You are here

digital security

Obama Proposes Safe Harbors for Cybersecurity Information-Sharing

Politico's David Perera reports on a cybersecurity proposal that President Barack Obama put forth today. One key part, pushed for a long time, would provide limited safe harbors to firms that share cybersecurity information with the government: "A central portion of the White House’s plan would grant targeted liability protection to companies that share cyberthreat information with the government — removing what critics say is a major stumbling block to private-sector partnership with federal authorities on cyber issues." The Department of Homeland Security, in turn, would share cyberthreat data with other federal agencies and with private-sector information-sharing organizations.

There are privacy safeguards as part of the plan. Firms would be required to take steps to remove personally identifiable information unrelated to cyberthreats when sharing that information.

Sony Hack Could Spur Cybersecurity Legislation

The Hill's Cory Bennett reports that the hack of Sony Pictures is inspiring much more urgent interest from Congressional lawmakers about cybersecurity legislation, including legal protections for companies that exchange cyberthreat information with the government. But Robyn Greene, policy counsel for New America Foundation’s Open Technology Institute, told The Hill that “it is unlikely that information sharing would have prevented the Sony hack. Eighty to 90 percent of all attacks are the result of poor cyber hygiene and internal system monitoring.”

FDA Pushes for Cybersecurity for Medical Devices, Health Information Technology

Submitted by Amaris Elliott-Engel on Sat, 10/25/2014 - 11:25

What if hackers caused medical devices to malfunction? Disrupted healthcare services? Accessed patient information or electronic health record data? Those are examples of potential digital security pitfalls for the healthcare industry. Here's a piece I wrote for the National Law Journal about the need to develop industry standards for cybersecurity for medical devices and other health information technology: 

A cybersecurity framework for medical devices and health-care technology needs to be developed in a partnership between the government, manufacturers and health-care providers, officials from across the public and private sectors during a workshop convened by the U.S. Food and Drug Administration.

“Right now, for cybersecurity, we’re all in a reactive mode,” said Deborah Kobza, executive director of the National Healthcare Information Sharing and Analysis Center. “We need to change that to be in a preventive mode.”

The concern is that hackers could cause medical devices to malfunction, disrupt health-care services or steal patient information and electronic health records. The FDA, along with the Department of Health and Human Services and the Department of Homeland Security, sponsored the two-day workshop this week.

The Advanced Medical Technology Association’s Jeffrey Secunda said that, “for devices that are facing the Internet, you do have the risk of advanced persistent threats.”

How the FDA is going to approach cybersecurity, including evidence that devices have led to patient harm, “is exactly why we’re convening this meeting,” said Suzanne Schwartz, director of the FDA’s emergency preparedness/operations and medical countermeasures in the Center for Devices and Radiological Health.

Workshop participants said they were unsure how much tolerance there is for the risk that patients information could be breached in the effort to make electronic health records and health information technology “interoperable” and more accessible to patients.

Dr. William Maisel, the FDA’s chief scientist and deputy center director for science at CDRH, said there are 100,000 medical devices on the market and the technology changes rapidly. The FDA doesn’t view it as a solution to take in all the information about digital security vulnerabilities in medical devices and pass it on to the community, he said.

Instead, federal regulators want an “ecosystem where that information is being shared,” such safe harbors for medical device manufacturers and health-care providers to make reports about cybersecurity breaches without incurring liability, he said.

Participants said that providers don’t report digital security breaches for fear or exposure during litigation.

The National Healthcare Information Sharing and Analysis Center’s Kobza noted that her group has entered a memorandum of understanding with the FDA to develop a protocol about sharing information about medical devices.

Subscribe to RSS - digital security