Top Banner
GNYHA & CYBERSECURITY April 26, 2018
12

GNYHA & Cybersecurity › wp-content › uploads › 2018 › 05 › 5-Logan-_G… · Attention at Federal level Cybersecurity Act of 2015 Health Care Industry Cybersecurity (HCIC)

Jun 25, 2020

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: GNYHA & Cybersecurity › wp-content › uploads › 2018 › 05 › 5-Logan-_G… · Attention at Federal level Cybersecurity Act of 2015 Health Care Industry Cybersecurity (HCIC)

GNYHA & CYBERSECURITYApril 26, 2018

Page 2: GNYHA & Cybersecurity › wp-content › uploads › 2018 › 05 › 5-Logan-_G… · Attention at Federal level Cybersecurity Act of 2015 Health Care Industry Cybersecurity (HCIC)

□Cybersecurity concerns expand as industries modernize

□Healthcare sector has gone digital, largely insecurely

□ Greater than 95% EHR utilization exposed to threats emanating

from employees to sophisticated cybercriminals

□ $$ for PHI on the dark web

□ Ransomware most common attack vector

□ Lost revenue and reputational damage for impacted facility

Overview: Cybersecurity in Healthcare 2

Page 3: GNYHA & Cybersecurity › wp-content › uploads › 2018 › 05 › 5-Logan-_G… · Attention at Federal level Cybersecurity Act of 2015 Health Care Industry Cybersecurity (HCIC)

3

Page 4: GNYHA & Cybersecurity › wp-content › uploads › 2018 › 05 › 5-Logan-_G… · Attention at Federal level Cybersecurity Act of 2015 Health Care Industry Cybersecurity (HCIC)

4

Page 5: GNYHA & Cybersecurity › wp-content › uploads › 2018 › 05 › 5-Logan-_G… · Attention at Federal level Cybersecurity Act of 2015 Health Care Industry Cybersecurity (HCIC)

□Attention at Federal level □ Cybersecurity Act of 2015

□ Health Care Industry Cybersecurity (HCIC) Task Force Report

□ CISA 405(d)

□Attention from NYS□ NYS DOH Medicaid increased security to

protect sharing of Medicaid data

□Attention in NYC □ NYC CISO/DA/NYP Cyber Command

Overview: Cybersecurity in Healthcare 5

Graphic from CISA 405(d) draft report

Page 6: GNYHA & Cybersecurity › wp-content › uploads › 2018 › 05 › 5-Logan-_G… · Attention at Federal level Cybersecurity Act of 2015 Health Care Industry Cybersecurity (HCIC)

□ Agency Players:

□ Preparedness (ex. DHS, HHS)

□ Response (ex: FBI, NYPD)

□ Recovery (ex: DOH, DHS)

□ Regulatory (ex: CMS/OCR)

Overview: Cybersecurity in Healthcare 6

Graphic from HCIC Task Force Report 2017

Page 7: GNYHA & Cybersecurity › wp-content › uploads › 2018 › 05 › 5-Logan-_G… · Attention at Federal level Cybersecurity Act of 2015 Health Care Industry Cybersecurity (HCIC)

□ Interdisciplinary team model:

□ Emergency preparedness

□ Legal

□ Health information technology

□ Regulatory

□ Supply chain

GNYHA & Cybersecurity 7

Page 8: GNYHA & Cybersecurity › wp-content › uploads › 2018 › 05 › 5-Logan-_G… · Attention at Federal level Cybersecurity Act of 2015 Health Care Industry Cybersecurity (HCIC)

□Past and Existing Programs & Resources:

□ (Event) GNYHA & NYCDOHMH Emergency Preparedness

Symposia/Cybersecurity: Included CIO of Hollywood

Presbyterian Medical Center discussing ransomware attack

□ (Event) GNYHA & DHS Tabletop Exercise

□ (Resource) Hospital Guide to Cybersecurity

Reporting/Resources

□ (Business Offering) Cybersecurity Targeted Solution Set

GNYHA & Cybersecurity 8

Page 9: GNYHA & Cybersecurity › wp-content › uploads › 2018 › 05 › 5-Logan-_G… · Attention at Federal level Cybersecurity Act of 2015 Health Care Industry Cybersecurity (HCIC)

9

Page 10: GNYHA & Cybersecurity › wp-content › uploads › 2018 › 05 › 5-Logan-_G… · Attention at Federal level Cybersecurity Act of 2015 Health Care Industry Cybersecurity (HCIC)

□Events & Resources Continued –

□ (Event) Threat Briefing with DHS

□ (Event) Erie County Medical Center shares Lessons

Learned from Cyber Attack

□ (Event) Cyberattack at the Bedside: Live Simulation for

Clinicians

□ (Event) Cybersecurity Webinar with Drs. Halamka and

Baker

GNYHA & Cybersecurity 10

Page 11: GNYHA & Cybersecurity › wp-content › uploads › 2018 › 05 › 5-Logan-_G… · Attention at Federal level Cybersecurity Act of 2015 Health Care Industry Cybersecurity (HCIC)

□Upcoming Events and Sharing of Relevant Information

□ (Event) Cybersecurity Tactical Simulation (CTS) with vendor

Sensato

□ (Event) Cybersecurity Insurance Webinar

□ (Member Info) Cybersecurity Bulletin: GNYHA Cyber Team

continues to send relevant cyber alerts and recommendations

GNYHA & Cyber 11

Page 12: GNYHA & Cybersecurity › wp-content › uploads › 2018 › 05 › 5-Logan-_G… · Attention at Federal level Cybersecurity Act of 2015 Health Care Industry Cybersecurity (HCIC)

□What are your biggest concerns related to cybersecurity

preparedness and response?

□Who is involved in planning efforts at your facility/system?

□How can GNYHA assist your facility/system in this area?

Conclusion & Suggested Next Steps12

Logan A. Tierney Project Manager, Regulatory and Professional Affairs GREATER NEW YORK HOSPITAL ASSOCIATIONphone: 212.554.7207email: [email protected]