Wednesday, 1 July 2015

Health Data Security Use-Cases for Securing Data Centers

We stay on the topic of health data security because as a critical piece of technology, this will always be a challenge for any healthcare organization housing sensitive data. Healthcare is also bound by regulation, compliance, and evolving considerations around the end-user.

When you look at a healthcare ecosystem, you’ll see a lot of the same cloud and even data center components that other verticals will deploy. There’s application delivery, storage controls, wireless architectures, and more. However, policy deployment and health data security best practices can be quite different. Still, the idea for healthcare organizations is to deploy smart security. This means properly locking down an entire environment while still empowering the end-user.

Health data security necessary as organizations improve data centers

To do so, health data security professionals must think outside the box when it comes to securing traditional data center platforms and the workloads that they support. With that in mind, let’s look at three healthcare data center use-cases and where security plays a direct role.

Application delivery

It used to be easy to define what an “app” was. Now, there are a number of new applications being delivered through a number of different means. You can have traditional applications being delivered from a single server platform, or you could be virtualizing your entire management platform like EPIC on Citrix. Regardless of how you’re pushing down your apps, there are some great ways to secure it all. New, centralized controls will now allow you to deliver a diverse set of applications all from one portal. These can be apps delivered via the web (HTML5), streamed, virtualized and pushed down with a client, and they can even be local to the data center. The idea is to point all of these applications into a controlled portal. Allow users to access all of their applications from one spot and then secure their entry methodology. This allows you to centralize your applications and always control who is accessing applications, where they’re coming in from, and even the kinds of devices they might be using. Geo-fencing, compliance monitoring, and even security policies can be deployed based on contextual awareness. This allows for greater security and better application flow. Furthermore, this allows you to support more devices and greater amount of content delivery use-cases.

Wired/Wireless Control

Network density will only continue to increase. We’re seeing a large influx of new devices coming into healthcare architectures. Today, your network must act as both a sensor and an enforcer when it comes to health data security. Fortunately, this also means optimizing user experiences and how content is delivered. New kinds of identity engines allow you to dynamically control who is accessing your network and what they’re looking at. Most of all, you can dynamically control user connections all from one centralized location. Network operations can be a powerful tool for both security and user awareness. For example, if a user is accessing an application and they leave a facility, you can set a policy that a VPN is automatically created when the switch from a secure wireless connection to a cellular link. The cool part is that this is all done seamlessly, and allows the user to be continuously productive. Furthermore, new wireless controls allow you to catch rogue devices, mal-formed packets, and even anomalous traffic that might be flowing through your network. All of this helps you control the threat continuum and still allow the user to be productive.

Storage and data management (on premise and in the cloud)

The ways that healthcare organizations manage their data has changed pretty dramatically. The cause has been the digitization of the healthcare industry. Originally, there were challenges around scaling into the cloud. Now, new changes in HIPAA – like the Omnibus Rule – allow you to upload files into a business associate (BA) cloud architecture while still remaining compliant. New data management solutions allow you to always own the keys to your kingdom and continuously control the entire data tokenization process. When working with storage and data solutions, don’t be afraid to look at the cloud for options. From a security perspective, you still retain control of how the data flows, where it’s stored, and how it has access. However, you can now scale some of this information into a cloud ecosystem. Not only can this be a secure architecture, this also helps offset costs around data storage.

New use-cases are always emerging within the healthcare field. Soon, IoT and more interconnected devices will redefine healthcare operations and even patient care. All of this will need to be controlled as new applications are delivered with richer content, more network density takes place, and even more information is passed through the data center. When it comes to securing your new kinds of workloads, don’t be afraid to get creative and test out new solutions. New capabilities around environment segregation allows you to create powerful sandboxes and containerized ecosystems to test out new solutions. Take advantage of virtual systems and data center multi-tenancy when testing out new kinds of health data security platforms. This will help keep your healthcare security architecture agile and ahead of the curve.

View the original content and more from this author here: http://ift.tt/1dxRUZV



from health IT caucus http://ift.tt/1BYK5Z0
via IFTTT

Identity & Access Risk Intelligence

Business Overview

Client is a global healthcare company that provides medical technologies and services for global healthcare customers. Headquartered in the United Kingdom, the company is a world leader in healthcare technologies and solutions.

