Welcome!

Java IoT Authors: Yeshim Deniz, Elizabeth White, Liz McMillan, Zakia Bouachraoui, Pat Romanski

Related Topics: @CloudExpo, Java IoT, Microservices Expo, Linux Containers, Agile Computing, Cloud Security

@CloudExpo: Blog Post

Healthcare Industry and Data Security By @CipherCloud | @CloudExpo [#Cloud]

Healthcare organizations must see the CHS breach as a wake-up call to reevaluate and strengthen their data security measures

The Healthcare Industry Must Address Data Security Threats

Despite the data privacy protections supposedly conferred by regulations like HIPAA and HITECH, consumers' confidential health and personal information is still not safe enough. That's the lesson to be learned from Franklin, TN-based Community Health Systems' (CHS) August 18 regulatory filing. In the filing, CHS disclosed that the names, SSNs, addresses, birth dates, and phone numbers of approximately 4.5 million people across 28 states have been stolen, according to Computerworld. Those 4.5 million victims, whom Computerworld reported had either received or been referred for services to CHS-affiliated physicians, are now at risk of identity theft, thanks to the security weaknesses of their healthcare provider. This latest large-scale data breach serves to highlight just how critical data security is in today's connected age.

Computerworld reported that the breach is being investigated by Mandiant, which "believes that a known Advanced Persistent Threat (APT) group, based in China, is responsible for the breach." Computerworld further notes that "since the breach was discovered, CHS is working with Mandiant to clean out its systems and implement new remediation measures" as well as cooperating with federal investigators. These post-incident measures come a bit too late to protect those 4.5 million victims, or CHS's reputation itself, but provide a fresh reminder to other healthcare organizations that data security matters.

HIPAA and HITECH aren't the end-all, be-all of healthcare data security. As CIO.com pointed out after the CHS breach was disclosed, "many organizations pay little more than glancing attention to the rules because of the relatively lax enforcement of the standards." Even though regulations are growing stricter and penalties stiffer, auditing requirements still fall behind those of other regulated industries, such as financial services. Healthcare organizations see little incentive to beef up their data security. Then a breach happens, and both patient trust and public reputation suffer.

What's the Solution?
Healthcare organizations must see the CHS breach as a wake-up call to reevaluate and strengthen their data security measures. This process must go all the way to the top of the organization. Security leadership is absolutely essential at any security-conscious enterprise. Having data security leadership that's independent of the IT department and able to communicate and work effectively with the business, legal, and financial leadership of the organization will go a long way toward making sure that patient data gets the attention and protection it needs. Risk assessments, data classification, strict access controls, and data encryption are all critical components. So is a change in culture to one that values data privacy and data security enough to invest in it.

The consequences of this lack of security leadership and prioritization may not always be apparent when regulatory bodies are lax in enforcing their own rules, but they will become all too apparent to any healthcare provider that suffers a breach like CHS did. If you want to prevent your organization from becoming the next CHS, you must act while you have a chance. Protect your data before it comes under attack so that you won't have to suffer the aftermath of one for which you weren't prepared. The alternative is to lose control of millions of patients' data-and millions of patients' trust.

What lessons have you learned from the CHS data breach? Tell us what you think in the comments.

More Stories By Paige Leidig

Paige Leidig is SVP at CipherCloud. He has 20 years of experience in technology, marketing, and selling enterprise application solutions and managing trusted customer relationships. As SVP of Marketing, he is responsible for all aspects of marketing at CipherCloud. Paige was previously in the Office of the CEO at SAP, where he was responsible for leading and coordinating SAP’s acquisition and integration activities on a global basis. He has managed a number of marketing initiatives at SAP, including responsibility for all go-to-market activities for SAP’s Cloud applications portfolio. Preceding his SAP career, Paige held senior management positions with Ariba, Elance, and E*Trade.

Comments (1)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


IoT & Smart Cities Stories
Cloud-enabled transformation has evolved from cost saving measure to business innovation strategy -- one that combines the cloud with cognitive capabilities to drive market disruption. Learn how you can achieve the insight and agility you need to gain a competitive advantage. Industry-acclaimed CTO and cloud expert, Shankar Kalyana presents. Only the most exceptional IBMers are appointed with the rare distinction of IBM Fellow, the highest technical honor in the company. Shankar has also receive...
DXWorldEXPO LLC announced today that ICOHOLDER named "Media Sponsor" of Miami Blockchain Event by FinTechEXPO. ICOHOLDER gives detailed information and help the community to invest in the trusty projects. Miami Blockchain Event by FinTechEXPO has opened its Call for Papers. The two-day event will present 20 top Blockchain experts. All speaking inquiries which covers the following information can be submitted by email to [email protected] Miami Blockchain Event by FinTechEXPOalso offers sp...
DXWordEXPO New York 2018, colocated with CloudEXPO New York 2018 will be held November 11-13, 2018, in New York City and will bring together Cloud Computing, FinTech and Blockchain, Digital Transformation, Big Data, Internet of Things, DevOps, AI, Machine Learning and WebRTC to one location.
@DevOpsSummit at Cloud Expo, taking place November 12-13 in New York City, NY, is co-located with 22nd international CloudEXPO | first international DXWorldEXPO and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time t...
Headquartered in Plainsboro, NJ, Synametrics Technologies has provided IT professionals and computer systems developers since 1997. Based on the success of their initial product offerings (WinSQL and DeltaCopy), the company continues to create and hone innovative products that help its customers get more from their computer applications, databases and infrastructure. To date, over one million users around the world have chosen Synametrics solutions to help power their accelerated business or per...
Charles Araujo is an industry analyst, internationally recognized authority on the Digital Enterprise and author of The Quantum Age of IT: Why Everything You Know About IT is About to Change. As Principal Analyst with Intellyx, he writes, speaks and advises organizations on how to navigate through this time of disruption. He is also the founder of The Institute for Digital Transformation and a sought after keynote speaker. He has been a regular contributor to both InformationWeek and CIO Insight...
When talking IoT we often focus on the devices, the sensors, the hardware itself. The new smart appliances, the new smart or self-driving cars (which are amalgamations of many ‘things'). When we are looking at the world of IoT, we should take a step back, look at the big picture. What value are these devices providing. IoT is not about the devices, its about the data consumed and generated. The devices are tools, mechanisms, conduits. This paper discusses the considerations when dealing with the...
Machine learning has taken residence at our cities' cores and now we can finally have "smart cities." Cities are a collection of buildings made to provide the structure and safety necessary for people to function, create and survive. Buildings are a pool of ever-changing performance data from large automated systems such as heating and cooling to the people that live and work within them. Through machine learning, buildings can optimize performance, reduce costs, and improve occupant comfort by ...
Digital Transformation is much more than a buzzword. The radical shift to digital mechanisms for almost every process is evident across all industries and verticals. This is often especially true in financial services, where the legacy environment is many times unable to keep up with the rapidly shifting demands of the consumer. The constant pressure to provide complete, omnichannel delivery of customer-facing solutions to meet both regulatory and customer demands is putting enormous pressure on...
Bill Schmarzo, Tech Chair of "Big Data | Analytics" of upcoming CloudEXPO | DXWorldEXPO New York (November 12-13, 2018, New York City) today announced the outline and schedule of the track. "The track has been designed in experience/degree order," said Schmarzo. "So, that folks who attend the entire track can leave the conference with some of the skills necessary to get their work done when they get back to their offices. It actually ties back to some work that I'm doing at the University of San...