Recent Posts

CBD May Offer Health Benefits for Postmenopause, Research Shows

CBD May Offer Health Benefits for Postmenopause, Research Shows

Share on PinterestA recent study investigating the effects of CBD in estrogen-deficient mice found that CBD improved several menopause-related symptoms and conditions. Trinette Reed/Stocksy Menopause is a natural process and not a disease or disorder, but it can cause a host of unpleasant physical and 

Former CEO of Health Clinic Convicted of Medicaid Fraud | OPA

Former CEO of Health Clinic Convicted of Medicaid Fraud | OPA

A federal jury convicted a former CEO of a overall health clinic for defrauding the Louisiana Medicaid System about many a long time.  According to courtroom files and evidence presented at demo, Victor Clark Kirk, 73, of Baton Rouge, Louisiana, was the CEO of St. 

Health system CISOs offer tips for building cybersecurity ‘muscle memory’

Health system CISOs offer tips for building cybersecurity ‘muscle memory’

By focusing on broader incident response training efforts – which involves medical, operational and other teams – as part of overall emergency preparedness programs, healthcare providers will be better positioned to maintain and deliver patient care when systems are breached and potentially disabled following a cyberattack.

Cyber attacks risk patient care

A recent study by the Ponemon Institute involving more than 640 healthcare IT and security leader participants found that while most of the provider organizations experienced nearly an attack each week last year, 57{b574a629d83ad7698d9c0ca2d3a10ad895e8e51aa97c347fc42e9508f0e4325d} also say these attacks are resulting in adverse impacts on patient care.

Half of respondents cited an increase of complications from medical procedures – and 20{b574a629d83ad7698d9c0ca2d3a10ad895e8e51aa97c347fc42e9508f0e4325d} reported an increase in mortality rates.

“This report aligns with the reality that healthcare organizations are facing in terms of the effects to patient safety,” said Anahi Santiago, chief information security officer at Delaware-based Christiana Care Health System.

She and other healthcare cybersecurity leaders spoke with Healthcare IT News about the connection between cyber hygiene and patient safety and how to prepare for healthcare cyber attacks. 

“When cyber attacks take place in healthcare, and organizations are forced to either divert services from emergency rooms or have to cancel services because of the unavailability of systems – it does put patients at risk,” she said.

There is always going to be an adversary out there trying to break in, said Erik Decker, CISO for Salt Lake City-based Intermountain Healthcare. 

“The length of time of these outages, you know most people think ‘Well, it’ll just be a day or two,’ but no, these things can last weeks and months,” said Decker.

“You must also put an equal amount of vigilance into response,” said Decker.

“I don’t think organizations do enough to prepare for how to care for patients when systems are not available,” said Santiago, who is also a member of the board of directors for the Health Information Sharing and Analysis Center, or H-ISAC. “Where are your downtime procedures? How do you work across different departments?”

Industry size makes all players a target

Many healthcare organizations have various types of specialized hospital information systems along with thousands of hospital infrastructure and connected medical devices, including smart elevators, smart heating, smart infusion pumps, remote patient monitoring devices and more.

While larger provider systems may be more complex than small medical groups, “they still have the same kind of risk, as we have [all] leveraged technology to deliver care,” said Decker.

Not only a complex one, healthcare is also a very large industry, said Darren Lacey, vice president and CISO for Johns Hopkins University and Johns Hopkins Medicine.

“We’re 15{b574a629d83ad7698d9c0ca2d3a10ad895e8e51aa97c347fc42e9508f0e4325d} of the U.S. economy, maybe 18{b574a629d83ad7698d9c0ca2d3a10ad895e8e51aa97c347fc42e9508f0e4325d} of the U.S. economy. We’re a significant portion of the employees. I mean in much of America, the largest organization in that town or that county is the local hospital. It employs everybody,” said Lacey.

“We get hit a lot, but that’s because we are so big.” 

Data breach was the focus of healthcare cybersecurity 10 years ago, so traditionally the concern has been on protecting data. But the rise in prevalence of ransomware is driving rapid change in approaches to cyber preparedness.

The sophistication of threat actors has evolved – they have the ability to shut down systems and key critical processes and functions, said Decker, who is also chair of the Healthcare and Public Health Sector Coordinating Council Cyber Security Working Group. 

What happened is a shift “from not only the exfiltration and theft of data and monetization of that data, but the monetization of your operational ability and your ability to recognize revenue,” he said. 

“When you disrupt the pipeline of that technology, you disrupt the pipeline of volume and the ability to care in the way that our providers are expecting normal operations to look like,” he said. 