Challenges
Privileged Account Monitoring

With over 4000 servers being used for various applications and processes, the company was unable to monitor activities carried out by high privileged accounts. With various security policies set in place, monitoring for privileged accounts and privileged account owners, there existed no technological solution within their existing security portfolio that would allow for data driven threat and risk assessments and monitoring of their infrastructure and sensitive information.

Data Egress of Classified Information

As a pioneer in the medical technologies space, the client has a large number of highly sensitive and proprietary design documents and sketches. Classified data specification is stored in the clients existing document management solution. These documents are stored in a common, central repository along with general unclassified documents. The security team was not able to identify users who may be downloading classified documents that do not meet their classification.

Rogue Access Privileges
Access Outlier Analysis

Detection of outlier access privileges held by user accounts, shared and service accounts using peer group comparison analytics.
Securonix was implemented to extract all privileged accounts and correlate them to identities through its identity analytics module. The system then ingested all entitlements for these accounts and identities, providing automated reports that show the access outliers in their environment allowing the security team to mitigate access risk by providing visibility into accounts where some access needed to be removed, certified or excluded.

Securonix Implementation Scope
Privileged Account Monitoring
Inactive Unix Account Cleanup

The client required an automated process that would detect inactivity of Unix accounts and flag for the suspension or removal of such accounts after a stated period of inactivity. Securonix was setup to detect inactivity of these accounts according to the customer’s policies and create alerts that would allow the security team to remove these accounts and privileges.

Service Account Monitoring

By policy, Windows Service Accounts are not allowed to perform interactive logon capability for a period of more than 14 days from the time they are provisioned. The client needed the ability to detect interactive logon activities that were happening past the set time frame and provide alerts on these activities.

Monitoring High Privileged Account Interactive Logins on Service Account

According to the customers policy, Windows Service Accounts are not allowed to perform interactive logon ability for a period of more than 14 days. The goal was to identify Unix and Windows non personal accounts as well as High Privileged Accounts with the ability to establish interactive logon sessions that are granted Administrative Access on servers that host critical systems or SOX L1 regulated applications and flag them for remediation.

Non Admin Accounts Present in Admin Groups

The client defined a goal to be able to identify Non ‘Admin’ accounts that are present in admin groups within the different directory services in the organization. According to the customer’s policy, users should never use their primary identity account present in admin or high privileged groups. Securonix Privileged Account Intelligence was used to detect such cases and flag them for remediation.

Terminated Users Access Privileges Cleanup

The objective was to create the capability to allow the customer to rapidly detect accounts and entitlements that are not deleted from the organizations directories within 48 hours of a user’s termination. Securonix was used to detect the termination flags in the company’s HR system and immediately identify events where employees were terminated while leaving their access entitlements intact.

Continuous Provisioning Control Violation

Detect accounts with privileged entitlements or accounts in privileged groups that are created directly on the Windows or Unix directory services thus circumventing the company’s IDM system. This was done by comparing account creation events to trace or evidence of creation in the IDM activity logs.

Smart Card Enforcement Violation

The client has strict rules and policies governing physical access through smart cards. The policy states that privileged accounts not having smart card authentication should not be seen logging in to systems. The capability was needed to detect such events and create the relevant flags and alerts.

Real time Fire call account Monitoring

Identify Fire call accounts that have been used on High Privileged Accounts on Windows/Unix Servers that do not show correlated check out activity in the vault(CyberArk).

Data Egress of Classified Information

  • Real time behavior based analysis of document checkout of type of document from the document management system
  • Real time fraud analysis to identify frequent checkout of a single document type
  • Real time peer based activity analysis to identify users checking out documents not accessed by their peers
  • Identify documents sent outside the customer’s environment after document downloaded from document management system – analysis using Palo Alto FireWall logs
  • Identify documents sent out via a DLP egress point after it had been checked out from document management system having the same file name
  • Identify document sent out via DLP egress point after it had been checked out from document management system depending on the file size of document checked out
  • Monitor DLP egress activity after document type checkout from document management system

Rogue Access Privileges

Spread across the globe in over 100 countries with IT privileges spread across multiple Active Directory Domain Controllers, this healthcare solution provider is unable to identify the access privileges that are required by its employees and contractors to perform their duties. With a complex Active Directory that has multiple nesting of permission groups and privileges, it is difficult for them to identify and cleanup rogue access permissions associated with user accounts, service accounts and shared accounts.

