Healthcare Security Insights and Perspectives from Mac McMillan

Healthcare IT Today has been a partner with the HCP Conferences for a while now, but this week was the first time I was able to attend in person.  The event has a unique reverse expo format where the health IT professionals sit at tables and the vendors go around visiting the tables.  It was a well run event with some really great health IT professionals and vendor sponsors.

Along with the reverse expo, they also do a number of education sessions, networking, full meals, and they love to have fun (HCP put on a great party with attendees at Drai’s Nightclub in Vegas).  Today’s keynote session was with Mac McMillan who everyone in the healthcare security world probably knows.  He was founder of Cynergistek which recently sold to Clearwater so Mac could finally start his retirement where he’s still researching and following the healthcare security industry.

We live tweeted Mac’s talk and here were some of the great healthcare security insights he shared.

Many of us only think about the first two expenses when it comes to cybersecurity. However, Mac appropriately points out that the later two are much more expensive.

Given the risks, it’s pretty sad to hear that Mac suggested that most healthcare organizations are flying blind. They don’t really even know their risks and they’re not appropriately monitoring for breaches.

He then reframed security for us to focus not on the data, but on the patient. When you lose some data, that doesn’t seem like that big of an issue. However, when you start talking about how a breach will impact patients, it becomes more real and important.

You’ve probably all seen this, but healthcare has proven to be a great target for hackers since it’s just as lucrative as other industries like banking.

I’d seen the uptick in ransomware, but this stat astounded me.

Lots to think about with ransomware, but Mac described ransomware as really a triple attack. We often just hear about the first, but ransomware hackers keep attacking even if you choose not to pay the initial ransom.

For those healthcare organizations that are wondering if they should pay a ransomware or not, Mac shared this compelling info about those who paid and those who didn’t. The last stat illustrates that many have good backup and business continuity plans and that everyone should invest more in those.

Mac also shared a number of great insights into the security challenges facing healthcare. First up is third parties being compromised and impacting your organization.

He told some amazing stories of organizations that didn’t disclose when a breach happened. Plus, the story of the Uber CISO who may be facing jail time for not doing so. Long story short, you have to disclose.

We hear a lot of talk of digital transformation. Mac reminded us that these two words are really scary for CISO’s.

Mac also highlighted the disadvantage we have against those exploiting us and our systems. He suggested we need to close this gap.

Mac also shared a view into the future of what security challenges are coming. Plus, he made an impassioned case for why we need to start thinking about things like Quantum Computing security challenges now before it’s too late.

Finally, he took from his military background to suggest an approach healthcare organizations should take towards cybersecurity.

Thanks to Mac McMillan for all his done for the healthcare cybersecurity industry. Plus, it’s great to see that even in retirement, healthcare cybersecurity’s chief educator is still sharing his wisdom.

About the author

John Lynn

John Lynn is the Founder of HealthcareScene.com, a network of leading Healthcare IT resources. The flagship blog, Healthcare IT Today, contains over 13,000 articles with over half of the articles written by John. These EMR and Healthcare IT related articles have been viewed over 20 million times.

John manages Healthcare IT Central, the leading career Health IT job board. He also organizes the first of its kind conference and community focused on healthcare marketing, Healthcare and IT Marketing Conference, and a healthcare IT conference, EXPO.health, focused on practical healthcare IT innovation. John is an advisor to multiple healthcare IT companies. John is highly involved in social media, and in addition to his blogs can be found on Twitter: @techguy.

   

Categories