For organizations in highly regulated sectors such as health care, compliance with regulatory standards is not just a good idea; it’s the law. Moreover, there is a broad consensus that the regulatory standards are soundly based on security principles. Complaints about excessive or misguided regulations are not often heard.

But the flip side of this regulatory soundness cannot be taken for granted. Being in compliance with regulatory standards does not, in itself, ensure adequate security. This is for two different reasons, though both are rooted in technological complexity.

The first is the rapid evolution of technology, in particular the explosive growth in the number and variety of network connections. The second is the human factor in security, meaning that it is ultimately as much a state of mind as a matter of specific technical measures.

Listen to the podcast: The Biggest Security Risks in Health Care IT Systems

Compliance Is a Moving Target

According to a Level 3 report, “cyberthreats and the security landscape evolve rapidly, and industry standards cannot keep pace.” Compliance standards can only reflect best practices as of the time when the draft standards were approved. But because of the rapid evolution of the technology environment, best practices are a fast moving target.

Today’s networks are liable to have far more endpoints than what was typical even a few years ago. Indeed, the contemporary focus of security thinking is shifting from primarily endpoint protection to an emphasis on trust of specific users and devices. The current compliance framework only imperfectly reflects this very recent development.

In health care, we are now moving from mere mobile connectivity to the Internet of Things (IoT) and connected devices. This can mean that critical devices such as dialysis machines may now be potentially vulnerable to malware. In other industries with compliance rules, from finance to utilities, the IoT poses comparable evolving threats that the current compliance framework is not fully designed to handle.

Social Engineering and the Human Factor

Connected devices are one of the three leading threats for the health care sector — the others being distributed denial-of-service (DDoS) attacks and phishing attacks, according to the Level 3 report. DDoS attacks can paralyze networks, which in health care can be literally life-threatening.

But the challenge of phishing, as with other types of social engineering, is that it attacks systems through their human users. A particular insidious version, called spear phishing, goes even further by leveraging personal social information to trick users.

Health care is uniquely exposed to social engineering threats because of its large and varied workforce. But the hazards of social engineering attacks extend across industries, and there is no purely technical solution to the challenge of human error. Not even a fully updated set of compliance standards could automatically protect against social engineering attacks. User education is more important than ever, and security will ultimately depend on this human factor.

Compliance Is Not a Cure-All

Meeting compliance standards remains essential to security, not just in health care, but in all industries subject to compliance rules. But compliance should be regarded as a framework that helps make security possible, not a magic wand that automatically makes your organization secure.

Read the IBM X-Force Research Report: Security Trends in the Health care industry

More from Data Protection

Why safeguarding sensitive data is so crucial

4 min read - A data breach at virtual medical provider Confidant Health lays bare the vast difference between personally identifiable information (PII) on the one hand and sensitive data on the other.The story began when security researcher Jeremiah Fowler discovered an unsecured database containing 5.3 terabytes of exposed data linked to Confidant Health. The company provides addiction recovery help and mental health treatment in Connecticut, Florida, Texas and other states.The breach, first reported by WIRED, involved PII, such as patient names and addresses,…

Addressing growing concerns about cybersecurity in manufacturing

4 min read - Manufacturing has become increasingly reliant on modern technology, including industrial control systems (ICS), Internet of Things (IoT) devices and operational technology (OT). While these innovations boost productivity and streamline operations, they’ve vastly expanded the cyberattack surface.According to the 2024 IBM Cost of a Data Breach report, the average total cost of a data breach in the industrial sector was $5.56 million. This reflects an 18% increase for the sector compared to 2023.Apparently, the data being stored in industrial control systems is…

3 proven use cases for AI in preventative cybersecurity

3 min read - IBM’s Cost of a Data Breach Report 2024 highlights a ground-breaking finding: The application of AI-powered automation in prevention has saved organizations an average of $2.2 million.Enterprises have been using AI for years in detection, investigation and response. However, as attack surfaces expand, security leaders must adopt a more proactive stance.Here are three ways how AI is helping to make that possible:1. Attack surface management: Proactive defense with AIIncreased complexity and interconnectedness are a growing headache for security teams, and…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today