Even though the client has a very mature information security practice, as well as corporate awareness, traditional tools that they were using could not provide the capabilities for detecting rogue access permissions, risk assignment to access permissions and assignment of an identity perspective to each risk associated to the organization.

Provide Privileged Group Data Owners With a Clear Certification Process

The objective was to allow corporate data and application owners from multiple domains in the company to log into Securonix in order to review high risk users and privileges. This was done on a complex environment using Active Directory Authentication transactions that were run across multiple domain controllers with no trusted connection between the different domains.

Business Impact

Privileged Account Monitoring

The organization now has the ability enforce all of their existing security policies and detect the riskiest violators of their security policies. The Securonix platform provides the customer with the ability to enforce security policies and take immediate action on violations as opposed to their previous manual quarterly process. Privileged account monitoring has allowed the customer to implement security policies and have effective monitoring controls to detect violators in real time for previously non existing policies. The Securonix solution also included detection and monitoring capabilities for new risk vectors in their infrastructure and critical applications.

Data Egress of Classified Information

The client now has the ability to monitor data egress of their classified information. By introducing a behavior and peer based analytics approach to analyze risk, the client is now able to monitor risk and detect advanced persistent threats as they evolve. The Securonix Investigation Workbench was configured to allow the security and forensics team to investigate events from different dimensions, allowing them to visualize and understand the true threat scape posed by Advanced Persistent Threats (APTs). By implementing behavioral and peer based approach to risks, the client has detected risky events and security violations on their classified data and were able to mitigate the threats before damage was incurred.

Rogue Access Cleanup

For the first time the client has the ability to provide the data owners with the identity of the riskiest access privileges present in the groups that they own. They have the ability to identify rogue access permissions held by user accounts and non-personal accounts. The client’s security team now has the ability to detect derived permission and unauthorized permissions held by user accounts and service accounts when they are in nested directory groups. By risk scoring the rogue access privileges, the client has the ability to prioritize access cleanup during their quarterly access certification process.

View the original content and more from this author here: http://ift.tt/1BYkDCJ



from health IT caucus http://ift.tt/1dxRUJv
via IFTTT

Advanced Data Loss Analytics for a Global Defense Technology Provider

The Business

The customer is a high profile international defense contractor developing advanced defense and security products servicing a global customer base. The company has over 80,000 employees worldwide and operates in 25 different geographical areas. The company is a leader in defense innovations and sells its products to governments and large organizations.

Challenges

As a large defense and technology provider, the customer was facing high risk of sensitive data theft by rogue employees and contractors as well as a need to protect against theft by external attackers trying to get their hands on the company’s vast intellectual property information.
The client invested in an advanced DLP solution and SIEM to be able to monitor for risky events but due to the sheer size of the organization and the amount of data accessed on a daily basis, those solutions on their own were not enough and were generating false positives in high numbers that were not manageable.

The Securonix Solution

Faced with a critical need to be able to monitor and gain insights into how and by who their sensitive information is being accessed and the fact that they were not able to monitor for rogue employees, external attacks or activities performed by terminated employees Securonix was brought in to implement its Data Exfiltration and SIEM intelligence products to provide rapid visibility and behavioral analytics for sensitive data access and terminated user account monitoring

Client’s Solution Tour:

Core Use Cases Deployed:

Data Exfiltration

Securonix was implemented to analyze events that are generated by the customer’s DLP solution and enrich each event with identity and activity context. Securonix analyzes the activities performed by users by comparing each event to previous behavior by the user and also comparing it with colleague activity through its automated peer group analysis functionality. The solution then goes on to evaluate and risk rank each event by adding context that comes from HRMS, Firewall and Proxy data, allowing the security team to be aware of disgruntled employees (bad review, notice of termination in HRMS) as well as being able to flag employees for possible flight risk by evaluating other activities such as browsing the web on job sites etc. This creates a comprehensive picture that allows the security team to focus on those events that really need to be investigated.

By using Securonix to monitor the usage of its most sensitive information, the customer is able to significantly reduce the risk of data theft. The customer is no longer drowning in thousands of DLP alerts that more often than not, turn out to be false positives and is able to focus their efforts on those events that really matter.

