For organizations in highly regulated sectors such as health care, compliance with regulatory standards is not just a good idea; it’s the law. Moreover, there is a broad consensus that the regulatory standards are soundly based on security principles. Complaints about excessive or misguided regulations are not often heard.

But the flip side of this regulatory soundness cannot be taken for granted. Being in compliance with regulatory standards does not, in itself, ensure adequate security. This is for two different reasons, though both are rooted in technological complexity.

The first is the rapid evolution of technology, in particular the explosive growth in the number and variety of network connections. The second is the human factor in security, meaning that it is ultimately as much a state of mind as a matter of specific technical measures.

Listen to the podcast: The Biggest Security Risks in Health Care IT Systems

Compliance Is a Moving Target

According to a Level 3 report, “cyberthreats and the security landscape evolve rapidly, and industry standards cannot keep pace.” Compliance standards can only reflect best practices as of the time when the draft standards were approved. But because of the rapid evolution of the technology environment, best practices are a fast moving target.

Today’s networks are liable to have far more endpoints than what was typical even a few years ago. Indeed, the contemporary focus of security thinking is shifting from primarily endpoint protection to an emphasis on trust of specific users and devices. The current compliance framework only imperfectly reflects this very recent development.

In health care, we are now moving from mere mobile connectivity to the Internet of Things (IoT) and connected devices. This can mean that critical devices such as dialysis machines may now be potentially vulnerable to malware. In other industries with compliance rules, from finance to utilities, the IoT poses comparable evolving threats that the current compliance framework is not fully designed to handle.

Social Engineering and the Human Factor

Connected devices are one of the three leading threats for the health care sector — the others being distributed denial-of-service (DDoS) attacks and phishing attacks, according to the Level 3 report. DDoS attacks can paralyze networks, which in health care can be literally life-threatening.

But the challenge of phishing, as with other types of social engineering, is that it attacks systems through their human users. A particular insidious version, called spear phishing, goes even further by leveraging personal social information to trick users.

Health care is uniquely exposed to social engineering threats because of its large and varied workforce. But the hazards of social engineering attacks extend across industries, and there is no purely technical solution to the challenge of human error. Not even a fully updated set of compliance standards could automatically protect against social engineering attacks. User education is more important than ever, and security will ultimately depend on this human factor.

Compliance Is Not a Cure-All

Meeting compliance standards remains essential to security, not just in health care, but in all industries subject to compliance rules. But compliance should be regarded as a framework that helps make security possible, not a magic wand that automatically makes your organization secure.

Read the IBM X-Force Research Report: Security Trends in the Health care industry

More from Data Protection

Defense in depth: Layering your security coverage

2 min read - The more valuable a possession, the more steps you take to protect it. A home, for example, is protected by the lock systems on doors and windows, but the valuable or sensitive items that a criminal might steal are stored with even more security — in a locked filing cabinet or a safe. This provides layers of protection for the things you really don’t want a thief to get their hands on. You tailor each item’s protection accordingly, depending on…

What is data security posture management?

3 min read - Do you know where all your organization’s data resides across your hybrid cloud environment? Is it appropriately protected? How sure are you? 30%? 50%? It may not be enough. The Cost of a Data Breach Report 2023 revealed that 82% of breaches involved data in the cloud, and 39% of breached data was stored across multiple types of environments. If you have any doubt, your enterprise should consider acquiring a data security posture management (DSPM) solution. With the global average…

Cost of a data breach: The evolving role of law enforcement

4 min read - If someone broke into your company’s office to steal your valuable assets, your first step would be to contact law enforcement. But would your reaction be the same if someone broke into your company’s network and accessed your most valuable assets through a data breach? A decade ago, when smartphones were still relatively new and most people were still coming to understand the value of data both corporate-wide and personally, there was little incentive to report cyber crime. It was…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today