Advancing Surgical Care Podcast
Essential news and information for ambulatory surgery centers (ASCs)
Advancing Surgical Care Podcast
Cybersecurity for Surgery Centers
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode of the Advancing Surgical Care Podcast, ASCA Chief Executive Officer Bill Prentice talks with Dr. Paul Alcock, chief information security officer for Surgical Information Systems, where he leads the company’s enterprise cybersecurity program, including threat and incident management, security policy and governance. Their conversation took place at ASCA’s Annual Conference in Orlando, Florida, following Dr. Alcock’s presentation on cybersecurity in ASCs. With the advent of serious online threats to health care providers and their patients, Dr. Alcock’s timely counsel and advice should not be missed.
Welcome to the Advancing Surgical Care Podcast, brought to you by ASCA, the Ambulatory Surgery Setter Association. ASCA represents the interests of outpatient surgery setters of every specialty and provides advocacy and resources to assist them in providing safe, high-quality, cost-effective patient care. As with all of ASCA's communications, please check to make sure you are listening to or viewing our most up-to-date podcasts and announcements.
SPEAKER_01Hello and welcome to the Advancing Surgical Care Podcast. My name is Bill Prennis. I'm the Chief Executive Officer of the Ambulatory Surgery Center Association, or ASCA, and host of this episode. We're recording today at ASCA's 2024 Annual Conference and Expo in Orlando, Florida. My guest today is Dr. Paul Alcock, who joined us from a very timely presentation titled Protect, Prevent, Prevail: A Proactive Approach to Cybersecurity in ASCs. Dr. Alcock is the Chief Information Security Officer for Surgical Information Systems, where he leads the company's enterprise cybersecurity program, including threat and incident management and security policy and governance. Dr. Alcock also serves on the Global Information Assurance Certifications Advisory Board and is an adjunct professor of cybersecurity at New York University, North Carolina State University, and the University of Central Florida. Welcome, Paul.
SPEAKER_02Thank you for having me.
SPEAKER_01So, Paul, at our Ask a Board meeting yesterday, it was clear that cybersecurity threats were on every board member's mind, given the events that took place at Change Healthcare in February, which led to the disruption of healthcare building and data systems across the country. So needless to say, cybersecurity has moved to the top of mind for the entire healthcare community, making your participation here at the conference both timely and welcome. So let's begin with your assessment of both big picture threat levels in healthcare, and then if you could, bring it down to the level of a standalone surgery center and what they need to do and should be most concerned about in terms of cybersecurity.
SPEAKER_02Yes, certainly great question. So I think broadly speaking, the change healthcare incident really highlights that the healthcare industry continues to be highly susceptible to extortion type attacks such as ransomware. And with the interconnectedness of the healthcare ecosystem and the dependence we have on third-party vendors for critical business functions, I think organizations are at significant risk, not just from their own business being compromised, but through the compromise of partner organizations, which is really what we saw with the change healthcare incident. Now, for a standalone surgery center, they really need to focus on understanding the risks to their business, not just from threat actors looking to gain access to their systems, but also how dependent they are on vendor relationships for providing full service patient care. I think it's also important to not have the mindset that as a smaller healthcare provider, adversaries wouldn't be targeting your data. In fact, the opposite is true. We typically see these high-profile attacks like the change healthcare incident all over the media. But it's much more common for the small to medium-sized healthcare businesses to be the victims of these extortion tactics.
SPEAKER_01That's a really important point, and I just want to highlight that. So it's really that, you know, because you do take notice of these really big exposures, but these are happening all the time in smaller healthcare settings like a surgery center.
SPEAKER_02Yeah, and I was reading statistics earlier today. In fact, across all of the critical infrastructure services, healthcare is the number one targeted, the number one industry targeted for ransomware type attack. So yes, we do typically see all those big healthcare systems being targeted in the media. The smaller ones don't make the news, but they're much more prevalent.
SPEAKER_01Wow, very interesting. Well, I'm sure a lot of surgery centers that are listening to this are asking themselves today where to even begin to assess the risks. Do they attempt to do this on their own? Do they need professional help? And as you know, we're primarily talking about small businesses that don't have the resources of a large corporation or even a large health system. So what advice can you give there?
SPEAKER_02Yeah, I think it's a combination of both. I think for most small healthcare businesses, kicking off a risk assessment internally is a good first step. And this really can start with a simple audit of their current practices and systems, trying to identify any obvious gaps or vulnerabilities that may exist. We've also got organizations like the Healthcare Information Sharing and Analysis Center, the HISAC, and they have dedicated working groups for assisting healthcare organizations in areas such as risk management, supply chain risk management, incident response, many other areas of cybersecurity where you can begin to discuss and seek advice from other healthcare businesses who've implemented some of these strategies in the past. And I think that's a really good start.
SPEAKER_01So taking into account, you know, as we're talking about this, the scale of an independent surgery center and the personnel and the resource limitations that obviously go along with that, and you kind of were touching on this, but what what are some of the most practical and affordable, likely most important preventive measures that our members should be thinking about in terms of mitigating their exposure to both an internal or external cybersecurity threat?
SPEAKER_02Yeah, uh and another great question. And I think implementing fundamental cybersecurity controls, it really doesn't have to be expensive, right? I mean, there are technology is expensive from a security standpoint. We've got sophisticated security tools that you can go out and purchase for your organization. But if we just stick to the fundamentals, those alone really reduce the risk significantly. So I'm talking about things like strong password management policies, leveraging multi-factor authentication whenever possible, making sure that you're updating and patching your systems regularly, segmenting your networks, not to get too technical, but maybe deploying some antivirus, some endpoint protection technologies, which is obviously going to require some form of investment, but it's typically on the lower end of the scale when we're talking about the cost. Employee training is also going to be really important for they're the individuals that are being targeted at the end of the day. It's your employees through these social engineering type attacks.
