ACHDM

American College of Health Data Management

American College of Health Data Management

Why a vendor solution isn’t the fix for a security breach

When a technology gap is exploited in a hack, most organizations reflexively look for a tech solution. It’s more nuanced than that.



This article is the second in a 3-part series. Read part 1: Digital readiness in healthcare begins with data readiness and part 2: What the Scott County HIV outbreak can teach us.

A hospital goes live on a new EHR, running clinical and financial systems together in a single "big bang" cutover. Six months later, staff are still stabilizing workflows. Security has not been the priority. It rarely is, in that phase.

Then two things happen, in a pattern that repeats constantly across the hundreds of incidents reported to federal regulators every year. An unencrypted laptop is stolen, and a phishing email triggers a ransomware event. Together, breaches like this regularly expose protected health information for hundreds of patients and trigger a compliance audit.

The instinct at this point is predictable – buy a better tool. A stronger firewall, a flashier detection platform, whatever the vendor with the best pitch is selling. That instinct is the wrong lesson to take from a breach like this.

The problem is never a missing product

A structured risk assessment of this kind of breach typically exposes the same pattern, because the vulnerabilities were not exotic.

They're access accounts that were left active for former employees. Devices with no encryption. Personal devices connecting to hospital systems, with no way to verify their security posture or to remotely wipe them. Ad hoc video tools stand in for a real telehealth platform.

There's no centralized way to see any of it happening at once. Phishing remains one of the most common entry points behind incidents like this.

None of that is a technology gap in the way people usually mean it. It is a visibility and governance gap. The hospital had tools. It did not have a system.

Five domains, one question

A defensible remediation strategy for this kind of environment maps risk across five domains, which include identity and access, endpoint protection, mobile device governance, telehealth standardization and centralized monitoring.

For each domain, the evaluation question is the same, and it has nothing to do with brand reputation. Does this control reinforce the other four, or does it operate in isolation?

Identity controls decide who is allowed to reach a system. Device controls decide whether an entity’s access should be trusted. Endpoint protection watches behavior after access is granted. Monitoring aggregates all of it and automates a response when something looks wrong. Each layer individually stops a different failure mode. Together, they mean no single control failure compromises the whole system, a principle security professionals call defense-in-depth.

That framing changes the buying conversation entirely. The question stops being, "Which vendor has the best individual product?" and becomes, "Which combination of controls actually talks to each other?"

Governance must be enforceable, not aspirational

A policy that says devices must be encrypted means nothing if nobody checks. The stronger pattern pairs every policy with an enforcement mechanism. Examples are automated deprovisioning the same day an employee leaves, conditional access that blocks non-compliant devices before they connect and quarterly access recertification instead of a policy binder that nobody opens.

This is the piece organizations most often skip. It is also the piece regulators care about most. The HIPAA Security Rule does not ask whether an organization owns security software. It asks whether access, encryption, and audit controls are actually functioning.

Feasibility beats sophistication

One more principle matters for any leader evaluating a post-breach roadmap. The most advanced tool on the market is not automatically the right choice. A resource-constrained hospital recovering from a breach needs controls it actually can operate with the staff it has, not a governance program that assumes a security operations center it cannot yet staff.

Selecting for integration and operational feasibility, rather than for whichever platform has the most features, is what turns a remediation plan into something a stretched team can sustain past the first 90 days.

Priorities for health data leaders

Map risk before mapping vendors. Use a threat-vulnerability-impact framework to identify what is actually exposed before evaluating any product category.

Score every control on integration, not just capability. A tool that does not reinforce your other layers adds cost without adding resilience.

Pair every policy with an enforcement mechanism. A rule that depends on someone remembering to follow it is not a control.

Build for the staff you have, not the staff you wish you had. Sustainable security in a resource-constrained environment beats a sophisticated program nobody can maintain.

Looking ahead

Breaches like this get reported as technology failures. They are more accurately governance failures masquerading as technology.

Hospitals that recover well are not the ones that bought the most expensive stack. They are the ones who built a system where identity, devices, endpoints and monitoring finally talk to each other, enforced by policy rather than good intentions.

That is the same lesson underneath every data story in this series. Whether it involves outbreaks, outdated infrastructure or a phishing email, failure is rarely a missing tool. It is almost always a missing connection.

Dr. Julia Rehman, DHA, FACHE, FACHDM, is an Executive Fellow of the American College of Health Data Management.


This article is the second in a 3-part series. Read part 1: Digital readiness in healthcare begins with data readiness and part 2: What the Scott County HIV outbreak can teach us.

More for you

Loading data for hdm_tax_topic #reducing-cost...