• About
  • Advertise
  • Contact
Saturday, September 23, 2023
24Newsy.com | Daily News
No Result
View All Result
  • International
  • Auto
  • Business
  • Entertainment
  • Gaming
  • Health
  • Lifestyle
  • Travel
  • Technology and Science
  • Sports
24Newsy.com | Daily News
  • International
  • Auto
  • Business
  • Entertainment
  • Gaming
  • Health
  • Lifestyle
  • Travel
  • Technology and Science
  • Sports
No Result
View All Result
24Newsy.com | Daily News
No Result
View All Result
Home Health

HHS cybersecurity leaders want healthcare industry accountability, but pledge support

24 Newsy by 24 Newsy
2 weeks ago
in Health
0
HHS cybersecurity leaders want healthcare industry accountability, but pledge support

HHS cybersecurity leaders want healthcare industry accountability, but pledge support

Share on FacebookShare on Twitter

BOSTON – At the HIMSS Healthcare Cybersecurity Forum on Thursday, Erik Decker, chief information security officer at Intermountain Health, led a discussion with cybersecurity leaders from the U.S. Department of Health and Human Services to talk about how the agency is driving accountability and competency in cybersecurity.

Decker was joined by Commander Thomas Christl, Director of the HHS’s Office of Critical Infrastructure Protection in the Administration for Strategic Preparedness and Response, Nicholas Heesters, Senior Advisor for Cybersecurity for the Office of Civil Rights and Nick Rodriguez, manager of the HHS 405(d) program.

Related posts

DEA suggests 2nd comment period for post-PHE online Rx registration

DEA suggests 2nd comment period for post-PHE online Rx registration

23/09/2023
Roundup: Pacific Health Info Hub project launched and more briefs

Roundup: Pacific Health Info Hub project launched and more briefs

22/09/2023

A ‘sea change’ in approach to risk management

Christl said there have been a lot of conversations recently within HHS about how his ASPR department can approach healthcare and public health sector cybersecurity more “holistically” – better and help HHS in its role as the Sector Risk Management Agency for healthcare under the Cybersecurity and Infrastructure Security Agency.

There’s been a “sea change in how we’re approaching cyber as the SRMA in ways that we couldn’t even have imagined two or three years ago,” he said.

Working with CISA and private sector partners, ASPR has plans to build its cyber capacity, is investing in cyber incident tracking and has released the Risk Identification and Site Criticality toolkit, a 94-question assessment built off the NIST Cybersecurity Framework. 

The tool will give HHS the ability to do anonymous aggregate data on the state of the sector, said Christl, who noted that ASPR may also have more staffing or resource capacity, too. “We’re getting an investment from our senior leadership,” which will allow HHS’s preparedness and response function “to do more at all levels.”

In response to a question about threat intelligence information sharing, Christl said that the agency is looking at how to downgrade and declassify information through “traffic light protocols” to make it “consumable” and helpful to HIT, and is also looking at adding full-time liaisons with the FBI and CISA to facilitate that. 

New resource for 405(d)

Decker provided a brief background on the 405(d)-sponsored landscape analysis, which he said aligns with the Healthcare Industry Cybersecurity Practices update released at HIMSS23 in April.

That analysis of what healthcare organizations are doing well and where they come up short gave HHS a road map, while it provides organizations data to benchmark themselves against their peers based on size and other factors, Rodriguez said.

Rodriguez said the 405(d) program is focused on working with ASPR and integrating their data and building their support to better support the industry “to produce more documents, to produce more trainings – to produce more education” and also provide direct outreach to small health systems.

Coupled with the recent HICP refresh, HHS is also offering new knowledge-on-demand. A four-part, free education and training program is designed for end user-training, and the files are available to download for organizations that have their own learning systems, he noted.

In the near future, 405(d) will also release a cyber enterprise risk management publication and an updated joint operational checklist for the first 12 hours after a cyber event, Rodriguez said.

How HICP can help with OCR investigations

Heesters said OCR has received more than 30,000 complaints about potential violations of health information privacy or security and more than 700 breach notifications for 2022.

Decker asked Heesters how new considerations under the HITECH Act give healthcare organizations a leg up on investigations if they have implemented HICP and other 405(d) guidance. 