Securonix is empowering the customer to rapidly detect and mitigate any misuse of data by providing immediate alerts to high risk events and providing the facilities to take action on these events in order to prevent the exfiltration of sensitive information from the organization. By being able to rapidly detect exfiltration attempts, the company is able to very significantly reduce the loss from exfiltration events.

Finding the needle in the needle stack

By enriching the events coming in from DLP with Identity and activity context, the client is able to reduce the total number of alerts that they need to investigate by up to 90%, and is reporting an overall reduction of false positive alerts of 99%. This is creating tangible savings for the client in time and resources that previously had to sift through thousands of false alerts.

View the original content and more from this author here: http://ift.tt/1R4wAO7



from health IT caucus http://ift.tt/1dxRSRJ
via IFTTT

The Cyber Security Personnel Shortage, Identity Theft & Fraud at the IRS

Question: What do a wave of baby boomer retirements and a trend toward outsourcing have in common?

Answer: The inability of state and local governments to fill cyber security jobs and increased risk of data theft.

It’s clear that years of wage and hiring freezes have made retirement or a move to the private sector an easy choice for cyber security pros in the public sector. From a recent article titled, States struggle to hire cyber security experts, “A run on retirement by an entire generation of baby boomers has exacerbated the shortage of qualified IT staff, with 86 percent of managers reporting they are having trouble filling vacant tech positions. The federal government isn’t immune to this trend as it’s been sited that the number of security personnel there has gone from over 400 to the mid-300’s.  When asked what skills are most challenging to attract and retain, two-thirds of state IT managers surveyed said “security,” followed by 57 percent who said, “programming and support.”  This trend is illustrated in figure below is from the 2015 NASCIO, “State IT Workforce: Facing Reality with Innovation survey.

 

Screen_Shot_2015-05-30_at_11.53.15_AM

This got me thinking about the recent attack at the IRS where hackers were able to request back tax returns for an estimated 100,000 people using data they’ve already collected. Where could this data come from? Of the organizations reporting data breaches in the last two years, ten data breaches ranging in size from 100,000 records to millions have been from state governments. While I’m not saying that citizen data used in the IRS fraud attack was stolen exclusively from state governments, this could be one likely source. Yes, I can hear those saying healthcare data can contain SSNs as can HR databases. What I am asserting is these problems are related. To identify fraud, it’s easy to link recent data breaches at the IRS and state governments to the shortage of cybersecurity personnel shortage, budget cuts, pay freezes and attrition.

 

What do we do about it?

While academic institutions are doing their best to educate more future cybersecurity professionals, most will opt for jobs in the private sector. Many will go to outsourcing companies to which state and local governments will continue to contract. Overall, this means security organizations need to hold vendors accountable for providing solutions that make fraud detection simpler and security operations more efficient.

 

One area in dire need for support is detection and incident response. Solutions in this area usually are either one or the other — detection or incident response. One always leads to another as the next logical step.  When we look at the current targeted attacks, it’s clear attackers know what kinds of defenses are in place and can figure out how to evade them. Even vaunted malware sandboxes aren’t a perfect solution when adding a few lines of code allows malware to detect the sandbox and not execute their malicious code. Once the malware is found, it often takes hours, days or weeks to find all of the hosts that were touched to determine which accounts were compromised and understand what data was stolen. This is hard and time consuming even for the most experienced cybersecurity professionals. This is due to processes built around the disjointed “detection OR incident response” crop of products organizations have bought.

While user behavior analytics products recently on the market give you additional visibility to do a good job of detection, most do not have the capability to build out the entire attack chain…except for Exabeam.  Exabeam learns normal behaviors to reveal those that are abnormal, assembles them into user session time lines that include relevant security alerts all in real-time. Not only will you see see the unusual behaviors, you’ll also save hours, days or weeks of time and lower the skill set required to detect andrespond.

View the original content and more from this author here:  http://ift.tt/1R4wAOi



from health IT caucus http://ift.tt/1f1nO2F
via IFTTT

Security Breaches and the “Crown Jewels” of Creativity and Research

The resent data breach at Penn State was a reminder to me of how much research and intellectual property is created at America’s universities. Research in quantum computing, materials science, and missile propulsion systems are a tiny fraction of the intellectual property and research being worked on by universities under contract with and a wide variety of defense agencies or waiting for commercialization.

