THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our Healthcare Tech Outlook Advisory Board.



As VP and CISO in Cyber security & Risk Management at M Health Fairview, Brady is responsible for leading the cyber security threat intelligence and incident response, security engineering, identity and access management, security operations, governance, risk, and compliance teams.
Before joining M Health Fairview, he was the CIO with the second-largest municipal health system in the nation, Los Angeles County, leading and empowering the talented IT staff within the Department of Health Services (DHS). He also had an opportunity to work as the CIO at Kaiser Permanente Orange County. As a highly successful IT executive leader with significant experience leading technology and security initiatives in complex academic medical centers and multi-hospital healthcare settings, he strives to be a committed, transparent, and strategic thinker, leaving a track record of quality, systematic decision making, and provides transformational and business-focused value in this new age of digital economy. To achieve a patient-centric approach at his organization, Brady sees cybersecurity as a major issue to address today.
What are the Cybersecurity Risks in the Healthcare Sector?
Today, it's no surprise that addressing cybersecurity risk is a hot topic among senior leaders responsible for healthcare organizations' financial viability and strategic success.
In recent years, there has been a major increase in cyberattacks that not only disrupt healthcare organizations but also affect them financially or cause operations to cease by varying degrees. There have been a number of prominent healthcare systems in the country that have fallen victim to ransomware and have unfortunately incurred a three to four week disruption to hospital and clinic operations. Another concern that has heightened the attention of decision-makers has been business email compromise and fraud. In this type of an attack, cybercriminals are not only sending ransom requests but also looking to illegally divert funds.
Most importantly, it's not just the healthcare organizations that are attacked but also the supply chain and third party organizations that we rely on. I think that's a big concern that has escalated over the last 12 to 18 months. All healthcare organizations are spending a lot of time trying to determine how they can best reduce such organizational risk.
What are Some of the Best Practices or Technologies that can be Adopted by Healthcare Organizations to Mitigate these Risks?
First and foremost, it's important to ensure that senior-level management is informed of any imminent threat that could have a significant financial and reputational impact on the organization. Second, having senior management buy-in and support is important as it takes money to hire the staff, put the right technologies in place, develop a robust defense, and detect and prevent malicious activities in the IT infrastructure.
"I believe early detection is the key to stopping cyber attacks from happening, whereas prevention is important but can't stop everything"
Third, every organization must not only detect threats but also analyze environmental risk. They should conduct a HIPAA risk assessment at least once a year to evaluate threats and minimize the level of risk by adding control measures. A risk assessment gives an objective view of risk and helps organizations come up with a remediation plan for what to do in terms of technology— do I need a managed security service or additional cybersecurity? It's a must for a healthcare organization to have good email protection and detection. On that note, I'd like to mention a techno or capability called 'Email Isolation,' that could be considered for email phishing in order to protect the organization and employees from advanced attacks. The second must-have technology is Multi-Factor Authentication (MFA), which is required for accessing e-resources or assets in the corporate network remotely. The third capability is network segmentation, which allows you to partition the internal technology network into several isolated sections. If a bad actor manages to get access to the network, they will be unable to move freely once they're inside the castle walls.
A fourth capability would be the ability to detect anomalous activity in its early stages, as it's difficult to prevent all cybersecurity attacks from happening. I believe early detection is a key to stopping cyberattacks from happening; while prevention is important, it can't stop everything. Technologies for threat intelligence and threat detection can assist you in examining the full security ecosystem to detect any malicious activity and raise an alert to take immediate action before it occurs.
Any Piece of Advice for Industry Veterans or Budding Entrepreneurs of the Healthcare Space?
I would advise my colleagues to first understand the business side of their organization, how the company gets its revenue, what are its strategic imperatives, and how it will differentiate itself in the marketplace. Armed with this information, one can then assess the technology environment to determine what the top areas of risk are, and how to best offer increased functionality and reduced risk that enables the organization to be successful. It’s important to engage all parts of the business, including partner organizations and third-party vendors, thereby positioning the security and technology with the right perspective to empower the organization.