As cases of COVID-19 have grown, a lack of capacity has led governments to erect temporary hospitals in our nation’s stadiums, parks, and convention centers.
Unfortunately, these ad-hoc medical facilities have created significant cybersecurity challenges for the already beleaguered healthcare industry. Healthcare IT News reports that makeshift care centers carry a unique set of vulnerabilities since they are built quickly with patient care in mind, not cybersecurity. These remote medical facilities also expand the attack surface beyond the traditional network perimeter, creating the perfect storm for hackers to exploit vulnerabilities.
In order to adapt to the “new normal,” cybersecurity professionals need to get creative. Here are three key measures that security leaders can take to mitigate risk in temporary hospital environments.
1. Visualize the risk landscape
During the coronavirus pandemic, field hospitals provide vital access to care when other resources are strained. But the medical devices used to triage, monitor, and manage COVID-19 patients are an easy target for bad actors looking to access hospital networks.
Managing cyber risk across this complex digital ecosystem can be particularly difficult because security teams may not have a handle on the risk hidden across these digital assets. They need a way to gain visibility into these digital assets so they can be secured no matter where they are — in a makeshift clinic or in new cloud instances that extend IT capabilities to remote users. After all, you can’t secure what you can’t see.
With a centralized cyber security dashboard view of the location of all these assets and the corresponding cyber risk associated with each, security teams can quickly develop plans for remediation. They can also visualize areas of disproportionate risk such as an insecure, yet critical, IoT patient monitoring device and prioritize that asset for mitigation — ensuring more efficient allocation of tools and resources.
2. Discover new and emerging risk in remote environments
The increase in temporary hospitals is analogous to the rise in the number of workers now working remotely since the pandemic began. Both present new, yet similar, challenges to cybersecurity professionals because they sit outside the defense-in-depth architecture.
These remote environments lack adequate security controls and are rife with vulnerabilities. Those field hospitals that run on local networks within stadiums or convention centers are especially vulnerable. The security posture of these networks is entirely unknown and likely to lack the necessary security provisions required to protect provider, patient, and financial data. Teams may also be unable to implement basic security procedures such as network segmentation to protect and isolated critical equipment such as connected medical devices.