Sponsored

Your Hospital Wasn’t Breached. So Why Did Operations Stop?

Advertisement

Hospital leaders often measure cybersecurity readiness by asking whether their own environment is protected. Are systems patched? Is multifactor authentication in place? Are employees trained to recognize phishing attempts?

Those questions matter, but they no longer cover the full scope of operational risk.

A hospital does not have to be breached for a cyberattack to disrupt patient care, delay claims or interrupt cash flow. An incident involving a clearinghouse, revenue cycle partner, cloud provider, software vendor or other connected organization can quickly become the hospital’s operational crisis.

Healthcare delivery now depends on an interconnected network of outside organizations. Each connection may support a critical function, from eligibility verification and claim submission to payment processing, clinical documentation and patient communications.

When one of those organizations becomes unavailable, the hospital may retain control of its own systems while losing access to the processes it needs to operate.

That distinction is important. Preventing unauthorized access is only one part of cybersecurity. Hospitals must also prepare to continue operating when a trusted partner suddenly cannot.

A Security Review Is Not a Continuity Plan

Vendor security assessments are an essential part of third-party risk management. Hospitals should understand how their partners protect data, manage access, monitor threats and respond to incidents.

However, a vendor can maintain a strong security program and still experience an attack.

The question cannot simply be, “Is this vendor secure?”

Leadership must also ask, “What happens to us if this vendor becomes unavailable?”

Those are different questions, and they require different forms of preparation.

A security review evaluates the vendor’s controls. A continuity plan evaluates the hospital’s dependency on that vendor. It identifies which processes will stop, how quickly the disruption will affect operations and what alternatives are available.

For example, if a clearinghouse cannot transmit claims, can the hospital send claims through another channel? If a revenue cycle platform is unavailable, can teams access the information needed to continue priority work? If automated eligibility tools go offline, is there a manual process for urgent cases?

These decisions should not be made for the first time during an incident.

Prepare for Days and Weeks, Not Hours

Many continuity plans are built around brief technology interruptions. Teams assume systems will be restored within several hours and normal operations will resume shortly afterward.

Cyber incidents do not always follow that timeline.

Investigations, system restoration, regulatory obligations and security validation may extend an outage for days or weeks. Even after systems return, organizations may face backlogs, reconciliation issues and delayed transactions.

Hospitals should determine how long they can realistically operate without each critical partner.

That includes understanding when the disruption begins to affect patient access, billing, collections, payroll, reporting and other essential functions. Leaders should identify which work can continue manually, which work can be redirected and which work must be prioritized when capacity is limited.

Contracts should also support continuity planning. Hospitals need clear expectations regarding incident notification, communication frequency, data access, recovery responsibilities and support during extended outages.

The goal is not to predict every possible scenario. It is to reduce uncertainty before the organization is under pressure.

Test the Dependency, Not Just the Response

Hospitals regularly conduct incident response exercises, but those exercises often focus on an attack against the hospital itself.

Tabletop testing should also include the sudden loss of a major third party.

Teams should walk through what happens if a clearinghouse is unavailable, a technology platform cannot be accessed or a revenue cycle partner loses connectivity. Clinical, financial, operational, legal and technology leaders should participate because the consequences will not remain confined to the security department.

The exercise should reveal where the hospital lacks alternatives, documentation, decision authority or visibility into vendor operations.

Healthcare organizations cannot eliminate every third-party risk. They can, however, prevent a partner’s cyber incident from becoming an uncontrolled operational emergency.

Cybersecurity readiness is not only about keeping attackers out. It is also about keeping the organization moving when a critical connection suddenly disappears.

About the author: Izhar Ahmed Mujaddidi is Chief Information Security Officer at Coronis Health. He has more than 20 years of experience in cybersecurity and information assurance, with expertise in security strategy, risk management, compliance and the development of resilient information security programs.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

Advertisement