Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Cybersecurity & Healthcare: Does Cybersecurity Act Help or Hurt?
Newest First  |  Oldest First  |  Threaded View
ChloeMica
50%
50%
ChloeMica,
User Rank: Apprentice
2/17/2016 | 3:18:41 AM
Re: Bankers and financiers have a direct understanding of risk, healthcare pros see risk differently
Improving operational efficiency and reducing cost, while also improving the quality of care is a global healthcare challenge.

Creative Peptides
royhugginsms
50%
50%
royhugginsms,
User Rank: Apprentice
2/13/2016 | 4:01:36 PM
Bankers and financiers have a direct understanding of risk, healthcare pros see risk differently
Firtly, thank you for this essay. It hits a lot of my frustration points, most especially the fact that committees trying to develop best practices could never keep up with security needs.

As a health care guy (mental health) who spends a lot of time consulting and training other health care pros on security in their small practices, I can say that we don't have a solid idea of risk management as a paradigm for protecting information. We work with risk all the time in clinical contexts, e.g. risk of self-harm or risk that certain activities or treatments could result in harm to a client/patient.

The idea of information security, however, is entirely grounded in "best practices" for us. Clinicians look to professional organizations for these best practices, and those orgs have little-to-no idea how to manage them.

When administrators try to advise and guide clinicians according to regs like HIPAA, we often chafe against it because those administrators are usually focused on the concept of "compliance," which feels antithetical to the concept of "care."

My point is: I think healthcare will continue to have significant security issues until healthcare professionals and security professionals learn to understand each other, much like healthcare pros and attorneys have managed to do over the years. 

 
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
2/12/2016 | 3:01:40 PM
Red Tape, Red Coffers
I pretty much agree with you here.  And, oh God - I actually read the whole subsection on Healthcare, including a good portion of the Cybersecurity Information Sharing Act of 2015.  What is it about formal Government process that just screams bleeding coffers from the outset?  Not to mention the muddled standards that are hard-to-read and inspire reactions of "yeah, obvious" and "in what world are you living".  

In the time it took to draft the Act, the game changed.  In the time it takes to pass the Act, the game will have changed again.  In the time it takes to form committees, auditing teams, processes, checks and balances...  

You called it: Healthcare needs to treat security the way Financial institutions (finally) are starting to.  Don't look to Government standards or regulations; get on the ball and hire the right InfoSec resources who are current, relevant and part of the hacking landscape.

As always, the distance between the Red Tape lovers and the tech community is light-years apart.

  


Commentary
How SolarWinds Busted Up Our Assumptions About Code Signing
Dr. Jethro Beekman, Technical Director,  3/3/2021
News
'ObliqueRAT' Now Hides Behind Images on Compromised Websites
Jai Vijayan, Contributing Writer,  3/2/2021
News
Attackers Turn Struggling Software Projects Into Trojan Horses
Robert Lemos, Contributing Writer,  2/26/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-27907
PUBLISHED: 2021-03-05
Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information. Abusing this functionality, a malicious user could inject javascript code executing unwanted action in the context of the user's browser. The javasc...
CVE-2021-20663
PUBLISHED: 2021-03-05
Cross-site scripting vulnerability in in Role authority setting screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type 6.7.5 and earlier (Movable Type 6.7 Series), Movable Type Premium 1.39 and ea...
CVE-2021-20664
PUBLISHED: 2021-03-05
Cross-site scripting vulnerability in in Asset registration screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type 6.7.5 and earlier (Movable Type 6.7 Series), Movable Type Premium 1.39 and earlie...
CVE-2021-20665
PUBLISHED: 2021-03-05
Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.39 and earlier, and Movable Type Premium Advanced 1.39 and ear...
CVE-2021-28031
PUBLISHED: 2021-03-05
An issue was discovered in the scratchpad crate before 1.3.1 for Rust. The move_elements function can have a double-free upon a panic in a user-provided f function.