Limit data access with architecture

Because healthcare data assets are high-risk, data management requires a risk-based approach where data managers in the healthcare space must act as “mindful custodians,” said Lacey.

To improve the cybersecurity posture of healthcare, the Department of Health and Human Services recommends enterprise-wide risk analyses and a series of best practices, including maintaining encrypted data backups, vulnerability scans of all systems and devices, regular patching and updating of operating systems and training employees to reduce vulnerability to phishing and other common cyber attacks. 

“Minimum necessary and role-based access are core components of an identity and access management program,” Santiago said.

“So before we even get to the point where we’re training people, it’s important for us to design an architecture that doesn’t allow for access beyond what is necessary for people within an organization to get to information.”

“It’s one of the few environments and industries where the majority of the workforce actually needs access to the private information that is restricted,” added Decker.

Healthcare providers could have hundreds or thousands of ancillary systems, making ecosystems complex. 

And “complexity is the enemy of security,” Lacey added.  

Detect malicious activity and vulnerabilities  

Resources from the HHS 505(d) Program, a collaborative effort between industry and the federal government that was launched in 2015 by Congressional mandate, and other agencies can help increase healthcare cybersecurity, resiliency and cyber hygiene with a number of tools and resources for both small and large providers. 

Regardless of provider organization size, they face the same five cyber threats:

  1. Email phishing attacks 

  2. Ransomware attacks 

  3. Loss or theft of equipment or data

  4. Internal, accidental or intentional data loss 

  5. Attacks against connected medical devices

Most healthcare organizations have service level agreements that offer an implied promise for patching vulnerabilities. But vulnerability management has been the most important part of cybersecurity for the past 20 years, said Lacey.

We chase down vulnerabilities and in fact, if you had to say what was the biggest change in cybersecurity over the last 10 years along with the ransomware spike would be the number of publicized vulnerabilities,” he said, noting that the number being disclosed is about 10 times what it was five years ago.

The program also identified the following 10 most effective practices to mitigate the most common cyber threats to healthcare: 

  1. Email Protection Systems 

  2. Endpoint Protection Systems 

  3. Access Management 

  4. Data Protection and Loss Prevention 

  5. Asset Management 

  6. Network Management 

  7. Vulnerability Management 

  8. Incident Response 

  9. Medical Device Security 

  10. Cybersecurity Policies

Application penetration testing may also pay off over time, according to Coalfire. Those running programs for three years reduced high-risk findings in web application tests by an average of 25{b574a629d83ad7698d9c0ca2d3a10ad895e8e51aa97c347fc42e9508f0e4325d}, according to the company’s fourth annual Penetration Risk Report.

I think it’s important to think of pen tests as not just a glorified vulnerability assessment, you really should use it to test your ability to detect malicious activity,” Lacey said. 

“Having a program that periodically tests your applications is recommended versus doing this only on an ad-hoc basis,” said Decker. 

“The environments change overtime and many elements of a cyber program need to be related to regular processes and periodic review. The more you can formalize it, the better you will be at aligning resources and managing priorities and expectations.” 

Explore what the outages can look like 

Santiago said she stresses going beyond efforts to create resilient IT teams by making organizational resiliency a practice.

“Organizational resiliency is ensuring that we’re communicating effectively and that people know how to work when they don’t have systems available,” she said.

Decker advises starting with the structure and contours of planning if you don’t have an incident response plan for your organization. 

“When an event comes in, how do you escalate it? And if and when it becomes a larger event, who are the first people that you call? What are the things that you’re going to be telling them?,” has explained.

The potential of impact will lead to further discussion about operational impacts. 

“Then it turns into, who are the operational leaders that need to be involved in the discussion, and how does this work with your emergency management departments and the activation of command?” said Decker.  

All of these stakeholders need to be onboard, including clinical leadership and service line leadership, he said. 

“People do not actualize how damaging these kinds of attacks can be,” he said. 

When you start explaining what these outages look like, “the appreciation for the problem starts to materialize.” 

The structure of cyber incident response command, how it is activated, who are the players and what are their roles and responsibilities should be connected to what the organization already knows through its emergency management channels.  

“One of the biggest mistakes is that when people do tabletop exercises, they focus just on the IT area – how to respond to a cyber incident – and less on the resiliency of an organization to be able to conduct patient care in the face of adversity,” said Santiago.

On the medical side, that involves emergency room teams and surgical groups, she said. 

“I think that that’s where organizations should really focus so that when systems are not available, patient care is least affected. So, continuous regular training of their ability to perform their work is integral to our ability to protect organizations.”

Bring everyone to the tabletop 

Conducting tabletop exercises are now an important part of building an effective incident response team and plan, the experts said.

“Tabletops went from being kind of marginal to what we do, to being central to what we do, in the space of a very short period of time,” said Lacey.

Santiago and Decker both say focusing on disaster recovery exercises is about “muscle memory.” 

Though unpredictable things can happen in an actual ransomware event, incident response security exercises can identify areas between various operational units that are vulnerable and illustrate how things can play out, helping to strengthen the information security triad – confidentiality, availability and integrity.

“If you’re addressing an issue for the very first time, you won’t be able to do it effectively, and so exercising regularly to be able to respond to incidents I think is really important in order to be able to face one when it actually does happen,” stressed Santiago. 

Training brings together emergency management and incident command teams, key leadership, compliance and privacy groups and others. 

Like any good sports team, “any good organization should practice and practice and practice so that it is not a surprise if and when something unfortunately happens,” said Decker.

“And instead, you are dealing with the contexts and circumstances of the issue versus dealing with the mechanics of how you stand up a response, and make sure everyone is involved.” 

These exercises focus on ensuring that the security operations center can detect and stop the spread of malware and that the larger organization can coordinate crisis response across all lines of business.

“Tabletops have not really been a big thing in our field, in what I would say civilian side or commercial sector cyberspace, up until about 10 years ago, and they didn’t really become a big deal till the big ransomware spike three years ago,” said Lacey. 

“And that’s when everybody realized, ‘Well, we we need to do a lot of tabletopping,’ because ransomware is so disruptive to the business.”

“Our workforce members are our most important assets, so continuous regular training of their ability to perform their work is integral to our ability to protect organizations,” said Santiago. 

“We, for example, do them multiple times a year,” she said, adding that her organization schedules monthly tabletops; twice per year with the executive, legal, vendor, compliance and privacy teams and once per year with operations. 

Decker noted that while conducting tabletop exercises annually is a good idea, there is no minimum regulatory requirement.

There are no efficacy studies revealing insights into the frequency of conducting tabletop exercises, Lacey added, but emphasis should be on the actions that result from a session. 

“If it’s a good tabletop, you’re going to give yourself a list of to-do items that’s going to take you several months to work your way through,” he said.

Approach tabletop exercises based on provider needs and resources

In 2007, Centers for Disease Control used tabletop exercises to drill response to the H5N1  virus, according to the University of Minnesota Center for Infectious Disease Research and Policy. 

CIDRAP shared a 10-step process for “one of the most talked-about ways to challenge and examine pandemic plans.” 

Although no tabletop exercise can convey a realistic picture of an incident, they said, the drills can help executives and planners find gaps, adding that the exercises can “sharpen group problem-solving under pressure and elevate preparedness provided that they are properly designed, carefully conducted, fully evaluated and actually use results to implement response process improvements.” 

Tabletops are valuable because they spin up gaps, and it’s a cyber hygiene tactic that “probably hits above its weight” said Lacey. 

But in terms of time, organizations should and will spend more time on incident and vulnerability protection, he said. 

The recent Coalfire report echoed this need, indicating that of the more than 3,000 penetration tests conducted across multiple sectors, security misconfigurations were a top vulnerability.  

Santiago noted that larger healthcare systems with mature programs and the capabilities do tabletop exercises on a regular basis and have been doing them for a long time. 

And while many larger provider organizations hire outside consultants to prepare and deliver these incident response drills, several agencies offer guidance and risk assessment tools to support health systems with more limited resources, including the Cybersecurity and Infrastructure Security Agency, which has tabletop exercises specifically designed for healthcare systems and medical groups.

Resources like the Health Sector Council’s Operational Continuity-Cyber Incident (OCCI) checklist, released in May 2022, can also help organizations get started, said Decker. 

For the smaller community hospitals and provider offices that just don’t have the resources, Santiago also suggested leveraging H-ISAC’s resources

“A lot of healthcare organizations don’t have that much money. So having some guidance like [CISA’s] makes a lot of sense,” Lacey added.

Improve IT skillsets

The good news for healthcare cybersecurity is that the skills gap in the field is narrowing. 

“The ceiling isn’t going up that much. But the floor is going up a lot, which is really good for healthcare because we’ve always sat along with municipal governments on the floor in terms of the security maturity of our field,” said Lacey.

“Sometimes as you peel back that onion you find more and more things at the center of the onion that you didn’t think about the first time around,” said Decker. 

“It’s okay for this to be boring,” he added, because if you get to that place, “one would hope you are so exercised in it, you know what to do.”

The goal is to make these things “non-events,” he said.

Looking at government’s role

Government is called on to intervene in an industry when problems begin to have overwhelming or alarming effects on people and assets. 

