HITRUST to Test Cybersecurity Readiness Of Health Care Orgs With Simulated Attacks

Bloomberg BNA's Health IT Law & Industry Report brings you concise, comprehensive, and timely news and analysis of the regulatory, legal, and compliance issues surrounding our nation’s...

By Alex Ruoff  

Jan. 21 --A dozen health-care organizations will put their cybersecurity plans to the test during a series of mock cyberattacks starting in March.

The health-care industry is fast becoming a prime target for hackers and online criminals seeking to steal personal data from electronic health records, Daniel Nutkis, chief executive officer for the Health Information Trust Alliance (HITRUST), the cybersecurity organization coordinating the mock attacks, told Bloomberg BNA Jan. 16.

The cybersecurity exercises will give security experts and health-care executives a better understanding of how well their security measures might fare against a real attack, he said.

“We've seen a steady increase in attacks on health organizations, and the industry as a whole has responded well,” Nutkis said. “Now the maturity of that response has reached the point where we need to get an understanding of what's being truly effective and what these organizations are ready for.”

HITRUST has been purposefully vague about the exact timing and nature of the simulated attacks, dubbed CyberRX, to make them as real as possible, Nutkis said. HITRUST will unleash “a little of everything” on the health information technology systems and medical devices of 12 organizations, a mixture of health plans, health-care provider organizations and pharmacies, he said.

Participating in CyberRX are: the Department of Health and Human Services, Children's Medical Center of Dallas, CVS Caremark, Express Scripts, Health Care Service Corp., Highmark, Humana, UnitedHealth Group, WellPoint and others.

The results of the mock attacks will be summarized in a report to be released in April, HITRUST said in a release.

Intelligence Testing

The mock attacks will test both the permanent security measures of the participating organizations, such as firewalls and anti-virus programs, as well as how well executives respond to cyber-intelligence reports from the HHS and HITRUST's Cyber Threat Intelligence and Incident Coordination Center, the organization's cybersecurity program, HITRUST said.

The HHS regularly issues cybersecurity warnings to HITRUST, which alerts the relevant health-care organizations, Nutkis said.

Intelligence gathering is crucial for cybersecurity, he said, as hackers and online criminals have access to very sophisticated technologies that allow them to be innovative in how they subvert security systems.

“The model for security used to be just build bigger and bigger walls around your system to block anything coming in,” Nutkis said. “It's not so simple now as attackers are becoming smarter and smarter.”

As part of CyberRX, HITRUST will, for some organizations, issue an alert about the possibility of a certain type of attack before simulating it to test how those organizations respond to warnings, Nutkis said.

Health Care as a Target

Underscoring the need for health-care organizations to improve their cybersecurity response, DataMotion, a Morristown, N.J.-based e-mail encryption provider, Jan. 21 released the results of a survey on corporate security that found that 75 percent of health-care workers routinely ignore the security policies of their employer.

The survey also found that although more than 90 percent of health-care companies had policies for encrypting e-mails and policies for securely transferring electronic files, 33 percent of health-care employees didn't fully understand those policies. Employees surveyed included health-care providers and administrative staff at health-care organizations, the survey said.

“Doctors are thinking about their patients when they're using a computer, not company policy,” Bob Janacek, chief technology officer for DataMotion, told Bloomberg BNA Jan. 21. “So it's important that an organization integrate security measures into their regular workflow.”

The survey concluded that health-care organizations should offer IT training for health-care providers and automate cybersecurity practices for providers.

To contact the reporter on this story: Alex Ruoff in Washington at aruoff@bna.com

To contact the editor responsible for this story: Kendra Casey Plank at kcasey@bna.com

More information about HITRUST is at http://www.hitrustalliance.net.

The survey can be downloaded at http://info.datamotion.com/datamotion-2013-survey-report.