More on Cybersecurity in Health Care
But threats to medical devices and critical infrastructure may be of even greater concern because of their potential effects on patient health and safety. Patients are especially at risk from attacks that could disrupt critical medical infrastructure, disrupt communications and services, interfere with medical devices, or alter or falsify critical data or make them unavailable. The “internet of things,” which connects physical equipment, such as patient monitors, that contains sensors or actuators and is programmed electronically, has enabled remote and distributed access to many diagnostic and treatment capabilities within health care institutions, but such connectivity has also created opportunity for attacks.
I believe that this threat is much more dangerous, than the mere threat of identity theft. The Norwegian Data Protection Authority and similar agencies should focus more time and energy on these areas.
The Ponemon study suggests that organizations that focus adequately on improving their cybersecurity posture, hire and empower a chief information security officer, and build strong incidence-response capabilities can reduce their potential financial risk from data breaches by 42%.
Just as public health strategies have been developed to detect and track emerging epidemics, identify population risks and vulnerabilities, and prevent or ameliorate adverse effects, analogous approaches can be used to improve cybersecurity in health care delivery organizations.