Protecting data in the healthcare industry continues to be an area of focus for regulators and lawmakers. HIPAA Journal noted that in 2016 more HIPAA covered entities reported breaches than in any other year since the U.S. Department of Health and Human Services (“HHS”) Office of Civil Rights started publishing breach summaries on its “Wall of Shame” in 2009. Almost all of these breaches affected healthcare providers. Add to the mix the global cyberattacks we saw in May 2017 and the growing threat from ransomware and you can see a perfect storm forming.

One potential aid in weathering this storm is the public-private partnership discussed at a recent Congressional hearing before the U.S. House of Representatives Energy and Commerce Subcommittee on Oversight and Investigations. Subcommittee Chairman Representative Tim Murphy (R-PA) called cybersecurity in the healthcare sector “essential” and encouraged healthcare institutions to continue ongoing efforts to form an effective public-private partnership to assist in these efforts.

The hearing focused on the National Health Information Sharing and Analysis Center (“NH-ISAC”), which is a global, nonprofit organization whose members represent approximately one-third of the U.S. health and public health GDP. There are approximately 200 members of the NH-ISAC. The purpose of an ISAC is to help private sector entities share cyber-related threat information with one another. The NH-ISAC works closely with HHS in its efforts to combat cyber threats.

During the hearing, Denise Anderson, the President of the NH-ISAC, noted there are many small healthcare providers like physician practices, chiropractor offices and dental practices that are vulnerable to cyberattacks and would benefit from education through the NH-ISAC. She also stated that she was concerned that many small and mid-sized providers do not even realize the NH-ISAC exists.

Several examples were given at the hearing of NH-ISAC work that could help smaller healthcare providers reduce their vulnerability to cyberattacks. One example of that work is the CyberFit suite of services, which Anderson explained allows members to leverage the NH-ISAC community to realize cost savings and efficiencies. Another was the Medical Device Security Information Sharing Council, a forum for manufacturers and hospitals to interact and collaborate in order to advance medical device security and safety. There also was testimony at the hearing regarding an NH-ISAC project in which different members create portions of a security incident response plan or a security operations plan, and then donate that into the public domain or at least into the healthcare sector.

Members of the committee expressed appreciation of the serious consequences that cyberattacks could have on the healthcare sector. These members also expressed interest in the efforts of the NH-ISAC to increase its membership and improve cybersecurity in the healthcare sector. In this environment of heightened cyber-threats and HIPAA enforcement, healthcare providers may wish to consider including the NH-ISAC as a resource in their cybersecurity efforts.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Michael R. Bertoncini Michael R. Bertoncini

Michael R. Bertoncini is a principal in the Boston, Massachusetts, office of Jackson Lewis. He is a member of the Healthcare industry group and a member of the Higher Education group.

With a background as a former Deputy General Counsel, Michael understands first-hand…

Michael R. Bertoncini is a principal in the Boston, Massachusetts, office of Jackson Lewis. He is a member of the Healthcare industry group and a member of the Higher Education group.

With a background as a former Deputy General Counsel, Michael understands first-hand the competing demands and unique challenges faced by in-house counsel. Before joining Jackson Lewis, he was responsible for all labor and employment law matters for the largest fully integrated community care hospital system in New England. Michael provides timely, practical advice that helps clients achieve their strategic goals while ensuring compliance with legal obligations.

With deep experience in a broad range of industries, Michael has a keen interest in the healthcare, higher education, museum, and arts & music sectors. He is dedicated to supporting clients in these areas, leveraging his extensive experience to address the specific challenges faced by institutions and organizations in these fields.

Michael regularly partners with clients to establish positive employee relations. In labor relations matters, he negotiates collective bargaining agreements on behalf of organized clients, represents clients in labor arbitrations and National Labor Relations Board proceedings, and counsels clients with respect to rights and obligations under collective bargaining agreements and applicable labor and employment laws. He also has extensive experience in advising organizations responding to corporate campaigns and negotiating neutrality agreements.

Michael’s privacy and data security practice focuses on advising clients on complying with HIPAA and other state and federal privacy and data security laws. He reviews and develops policies and procedures, written information security plans and integrated compliance programs to ensure his clients meet their obligations under privacy and data security laws. Michael represents clients in investigations of alleged data breaches and advises them on reporting obligations.. He also conducts workplace training programs on HIPAA compliance and related privacy and data security topics.