
Groups Aim to Strengthen Health Ecosystem Incident Response
About this episode
Get every episode summarized
Each time Data Breach Today Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
69 searchable segments. Every word is indexed and playable.
Full transcript
Data Breach Today Podcast — Groups Aim to Strengthen Health Ecosystem Incident Response. Machine-transcribed; use the interactive transcript above to jump the player to any line.
I'm Marianne Kolbisak-Viggy of Information Security Media Group and I'm here at him's 26 talking to Greg Garcia who is executive director of the Cyber Security Work Group of the Health sector coordinating council which today just announced a first for its group and that is a national tabletop exercise. Greg tell us a little bit about why you're doing this, how it's going to work and what do you hope to get out of this? Well just in the past couple of presentations at this morning's cyber forum we learned about how disruptive, how crippling, how expensive, ransomware attacks are and other forms of cyber attack and we just know that we've got to develop more muscle memory not just within an enterprise but across enterprises in a community setting and with the government. So we thought that it would be best if we partnered up with the Health I-Sat the information sharing and analysis center they're the real firefighters to work with the Cyber Security Working Group of the sector council to do this joint national exercise and we're
inviting all healthcare stakeholders, the providers, the payers, the health IT organizations, the medical technology and pharmaceutical companies and we'll invite the government as well and we expect that we'll be testing again not just internal capabilities and response mechanisms but how we coordinate across boundaries in terms of communications and response and resilience operational continuity. So will it be sort of attacked that they're dealing with or what can you tell us of what they will be dealing with and will it touch all the tentacles of you know people with and their organizations that would have to be involved? Exactly we want to bring in different disciplines as a previous presentation noted about their incident response they've had to bring in the compliance person the general council the operations people the CEO so we need to have different
disciplines working together on this and you asked about scenario planning so yes so we're in that process now working with the health ISAC with Booz Allen and with others to say what kind of scenario is realistic and cross-cutting and then as cyber exercises go you have injects okay this happened now three hours from now this happened tomorrow this happened and so information starts to build and accumulate causing more questions about how you respond and we're going to be doing this virtually it's going to be across a virtual platform all around the country and it could be quite large and when you say quite large how many organizations how many people and do they have to be a member of either the health ISAC or HSCC in order to participate? They do not we are
looking for organizations across the spectrum and I don't know what the number will be we haven't decided where there whether there is a cap the registration link is now available online and and health ISAC is managing that I did a LinkedIn post about it earlier today but but again all of the critical health care sub sectors that are part of this interdependent ecosystem are invited to participate and it's really the the regulated entities of health care not so much are we going to have consultants and technology vendors and such but it's those who are responsible for restoring data and systems and getting back on your feet operationally and when does when is it taking place and if someone is interested what do they do to participate? It will be July 21st and 22nd two half day sessions I believe a four hours each interested organizations can go to the health
ISAC website and register not necessarily everybody who registers will be accepted depending on their status in the health care sector but but go to that the registration now is live and we will be collecting registrations over time and at some point we'll decide whether we have that critical and then we need to close registrations and in terms of the tabletop I know you said you're going to come up with a scenario would it be like an industry sort of scenario you know I'll change health care where you know affected so many or is it something that could happen at your organization and you'll have to deal with it it will be more the former what kinds of what what we published last year you may recall is something called smart the sector mapping and a risk toolkit which is a way of visualizing national health care workflows and all of the critical functions and utilities and services that need to take place to complete those workflows so that the patient
gets served the doctor gets paid and the health system continues to operate so really we're going to be testing a lot of those externalities those third parties and we'll be testing internal capabilities we're going to be testing what resources does the government have to assist us how do we share information with them so stay tuned the scenario is not yet fully planned we're still working on it and bringing in a lot of different stakeholders to sort of help refine and provide more nuance to the type of scenario that will be most cross-cutting and impactful the participants be participating with each other like collaborating during this or is it something happens and this is how we have to deal with it so every organization is going to be encouraged to go inward and bring the right people to the table how they organize it as individual participants is up to them but there will be and again I don't have all the details about how
technically operationally it's going to be carried out but whatever our sharing platform is will be the virtual platform on which participants will engage real time facilitated with questions and answers perhaps perhaps there will be breakout sessions I don't know we're still in the planning phase so it's exciting so I know this is a first for the health sector coordinating councils cyber security working group is this a first for the industry in terms of the you know the magnitude of what you're hoping to do this is a first in terms of making it national today all healthcare stakeholders welcome we have had during our twice annual all hands meetings we've had two tabletop exercises with similar scenario designs but it would be just about a three-hour session just within the confines of the all hands membership meeting and some virtual
participants this is going to be much broader and scope well good luck with this Greg thank you very much thank you I've been speaking to Greg Garcia I'm Marianne Kolbassakniki of information security maybe a group thanks for joining us
More episodes
More from Data Breach Today Podcast

Why 'Emerging Threats' Are Harder to Prioritize in the AI Era
Data Breach Today Podcast

The End of Static Security: Why AI Demands Real-Time Microsegmentation
Data Breach Today Podcast

Why Data Security Standards in Cancer Innovation Matter
Data Breach Today Podcast

How Main Line Health Secures Devices With Microsegmentation
Data Breach Today Podcast