How to Secure Electronic Health Record Systems

116 views
•
February 23, 2017
by
RSAC Cybersecurity
YouTube video player
How to Secure Electronic Health Record Systems

TL;DR

Electronic health record security depends on protecting the integrations connecting clinical systems with the rest of the organization and outside providers, not merely examining the core vendor platform. Healthcare organizations must balance meaningful-use requirements, broader patient-care goals, information sharing, limited resources, vendor-dependent patching, and an immature vulnerability-reporting ecosystem when managing EHR risks.

Transcript

Thanks, uh, thanks for coming to the session. I know it's, uh, hopefully not too early. It's, uh, n-not the eight AM session, but, uh, nonetheless, I appreciate everyone for coming. Just a, j-just a rough understanding of, uh, the audience, how many people either work for a healthcare provider or support them in some way? Okay, great. So we're with... Read More

Key Insights

  • EHR security is strongly affected by integration because many weaknesses arise from connections with other organizational and external systems, rather than from the core platforms purchased from vendors. Security assessments therefore need to consider the broader environment in which medical information is created, stored, and exchanged.
  • An electronic healthcare record is broader than an electronic medical record because it can encompass the patient's total health rather than only an electronic version of a clinician's chart. Its scope can include information originating beyond a single healthcare organization or medical practice.
  • Meaningful use is a government-backed approach that encouraged EHR adoption through incentives and, in some cases, penalties. Its goal was not simply to support insurance payments, but to help providers use medical information effectively for patient care, communication, condition identification, and coordination.
  • Healthcare information sharing is necessary because patients often receive care from multiple providers and specialists at different practices. A primary care physician may need information held by a specialist, making secure exchange across organizational boundaries an important part of EHR use.
  • EHR adoption can increase work for individual medical practices even when it is intended to benefit the healthcare system overall. Some organizations hire scribes to record information while doctors examine patients, illustrating how complete electronic documentation can create new operational demands.
  • Security requirements must be considered alongside requirements encouraging healthcare organizations to use electronic record systems. Security practitioners need to understand the motivations behind adoption, including incentives, penalties, patient-care objectives, and the decline in net new installations as incentives faded.
  • EHR vulnerability reporting is still developing because researchers may have difficulty finding an organized channel for disclosing weaknesses. The industry reflects a maturity pattern previously experienced by industrial control systems, automobiles, and major technology vendors that initially resisted vulnerability reports.
  • Healthcare security weaknesses can persist because funding is limited, internal resources may be spread too thin, and organizations sometimes depend on vendors for patches and other controls. These constraints complicate the response to vulnerabilities across electronic records, medical devices, and related healthcare technology.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should healthcare organizations approach EHR security?

Healthcare organizations should evaluate the entire environment surrounding an electronic health record, especially its connections to other internal systems, outside providers, and emerging data sources. The core vendor platform is only one part of the risk. Security planning should also account for information sharing, organizational resources, vendor-provided patches, regulatory requirements, and the developing process for reporting vulnerabilities.

Q: What is the difference between an EHR and an EMR?

An electronic medical record is traditionally understood as a doctor's chart in electronic form. An electronic healthcare record has a broader scope and can represent the patient's total health, including information extending beyond one clinician or healthcare organization. That broader definition accommodates coordination among providers and may eventually include reliable information from specialized devices or fitness trackers.

Q: Why were meaningful-use incentives created for EHR systems?

Meaningful-use incentives were created because medical practices might not adopt electronic record systems on their own, particularly when adoption could increase their workload or costs. The broader goal was to improve the healthcare system by supporting patient care, identifying conditions, prompting needed visits, communicating information to patients, and enabling records to be shared among multiple providers.

Q: How can EHR systems improve care across multiple providers?

EHR systems can make relevant patient information available when care is distributed among primary physicians, specialists, and separate medical practices. A primary care physician may need records from an orthopedist or another specialist to understand a patient's condition. Effective electronic sharing supports coordination, provided that the integrations and exchanges carrying the information are appropriately secured.

Q: Why can EHR adoption create more work for medical practices?

Electronic documentation can require clinicians and their staff to capture more complete information during patient care. The transcript notes that some practices hire scribes to take notes while doctors examine patients, a role they may not have needed previously. The resulting burden can make EHR adoption appear costly to an individual practice, even when broader system-wide benefits are intended.

Q: Why are EHR integrations a major cybersecurity concern?

EHR integrations expand the area that must be protected because patient data moves between the core record platform, other organizational systems, outside healthcare providers, and potentially connected devices. According to the talk, many vulnerabilities and weaknesses are associated with how systems are integrated rather than with the purchased core product itself. Security reviews should therefore follow these connections and data flows.

Q: Why is EHR vulnerability reporting difficult?

EHR vulnerability reporting is difficult because the market has not yet developed consistently organized disclosure channels. Researchers who identify a weakness may struggle to determine where or how to report it. The talk compares this stage with earlier periods in other technology sectors, when vendors were resistant to researchers and bug reports before more robust reporting processes developed.

Q: What limits healthcare organizations' ability to fix security vulnerabilities?

Healthcare organizations may have limited funding and security resources spread across many systems and responsibilities. They can also depend on technology vendors to supply patches or other protections after vulnerabilities are discovered. These constraints mean that identifying a weakness does not automatically produce a prompt remedy, especially within an industry whose vulnerability research and reporting practices are still maturing.

Summary & Key Takeaways

  • Electronic health records extend beyond electronic versions of clinicians' charts. They can represent the patient's total health, incorporate information from multiple providers, and potentially receive reliable data from specialized devices or fitness trackers. This broad scope makes connections outside the core healthcare organization central to both patient care and cybersecurity risk.

  • Meaningful-use incentives and penalties encouraged healthcare organizations to adopt EHR systems. The intended purpose extends beyond insurance payments to maintaining patient care, identifying conditions, scheduling needed visits, communicating with patients, and sharing information among providers. Individual practices may experience additional work even when the broader healthcare system is expected to benefit.

  • EHR vulnerability research and reporting remain relatively immature. Researchers may struggle to identify appropriate reporting channels, while healthcare organizations face limited funding and security resources. Vendors may also control necessary patches and protections. These conditions resemble earlier maturity challenges involving industrial control systems, automobiles, medical devices, and major information technology vendors.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