HeathCare and Cybersecurity : Taking a Zero Trust Approach
HeathCare and Cybersecurity: Taking a Zero Trust Approach
Healthcare and Cybersecurity: Taking a Zero Trust Approach is a research article written by George Vukotich. This article focuses on the rising cyberattacks on the healthcare system, primarily based in the US. With the rise of technology day by day, the different methods hackers use to attack also advance. Hospital systems still view this issue as a technical issue, with the IT departments being solely responsible. The author of this article argues the fact not only should this be viewed as a technical issue, but rather all levels, from the user to the network layer to the visibility and analytical layer should be taken into consideration. The author reviews a newer approach known as the Zero-Trust Approach, which addresses 7 key areas to protect.
Cyberattacks on Healthcare organizations have a critical impact because the targeted data includes patients' protected health information(PHI), financial information like credit card and bank account numbers, social security numbers as well as intellectual property, medical research, and innovations. Due to the importance of this data, in case of an attack, these organizations have a higher propensity to pay a ransom to get their data back, making these organizations vulnerable. It should also be noted that stolen health records may sell up to 10 times more than stolen credit card numbers in the dark web, and the cost to remediate a breach is almost 3 times of other industries.
In this article, the author mentions two technologies that are used to get protect from cyberattacks. These two technologies are Blockchain technology and Artificial Intelligence(AI). Blockchain technology, which is related to cryptocurrency, provides decentralized, peer-to-peer security for all transactions, although security vulnerabilities still remain. AI is also a widely used technology that grows rapidly.
The Zero-trust-Approach is a type of technology that focuses on users, assets and resources. The 7 pillars of this technology are as follows.
- Users: At the user level, the main focus is authentication, access and monitering of user activities.
- Devices: This is the physical device a user would use.
- Applications and Workload: This level should focus on making sure only certain users have login access, depending on the needs of each user.
- Data: This is where the value actually is. A strong encryption method should be used to protect data.
- Network and environment: This level focuses on data in motion. This should also include encryption methods.
- Automation and Orchestration: There should be an automated security response based on defined processes and security policies.
- Visibility and Analytics: Monitoring and analyzing events and activities should be done.
This technology, suggested by the author, can be used to minimize cyberattacks. As stated in the article, even though a system has high technology, a simple mistake from the user would be enough for attackers to gain access to the system. Something as simple as a common password, or clicking on a wrong link could result in a whole system compromise. The Zero Trust approach includes educating the users at its first level. This would make users more aware of such attacks and ensure they remain cautious in their actions. As the author states, though AI helps in many ways to protect against cyberattacks, it has many vulnerabilities as well. Day by day, attackers develop new tools, which includes AI to hack into systems.
The article mentions some examples for system breaches, The Target Store case and the Colonial Pipeline case. Though these attacks give an idea about the danger of cyberattacks, mentioning some attacks related to a healthcare breach would have given the reader a more thorough idea about the problem at hand. Though a brief mention of the growing cyberattacks in the healthcare system is mentioned, some data related to that claim being added would emphasize the point a bit more. Though the Zero-Trust Approach gives all-around protection, the technology is yet to be tested in the healthcare system. This technology might seem like a win on paper, though practically, it could be difficult to implement.
The issues that exist with the current cybersecurity measures in the healthcare system should be viewed not only as a technical issue, rather an issue that requires more than one party to be cautious on. While cyberattacks continue to evolve, a way to be protected from these attacks has become a necessity. The Zero-Trust approach gives a protection method that covers all levels related to a system, making this approach promising to make a difference in the healthcare system.
Research article Author: Geaorge Vukotich
Research article name: HealthCare and Cybersecurity: Taking a Zero Trust Approach
Critical review by: UOG0623003
This article gave a clear understanding about heath care and cyber security.I really appreciate how this blog enhances the information better.
ReplyDeleteThis review provides a clear understanding about healthcare and cyber security and got an ideaon the rising cyberattacks on the healthcare system.
ReplyDeleteOverall, this is a good piece of writing with relevant ideas and logical organization.
ReplyDelete