Let’s talk about Change Healthcare. This latest healthcare industry crisis was entirely driven by ransomware. It has resulted in a situation where hospitals, providers, patients, and everybody involved in anything to do with pharmacy are having a lot of serious trouble. The trouble is basically that they can't write prescriptions or get paid in the way they're used to doing. One reason is that these systems are all interconnected. This system shutdown is affecting almost everybody--every hospital, every patient, every clinic you could go to right now.
Going analog with pen and paper
How has the industry responded? They're writing down prescriptions on notepads like we used in elementary school. I don't know if they're Big Chief yellow tablets, but they're writing down all their prescriptions and literally guessing on the prices. They have no idea about the cost, and they have no idea if they're going to get paid back. They're guessing because Shannon over here or Jamie over there or Bill over there vaguely remembers that the price for something was about $15. They're guessing, making notes, and hoping they can go back and fix it later. This is absolute insanity.
You are only as secure as your weakest vendor
The interesting part about this snafu is this is a vendor situation. One vendor that everybody uses has gone down. Here’s another lesson that your vendor security affects you in more ways than you know. This is why people come to us at Altiam Digital and ask us to look at their vendors, rate them and measure them, and sometimes help them choose the right vendor. That's one of the things we do. But frankly, it also tells you what this industry segment didn't have… a business recovery plan. Not just a business continuity plan, but a cyber recovery plan for what happens if somebody manages to put ransomware on something. That's exactly what just occurred, telling us about the contingency plan that was missing.
Security cannot be an afterthought
Change Healthcare did come up with an alternate system, which apparently, according to the American Hospital Association, is notworking very well, or not working for everybody. At least they put out a tersely worded comment about it because they're angry that their grandmother is having trouble with their prescriptions. Know that no one is happy about this breakdown. But what if you're a vendor? And especially what if you're one of these healthcare vendors? You've got to recognize that businesses are reliant on you in every single way. Security cannot be an afterthought. The hard truth is that I think it is for some folks. This is how ransomware can have a big impact.
A potential solution
A couple of the hacker groups are arguing over it like they always do. The last I heard, one of them actually stole $22 million from the other one, because the only thing they like more than messing with us is messing with each other. The bottom line is that somebody got in somewhere where they shouldn't have. They had credentials that were incorrect, or they had a system that was shut down and found a way in. There's some back door that needs to be closed. But your contracts, your revenue, your insurance costs, your company's reputation, all of these get hurt when issues like this arise. The AHA wrote a sternly worded letter to a couple of senators and congressmen asking for help with a solution to this kind of attack like a secure ID program.
Protection and recovery plans
We're going to need to get there. Your online life used to be a diversion. It was how you enjoyed time away from the real world. Today, your online life goes everywhere with you. Someday it's going to be the backbone of your life. So we need a secure ID program and legislation, but at this point, that's probably 500 years away. In the meantime, we've got to take care of security. While Washington argues about it, we need to be sure we're ready with business recovery plans and secondary systems.
That's why you call somebody like Altiam Digital if you don't know whether you're ready for this kind of an event. If it can happen to the U.S. healthcare system, it can happen to you too. Think about all the security frameworks that are out there--HIPAA, PCI, ISO, everything else, and then times it by ten. The fact of the matter is that security is changing, and these things catch up to the need.
Be prepared or hire a vendor who will be prepared
You've got to be stronger than just PCI compliant. You need to go to NIST and get the latest version, and you've got to read what's coming down the pike in the next two years. Most companies can't keep up with these things. That's why we're here. You need a third-party vendor that keeps up not just what's currently required, but what's going to be required in the next one to two years. That's what you need to do, if you're in critical services as a vendor.
Learn more about Altiam Digital cybersecurity services.