Andrew Kagan - CTO - Planet TechnologiesThe Government Accountability Office (GAO) has criticized the Department of Health and Human Services (HHS) for falling short on its cybersecurity goals for the healthcare sector. The GAO has found that HHS needs to do more work on several security issues, including assessing appropriate cybersecurity practices, developing evaluation procedures for ransomware risk reduction, and performing risk evaluations of Internet of Things (IoT) and operational technology (OT) devices. The GAO has emphasized the need for further action, as cyberattacks on the health sector are becoming increasingly complex.
Despite the GAO's criticism, HHS has taken some steps to improve cybersecurity in the healthcare sector. In 2019, HHS, in collaboration with the Department of Homeland Security (DHS), the National Institute of Standards and Technology (NIST), and the Health Sector Coordinating Council (HSCC), established the Health Industry Cybersecurity Practices (HICP). These practices define cybersecurity best practices for hospital organizations and are considered "recognized security practices" by the Office for Civil Rights (OCR).
In addition to the HICP, Congress has proposed the Health Care Cybersecurity Resiliency Act of 2024 to strengthen healthcare cybersecurity. The bipartisan bill seeks to:
The proposed legislation aims to address the increasing cyberattacks and ransomware attacks on the healthcare sector, which cause massive disruption to healthcare operations and put patients' sensitive health data at risk.
To help address the challenges faced by HHS, Microsoft Cloud for Healthcare provides a foundation of trust and security for healthcare organizations. Built on the Microsoft Cloud, this platform brings together capabilities from Microsoft Azure, Dynamics 365, Microsoft Power Platform, and Microsoft 365 to provide more efficient care and help ensure the end-to-end security and compliance of health data.
Here are some key aspects of Microsoft Cloud for Healthcare's secure foundation:
Microsoft is also investing in innovations aiming to improve healthcare experiences and outcomes. These innovations include: