If you’re involved in a healthcare-based organization, you’ve likely noticed the push for stronger vendor security and vendor risk management (VRM) practices. There are a few reasons for this.
First, medical data and personal patient information is migrating to the digital world, opening up the potential for cyber crime. Second, cyber attacks and cybersecurity risks in healthcare are continuing to grow in complexity, and cyber criminals may steal data or ensure the organization cannot access said data until a ransom is paid. And finally, the regulatory landscape is evolving, so if a vendor compromises or mishandles patient data, you could see major regulatory consequences.
With that in mind, consider these four cybersecurity risks healthcare providers face in relation to their vendors and third parties — as well as a look at why they’re so critical.
1. Outdated Endpoints
Healthcare providers work with a wide range of vendors — from those in HR to medical device providers to insurance companies. With this diverse vendor ecosystem, it’s critical to remember that some of your third parties could be accessing your network and sensitive data through outdated endpoints (i.e. computers, laptops, mobile devices, tablets, etc.). If any of your vendors allow individuals to connect to your network on a device running old software — or taking part in risky cyber behavior via that endpoint — you could expose your organization to vulnerabilities.
2. Outdated Medical Devices
Medical devices may not be top-of-mind where cybersecurity is concerned, but they should be. For example, even if you’ve transitioned away from a legacy operating system, your medical equipment — say, an X-Ray machine — may still have that legacy OS embedded. If that OS becomes infected with a worm, it has the potential to threaten your entire network.
Interestingly, we’ve been seeing more medical device manufacturers beginning to use security as way to differentiate themselves in the marketplace, signaling a shift in the way medical third parties are thinking about cybersecurity in healthcare.