But what is the government’s role – federal, state/tribal and local – in protecting healthcare systems from cybersecurity attacks?

Lacey said CISA’s suggestions on how to close off technical vulnerability boundaries in healthcare cybersecurity are things providers should be paying “persistent attention” to.

He also said the government is doing a good job of shepherding information by drawing intel from multiple sectors and providing guidance and resources.

“I don’t have any complaints on the way the Federal government is going about this,” said Lacey. “I don’t know what more they could do.”

Decker sees the government agencies involved as partners assisting in the protection of critical infrastructure. 

“There are laws that define this relationship, specifically the National Defense Authorization Act. This codifies the critical infrastructure relationship between the Federal government, through a Sector Risk Management Agency and the [critical infrastructure]. 

“For healthcare, the SRMA is HHS, and the industry is represented by providers, payors/plans, biotech, labs, pharma, mass fatality and others. There is collaboration happening at all levels (all hazards) and cyber-specific collaboration to ensure we are protecting our infrastructure,” Decker shared by email as a follow-up.”

Andrea Fox is senior editor of Healthcare IT News.
Email: afox@himss.org

Healthcare IT News is a HIMSS publication.

Healthy lifestyle linked to 90{b574a629d83ad7698d9c0ca2d3a10ad895e8e51aa97c347fc42e9508f0e4325d} lower risk of diabetes in susceptible women

Healthy lifestyle linked to 90{b574a629d83ad7698d9c0ca2d3a10ad895e8e51aa97c347fc42e9508f0e4325d} lower risk of diabetes in susceptible women

Credit rating: Pixabay/CC0 Public Domain Females with a record of diabetes in pregnancy can continue to minimize their possibilities of building sort 2 diabetes by adopting a balanced life-style, these types of as having nutritious, halting using tobacco, working out on a regular basis, and 

marijuana, CBD, and hemp > Eglin Air Force Base > Article Display

marijuana, CBD, and hemp > Eglin Air Force Base > Article Display

&#13 &#13 &#13 &#13  &#13 &#13  WRIGHT-PATTERSON AIR Drive Base, Ohio – The use of cannabis and cannabis-similar substances is prohibited by all armed service company members and Department of Protection civilian employees. Even while some states have decriminalized or legalized marijuana for healthcare or recreational use, underneath 

Reducing health disparities through community health center partnerships

Reducing health disparities through community health center partnerships

Well being programs have an chance to husband or wife with group wellness centers to cut down healthcare mistrust among the traditionally marginalized teams, impacting overall health results and fairness.

Approximately 30 million persons in the United States get their main treatment from a local community health and fitness centre. Whether or not they are city or rural — or focus on a certain inhabitants this kind of as girls or latest immigrants — these facilities are a dependable bedrock for many of the country’s marginalized populations.

Now, info is emerging that those people centers are outperforming the national average in important healthcare high quality measures. This analysis is placing a highlight on local community health and fitness partnerships as a route toward cutting down health and fitness disparities.

Where by are neighborhood wellbeing facilities succeeding?

Get serious diseases, for instance. In accordance to the National Affiliation of Local community Well being Facilities, neighborhood well being clinics see improved diabetic issues and hypertension management — 63{b574a629d83ad7698d9c0ca2d3a10ad895e8e51aa97c347fc42e9508f0e4325d} and 67{b574a629d83ad7698d9c0ca2d3a10ad895e8e51aa97c347fc42e9508f0e4325d}, respectively — in comparison to the nationwide fees of 60{b574a629d83ad7698d9c0ca2d3a10ad895e8e51aa97c347fc42e9508f0e4325d} and 57{b574a629d83ad7698d9c0ca2d3a10ad895e8e51aa97c347fc42e9508f0e4325d}. Presented that these clinics currently see a disproportionate share of people today with continual disorder, there is one thing at play that wellness units just about everywhere can master from.

Perinatal health is another place in which local community health and fitness facilities glow. In a self-control wherever sufferers are now emotion mentally and physically susceptible, culturally sensitive care is important. Neighborhood clinics not only develop accessibility to prenatal treatment, but also present lower rates of reduced birthweight than the national common, experiences NACHC.

How area centers arrive at underserved individual populations

Partnering with profitable neighborhood centers can broaden their types additional broadly and assist wellness units bolster current outreach, suggests Nkechi Conteh, MD, MPH, Personnel Psychiatrist, Massachusetts Normal Clinic. In a recent post on perinatal psychological health and fitness for the Harvard Evaluation of Psychiatry, Dr. Conteh and coauthors cite neighborhood health heart partnerships as a starting off position to crack down boundaries stemming from years of wellness inequity for pregnant people today.