Given that the regulations are designed to be non-prescriptive, Heesters said he believes that the specific actionable items in HICP are helpful to organizations for thinking about how to better fortify their environments and protect ePHI. He named HICP’s risk analysis, endpoint control, asset inventory, multi-factor authentication and other network security protocols.

Many of the items have a direct correlation to security requirements. 

“So even though the security rule is non-prescriptive, the requirements are to protect health information,” Heesters said.

For example, he said the section on phishing simulation exercises “dovetails very well” with the requirement for providing security reminders that entities must meet.

Andrea Fox is senior editor of Healthcare IT News.
Email: afox@himss.org
Healthcare IT News is a HIMSS Media publication.

ShareTweet
Previous Post

NBA 2K24 Rebirth – Where To Find Ronnie 2K

Next Post

Ashton Kutcher, Mila Kunis respond to backlash over their letters supporting Danny Masterson

Next Post
Ashton Kutcher, Mila Kunis respond to backlash over their letters supporting Danny Masterson

Ashton Kutcher, Mila Kunis respond to backlash over their letters supporting Danny Masterson

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

Italian PM Meloni leaves G7 early to deal with worst flood in a century

Italian PM Meloni leaves G7 early to deal with worst flood in a century

4 months ago
Gamma ray detection marks highest energy light from the Sun

Gamma ray detection marks highest energy light from the Sun

2 months ago
Can The NBA’s Experimental Endgame Make It To Games That Count?

Can The NBA’s Experimental Endgame Make It To Games That Count?

7 months ago
Damaged Soyuz spacecraft returns to Earth without crew

Damaged Soyuz spacecraft returns to Earth without crew

6 months ago

BROWSE BY CATEGORIES

  • Auto
  • Business
  • Entertainment
  • Gaming
  • Health
  • International
  • Lifestyle
  • Others
  • Sports
  • Technology and Science
  • Travel

BROWSE BY TOPICS

2023 AI Benjamin Irish Bigfoot Bigfoot Bob Gymlan Bob Gymlan Call Of Duty ChatGPT China Club of Angry Patriots DocsGPT electric vehicles Erdogan Gamers8 Games Google Street View Holidays HSBC Igor Girkin jacket Jocko Willink Lithuania London Lord Of The Rings Maldives mattresses Mercedes Metaverse Microsoft NBA Octopath Traveler 2 OpenAI PVC Restoring Rexfel Russia Safari SEO SVB Taiwan The Mukaab Ukraine Wagner Group war Warren Buffett

POPULAR NEWS

  • Irish sustains head injury in car accident

    Irish sustains head injury in car accident

    0 shares
    Share 0 Tweet 0
  • It’s Called Crash Casting

    0 shares
    Share 0 Tweet 0
  • The Metaverse: What it is and Why it Matters

    0 shares
    Share 0 Tweet 0
  • China’s role in the Russia-Ukraine conflict: promoting peace and negotiations

    0 shares
    Share 0 Tweet 0
  • Five tips for municipalities to prepare for the electric mobility era

    0 shares
    Share 0 Tweet 0
24Newsy.com | Daily News

24Newsy.com | Daily News

Follow us on social media:

DEA suggests 2nd comment period for post-PHE online Rx registration

DEA suggests 2nd comment period for post-PHE online Rx registration

23/09/2023
The 7 Best Running Strollers According to One Running, Stroller-ing Dad

The 7 Best Running Strollers According to One Running, Stroller-ing Dad

23/09/2023

Category

  • Auto
  • Business
  • Entertainment
  • Gaming
  • Health
  • International
  • Lifestyle
  • Others
  • Sports
  • Technology and Science
  • Travel
  • About
  • Advertise
  • Contact

@ 2023 | 24Newsy.com | Daily News Tiksaviems.LT - EntreNosotros.ES - CBDnutzen.DE - 365Nachrichten.DE - mobellex.DE - CBDtropf.DE - Rexfel.COM

No Result
View All Result
  • Home
  • International
  • Auto
  • Business
  • Gaming
  • Entertainment
  • Travel
  • Technology and Science
  • Health
  • Lifestyle
  • Sports

@ 2023 | 24Newsy.com | Daily News Tiksaviems.LT - EntreNosotros.ES - CBDnutzen.DE - 365Nachrichten.DE - mobellex.DE - CBDtropf.DE - Rexfel.COM