H-ISAC Hacking Healthcare 7-16-19
#Alexa, #Cloud, State Cyber Resiliency Act
TLP White: In this edition of Hacking Healthcare, we discuss a unique partnership between Alexa and the UK’s National Health Service. We then check in on resistance to Cloud adoption in the Healthcare industry. Finally, we examine the lack of sufficient cybersecurity at the state level and what is being done to improve it.
As a reminder, this is the public version of the Hacking Healthcare blog. For additional in-depth analysis and opinion, become a member of H-ISAC and receive the TLP Amber version of this blog (available in the Member Portal.)
Welcome back to Hacking Healthcare.
Hot Links –
1. Alexa.
If you ask anyone how they envision new technologies will revolutionize the healthcare industry, they’ll likely reference developments in AI and machine learning and how they are increasing the speed and accuracy of diagnoses.[1] Perhaps they’d mention how they recently read about robotics being incorporated into surgical procedures to increase precision and control, or even how embracing cloud technology and prioritizing interoperability is ensuring that healthcare providers can quickly and securely access patient data whenever and wherever it’s needed.[2]
All of these use cases are rapidly becoming part of routine reality, but a recent agreement in the UK is attracting attention for using the rapid growth of IoT, in this case virtual assistants, to tackle a more fundamental issue—access to basic health advice and information. The UK’s National Health Service (NHS) has partnered with Amazon to provide accurate, basic healthcare advice through Amazon’s Alexa. In a world clouded with misinformation, and where anyone can post anything on the Internet, the ability to receive professionally vetted medical advice by simply asking “Alexa, how do you treat allergies?” is an interesting development. NHS hopes that this partnership will have a beneficial effect on the quality of medical advice given to individuals, while also alleviating some of the strain placed on primary healthcare providers by reducing the number of face-to-face visits for trivial issues.[3]
NHS’s view is that Amazon Alexa represents a novel way of using cutting edge technology to improve healthcare generally and it has an added benefit to users who can now receive trusted medical advice from a reputable source. It is currently unclear if this new use case will extend to geographical areas beyond the UK.
2. Bringing Cloud Back to Earth.
The Cloud has been touted, and not without reason, as having enormous potential for the healthcare industry. Improved data access, improved interoperability, and cost reductions are potential benefits of embracing cloud technologies. So why are some still resistant to the Cloud revolution?
Jonathan Armstrong from the London-based legal services firm Cordery says that it often has to do with the oversimplification of the security aspects of the Cloud architecture.[4] While many resisters argue from a philosophical point that the Cloud can never be completely secure and therefore needs to be avoided, Armstrong takes an even stronger viewpoint. He believes that cloud vendors often oversell security aspects, like the “full anonymization” of data, and has said that “every time [he has] read [about full anonymization of data he has] found it to be untrue.”[5] When it comes to personal health data, Armstrong says there are always enough details (e.g., dates, location, age, etc.) to make an individual identifiable, and that this data is really pseudo-anonymized as opposed to fully anonymized.[6] When companies have a false sense of their Cloud technologies’ data anonymization capabilities, they can accidentally become non-compliant with regulations regarding the storage and dissemination of sensitive data. Incidents like that can stoke fears and distrust of Cloud vendors’ products and can make healthcare providers reluctant to jump wholeheartedly into embracing the technology.
Another factor in healthcare’s slow adoption of Cloud technologies is the uneasiness of healthcare providers in not having complete control over their highly sensitive data.[7] Once sensitive data leaves a provider’s network and moves onto the Cloud, the exact location of that data and the security and access controls related to that data are no longer fully within the provider’s control. The risk of misconfigurations, improper or lax security, and unknown access controls can make it difficult for healthcare providers to relinquish sensitive data, especially in the face of enormous potential reputational damage and regulatory fines should something go wrong.[8] This has led to nearly 20% of healthcare organizations considering moving back to an on premises model according to a new Netwrix study.[9]
3. States Need Help.
As we covered previously, there has been a significant uptick in malicious cyberattacks against state and local governments this year. These largely unattributed attacks have cost hundreds of millions of dollars to cities and states and have exposed the lamentable state of cybersecurity below the federal level. The silver lining in all of this might be that Congress is finally taking the matter seriously. The first few federal legislative attempts to provide cybersecurity resources and training to states have not made too much headway in this contentious political climate, but the existence of legislation at all is positive sign that at least some legislators do not want to leave states and cities to fend entirely for themselves.
Perhaps the best example of legislation looking to address the issue is the State Cyber Resiliency Act introduced by Sens. Warner (D-VA) and Gardner (R-CO). The bill would create grant opportunities for states looking to improve their cybersecurity capabilities through a broad range of activities. Everything from “supporting dedicated cybersecurity and communications coordination planning” to establishing scholarships or apprenticeships for those pursuing cybersecurity training and education would be covered under one of two grant pathways.[10]
Bills like the State Cyber Resiliency Act have the potential to greatly improve the under-resourced communities they target, and this is an issue that appears ripe for bi-partisan cooperation. However, the reality is that federal cybersecurity legislation has faced an uphill battle lately. Furthermore, throwing money at the issue will likely not be enough to fix the short term problems affecting states. Many state government cyber deficiencies stem from a lack of trained cybersecurity professionals and a workforce that hasn’t been properly educated on basic cyber hygiene, both of which are problems that may take years of focused attention to improve.[11]
Congress –
Tuesday, July 16th:
-No relevant hearings
Wednesday, July 17th:
-No relevant hearings
Thursday, July 18th:
-No relevant hearings
International Hearings/Meetings –
EU – No relevant hearings.
