Healthcare Regulation Changes and Cybersecurity Impact with Scott Trevino
Scott Trevino, senior vice president for TRIMEDX, explains how rapidly evolving changes to healthcare regulations in the Trump era will likely impact cybersecurity teams.
Transcript
This is Textron tv. Hey guys, thanks for the throwaway here with Scott Trevino, who's vice president of Cybersecurity for TriMedX. And we're talking about, well, what to expect in the coming year and beyond with the new administration as it applies to cybersecurity and healthcare.
'cause there's lots of regulations and well, the regulations are subject to change. Scott, welcome to the show. Thanks for having me.
So what's your read on what's happening here? There's a lot of, uh, people focused on what's happening around regulations in general, and maybe not everybody's paying attention to what's gonna happen in healthcare specifically, but cybersecurity folks, you know, they kinda live and die by a lot of those regulations in that particular sector. 'cause we have things like hipaa.
So what's going on? Well, there's a lot going on. As you are probably well aware, there were a number of, uh, increasing cyber events last year in healthcare.
Uh, maybe towards the top of the list. We might all be familiar with change healthcare and the significant impact there. And as a result of, uh, that continuing, uh, tough environment for healthcare, um, we've seen a number of legislation introduced last year.
Um, you know, not the, uh, the least of which was some healthcare infrastructure security and accountability act. We saw Healthcare Cybersecurity Resiliency Act, a and a few other key pieces of legislation that were proposed. And I think that's a natural outcropping of what's, what's going on in the environment.
We're seeing hospitals in the US with, you know, almost 2000 attacks per week, uh, coming after them. Healthcare information's highly lucrative. Uh, the sector as a whole per critical infrastructure is the highest, you know, it's the highest targeted, the most lucrative data to obtain.
And unfortunately, it's probably one of the more immature, critical infrastructure is creating a, a pretty rich environment for the bad actors. The Supreme Court has also taken aim at some of their regulatory authority of a lot of agencies, and I imagine that, uh, healthcare is gonna be one of those affected eventually. So are those regulations going to get reviewed at some point if they were enacted by the agency versus something that was passed by Congress?
Uh, I think that's a great question. And, you know, one, one example, or case in point is, uh, health and human services through the, uh, OCR, uh, released, uh, proposal on updating the HIPAA security rule. And, uh, it's a significant change that, uh, you know, has been proposed.
It's in the 60 day, it was released January 6th, and there's a 60 day window for commenting, and I think the proposal's about 400 and, uh, almost 500 pages in total. So it's pretty, it's pretty meaty. Uh, does some things to align the security role with, you know, modernized cybersecurity practices.
It creates, you know, things like the requirements for inventory, network mapping, uh, better controls and requirements from patch management, encryption of PHI and so forth. So that, that's a significant proposed change. I, I think, you know, I'm not Nostradamus, I think with the new, uh, you know, uh, white House, a new administration, some of the new appointees, I think it's gonna take a little bit of time to see, I think, you know, give it 90 days to a hundred days to see some of the confirmations are done.
What does it mean? You hear some things out of the, uh, the new administration to eliminate 10 regulations for every one new one? Um, you know, so I think there's gonna be a few things that shake out.
So that's one of the big ones that came, uh, you know, came, came out on in January 6th. So that's right at the change in the administration. It'll be interesting to see what, uh, the new the new group does.
Uh, I would say that there's a need for better, uh, application of legislation and regulatory requirements for cybersecurity and healthcare in particular. Um, just given the nature of the things I mentioned before, I think there would be a benefit there. However, un you know, unfunded mandates legislatively are, would be bad.
Uh, so requiring, you know, the application of rules and essentially the introduction of significant cost to implement without funding or a way to recoup, some of that's a challenge. So if I use the, the HIPAA new new proposed rule example as way of example, uh, that's estimated to cost, I think upwards of $9 billion in the first year, and then about four or five every year after that. So, um, there's a significant cost to be beared by the, uh, those who have to apply and abide by HIPAA rules.
Uh, and although you can avoid the pain of a breach potentially through implementation, uh, that's a cost avoidance versus, uh, covering cost to implement. So you still have to outlay the investment there. So that's what I'll be looking at as I study that and, and comment on that further To your point, we're kind of torn a little bit about some of this because, um, we kinda like the idea of more regulations if it improves security, but if they're not funded, it becomes a bigger problem.
