HIMSS TV is your Insider’s Guide to everything HIMSS. We are the world’s first online broadcasting network, focused on global innovation and how information and technology are driving change in healthcare.
Renee Broadbent, CIO and information security officer at SoNE Healthcare, says creating a culture of security starts from the top down and keeping staff educated about increasingly sophisticated phishing attacks.
Will Braxton, account executive at Cynerio, talks about the importance of securing not only computers and phones, but any IoT device that expands attack surfaces.
Andy Belval, chief revenue officer at Keystone Technologies, recommends user education and cloud enablement technologies that quickly restore clinicians' access to EMRs when an incident occurs.
Dr. Benoit Desjardins, professor at the University of Pennsylvania Medical Center, discusses cybersecurity risks posed by smart medical devices, but adds that most people would not be a target of such attacks.
Dr. Eric Liederman, director of medical informatics at Kaiser Permanente, discusses the need for healthcare organizations to prepare for cyberattacks and communicate honestly and promptly about these events with staff and patients when they occur.
Dr. Brian Anderson, chief digital health physician at MITRE, talks about the importance of partnerships between digital health companies, health systems and regulators as the development and use of advanced AI tools for healthcare increases.
IoT and IoMT devices may comprise 20% to 30% of a healthcare organization’s attack surface. John Vecchi, chief marketing officer at Phosphorus Cybersecurity, discusses how healthcare IT teams can monitor these tools and strengthen their security.
Jay Stewart, vice president of sales for CORL Technologies, Meditology Services, advises healthcare organizations to discuss AI use and governance with vendors, regularly testing cyber defenses and routinely assessing internal and third-party risks.
Lawrence Stowers, business development manager at Carahsoft, recommends ongoing staff training and communications to prevent phishing and other cyber threats – and a strong incident response plan to mitigate damage if a breach does occur.
ePHI is often found in unstructured files outside of EHRs, posing a major security risk for healthcare organizations. Matthew DiMatteo, business development at Tausight, talks about helping IT teams find and secure this stray data.
Employee and vendor buy-in can strengthen a healthcare organization's cybersecurity posture. Chris Logan, SVP and chief security officer at Censinet, encourages actively managing and mitigating cyber risk among vendors and across the organization.
OrthoVirginia didn't pay the millions attackers demanded and instead embarked on an 18-month recovery process while continuing to serve patients coming in for overdue surgeries following the COVID-19 pandemic, says CIO Terri Ripley.