Insights into the Changing Healthcare Cybersecurity
Healthcare Tech Outlook

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our Healthcare Tech Outlook Advisory Board.

Chief Information Security Officer & Director of IT Security at Adventist HealthCare

Insights into the Changing Healthcare Cybersecurity

Michael Prakhye

I have the privilege of serving as a chief information security officer and director of information security at Adventist HealthCare. I hold two Master's in Cyber Security and in Business Administration from the University of Maryland, as well as an Executive Healthcare Leadership and Healthcare Change Management certificate from Cornell University. I have over 20 years of experience in information security, risk management, compliance, strategy, and consulting within healthcare and the Department of Defense. I hold industry certifications, including project management professional, C|CISO, ITIL, CISSP, and others. I am an adjunct professor at the University of Maryland, teaching information assurance, compliance, and risk management. I am currently responsible for establishing, implementing, and managing comprehensive cybersecurity programs that align with the organization's objectives and ensure the confidentiality, integrity, and availability of data.

Challenges and Trends Impacting the Enterprise Security Industry

Speaking of the challenges and trends within the HealthCare industry, its approach to cybersecurity is indeed unique due to the sensitive nature of the data it handles, the critical role it plays in patient care, and the evolving threats it faces. The healthcare industry has been undergoing significant changes and facing various challenges. It is currently one of the most targeted and attacked industries. Healthcare organizations provide critical and time-sensitive services, making them more likely to pay a ransom quickly to restore operations and patient care. Additionally, healthcare organizations and hospital systems contain vast amounts of sensitive and valuable patient data, including medical records, personal information, and payment details. This data is much more valuable than credit card numbers and can be sold on the black market or used for identity theft and financial fraud.

"In the dynamic realm of cybersecurity within a healthcare industry, staying up to date and continuously learning is paramount to leading a successful program"

Cybercriminals often target vendors to gain access to their systems and subsequently move laterally into the healthcare network. By compromising a less secure vendor, they can reach more valuable targets or gain access to sensitive data that the vendor possesses and hold it, hostage for ransom.

Major Predicaments in the Enterprise Security Industry

* Any potential patient care disruptions that can cause patient harm are the top concern, such as ransomware Attacks.

* Any breach of patient records could lead to significant legal, financial, and reputational consequences.

* Third-party vendor risk and ensuring that vendors maintain a high level of security and do not compromise your hospital's network is a significant concern.

* Emerging threats and zero-day vulnerabilities. Keeping up with the latest attack techniques and developing proactive defense strategies is a continuous effort.

Exciting Technological Trends for the Future of the Enterprise Security Industry

Artificial intelligence offers transformative possibilities for improving healthcare outcomes, increasing efficiency, and enhancing patient experiences; their successful implementation will require careful security considerations as well as ethical, legal, and privacy implications.

Reaching you for Suggestions to Streamline Business

I am available on LinkedIn to connect with other healthcare professionals. Knowing that your work directly contributes to protecting patient data, maintaining medical operations, and ensuring patient safety provides me with a strong sense of purpose and fulfillment. I have a genuine interest in healthcare IT with a desire to contribute to the well[1]being of patients and the healthcare industry; specializing in healthcare cybersecurity allows me to align my passion with my professional expertise.

Brief Overview of Your Career Path

I started as a systems administrator with a government contractor, working closely with the Department of Defense, the Navy, and the Marines. My responsibilities included supporting the IT infrastructure of the headquarters, from building and reimaging workstations and servers to backups, exchange, networks, and overall security. My role also included building closed networks that complied with the National Industrial Security Program Operating Manual and later Risk Management Framework. I traveled to various Marine and Navy bases, setting up their networks and configuring their systems. After a decade with the DoD, I moved to the healthcare sector and joined Adventist HealthCare as the information security manager to build the organization's security program. I moved into the CISO role a few years later and have the pleasure of serving in that role today.

Adapting to Rapid Changes in the Industry

In the dynamic realm of cybersecurity within a healthcare industry, staying up to date and continuously learning is paramount to leading a successful program. As a CISO, remaining current with the evolving threat landscape, emerging technologies, and ever-changing compliance requirements is not just beneficial – it's essential. The healthcare industry's unique challenges and the critical nature of patient data demand proactive measures to safeguard against sophisticated cyber threats. Attending industry-specific conferences and staying up to date helps me and my team to develop targeted strategies, implement robust defenses, and respond swiftly to emerging threats.

Currently, at Adventist HealthCare, I place great importance on working at an organization whose mission, vision, and values closely align with my own. Being part of an organization that strives to make a positive impact in ways that resonate with my beliefs not only enriches my professional journey but also empowers me to contribute meaningfully to a shared vision of success and to grow my career at the same time.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief