From: HealthITSecurity
Author Name Patrick Ouellette
Just because there is some overlap in language between the recently-released National Institute of Standards and Technology (NIST) cybersecurity framework what many healthcare organizations are already doing in terms of compliance and security doesn’t mean there isn’t value for providers.
Alvarez & Marsal’s Tom Kellermann, cyber security expert and former Presidential advisor, broke down the critical portions of the recently-released NIST framework for healthcare providers. In this Q&A with HealthITSecurity.com, Kellermann offered his perspective on what was included within the framework, the best next steps for organizations, and what this means long-term for healthcare.
How will the framework affect those already regulated under HIPAA and HITECH?
Kellermann: Because of that regulation, they’re already adhering to a higher level of cybersecurity. The only difference is this executive announcement on the cybersecurity framework elevates the conversation beyond the CIO. Under HITECH and HIPAA, CIOs are required to implement a modicum of cybersecurity controls, policies and procedures. Usually, those are over-reliant on technical solutions such as encryption. Whereas this framework challenges you to elevate the conversation to your senior management and to your board and to distinctly state what your cybersecurity plan is and how you would respond to a security incident if one occurs. That really elevates the conversation beyond a compliance exercise to one of a risk management and due diligence exercise.
Leave a Reply