Healthcare is full of tensions. For security professionals at innovative health systems, one tension that can be hard to navigate is the pull between innovation and caution, a topic several experts discussed last month at the Healthcare Security Forum in Boston.
The job of the CISO is to say no, to look at risk, John Halamka, president of the Mayo Clinic Platform, said at the event. I had a CISO once tell me The most secure library never checks out any books.Well thats true, but that would be a somewhat useless library.
That perception of the security team, as the gatekeeper of progress, needs to be actively overcome, said Karl West, CISO and AVP at Intermountain Healthcare.
You as CISOs, you set a tone, he said. I was invited to speak to a group of CEOs of large healthcare groups in America earlier this year. [One thing they told me was] the 'Dr. No' issue is associated with who we are as part of our identity. We have to change that. If youve listened to us talk about consumerism, go away with this message: You can change that on your teams. Hold people accountable. [For] my employees goals every year, one is to be an enabler, to make this frictionless.
Sunita Patolia, team lead for human-centered design at Partners Healthcare Pivot Labs, agrees.
Language is so important, she said. Establishing the right kind of language in your organization, from the CEO to the front line. It has to stay the same: the message, the language and I think that gives people safety to experiment with different things because you all know youre working toward the same goal.
One goal shared by many innovative hospitals across the country is bringing more care out of the hospital and into the home a prospect that excites clinicians but is likely to worry security professionals, who have to concern themselves not only with data security, but also privacy, and not just with legal responsibilities but also ethical ones.
Although consumers want to take part in healthcare, we also have to educate them,Anahi Santiago, CISO at ChristianaCare, said. They want to bring in apps. They want to download the medical record to an app of their choosing, but we have a social and ethical responsibility to make sure that were educating them and ensuring them that the app they want to bring is protecting their information. Althoughonce that information leaves our ecosystem and ends up in their devices its technically, legally, not our issue, we still have an ethical responsibility to make sure were educating them and that they understand that there are risks.
Not only do CISOs need to be thinking about patient education, they need to make sure physicians are educated about security issues, at least enough to know how to spot potential issues and where to direct inquiries from patients.
Whats happening now is that a Medtronic vulnerability for the insulin pumps is showing up on the news and patients are coming to our physicians to say Hey, I have this device that I bought at home. I saw in this news article that theres a vulnerability. What should I do? Santiago said. And the physicians are not educated enough to respond, but they need to be. So as CISOs, we need to become educators to our clinicians and our patients and to our stakeholders to make sure that they understand some level of cybersecurity so we can bridge the gap of this new ecosystem of healthcare. So from the hospital to the home, cybersecurity is now a conversant topic across the ecosystem.
On a systemic side, theres some work underway to build cybersecurity into the medical education curriculum for residents, Santiago said. But given the speed at which the industry moves, that wont be a substitute for ongoing education and conversations.
We are going to have to change, West said. It will make us uncomfortable. So we are going to have to figure out how to do what has to be done.
I think we all agree that security is completely foundational, added Halamka. So as we now do more partnerships and we think of more platforms, security has to be at the very base of everything that you do. Understand what data youre exchanging, for what purpose, data governance, and even ethical uses of data.
