March 17, 2016 By Christopher Burgess 3 min read

Pick up a newspaper or open your news portal and you’ll likely encounter a story detailing a data security incident within the health care industry. One would think that the health care sector wouldn’t need to worry about cybersecurity. Or perhaps these incidents are due to the many cybersecurity jobs going unfilled? Both of those assumptions would be incorrect.

HIPAA

2015 was the year of the health care data breach in the U.S. Like a punch in the nose, the health care sector has been stung and is a bit bloodied, but it is still in the ring.

The Department of Health & Human Services (HHS) Office for Civil Rights (OCR) is working closely with the Department of Justice (DOJ) to address health care security. They are taking a bite out of covered entities with the enforcement of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule.

The OCR noted that since HIPAA was enacted in 2003, the top five areas of investigation are:

  • Impermissible uses and disclosures of protected health information (PHI);
  • Lack of safeguards of protected health information;
  • Lack of patient access to their protected health information;
  • Lack of administrative safeguards of electronic protected health information; and
  • Use or disclosure of more than the minimum necessary protected health information.

All these topics would fall within the expected purview of a health care entity’s CISO or IT team. Those entities most affected and required to take voluntary corrective action to achieve compliance are:

  • Private practices;
  • General hospitals;
  • Outpatient facilities;
  • Pharmacies; and
  • Health plans (group health plans and insurance issuers).

When the OCR’s compliance investigation finds that the entity was in gross violation of HIPAA, it refers the case to the DOJ. Since the inception of HIPAA, the OCR has referred more than 560 cases to DOJ.

A number of covered entities found themselves on the receiving end of DOJ-mandated fines or settlements due to deficiencies in their HIPAA compliance programs. Covered entities are learning that to be HIPAA-compliant is not synonymous with being secure. Those who display their unwillingness to be secure will be materially affected.

Cybersecurity Jobs and Infrastructure

One might expect that private practices and pharmacies are of such diminutive size that outsourcing IT infrastructure would be prudent from a cybersecurity perspective. One might also believe that hospitals, outpatient facilities and health plans/insurers would have substantive resources to not only have a CISO, but to also have cybersecurity professionals on hand.

Entities of all sizes are in the hunt for skilled personnel. Reviewing open position requirements, one sees the need for qualified security personnel for the cybersecurity jobs. According to Modern Healthcare, more than 50,000 positions posted in 2014 required applicants have the crown jewel of security certifications: the Certified Information Systems Security Professional (CISSP).

That might be tough, as there are just under 68,000 individuals in the U.S. who have obtained their CISSP certification. The health care sector competes against all other industries for those individuals.

With the need clearly identified, there is no shortage of opportunities or cybersecurity jobs. Indeed, a review of the IT jobs within the Health Information and Management Systems Society (HIMSS) showed that the states of California, Florida, Texas, Pennsylvania, Ohio, New York, Illinois, Massachusetts, Virginia and Michigan were the top 10 centers where HIMSS IT talent is being sought.

The HIMSS predicted sustained growth of IT requirements within the health care sector. However, there is a dearth of qualified personnel. CIO discussed how the talent shortage in cybersecurity is hitting the health care arena hardest. One salient point is that there is a greater demand for IT professionals, including cybersecurity professionals, than budgets permit.

Are You Resourced?

CIO shared a question from Ernie Hood, senior research director for the Advisory Board Co., a large health care consulting firm based in Washington, D.C. He asked: “Is the barrier, ‘I can’t find people with the skills I need,’ or is the barrier, ‘I don’t have the resources from the organization to execute what they’re asking me to do?'”

Those in the health care sector with cybersecurity jobs to fill may want to step back and assess their resource distribution and realign to the reality. Invest now in cybersecurity or continue to be the ignoble poster child when the annual data breaches are tallied.

More from CISO

Making smart cybersecurity spending decisions in 2025

4 min read - December is a month of numbers, from holiday countdowns to RSVPs for parties. But for business leaders, the most important numbers this month are the budget numbers for 2025. With cybersecurity a top focus for many businesses in 2025, it is likely to be a top-line item on many budgets heading into the New Year.Gartner expects that cybersecurity spending is expected to increase 15% in 2025, from $183.9 billion to $212 billion. Security services lead the way for the segment…

On holiday: Most important policies for reduced staff

4 min read - On Christmas Eve, 2023, the Ohio State Lottery had to shut down some of its systems because of a cyberattack. Around the same time, the Dark Web had a “Leaksmas” event, where cyber criminals shared stolen information for free as a holiday gift. In fact, the month of December 2023 saw more than 2 billion records breached and 1,351 disclosed security incidents, according to research from IT Governance — an increase of 332% and 187%, respectively, over the month of…

Overheard at RSA Conference 2024: Top trends cybersecurity experts are talking about

4 min read - At a brunch roundtable, one of the many informal events held during the RSA Conference 2024 (RSAC), the conversation turned to the most popular trends and themes at this year’s events. There was no disagreement in what people presenting sessions or companies on the Expo show floor were talking about: RSAC 2024 is all about artificial intelligence (or as one CISO said, “It’s not RSAC; it’s RSAI”). The chatter around AI shouldn’t have been a surprise to anyone who attended…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today