'cause a lot of these healthcare organizations, I mean, some of them are huge, but by and large, most of them were kinda mid-sized to small and maybe marginally profitable. So can they afford these kind of fundings? Yeah, that's another very, uh, important aspect to this.
And if I, you know, were to share a bit about rural healthcare, there's roughly 1800 rural hospital systems, about 80% of those, uh, or just about, or, you know, 25 beds, uh, hospital systems. So when you look at the challenges a rural system faces, there's a multiplicity of factors here. Attracting the right talent, uh, you know, delivering good services and, and staffing, not to mention, trying to get access to talent such as cybersecurity professionals.
There's a huge shortage of cybersecurity talent, uh, within the US and globally as well as biomeds to help maintain your equipment. And when you combine those two needs, uh, you're really looking at a highly specialized individual. And, you know, the rural health system suffer with that, uh, you know, probably to a greater degree than some others.
Uh, you know, we're keeping an eye on this as well. When a cyber event happens for some of those smaller systems, they may not have the resources to endure the financial impacts. Uh, and I see a real risk of after a breach or some cyber event that that would contribute to closing down some of our more vulnerable systems.
To that end though, it seems like in the last year, especially that cyber criminals are especially focused on healthcare organizations that I don't know, is that because they're gonna get rich off that or are they just that the value of that data is a lot higher and they can sell it somewhere? Yeah, I think there's a couple factors here. Uh, one, the data is very valuable.
That's, that's one. Two, it's a, uh, target rich environment to my, you know, comment before if, uh, you have, you know, a, a number of vulnerabilities or you can socially, you know, mini manipulate folks to get access into a system and do it at fairly low cost with high reward, uh, that makes it a very lucrative, uh, you know, area to focus on versus some of the other sectors. Furthermore, I would say the US is in particular, um, you know, targeted more than any other country in the world from a healthcare standpoint.
And there's, I think, some factors that play into that versus, you know, if you have nationalized healthcare and you got the full weight and consistency of, you know, government run health system, uh, going after some of the bad actors or at least applying rules in a consistent way. I think that, uh, you know, our, our system here in the US I think lends itself to having more valuable data, a more complex environment, uh, with some, you know, a potential need for, uh, you know, more consistent, uh, regulations as well as more consistent operation across, uh, different government agencies to help support. Do you think maybe we need to take a giant step back as a government and look at healthcare and say, maybe we need a, a different approach here that is led by the government to secure all these hospitals versus just asking the hospitals to fit the bill because ultimately isn't this a form of, you know, national security or citizens are under attack?
Yeah, I think that's a conversation that's, uh, you know, come up for some time and maybe gaining some, some interest because you have nation state actors who are targeting our critical infrastructure, which, you know, happens to be, you know, a, a number of nonprofits and other systems versus, as I mentioned, fully nationalized healthcare. So of course you've got, you know, DHA and the VA and other government run health systems which would fall under, uh, you know, the military or you know, the, the defense department. Um, I, I think that's worthy consideration to say, what can we do?
What should we do to protect our most critical, you know, infrastructure and healthcare being right at the top, uh, that directly applies to access to care, uh, treatment. You know, imagine if you're in route, uh, in an ambulance to a level one trauma unit and that hospital system is shut down because they've been breached, the elevators are shut down, can't move equipment, can't move patients, and you have to be either rerouted to a less than level one trauma center or maybe have to take another hour or two hour ride in the ambulance to get there. A lot of the people who work in healthcare are not cybersecurity experts.
They're, uh, most of the time they're just nurses, doctors at attendants who are just trying to do the right thing. Are we expecting too much of them in terms of their cybersecurity acumen to fight this fight? And maybe that's part of the issue here is that, um, it's not just about how many cybersecurity professionals we could find, it's also about people who work there.
You know, they're all intents and purpose, they're defenseless. Yeah, I think, you know, I think of we need to raise all boats, and it's not just the healthcare industry, whether you're in, in banking or any other industry and including your personal life, you need to be aware, if you haven't had a phish email come, you're probably a rare breed if you haven't gotten a letter from one of your banking institutions or a phone company that's lost your records. I think we really do need to raise the level of education for all employees, in particular in healthcare.