Excerpt from:
As healthcare moves to the home, CISOs can't be 'Dr. No' - MobiHealthNews
- Green with Envy | How to Spot an Eco-Snob | Part III - November 8th, 2009 [November 8th, 2009]
- EcoLogo - November 8th, 2009 [November 8th, 2009]
- 5 Ways to Green Your Exercise Routine - November 8th, 2009 [November 8th, 2009]
- Seed Bombs - November 8th, 2009 [November 8th, 2009]
- Guerrilla gardening - November 8th, 2009 [November 8th, 2009]
- Green Your Morning Routine - November 8th, 2009 [November 8th, 2009]
- Environmental Benefits of Telecommuting - November 8th, 2009 [November 8th, 2009]
- Safeway Sponsors Portland Community Cleanup - November 8th, 2009 [November 8th, 2009]
- Electric Vehicle Race - November 8th, 2009 [November 8th, 2009]
- Portland Bridge Pedal 2009 - November 8th, 2009 [November 8th, 2009]
- E-waste in Oregon - November 8th, 2009 [November 8th, 2009]
- Bike Sharing in Portland - November 8th, 2009 [November 8th, 2009]
- Bucks for the Bay Challenge - November 8th, 2009 [November 8th, 2009]
- Drive to Make a Difference with MyMPG - November 8th, 2009 [November 8th, 2009]
- Bathroom Sprayers - Green your Toilet Routine - November 8th, 2009 [November 8th, 2009]
- Ubuntu OS can Save Energy - November 8th, 2009 [November 8th, 2009]
- Green Metropolis, David Owen - November 8th, 2009 [November 8th, 2009]
- Sustainable Pens: GLO Pens - November 8th, 2009 [November 8th, 2009]
- International Day of Climate Action - November 8th, 2009 [November 8th, 2009]
- Donate to Oregon Toxics Alliance - November 8th, 2009 [November 8th, 2009]
- Biomass Energy Generation Myths - November 8th, 2009 [November 8th, 2009]
- Crude The Real Price of Oil | Playing in Portland - November 8th, 2009 [November 8th, 2009]
- Pictures From 350 Climate Day in Portland - November 8th, 2009 [November 8th, 2009]
- Arcimoto Electric Vehicles in Oregon - November 8th, 2009 [November 8th, 2009]
- Urban Rooftop Wind Turbines - November 8th, 2009 [November 8th, 2009]
- Chromium 6 Emissions from ESCO in Portland - December 13th, 2009 [December 13th, 2009]
- Food Inc. Review - December 19th, 2009 [December 19th, 2009]
- Making Maps with Google Earth and Google Maps by Shane Bradt of the University of New Hampshire Cooperative Extension - March 23rd, 2010 [March 23rd, 2010]
- Demonstration of Miradi 3.1 by Nick Salafsky of Foundations of Success - March 23rd, 2010 [March 23rd, 2010]
- Advanced Mashups – KML and the Mapping API by Cary Chadwick of the University of Connecticut Center for Land Use Education and Research - March 23rd, 2010 [March 23rd, 2010]
- Demonstration of InVEST by Heather Tallis of the Natural Capital Project - March 23rd, 2010 [March 23rd, 2010]
- GIS Maps Online by Emily Wilson of the University of Connecticut Center for Land Use Education and Research - March 23rd, 2010 [March 23rd, 2010]
- From ArcGIS to Web Maps: Simple Techniques for Publishing GIS Maps Online by Emily Wilson of the University of Connecticut Center for Land Use Education and Research - March 25th, 2010 [March 25th, 2010]
- Demonstration of Marine InVEST by Anne Guerry of the Natural Capital Project - March 31st, 2010 [March 31st, 2010]
- Eliminate and Decrease Styrofoam - March 31st, 2010 [March 31st, 2010]
- Portland Plans to Spend $600 million on Master Bike Plan - April 2nd, 2010 [April 2nd, 2010]
- (Webinar in Spanish) Demostración sobre Vista 2.5 de NatureServe en línea (Webinar) por Ian Varley, Carmen Josse, y Alexandra Sanchez de Lozada de NatureServe. - April 6th, 2010 [April 6th, 2010]
- Using and Adding Your Content to Google Ocean by Charlotte Vick, Google Content Manager of Mission Blue - April 13th, 2010 [April 13th, 2010]
- End Paper Receipts - May 1st, 2010 [May 1st, 2010]
- Demonstration of CanVis by Chris Haynes of NOAA Coastal Services Center - May 6th, 2010 [May 6th, 2010]
- Demonstration of HD.gov Web Portal by Jeff Adkins from NOAA Coastal Services Center - May 13th, 2010 [May 13th, 2010]
- Demonstration of Ecosystem Assessment and Reporting Tool by Steve Schill of The Nature Conservancy - May 13th, 2010 [May 13th, 2010]
