Ransomware, Threat Management, Governance, Risk and Compliance, Threat Management, Security Strategy, Plan, Budget
NIST urged to help small healthcare providers, add ransomware to framework

The Workgroup for Electronic Data Interchange (WEDI) urged NIST to combine its ransomware guid with its flagship cybersecurity framework. ("
NIST
" by
Another Pint Please...
is marked with
CC BY-NC-SA 2.0
.)
As malware- and ransomware-based intrusions will continue to plague healthcare into the foreseeable future, the Workgroup for Electronic Data Interchange (WEDI) is urging NIST to combine its ransomware guide to its flagship cybersecurity framework to provide the sector with much-needed support.WEDI is a formal advisor for the Department of Health and Human Services Secretary, with a keen focus on advancing standards for data exchange and promoting data privacy and security. The group leveraged their experience to provide healthcare-specific recommendations to NIST in its request for information on the cybersecurity framework.In mid-February, NIST issued an RFI seeking industry feedback on its flagship cybersecurity framework and supply chain risk management guidance. WEDI issued comments based on its insights from the healthcare sector, noting the NIST resources could be modified to better address some of the most pressing issues facing the sector.In light of the persistent risk and threats posed by third-party apps, medical devices, and a lack of awareness and access to model cybersecurity policies in healthcare, NIST can assist providers by providing further resources and updating its cybersecurity framework, WEDI officials explained. Although the NIST cybersecurity standard “represents the benchmark for those seeking to develop a comprehensive cybersecurity program” in healthcare, WEDI believes there should be a stronger focus on ransomware.NIST issued a ransomware-specific guide in February, but WEDI believes it would best serve providers if it could be incorporated directly into the cybersecurity framework to address the current, persistent state of ransomware threats, which “is driving a lot of resource allocation on the part of healthcare entities.” By merging the two resources, WEDI believes it would better serve the healthcare sector.The guides could also be improved with the addition of specific case studies of healthcare ransomware victims of varying organizational size, along with the addition of ransomware-focused insights on contingency planning, execution and recovery.Ransomware attacks against healthcare organizations pose severe risks not faced by other sectors, as disruptions to operations can impact patient care and morbidity. Adding contingency planning strategies to its flagship guide, specific to healthcare, would greatly benefit the sector, as well.The framework should also include examples of how vendors, providers and health plans have mitigated these attacks and deployed contingency plans to minimize impact on patient care.
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds