Healthcare security and how updated HIPAA/HITECH Act regulations are changing the nature of risk in that industry are hot topics right now. "The rules have made it easier for organizations to have penalties levied against them because of the actions of a subcontractor," Elizabeth Warren, a healthcare attorney with Nashville Tennessee-based Bass Berry & Sims, is quoted as saying in this Becker’s Hospital CIO post. And she’s absolutely right.
To get some answers about how healthcare organizations are dealing with the increased risks, we thought it would be a great idea to speak with seven year hospital CSO veteran Eric Cowperthwaite. Cowperthwaite is no stranger to the Bitsight Risk Management Blog; he’s posted here previously about Building CISO Relevance Through Metrics.
Here’s what he had to say:
George: Why is third-party vendor risk management so important right now to the healthcare industry?
Eric: There are a number of issues. One is compliance. The reality is that in the new HITECH Act, which extends the Health Insurance Portability and Accountability Act, all business associates have had the full HIPAA security rule extended to and applied to them. The interesting thing here is that healthcare systems first have to figure out who all their business associates are and, number two, how to make sure that they actually meet the full requirements of the security rule.
That's very significant. The other side of it, I think, is that just like any other business, the Target breach really demonstrates how important it is to identify who all your third parties are and then get really good at managing all of the risk associated with them.
George: What were some of the high-level processes that you had in place while at Providence to manage third-party risk? For large organizations like Providence, and with hundreds of third parties, determining the status of their security posture has to be like triage?
Eric: You know, it really was like triage. I think calling it a triage process is a good descriptor of what we did. We had more than 1,500 third parties that interacted with us in some way. Any large company is going to be like that. So, trying to get down to a very detailed level with each one of those thousands of third parties is essentially impossible.
Instead, you need ways to eliminate the low-risk parties. If the third party legitimately didn't have access to any sort of critical assets, from an information security perspective, we could stop right there. That subset, which was probably 40 percent of our third parties, was eliminated just by asking the question: "Do they actually have access to critical data or critical assets of any kind?"
The next step was to determine whether they were a high or a low risk. One tool we used was a really simple questionnaire that asked eight or nine questions that we thought were important. This included things like “Do you have a designated security officer?” “Do you have a corporate security policy?” “Do you install antivirus on your computers?” If they failed on any one of those questions, then we took a much closer look.