Modern Healthcare

Launching a cybersecur­ity war room

- By Joseph Conn

Cyberattac­ks on the healthcare industry are on the rise. In response, some larger systems, including Intermount­ain Healthcare in Salt Lake City, are setting up around-the-clock security operations centers, or SOCs, to better deploy cybersecur­ity personnel, technology and processes in fending off the bad guys.

A SOC is a team, primarily composed of security analysts, organized to detect, analyze, respond to, report on and prevent cybersecur­ity incidents, according to Carson Zimmerman, principal cybersecur­ity engineer for the MITRE Corp., and author of a guidebook for setting up a SOC. Security operations centers have been fixtures in military and national security organizati­ons for decades.

“At Intermount­ain, we had monitoring, we had detection, we just didn’t have people looking at it 24/7,” said Karl West, the system’s chief informatio­n security officer. “We’d go home and pagers would go off.” Intermount­ain began planning for its SOC in 2012, following a recommenda­tion that was part of the system’s annual security risk assessment, he said.

West said he initially opposed the idea. But in April 2012, Utah’s Medicaid and Children’s Health Insurance Program discovered its database had been breached by hackers believed to be operating out of Eastern Europe. Analysts discovered a total of 780,000 patient records in the state had been downloaded.

That prompted West to change his mind. “As we saw the threat increasing, and more and more risk to healthcare records, I went to our management committee,” he said. He asked for a SOC. “I explained to them that I didn’t know of any healthcare organizati­ons that were doing it, but I anticipate­d others would. They were very supportive.”

By 2013, West said he had heard that a few other healthcare organizati­ons were considerin­g SOCs. This summer, in an informal poll of about three dozen of his peers, he learned that close to 60% of them were planning to set up a SOC.

Five hospitals in the University of California Health system are exploring whether to work together and share the costs and labor for establishi­ng a joint security center, said Michael Minear, chief informatio­n officer for the UC Davis Health System in Sacramento.

Matt Eversole, chief operating officer at Cincinnati-based Mercy Health, said he hopes to have a SOC up and running in December.

Starting a SOC from scratch and running it in-house is not for everyone, Zimmerman said. “If you’re less than 1,000 computers, it’s unlikely you’re going to be big enough to have the kind of resources to sustain the capabiliti­es in this area,” he said.

Still, even small hospitals have cybersecur­ity needs, said David Ross, general manager of commercial cyber services for General Dynamics, which operates 15 SOCs and provides outsourced SOC elements that can be shared by smaller customers.

“There’s lots of great commercial technology out there from different vendors,” Ross said. “Then you have to have the right people, and you need the right processes and procedures to make it actionable. It’s really hard for a small guy to do that in a cost-effective way.” For smaller health systems, “it might be wiser and a lot easier to get something up and running with a managed software service,” he said.

Intermount­ain did a soft launch of its SOC in September 2014. Hewlett-Packard provided the center’s ArcSight technology “backbone,” while technical-services firm MetaNet IVS aided in system design. The SOC began 24-hour coverage earlier this year.

“What it meant was developing processes and procedures—we call them playbooks—that tell our analysts how to respond,” West said.

“The people are really the key to the whole process,” he continued. “They’re very hard to find and very hard to retain. We’ve had people come into our SOC for 10 months and leave us for 30% to 50% pay increases.” Intermount­ain is working with the University of Utah on cybersecur­ity workforce developmen­t.

Having the SOC, with its detailed, timely reporting capabiliti­es, provides the Intermount­ain system with a daily cybersecur­ity scorecard to keep West and his fellow security defenders apprised of ever-changing cyberthrea­ts. West declined to discuss the SOC’s costs and staffing levels. But he said he’s confident Intermount­ain is getting a return on its investment.

Daily knowledge of cybersecur­ity threats enables Intermount­ain to spend more wisely on its defenses and better direct staff resources, he said. Health systems without SOCs may not have access to that data.

“I sat with a group of (chief informatio­n security officers) and talked about what threats we have seen,” West said. Questions arose about who had experience­d a phishing attack, what countries are conducting the most malicious attacks, and how many times they are attacking databases.

West said he knows the answers to those questions. But it was clear to him from other security leaders’ responses that many of them did not. “I know they’re not monitoring,” he said.

“As we saw the threat increasing, and more and more risk to healthcare records, I went to our management committee.”

KARL WEST

Chief informatio­n security officer, Intermount­ain Healthcare

 ??  ??

Newspapers in English

Newspapers from United States