Risk
10/18/2012
04:00 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Health Data Breach Response: Culture Change Needed

Seattle Children's Hospital CISO builds incident response team and culture of continuous improvement concerning data breaches.

7 E-Tools To Keep Patients Engaged
7 E-Tools To Keep Patients Engaged
(click image for larger view and for slideshow)
Someone has to be accountable for every part of managing a data breach incident, according to Cris Ewell, chief information security officer at Seattle Children's Hospital.

"It's bigger than privacy and security … it's about involving everyone in the organization at the highest level down to the help desk level [people] who are inputting calls into the system," he said. In a recent webinar hosted by ID Experts, Ewell said that in addition to accountability, there needs to be a shift in organizational culture to combat breaches.

Seattle Children's is a not-for-profit hospital and the academic research center for the University of Washington. It deals mainly with research, genetics and diseases, bioethics, and all avenues of pediatric care.

Ewell said the culture within his organization has changed since he implemented an incident response team. For instance, the employees at Seattle Children's have learned to expect breaches, no matter what they do to prevent them. "It's not a matter of if, but when," he said. The hospital operates under the assumption that "people will get in and there will be issues. You need to have that expectation that it's going to happen no matter what you do."

Ewell advises considering setting up outside help before an incident occurs. A small breach of 4,000 or 5,000 patients, he said, could be handled by the organization itself. But a larger breach might require additional help, such as call center professionals and interpreters. "You can do a lot in-house, but you have to have the ability to ad hoc within a short period of time for a large incident," he said.

Management should not be caught off guard by a breach, and should plan to be flexible enough to spend time rectifying problems, said Ewell. "Sometimes, we lack time and resources, and that's an element we see when you have a big or moderate incident," he said. "I've worked with small to large [breaches], and it's different depending on what resources you need, but you need to plan for that: incident response versus incident management. You want to get management pre-planning ahead of time and not just being active when you have an incident."

[ What about natural disasters? See Health IT Offers Safe Haven In A Storm. ]

Determining whether there is a breach in the first place can be one of the hardest tasks, said Ewell, followed by determining what the risk is to the institution and what patient data might have been compromised. "Part of our process is to determine that motive and intent," he said. Documentation of a breach is key. "With all breaches, tell the story: why did it happen and why did that person want that information."

"It helps me paint a picture and determine what the risks are," Ewell said. In order to meet the requirements of the Health Insurance Portability and Accountability Act, he said, an organization needs to determine if there was significant financial harm or harm of another kind done to the patient. It also needs to have documentation in place to show processes that were undertaken, and why it did or did not notify patients.

At Seattle Children's, Ewell and his team always circle back after an incident to see whether they can improve their processes, he said. "It's a continual loop of reviewing and assessing. That 60-day time limit: once you identify an incident, it gets spun up quickly and you have to make a determination of who to notify; that will keep going until the incident is done."

InformationWeek Healthcare brought together eight top IT execs to discuss BYOD, Meaningful Use, accountable care, and other contentious issues. Also in the new, all-digital CIO Roundtable issue: Why use IT systems to help cut medical costs if physicians ignore the cost of the care they provide? (Free with registration.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
jaysimmons
50%
50%
jaysimmons,
User Rank: Apprentice
10/23/2012 | 12:05:03 AM
re: Health Data Breach Response: Culture Change Needed
Regardless of what measures you put in place, data breeches and unauthorized access will always occur in a large organization with so many people requiring access to data. Seattle ChildrenGÇÖs Hospital is handling the situation correctly by fostering a culture that continuously provides feedback of breeches, and improving upon the weaknesses. Treating data breeches as an opportunity to improve current practices, rather than trying to cover them up, will only result in better policies and smaller scale breeches in the future. An organization must always be prepared for a large-scale data breech because of the resources required to stay within the 60 day time limit, regardless of how probable it may be because the possibility is always there and the result can be crippling.

Jay Simmons
Information Week Contributor
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2188
Published: 2015-02-26
The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from RADIUS and TACACS+ servers, which allows remote attackers to bypass authentication in opportunistic circumstances via a connection attempt that triggers an invalid code, as demonstrated by a connecti...

CVE-2015-0594
Published: 2015-02-26
Multiple cross-site scripting (XSS) vulnerabilities in the help pages in Cisco Common Services, as used in Cisco Prime LAN Management Solution (LMS) and Cisco Security Manager, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCuq54654 and CSCun1...

CVE-2015-0632
Published: 2015-02-26
Race condition in the Neighbor Discovery (ND) protocol implementation in Cisco IOS and IOS XE allows remote attackers to cause a denial of service via a flood of Router Solicitation messages on the local network, aka Bug ID CSCuo67770.

CVE-2015-0651
Published: 2015-02-26
Cross-site request forgery (CSRF) vulnerability in the web GUI in Cisco Application Networking Manager (ANM), and Device Manager (DM) on Cisco 4710 Application Control Engine (ACE) appliances, allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuo99753.

CVE-2015-0882
Published: 2015-02-26
Multiple cross-site scripting (XSS) vulnerabilities in zencart-ja (aka Zen Cart Japanese edition) 1.3 jp through 1.3.0.2 jp8 and 1.5 ja through 1.5.1 ja allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, related to admin/includes/init_includes/init_sanitize.php an...

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.