We already have training around HIPAA and patient information privacy. I think, uh, there is definitely a need based on some of the more recent events where you look at social engineering manipulation to get access to passwords or a reset password to make a breach versus some other form of more complex and costly and difficult attack. Um, I really do think there's a need for that, whether it's in healthcare or in, uh, other industries.
And I think it's unfortunately a part of the new, you know, the new norm, if you will, in terms of understanding what it means to be more skeptical of emails and other forms of potential manipulation, or just be aware of, you know, the sensitivity around the data and the other risks. If I assume that everything that comes to me in the first place is false, I'm gonna spend a lot of time verifying stuff. So that may add more time to their workflows and make things even more complicated.
I, I think that's, that's very true. And there's a number of programs, you know, we implement, um, tools that actually generate those to help you practice, uh, and detect those, uh, and sort of train you on being skeptical to do that. And it's fairly, fairly quick.
You, you basically hit an icon to say, Hey, report this as phishing and, and, and so forth. And I think programs like that, education, uh, that's, you know, basically annualized training and other, other forms of, uh, cyber education, um, go a long way. Do you think with the rise of ai, it seems like it's getting easier to create these, uh, fraudulent attacks and phishing schemes and whatever else is going on.
So might things get a little bit worse before they get better? Absolutely. I, I think that's, uh, that's, uh, gonna be something that's growing in prevalence that you see and read about more and more, uh, being able to fake, uh, somebody's voice, uh, and generate a phone call that sounds just like me.
Uh, it's incredible about how, how well that can be done with so few words, if you will. And, uh, it's very difficult to detect those things. So, um, there's a number of potential things that you can do to combat against that.
Awareness is good. Having, you know, your own, let's say called private key. I, I know of an example where, uh, a business owner, uh, actually had somebody impersonate them their voice while they were on a flight.
They knew they were on a flight and, uh, emailed their admin to approve a po. Uh, and they went so far as that CEO had a specific word, the, the admin would ask when asked to do those approvals as a double check, and they knew what that was. So, uh, things are getting quite sophisticated.
I know that's an anecdote, but it's happening more and more and it's, you know, it's, it's very real. It gives new meaning to the phrase safe word, right? That's right.
So when you look at all of this, what is your best advice to cybersecurity professionals in the healthcare field? Uh, 'cause it's easy to be overwhelmed, it's kind of, maybe it feels a lot like you're always fighting a losing battle, but what can you do to kind of preserve your sanity? Yeah, I think that's great.
And you know, I'm a big fan of the keep it simple methodology and it, it sounds very simple, but I think with some, uh, basic approaches here, you can make headway and what can seem like an overwhelming environment. Um, and it really comes down, I start in this order always, which is, um, you gotta invest in your people and help educate them. And we talked a little bit about that because it all comes down to your folks and the processes then that they implement.
So I think, you know, getting a few good cyber professionals are investing in some augmented support to put people with the expertise in place to look at and do a, a formal risk assessment and understand what your risk profile looks like and where to go first and where to start, uh, will help you look at what was previously maybe an overwhelming environment on not knowing where to start, uh, to come back with a risk treatment plan to say, okay, here's what my overall risk looks like. Here's a risk prioritized approach to go after it and then go implement that. And it really combines those people with those right processes, uh, and leveraging maybe some key technology, uh, that kinda round out your overall information security ecosystem for a hospital.
Um, I think one area of particular interest is the medical devices are unique compared to other OTIT, so you can't just do remote software patches. In fact, most medical devices, many medical devices may never get a patch for a known vulnerability. So you have this environment where you have to mitigate, not remediate risk 'cause you don't have a re remediation and you have to take those, those folks will have the right expertise and the right processes to know how to go do that, which can help re you know, improve your overall risk posture.
All right, folks, you heard of here, cybersecurity anywhere is a tough gig, but in healthcare, especially the folks that do that kind of work, it's they're unsung heroes. And so reach out to them at some point if you can and help whenever and however you can. Scott, thanks being on the show.
Thanks for having me. I really appreciate it. All right.
And back to you guys in the studio.