Conferences, Webinars, and Summits –
— 4th Annual Medical Device Cybersecurity Risk Mitigation Conference – Arlington, VA (7/23/2019-7/24/2019)
http://www.q1productions.com/device-cybersecurity/
–Healthcare Cybersecurity Workshop – Dublin, Ireland (7/31/2019)
https://h-isac.org/hisacevents/healthcare-cybersecurity-workshop-dublin-ireland
— Expo Health – Boston, MA (7/31/2019-8/2/2019)
https://www.expo.health/events/2019-expo-health
–H-ISAC Medical Device Security Workshop – Plymouth, MN (9/17/2019)
https://h-isac.org/hisacevents/h-isac-medical-device-security-workshop/
–HEALTH IT Summit (California) – Los Angeles, CA (9/19/2019-9/20/2019)
https://endeavor.swoogo.com/2019-LosAngeles-Health-IT-Summit
— Healthcare Cybersecurity Forum – Los Angeles, CA (9/20/2019)
https://endeavor.swoogo.com/2019-California-Cybersecurity-Forum
–HEALTH IT Summit (Northeast) – Boston, MA (10/3/2019-10/4/2019)
https://h-isac.org/hisacevents/health-it-summit-northeast/
–Northeast Healthcare Cybersecurity Forum – Boston, MA (10/4/2019)
https://endeavor.swoogo.com/2019-Northeast-Cybersecurity-Forum
–2019 H-ISAC European Summit – Zurich, Switzerland (10/16/2019-10/17/2019)
https://h-isac.org/summits/european_summit/
–Health IT Summit (Midwest) – Minneapolis, MN (10/17/2019-10/18/2019)
https://endeavor.swoogo.com/2019-Minneapolis-Health-IT-Summit
–Healthcare Cybersecurity Forum (Midwest) – Minneapolis, MN (10/18/2019)
https://endeavor.swoogo.com/2019_Midwest_Cybersecurity_Forum
–Health IT Summit (Southwest) – Houston, TX (11/14/2019-11/15/2019)
https://endeavor.swoogo.com/2019-Dallas-Health-IT-Summit
–Southwest Healthcare Cybersecurity Forum (11/15/2019)
https://endeavor.swoogo.com/2019_Southwest_Cybersecurity_Forum
–Health IT Summit (Northwest) – Seattle, WA (11/19/2019-11/20/2019)
https://endeavor.swoogo.com/2019-PacificNorthwest-HITSummit
–Pacific Northwest Healthcare Cybersecurity Forum (11/20/2019)
https://endeavor.swoogo.com/2019_Pacific_Northwest_Cybersecurity_Forum
–2019 H-ISAC Fall Summit – San Diego, CA (12/2/19-12/6/2019)
<https://www.loewshotels.com/coronado-bay-resort>
Sundries –
–British Airways fined $229 million under GDPR for data breach tied to Magecart
https://www.cyberscoop.com/british-airways-gdpr-fine-magecart/
–Bug in Anesthesia Machines Allows Changing Gas Mix Levels
–Synthetic identity theft is the fastest-growing financial crime in the U.S.
https://www.cyberscoop.com/synthetic-identity-theft-stolen-fake-data/
–AI algorithm to fight hospital-acquired infections gets support with NIH award
–NSA Isn’t Always Following Its Own Cybersecurity Policies, Watchdog Says
–Macs vulnerable to ‘bananas’ Zoom video flaw
https://www.bbc.com/news/technology-48922575
Contact us: follow @HealthISAC, and email at contact@h-isac.org
[1] https://www.nytimes.com/2019/02/11/health/artificial-intelligence-medical-diagnosis.html
[2] https://www.roboticsbusinessreview.com/health-medical/6-ways-ai-and-robotics-are-improving-healthcare/
[3] https://www.theverge.com/2019/7/10/20688654/amazon-alexa-health-advice-uk-nhs
[4] https://www.healthcareitnews.com/news/security-control-data-seen-key-barriers-cloud-adoption-pharma
[5] https://www.healthcareitnews.com/news/security-control-data-seen-key-barriers-cloud-adoption-pharma
[6] https://www.healthcareitnews.com/news/security-control-data-seen-key-barriers-cloud-adoption-pharma
[7] https://www.healthcareitnews.com/news/security-control-data-seen-key-barriers-cloud-adoption-pharma
[8] https://healthitsecurity.com/news/approaching-the-top-5-healthcare-cloud-security-concerns
[9] https://www.healthcareitnews.com/news/security-concerns-budget-restrictions-hamper-move-cloud
[10] https://www.congress.gov/bill/116th-congress/senate-bill/1065/text