- Demonstration of Version 2.0 of the Multipurpose Marine Cadastre by Adam Bode and Brian Smith of NOAA Coastal Services Center - May 17th, 2010 [May 17th, 2010]
- CRUDE Filmmakers Subpoenaed by Chevron - May 22nd, 2010 [May 22nd, 2010]
- Demonstration of the Digital Coast Coastal Inundation Toolkit by Steph Beard, Jodie Sprayberry and Billy Brooks of NOAA Coastal Services Center - May 25th, 2010 [May 25th, 2010]
- Presentation on the Creating Resilient Communities EBM Tool Demonstration Project by Jocelyn Hittle of PlaceMatters - June 10th, 2010 [June 10th, 2010]
- Presentation on Economic Data Needed for EBM by Linwood Pendleton of Duke University - October 11th, 2010 [October 11th, 2010]
- Recycling Water - October 16th, 2010 [October 16th, 2010]
- ODOT Partners with Oregon Toxics Alliance to Reduce Pesticides - October 17th, 2010 [October 17th, 2010]
- Goats Hired to Mow Portland Lot - October 17th, 2010 [October 17th, 2010]
- A World of Health: Connecting People, Place, and Planet - October 17th, 2010 [October 17th, 2010]
- Alternative Recycling Options - October 17th, 2010 [October 17th, 2010]
- No More Bullying the Bull Trout - October 17th, 2010 [October 17th, 2010]
- 1000+ EV Charging Stations Slated for Oregon I-5 Corridor - October 17th, 2010 [October 17th, 2010]
- The Vertical Farm Concept - October 17th, 2010 [October 17th, 2010]
- Blog Action Day 2010 | Water - October 17th, 2010 [October 17th, 2010]
- Eco Districts - October 24th, 2010 [October 24th, 2010]
- Will The Nissan Leaf Thrive? - October 24th, 2010 [October 24th, 2010]
- A Green Railroad - October 24th, 2010 [October 24th, 2010]
- Biomass is not Oregon's clean-energy future as currently promoted - October 24th, 2010 [October 24th, 2010]
- Electrified Parking Spaces - October 24th, 2010 [October 24th, 2010]
- Tree Planting - October 24th, 2010 [October 24th, 2010]
- Three Tips to Reduce Your Carbon Footprint and Live Longer. - October 24th, 2010 [October 24th, 2010]
- Biomass is not Oregon’s clean-energy future as currently promoted - October 31st, 2010 [October 31st, 2010]
- Rail~Volution - October 31st, 2010 [October 31st, 2010]
- Green Streets Initiative - October 31st, 2010 [October 31st, 2010]
- Mayor Kitty Piercy and Envision Eugene - November 7th, 2010 [November 7th, 2010]
- The Willamette River Transit Bridge - November 13th, 2010 [November 13th, 2010]
- Collaborative Learning and Land Use Tools to Support Community Based Ecosystem Management by Chris Feurt of the Wells National Estuarine Research Reserve - November 14th, 2010 [November 14th, 2010]
- Portland Federal Building Begins Green Makeover - November 14th, 2010 [November 14th, 2010]
- Vestas’ New HQ in Portland Shoots for LEED Platinum - November 14th, 2010 [November 14th, 2010]
- College Degrees to Get You in the Environmental Field - November 14th, 2010 [November 14th, 2010]
- Demonstration of openNSPECT, an Open Source Version of the Nonpoint-Source Pollution and Erosion Comparison Tool by Dave Eslinger of NOAA Coastal Services Center - February 14th, 2011 [February 14th, 2011]
- Demonstration of EMDS by Keith Reynolds of the US Forest Service - February 14th, 2011 [February 14th, 2011]
- Demonstration of Habitat Priority Planner by Chrissa Waite and Danielle Bamford of NOAA Coastal Services Center - February 14th, 2011 [February 14th, 2011]
- Presentation on the Coastal Adaptation to Sea Level Rise Tool (COAST) by Sam Merrill of the New England Environmental Finance Center - February 14th, 2011 [February 14th, 2011]
- Presentation on the Coastal and Marine Ecological Classification Standard by Kathy Goodin of NatureServe - February 14th, 2011 [February 14th, 2011]
- Demonstration of Coral Reef Scenario Evaluation Tool (CORSET) by Jessica Melbourne-Thomas of the University of Tasmania - February 14th, 2011 [February 14th, 2011]
- Demonstration of Multi-scale Integrated Models of Ecosystem Services (MIMES) by Roel Boumans and David McNally of AFORDable Futures LLC - February 14th, 2011 [February 14th, 2011]
- Creating Life in the Desert - February 14th, 2011 [February 14th, 2011]