Cyber threats & mitigation strategies for IoT in healthcare: 5 key insights

As healthcare moves to further adopt internet-connected devices to deliver care, new cybersecurity threats require hospitals and health systems to deploy strategic mitigation strategies, according to Tony Howlett, chief information security officer at SecureLink.

Advertisement

During Becker‘s Health IT + Revenue Cycle Management Virtual Forum Feb. 9, Mr. Howlett discussed present cybersecurity threats with IoT devices as well as best practices for hospitals to adopt to improve cyber hygiene.

Five key insights from the presentation:

1. Hackers are increasingly targeting healthcare, with the number of cyberattacks on healthcare organizations rising 45 percent year over year. They didn’t back off on their cyberattack attempts during the pandemic, either, and have instead ramped up attacks such as email phishing attempts claiming to offer vaccines and testing.

2. Over the last few decades, healthcare has become an increasingly tech business. Providers are using IoT devices such as take-home insulin pumps, defibrillators, wearable monitoring devices and MRI machines to collect health data and expand the reach of care.  

“These devices are connected to us and deliver information to a network, app, etc.,” Mr. Howlett said. “So all that data gathered is out there and potentially subject to attack.”

3. To manage the cyber risks associated with IoT devices, hospitals and health systems must implement standard remediation techniques such as segmenting networks and establishing dedicated virtual local area networks for human-connected IoT including wearables. Establishing restrictive rules is the best way to ensure cybersecurity safety.

4. Third-party vendor access in and out of IoT devices needs to be treated differently than other technologies. These devices need more security than just a VPN, and healthcare organizations should implement multifactor authentication for any external third-party access to its network.

5. Vendor privileged access management, or VPAM, is a type of security framework specific to third parties. With SecureLink’s solution, healthcare organizations can identify all third parties not just by their company but also their security compliance regimes. Having this information allows the provider to more tightly control access to specific networks, hosts and amounts of time allotted for connections.

More articles on cybersecurity:
Renown Health to pay $75K settlement in HIPAA Right of Access case 
Ransomware group posts stolen North Carolina county health data online 
Hacker tries to poison Florida city’s water system: 5 details

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement

Comments are closed.