This isn’t limited to the US. In the UK the Guardian reports, “…Students come and go, bringing laptops and mobile devices; visitors pass through from across the globe; researchers link up with organizations worldwide.” Collaboration across the globe and with governmental agencies comes with the territory. “There simply isn’t the ability to lock things down the way you could in a commercial organization.”

In the last 12 months Carnegie-Mellon, Stanford, University of Maryland, University of North Carolina at Chapel Hill, University of Delaware, and Virginia Tech University, and Marquette University have all been hit with data breaches with hackers looking to steal usernames and passwords of students and facility.

The intellectual property that many research institutions generate is similarly appealing to state-sponsored actors looking to capitalize on U.S. economic investments. As the New York Times has reported, at least one university has faced up to 100,000 daily penetration attempts from China alone.

According to Eric Vanderburg, Director of Information Systems and Security at JURINNOV, Ltd., “Malwareis often seen as a nuisance or a productivity inhibitor but an infected computer can pose a much great risk to organizations and it should not be overlooked.  Malware gets behind the organization’s perimeter and it can act with the credentials of legitimate users including administrators.”

View the original content and more from this author here: http://ift.tt/1FR63Ii



from health IT caucus http://ift.tt/1f1nNMa
via IFTTT

Tuesday, 30 June 2015

The missed opportunity of Medicaid innovation

When CMS released a proposed rule to make significant changes to Medicaid last month, it was the first major change in 12 years. The proposed rule addresses a sweeping range of program goals, including a desire to “catch up” Medicaid to Affordable Care Act requirements and objectives now in place for Medicare and commercial plans.

One of the most important parts of the ACA is also the least controversial: the creation of the Center for Medicare and Medicaid Innovation (CMMI). Given a specific mandate and adequate funding, CMMI has already advanced innovation in healthcare. Today, CMMI has authored numerous value-based reimbursement innovations, all designed to improve quality and efficiency. These payment reform initiatives are critical to transforming healthcare from fee-for-service to fee-for-value.

Despite the equal size of both “Ms” in the acronym, CMMI has much broader authority in Medicare than Medicaid. In Medicare, they can create new initiatives, grant waivers and even adopt the best results as new Medicare policy without congressional action.

Medicaid is a different story. CMMI cannot simply create accountable care or medical home programs in Medicaid nor can they grant waivers to Medicaid policy. They also cannot apply the Medicare waivers to the program integrity laws (such as the Stark or Civil Monetary Penalty laws) to new Medicaid initiatives.

Instead, states must apply through a pre-ACA process to obtain waivers to Medicaid policy. This process is highly bureaucratic, needlessly complex and long. According to a recent study, it takes nearly a year for CMS to respond to a new waiver application.

In that same span of time, CMMI rolled out several new programs including ACOs, medical homes and the Bundled Payment for Care Improvement in Medicare. But not one of these applied to Medicaid.

To be clear, many states are trying to innovate in payment reform. Today, at least five states have various bundled payment programs in Medicaid and 19 states have Medicaid ACOs. In some states, such as Ohio, payment reform goals have been pursued for many years. But the states do not have enough authority on their own to innovate in the way CMMI has done with Medicare.

Among the barriers are the program integrity laws mentioned above. Medicare participants in CMMI projects receive exemptions that not only cover these laws relative to Medicare patients, but the waivers even cover care delivered under agreements with commercial payers. Without these waivers, providers currently participating in Medicaid payment reform may be taking an unacceptable legal risk.  Furthermore, once innovation is proven successful in a state, there is no CMS-based effort to translate these findings across states.

CMMI is trying to work with the law as it exists today. Rather than force a single medical home project for Medicare, it wisely chose to launch in key states where a Medicaid medical home program was already in place and tailor the program in each state to match the local Medicaid program. Recently, in creating the new Oncology Care Model, CMMI made great efforts to create a program that states could choose to enable for Medicaid. These multi-stakeholder approaches to payment reform are critical to their success.

Medicaid has its own specific attributes that make the ability to meaningfully innovate even more important.

• There is a sweeping trend in Medicaid to end the carve-outs of behavioral health, which is among the most expensive parts of the Medicaid system. The ability to innovate with payment reform methods would be a powerful tool for states to use as new models of delivering behavioral health with medical care emerge.