“Federally skilled wellbeing centers (FHQCs) deliver an noticeable goal for interventions to boost clinical mistrust, clinician cultural sensitivity, structural competency and medical results in transformational partnerships,” Dr. Conteh and her fellow authors produce. These partnerships “are proof-centered to deal with overall health disparities, significantly throughout the perinatal time period.”

Empowering local community partnerships for equitable treatment

Neighborhood partnerships also motivate “continuous good quality and method improvement” by opening opportunities for individuals to advise clinic leadership in an rapid, structured way.

But just partnering with a clinic isn’t enough, implies Dr. Conteh, who also operates for a community wellness centre. As COVID-19 has taught us, health and fitness disparities are deep-seated and perpetuated systemically. To make the most of these partnerships, healthcare leaders ought to prioritize investments to a higher extent than ever.

Here’s what Dr. Conteh and other researchers suggest.

1. Dedicate to health care financing

Local community wellness partnerships for perinatal wellbeing and other disciplines really should go beyond a superficial relationship, Dr. Conteh says. Somewhat than just possessing physicians volunteer at the neighborhood clinic — which is nevertheless a good point — wellbeing programs ought to “put their cash where their mouth is” with healthcare funding.

“Financing is a enormous problem,” she claims. “You can make all the expert services available, but if these expert services are not lined by insurance plan, they are not heading to be used.” The hole widens even a lot more for patients who really do not have insurance policy.

Besides allowing individuals to accessibility wellbeing solutions, monetary coverage can also foster treatment continuity, she adds. For instance, Medicaid only covers up to 60 days postpartum. Without having assist immediately after that, clients may perhaps discontinue treatment amid 1 of the most psychologically making an attempt times of their lives.

Funding culturally aligned and evidenced-dependent companies these as local community doulas could help to preempt these concerns prior to, throughout and immediately after childbirth. When doulas are included with large-chance expecting people, investigation demonstrates that breastfeeding is extra successful, problems go down and the chance of a healthful child improves.

2. Allow local community members guide

Well being facilities have the advantage of remaining deeply embedded in just the communities they provide. That gain positions them completely to advise and lead overall health program partnerships. And but, that’s not how several of these unions operate, Dr. Conteh claims.

“It’s anything that we as healthcare establishments don’t do very well,” she reflects. “We commonly function from the standpoint of a system telling everyone to do as they’re told. But the centre — and, extra broadly, the community — wants to have enter and direct the treatment. That is a excellent way to build have confidence in within these partnerships.”

Original initiatives to mobilize COVID-19 vaccination outreach demonstrated what transpires when local community customers are specified the reins. A paper in the American Journal of Clinical Quality describes how group liaisons and other procedures to elevate local voices were instrumental in expanding vaccination access amongst Black and Hispanic individuals in New York Town.

3. Serve multidisciplinary wants

Wellness is multidimensional partnerships with neighborhood facilities should admit that complexity by providing extra products and services outside the standard, Dr. Conteh suggests.

In perinatal health, for illustration, clients will need more than an appointment with an obstetrician. Partnerships need to also account for psychiatry, cardiology, endocrinology and other specialized care demands to offer sufferers true detailed care.

“We’re speaking about a model of collaborative treatment the place you have a team of suppliers relatively than just a psychiatrist working independently from an OB-GYN,” Dr. Conteh states.

In the scenario of perinatal overall health — in which Black women encounter postpartum depression at a price of 1.6 times that of White women — it’s quick to see how these collaborations make an effects. Dr. Conteh’s paper examines a person review from the Seattle-King County Public Well being Procedure exactly where participants acquired 18 months of multidisciplinary care and experienced marked improvements in depressive signs and symptoms and cure adherence.

4. Learn from past challenges

Even with the assure of neighborhood health middle partnerships, worries remain, many of them labor-linked. At this time, there are not more than enough medical professionals to provide neighborhood wellbeing clinics in the 1st area and countrywide developments stage to looming shortages of most important care suppliers. Overworked clinicians may possibly have constrained time for neighborhood treatment initiatives on top of their daily observe.

Growing schooling can assistance all set medical professionals for these roles. Healthcare establishments can also persuade companies to have interaction in community wellbeing jobs by producing “mentor days” or dedicated mastering possibilities for this operate.

These and other endeavours are vital to decreasing health and fitness disparities so that everyone can get the most effective treatment, in all places. Knowledge what has worked and what hasn’t can inform future partnership approaches so that local community customers can have a say when health techniques broaden their footprints.

Investigate Lippincott Journals to find proof-primarily based means that can support you chart a path forward in community partnership.

Master how you can increase inhabitants health management with our portfolio of clinical and operational answers.