loader from loading.io

Securing Healthcare.gov & Tackling Fourth-Party Vendor Risks

The CyberPHIx: Meditology Services Podcast

Release Date: 06/15/2022

Artificial Intelligence: Use Cases and Cybersecurity & Privacy Implications in Healthcare show art Artificial Intelligence: Use Cases and Cybersecurity & Privacy Implications in Healthcare

The CyberPHIx: Meditology Services Podcast

Join us for this episode of The CyberPHIx podcast, where we hear from Morgan Hague.   Morgan is the manager of IT Risk Management at Meditology Services and has been in the industry for nearly a decade. He has worked with hundreds of organizations in an advisory capacity helping to assess or audit security functions to drive program maturity. He also leads Meditology’s strategic risk management consulting service line and is a subject matter expert in threat mitigation and risk program development.  Topics covered in this session include:   A deep dive into...

info_outline
The CyberPHIx Roundup: Industry News & Trends, 5/8/23 show art The CyberPHIx Roundup: Industry News & Trends, 5/8/23

The CyberPHIx: Meditology Services Podcast

The CyberPHIx Roundup is your quick source for keeping up with the latest cybersecurity news, trends, and industry-leading practices, specifically for the healthcare industry.  In this episode, our host Britton Burton highlights the following topics trending in healthcare cybersecurity this month:  The Changes to HHS 405(d) HICP publication on the top 5 threats and top 10 security practices for healthcare  The NIST Cyber Security Framework 2.0 Discussion Draft   The riskiest connected medical devices and IoT (including nurse call, infusion pumps, and...

info_outline
HITRUST v11 and Third-Party Risk: Insights from HITRUST Leadership show art HITRUST v11 and Third-Party Risk: Insights from HITRUST Leadership

The CyberPHIx: Meditology Services Podcast

Join us for this episode of The CyberPHIx podcast where we hear from Ryan Patrick, Vice President of Adoption at HITRUST.   Ryan works with clients to understand and implement the HITRUST-validated assessments that best suit their organization’s risk profile. Prior to this role, he spent many years as a security practitioner and IT lead in a wide range of organizations from the US Army to Covered Entities to healthcare cybersecurity consulting firms. He has a wealth of practical security experience that informs every discussion about security or HITRUST.   ...

info_outline
The CyberPHIx Roundup: National Cybersecurity Strategy, 3/22/23 show art The CyberPHIx Roundup: National Cybersecurity Strategy, 3/22/23

The CyberPHIx: Meditology Services Podcast

The CyberPHIx Roundup is your quick source for keeping up with the latest cybersecurity news, trends, and industry-leading practices, specifically for the healthcare industry.  Our host Britton Burton spends this entire episode reviewing and analyzing the recently released National Cybersecurity Strategy, including:  Summarizing, and in some cases quoting, the key points from the document that are most relevant to healthcare security pros who may have time to listen but not read  Analyzing how those key points will affect the healthcare industry in the coming months...

info_outline
THE CYBERPHIX ROUNDUP: INDUSTRY NEWS & TRENDS, 2/7/23 show art THE CYBERPHIX ROUNDUP: INDUSTRY NEWS & TRENDS, 2/7/23

The CyberPHIx: Meditology Services Podcast

The CyberPHIx Roundup is your quick source for keeping up with the latest cybersecurity news, trends, and industry-leading practices, specifically for the healthcare industry.  In this episode, our host highlights the following topics trending in healthcare cybersecurity this month:  The Federal Trade Commission’s (FTC) first Health Breach Notification Rule Enforcement action against GoodRx  An unsurprising report from OCR on security rule compliance areas that HIPAA-regulated entities need improvement plus the most common remediation actions taken by breached...

info_outline
THE CYBERPHIX ROUNDUP: INDUSTRY NEWS & TRENDS, 3/1/23 show art THE CYBERPHIX ROUNDUP: INDUSTRY NEWS & TRENDS, 3/1/23

The CyberPHIx: Meditology Services Podcast

The CyberPHIx Roundup is your quick source for keeping up with the latest cybersecurity news, trends, and industry-leading practices, specifically for the healthcare industry.  In this episode, our host highlights the following topics trending in healthcare cybersecurity this month:  The Federal Trade Commission’s (FTC) first Health Breach Notification Rule Enforcement action against GoodRx  An unsurprising report from OCR on security rule compliance areas that HIPAA-regulated entities need improvement plus the most common remediation actions taken by breached...

