cybersecurity is a must for the successful provider. While this number represents an increase across all verticals, healthcare organizations are extremely vulnerable to these targeted attacks due to the inherent value of healthcare data and its historic vulnerability. 

 

Healthcare organizations are often at risk of cyberattacks due to both a lack of dedicated IT resources to support continuous monitoring and reliance on traditional reactive approaches, such as antivirus and firewalls, to detect and prevent known threats. Given the speed with which adversaries can move within in an organization, a breach can infect devices across an entire network within minutes. In some cases, attackers occupy systems for months before launching a progressive attack.

 

As many healthcare organizations transitioned to remote work structures in the wake of COVID-19, organizations faced increased challenges securing endpoints outside of organizational firewalls. As a result, cyber attackers focused their efforts on these susceptible, external systems.

 

To aid organizations in protecting against these adversaries, Netsmart sponsored the webinar “Cybersecurity and healthcare: Defending your data” with Binary Defense Co-Founder and Chief Technology Officer, Dave Kennedy.

 

Learn five strategies all healthcare organizations should employ to protect against cyberattacks. 

 

1. Multi-factor authentication

 

Multi-factor authentication refers to the authentication method that requires the user to provide two or more forms of verification to gain access to a system.

 

For Kennedy, multi-factor authentication is the most important practice to implement in any environment. “While multi-factor identification won’t always stop hackers penetrating your organization,” said Kennedy, “it will stop credential re-use issues.”

 

By implementing this process, organizations can ensure a more complex access path, limiting the likelihood of a hacker gaining entrance. 

 

2. Endpoint detection and visibility 

 

Endpoint detection refers to the practice of safeguarding the data and workflows of individual devices that connect to your network. By identifying and securing these devices, you can ensure an additional layer of security as your team works from home or from a conventional setting. 

 

With increased visibility into your infrastructure, you can quickly identify and defend against cyberattacks. Incorporating a 24/7/365 security operations center (SOC) into your information security strategy allows for continuous monitoring by expert analysts for any attackers attempting to penetrate your infrastructure. 

 

Increased visibility and around-the-clock monitoring permit a human analyst to identify threats in real-time, provide security alarm notifications and, if needed, contain the threat by isolating the infected device. This blocks damage by reducing spread across your entire network. 

 

3. Network architecture and segmentation

 

By assessing your network architecture, Kennedy explains that you can identify potential points of unnecessary system linkage. Through a structural analysis, organizations can ‘segment’ or isolate systems, so if a device is hacked in your finance department, the spread stops there instead of moving across the enterprise. 

 

4. Cloud services security

 

While many organizations have migrated to cloud-based structures, this move reduces visibility to what is happening within the cloud.

 

By implementing a cloud services security strategy designed for healthcare, organizations adopt a set of policies, controls, procedures and technologies that work in tandem to protect cloud-based systems, e.g. electronic health records. 

 

5. End-user education and awareness 

 

As employees continue to work from home, Kennedy argues that “it is vital to protect users, to make sure they are educated.” 

 

With a vast array of unfamiliar technologies now indispensable for remote support and function, employees must be educated on VPN use, routers and firmware updates. Without this continuing education, an important frontline in your organization’s cyber-defense strategy is weakened.  

 

Working in conjunction, these five strategies can dramatically improve your organization’s cybersecurity posture reducing the risk of a HIPAA breach or disruption in the provision of care. 

 

To learn more about protecting your organization from the threat of a breach, watch the webinar in its entirety here.

 

1 Binary Defense

 

 


About the Author

Bob Bowes, Director, Enterprise Security

Bob is a seasoned professional with over two decades of experience in Healthcare Information Technology, spanning various roles from development/QA and technical support to project and production management. His expertise also encompasses system engineering, operations, and security. Since joining Netsmart in 2017, Bob has been instrumental in driving technological advancements in healthcare. He holds a Bachelor of Science in Health Information Administration from the University of Kansas (2000) and a Masters in Business Administration from Baker University (2006).

Meet the Author

bob-bowes-photo
Bob Bowes · Director, Enterprise Security

From the CareThreads Blog

Justice-Involved Initiative: How Providers Can Help Bring Equitable Care

Monday, July 22 | Care Coordination,Human Services,Legislative/Policy

Californians who have spent time in jails, prisons or youth correctional facilities face a higher risk for both physical and mental illness. The number of incarcerated Californians with a mental health diagnosis rose by 63 percent in the last decade, and 66 percent of those currently incarcerated require substance use treatment. But even after their release, overdose is the leading cause of death for Californians who have been justice-involved––at a rate three times higher than other states.

More
Blog Client Satisfaction Blog Doctor using Netsmart Applications to help Patient

How and When to Analyze & Update Internal & External Medical Clinic Policies

Sunday, July 21 | Partnerships and Collaboration,Thought Leadership

Updating clinic policies and procedures ensures compliance and reduces risks. Learn how to review medical clinic policies and align with best practices.

More

Emergency Preparedness and Population Health: Understanding Your Data for Mobilization

Friday, July 19 | Care Coordination,Interoperability,Human Services

Rapid and effective crisis response—whether natural disasters, pandemics or other emergencies—can save lives. A modern data strategy, driven by actionable insights, is vital for ensuring sustainability, growth and the acceleration of mission-driven outcomes.

More