• Many states have a significant access problem, with providers unwilling to accept Medicaid patients, for a variety of business reasons, including rates. The ability of payment reform to make Medicaid more financially attractive would increase access and quality for patients who need care.

• Medicaid is intended to be a state/federal partnership. One reason to have 58 different Medicaid programs (50 states plus D.C. and the territories) is to allow for localized approaches. But the barriers created by CMS impeding local innovation do not allow the states the latitude they need.

• In many states, Medicaid is delivered by Managed Care Organizations, entities that could greatly benefit from direct participation in CMMI programs (either existing or new) for their Medicaid members. As many of these payers operate in multiple states, having national-level coordination and regulation of their efforts toward payment reform makes perfect sense.

There were many options available to CMS to address this problem in the new rule. They could have granted CMMI broader powers to extend the waivers of the program integrity laws that exist for Medicare to Medicaid. They could have allowed CMMI a broader role in partnership with states for payment reform initiatives.

Most importantly, they could have given CMMI the authority to grant waivers to Medicaid policy in the areas of payment reform and quality improvement, even if they insist on retaining the current year-long process for waivers to benefits or financing.

Another option would have been to advance the timing of a little known area of the ACA called Section 1332 or the Wyden waivers. This part of the ACA is now unavailable until 2017, but it will greatly ease the process for states to get any form of Medicaid waiver. Recently, President Obama expressed support for moving up the date when Section 1332 can apply. Doing so, either in full or limited to payment reform and quality related waivers through CMMI, was an obvious way CMS could have enabled innovation in Medicaid.

Perhaps during the current comment period, enough organizations will highlight the need for better innovation in the final rule. Medicare and commercial plans can innovate in payment reform; Medicaid also needs to do so.

View the original content and more from this author here: http://ift.tt/1FNhGzX



from health IT caucus http://ift.tt/1FNhDUY
via IFTTT

Debunking ICD-10 legends

Many healthcare organizations are focusing on being ready for the ICD-10 changeover on Oct. 1. Just as important is what will come after that.

Productivity losses
This is legend. The fear is that ICD-10 code set is so large and complex that medical coders aren’t going to be able to keep up with their current coding output.

ICD-10 opponents like to point to Canada’s 40 percent drop in coding productivity after their ICD-10-CA implementation. But they also switched from a paper-based system to PC-based system at the same time. Canadian coders had a lot to learn and get used to.

Whether American coders will face comparable challenges is something we won’t know until after Oct. 1. But those challenges could be mitigated by strong ICD-10 training and clinical documentation improvement (CDI) programs. These investments could help preserve medical claim productivity.

After Oct. 1, medical practices could look for other ways to streamline medical coding workflow. Remove inefficiencies. Add automation.

Denials
This is another legend. The American Medical Association (AMA) is predicting denial and rejection rates as high as 20 percent. Which is the basis of their call for an ICD-10 grace period.

Before medical practices panic over that possibility, they need to know their denial statistics now so they can compare what happens to claims after Oct. 1. They need to track:

  • Days in accounts receivable by healthcare payer
  • Denial rates
  • Amount of reimbursements denied
  • If reimbursements match the contracted rates
  • If tracking waits for Oct. 1, medical practices won’t know if the numbers reveal problems or business as usual. Weekly tracking could help keep small problems from becoming big ones at the end of the month.

And if tracking spots problems, there needs to be a process to contact healthcare payers for find out what is the status of claims.

ICD-10 denial management starts now. Medical practices need to understand what triggers denials now and what could cause problems with ICD-10 claims. This will help prevent crippling reimbursement delays.

Queries
If physicians aren’t documenting at a level that supports ICD-10 specificity, the number of queries from medical coding staff will increase. And that’s going to affect productivity for coders and clinicians. To keep the documentation process moving smoothly, medical coders can improve their queries to make them as efficient and useful as possible:

  • Write in clear, concise and precise language
  • Use evidence specific to the case
  • Avoid asking leading questions
  • Include query in the clinical documentation
  • Start using ICD-10 language
  • Avoid writing queries

Unfortunately these issues will require resources after Oct. 1. That date is not the finish line. Medical practices need to keep running long after the ICD-10 deadline.

View the original content and more from this author here: http://ift.tt/1T0GFcH



from health IT caucus http://ift.tt/1T0GCNQ
via IFTTT