info_outline
The CyberPHIx Roundup: Industry News & Trends, 2/7/23 show art The CyberPHIx Roundup: Industry News & Trends, 2/7/23

The CyberPHIx: Meditology Services Podcast

The CyberPHIx Roundup is your quick source for keeping up with the latest cybersecurity news, trends, and industry-leading practices, specifically for the healthcare industry.  In this episode, our host highlights the following topics trending in healthcare cybersecurity this month:  A new National Cybersecurity Strategy coming from the Biden administration in the next few weeks  Healthcare cybersecurity legislation with mandatory requirements coming from Senator Mark Warner by the end of 1Q  More ChatGPT analysis on malware writing and that it is NOT suitable...

info_outline
The CyberPHIx Roundup: Industry News & Trends, 1/16/22 show art The CyberPHIx Roundup: Industry News & Trends, 1/16/22

The CyberPHIx: Meditology Services Podcast

The CyberPHIx Roundup is your quick source for keeping up with the latest cybersecurity news, trends, and industry-leading practices, specifically for the healthcare industry.  In this episode, our host highlights the following topics trending in healthcare cybersecurity this month:  New FDA authority granted by December’s omnibus bill is a big step towards better medical device security  HITRUST teases their new CSF v11 release  CommonSpirit Health class action lawsuit  The fallout from the LastPass follow-on breach  The possibly similar situation...

info_outline
Top 10 Cyber Risk Exposure Trends and Predictions for 2023 show art Top 10 Cyber Risk Exposure Trends and Predictions for 2023

The CyberPHIx: Meditology Services Podcast

The CyberPHIx is your source for keeping up with the latest cybersecurity news, trends and industry leading practices, specifically for the healthcare industry.  In this episode, our host highlights some bold, and some not so bold, predictions for healthcare cybersecurity in 2023. Topics covered include:  Continued escalation and evolution of ransomware attacks  Our growing dependency on cloud platforms and vendor solutions shifting the attacker’s focus and changing breach trends  New baseline expectations for critical infrastructure cybersecurity that could...

info_outline
The CyberPHIx Roundup: Industry News & Trends, 12/15/22 show art The CyberPHIx Roundup: Industry News & Trends, 12/15/22

The CyberPHIx: Meditology Services Podcast

The CyberPHIx Roundup is your quick source for keeping up with the latest cybersecurity news, trends, and industry leading practices, specifically for the healthcare industry.  In this episode, our host Britton Burton highlights the following topics trending in healthcare cybersecurity this week:  OCR releases more detail on their Recognized Security Practices (RSPs) and what they mean for Covered Entities  A cool new tool from the FTC for mobile health app developers to quickly determine which security and privacy regulations are in scope for their app  Trends in...

info_outline
 
More Episodes

Join us for this episode of The CyberPHIx podcast where we hear from Bart Layton, VP of Product for CORL Technologies, who was also a leader on the team that overhauled and secured healthcare.gov. 

In this two-part conversation, we discuss Bart’s insights into the deployment and security of healthcare.gov as well as his perspectives on third- and fourth-party cyber risks for healthcare organizations. 

About Healthcare.gov 

Healthcare.gov is the nation's federal exchange for health insurance coverage that was created from the passing of the Patient Protection and Affordable Care Act (ACA). The initial launch of the website was fraught with challenges and was ultimately "rescued" by a large team contracted to get the site operating in tip-top shape. 

About Fourth-Party Vendor Risks 

Cybercriminals and nation-states have also unleashed relentless cyber-attacks on the U.S. healthcare industry and its suppliers this year. Unfortunately, cyber risk exposures have not been limited to third-party vendors, and risks to sensitive data and systems often extend across the full supply chain including fourth-party vendors and open-sourced products. 

Topics covered in this session include:  

  • What is healthcare.gov? 
  • How and why was healthcare.gov overhauled in the early stages of its development? 
  • Security challenges and solutions for healthcare.gov that arose during implementation 
  • Cloud security considerations for hosted healthcare applications including healthcare.gov 
  • What is fourth-party vendor risk and how is it impacting healthcare organizations?
  • Examples and case studies of prominent fourth-party vendor breaches in healthcare
  • Emerging solutions and innovations in third- and fourth-party vendor risk management
  • New federal regulations and standards for managing supply chain risks