SPEAKER_01And so this seems like one of those areas where if you spend a little bit money and time and energy on the front end, you are probably saving yourself a lot of time, money and energy on the back end if a problem pops up.
SPEAKER_02That's exactly true. And you're always gonna have some some level of risk, right? No matter what controls you put in, whatever investments you make, you look at change healthcare, you would think a company of that size, they're gonna have some pretty expensive, sophisticated tools protecting their networks, yet they still got compromise. So the goal here with cybersecurity is to reduce the risk as much as possible. Hopefully it frustrates the bad guys enough that they move on to the next uh the next organization, right? That's very well put.
SPEAKER_01And that's obviously an admirable goal to have. So, as you know, if a surgery center were, let's let's look go to the worst case scenario, were to suffer a serious data breach or cyber attack, their reputation of future viability will also largely depend on how well they respond, right? Both in terms of taking remedial actions and how they communicate with their various publics and regulators. And I think this is probably something we now learn from the change healthcare experience, too. So I'm sure we could spend uh probably a college semester or more on this topic, but since we only have a few minutes, can you share your best advice on how to prevent turning a bad situation into a disastrous one?
SPEAKER_02Yeah, it's gonna be in the preparation ahead of time. Uh I kind of talked about this this morning. Getting ahead of the game, being proactive, developing an incident response plan that includes dedicated team members. Uh, they don't have to necessarily be technical guys, but just folks who are going to represent the business from a technical standpoint, from a response standpoint, should there be any type of incident, getting connections with third-party consulting firms that may be able to help you with incident response, with marketing communications, legal guidance, having the appropriate cyber insurance in place. The more that you prep ahead of time, the the the lesser the impact's going to be once uh once that that attack's realized.
SPEAKER_01And I imagine this isn't one of those like set it and forget it things. This is something that you want to be mindful of and be updating and staying current on, you know, year after year to make sure that you know you're you're you're always in the best position to protect yourself. And is that true?
SPEAKER_02Exactly. And cybersecurity, there is no end game in cybersecurity, there's no finish line that we're working towards. The threat landscape's always evolving, the bad guys are always trying new tactics, and we're always trying to keep up. But yeah, you're exactly right. Whatever processes, controls, plans that we put into place, we need to periodically be reviewing those and making sure that they remain relevant and that they're going to help us ultimately and build that resilience.
SPEAKER_01Paul, you mentioned uh an audit as one of the things to do. Can you go into a little more detail about what that would entail for a surgery center?
SPEAKER_02Yeah, certainly. So there's when we're performing any kind of risk type assessment, we really want to start off by getting an understanding of our own networking environment, our own IT infrastructure, inventory all of our systems, where our critical data lies, what is it that we're trying to protect within our organization, what are our critical third-party vendors? So we get a real good lay of the land relative to how our business functions from an IT standpoint and who we rely on for those critical business functions. Once we have that inventory in place, again, this is when we start looking towards the cyber threat landscape, getting an understanding of what type of adversary are we worried about, how are they likely to attack us? What motivates them? What are their tactics and techniques looking to get in tired of our organization and get their hands on their data? And then from there we can begin to look at compare the two, see where our vulnerabilities exist. If we have threat actors out there that we know like to exploit tools like remote desktop protocol, and we know that based off of our assessment, our inventory that we're using remote desktop protocol, then maybe we can start looking at that and how we can shore up that particular vulnerability. So it's kind of a multi-pronged approach, understanding your adversaries and what they're after, and then understanding your own environment and seeing where those gaps exist between the two and working to prioritize how we can reduce those gaps.
SPEAKER_01Paul, you mentioned insurance as being a component of that every surgery center should include in terms of their cybersecurity plan and protection. Can you go into a little more detail about what kind of insurance are we talking about? What should they be asking for? You know, just what that would look like for a surgery center?
SPEAKER_02Yeah, yeah, of course. And you can often tie in specific cyber insurance to your annual business insurance policies. There are certain vendors who offer these types of coverage and they're really gonna protect you in the event, maybe like the change healthcare situation where a lot of uh providers were struggling, they weren't able to receive payments, process claims due to the outage that change healthcare suffered. So having a cyber insurance policy running in the background is gonna help alleviate some of those financial burdens. Also, if you're the victim of a ransomware type attack, these insurance policies are gonna cover you up to your certain level. Should you need to pay the ransom to recover your data? Should you incur expenses from we talked about leveraging third-party consultants to help you with the response, any external legal counsel, that sort of thing, any annual credit monitoring that you may have to offer compromised patients?
SPEAKER_01Uh that's great information. Uh, it's something that I'm sure a lot of folks haven't thought about and something that they definitely should be talking to their insurance brokers about. So that's a great point. Well, this is an extraordinarily important topic, obviously a very timely one, and one that I think we're gonna have to make sure that the AskA membership stays focused on year after year. So I know that I appreciate the fact that you came here to Orlando and spoke at this conference, and I imagine we'll need you back again and again and again to continue to make sure that people are focused on the right thing. So thank you for your participation here at ASCA 2024 and for taking the time to talk with me today. As I said at the outset, this is something that we're gonna just have to keep in the minds of our members forever, and I appreciate your willingness to share your expertise with us today. So thank you for being here, Paul.
SPEAKER_02No, no, thank you. And I'd be happy to come back uh and and talk to you guys about cybersecurity. Keep it front of mind for everybody.
SPEAKER_01I will sign you up for that. So before concluding, I would like to acknowledge our podcast sponsor, AMSurge, a leading ASC management company with more than 250 ASC partners in 34 states. To learn more, visit AMSurge.com.