TAKING A PULSE [SC Magazine] - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Meet our Editorial Staff
    • Advertise
    • Contact
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
December 22, 2011 Newswires
Share
Share
Post
Email

TAKING A PULSE [SC Magazine]

Armstrong, Illena
By Armstrong, Illena
Proquest LLC

Data protection concerns abound for health care professionals. Getting a sound handle on steps to address these is key, reports Illena Armstrong.

Few can argue 2011 has been a banner year for frequent and massive data breaches, and health care organizations have carried their share of the burden.

Compromises encountered by the likes of Sony, Citibank and others may have seen the exposure of between hundreds of thousands to some 100 million critical records. However, various hospitals, insurance and health care providers, clinics and others have experienced a staggering number of data violations. Whether the personally identifi able information (PII) was stored on networks or backup tapes, was lost on mobile devices or mistakenly posted to websites, incidents in the health care space have been common this year.

Yet, breaches are unsurprising to many in the space. At an SC Magazine Health Care Roundtable held late last year, attendees spoke frankly about their challenges. Understanding just how far their confi dential data extends, addressing more highly targeted vectors of attack, like mobile devices or cloud computing, ensuring business partners have adequate security, and getting the support they need from equipment vendors whose tools now are networked to wider corporate infrastructures, were only a few worries they voiced.

"The problem is that in health care, all data is sensitive - whether its PII or protected health information," says Larry Whiteside, CISO of the Visiting Nurse Service of New York, who attended the event, which was sponsored by IT security solutions provider Arcsight, now an HP company.

In reiterating a point he made at the Roundtable, Whiteside adds that keeping track of this data is the most critical duty for health care security pros - and the most confounding.

"All I can say is due diligence," he explains. "Health care and every other vertical should ensure they are continuing to do the things they know they should in order to protect patients and their electronic information."

One top concern for Roundtable attendees is insider threats. Not only do they have to worry about the typical security vulnerabilities other types of companies face, like the provisioning (and de-provisioning) of internal applications, or too many shared accounts, but they must also deal with what Roundtable participants referred to as "neighbor snooping."

To address this problem, some pros who attended the Roundtable are in the midst of rolling out dual-factor authentication solutions. Among other technologies, they're also relying on encryption, security incident and event management (SIEM) solutions, awareness training, and identity management (IDM) to help with end-user provisioning and the deletion of shared accounts.

The problem with many of these solutions, though, is that they are based on policy, says Ryan Kalember, director of product marketing for Arcsight. And this means that organizations have to do some work up front to understand the extent of their user base. For example, with IDM, a company often turns to business units for details about users and what they should have access to, but they don't always know what that should be.

"We've seen that most of our customers who are really serious about user monitoring and need an authoritative source of data turn to [Microsoft's] Active Directory, because the information in there is better than what is in their IDM," Kalembar says. "So, that's scary."

The data that business partners have access to only complicates the problem more, says Jon Gossels, president and CEO of consultancy SystemExperts.

"Once that initial data is used for something else, all bets are off," says Gossels. "That's the nightmare in health care right now. It's not the initial collection. It's all the uses after that."

If data security needs like these are met, then compliance with the Health Insurance Portability and Accountability Act (HIPAA) should come naturally. However, security funding still seems to stem from higher-ups' concerns about meeting mandates, as opposed to safeguarding the data. This may be one reason why many health care organizations PULSE end up failing to take a comprehensive look at their overall security management plans, says Bryan Cline, VP for Common Security Framework (CSF) development and implementation at the Health Information Trust Alliance (HITRUST).

A "fi refi ghting exercise" up until now, robust security and risk management plans in the health care space must be built fi rmly on standards, such as ISO 27001, guidance from the National Institute of Standards and Technology (NIST), HITRUST's CSF or others, Cline adds, reinforcing a point he made while at the SC Roundtable last year, when he was CISO at Catholic Health East.

Organizations need to adopt a standard prescribing reasonable and appropriate security practices in order to do a valid gap analysis as part of their risk assessment, he says.

Yet, it's not just a question of privacy. It's also one of authenticity of the data, says Dov Yoran, co-founder of MetroSITE Group, an information security consultancy that provides services to technology companies. Organizations, must ensure data is not tampered with or changed, and that it remains authentic, safe and available system-wide, he adds.

Standards come in handy when undertaking this process, says HITECH's Cline. By looking to industry guidance and best practice, and then conducting an analysis of where security gaps are, organizations can establish and maintain an overarching governance, risk and compliance management plan that considers the entire corporate infrastructure.

"[HIPAA] helps and hinders," Cline says. "It helps because it got security some attention, so people were able to do some things they wanted to do after they got the money for them. It hinders because they end up focusing on compliance, and compliance doesn't equal security."

With Offi ce of Civil Rights audits coming, Cline believes 2013 will be a watershed year for health care security. After audits show that some still are clinging to ineffectual risk management plans, the industry is bound to witness action against them, he predicts.

"2013 will be the fi rst year organizations will be looking at security through the right lens, so there should be a lot of improvements," says Cline.

A longer version of this story is available at scmagazineus.com.

Copyright:  (c) 2011 Haymarket Media, Inc.
Wordcount:  1013

Older

Marketing for Organizational Excellence [Firehouse]

Newer

Identity theft: A good name is more desirable than riches [New Pittsburgh Courier (PA)]

Advisor News

  • Help women break through their retirement roadblocks
  • Advisors await SEC decision on Vanguard fair fund distribution
  • What to do when adult children become the client
  • Judge rules insurers not liable for Newport Group’s AME Church pension lawsuit
  • Why vacation homes are becoming a major blind spot for advisors
More Advisor News

Annuity News

  • Legacy Marketing Group partners with Malibu Life USA for annuity launch
  • Best’s Market Segment Report: Global Life/Annuity Reinsurers Remained Poised for Steady Growth
  • When technology becomes easy to rent, what still separates life and annuity carriers?
  • Legacy Marketing Group® and Malibu Life USA Announce Distribution Partnership for New Fixed Indexed Annuity Platform
  • Empower Annuity Insurance Company of America Trademark Application for “EMPOWER WHAT’S NEXT” Filed: Empower Annuity Insurance Company of America
More Annuity News

Health/Employee Benefits News

  • Trump administration cuts health care coverage for some transgender youth in California
  • ‘Downright unaffordable’: State employees in Montana to face higher healthcare costs
  • ACA premiums to rise in Virginia
  • GSP Health plans new Woodward community health center
  • BRAND DRUGMAKERS RAISED PRICES ON 250 DRUGS THIS SUMMER
Sponsor
More Health/Employee Benefits News

Life Insurance News

  • How advisors can get clients to act sooner on life insurance
  • AM Best Affirms Credit Ratings of Crum & Forster Insurance Group’s Members and Monitor Life Insurance Company of New York
  • AM Best Affirms Credit Ratings of Life Insurance Company Centras Life JSC
  • AM Best Withdraws Credit Ratings of New Providence Life Insurance Company
  • When technology becomes easy to rent, what still separates life and annuity carriers?
More Life Insurance News

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Press Releases

  • Classic Car Insurer OpenRoad Insurance Expands to 40 U.S. States in Two Years
  • How Aspire General Turned an Early Technology Bet Into Claims Automation at Scale with Kyber
  • Adjusto launches AI-Native contents claims services powered by its technology platform
  • URL Insurance Group Celebrates 40 Years of Service, Growth, and Industry Leadership
  • MassMutual Ascend Surpasses $2 Billion in Lifetime Advisory Annuity Sales, Reflecting Continued Momentum in RIA Channel
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Meet our Editorial Staff
  • Advertise
  • Contact
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.