exposing the data risks and offering the recommendations for the secure consumerization of e-health...

20
Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May 28, 2013

Upload: gwendolyn-collie

Post on 14-Dec-2015

216 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health

Jason Lin, Corporate Security OfficerTuesday, May 28, 2013

Page 2: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

Faculty/Presenter Disclosure

Faculty: Jason Lin

Relationships with commercial interests:– None

Page 3: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

Background

Personal Videoconferencing

Access

Productivity

Quality

Page 4: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

Scope Timeline

2012• Laptops• Providers

2013• Tablets• Providers

Review of policies and agreements to support the PCVC serviceFocus on the extension of the PCVC service to mobile device platforms (Android and iOS)

2014+• Mobile Devices• ???

Page 5: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

“Our mission is to develop and support telemedicine solutions that enhance access and quality of health care in Ontario, and inspire adoption by

health care providers, organizations, and the public.”

Access “and” Quality

5

Page 6: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

Confidentiality: Privacy of patients depends upon maintaining the confidentiality of personal health information (PHI) at all times.

Integrity: Patient safety depends upon maintaining the integrity of PHI (e.g. ensure no systematic errors exist). Failure to maintain integrity can result in illness,injury or even death.

Availability: In order to provide safe care, HCP must have ready access to important PHI before, during and after providing care.

Integrity

Confidentiality

Availability

Quality includes Information Security CIA Triad

Page 7: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

Center for Information Technology Leadership (CITL) Maturity Model

Page 8: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

PCVC Threat Risk Assessment Findings

Impact

Very High

High

Medium

Low

R1, R3, R4 R2

Very Low

Very Low Low Medium High Very High

Likelihood 8

R1: Unauthorised disclosure of PHI due to re-provisioned or lost/stolen device containing Vidyo

Mobile Logs

R2: Inadvertent exposure and unauthorised access to PCVC sessions

due to limitations in Guestlink operations and configuration

R3: Breach of physician privacy due to lack of end user guidance

and surreptitious recording capabilities of consultations by end users/patients, especially within a BYOD configuration

R4: Limitations and complexity within

policies, MOUs, member and end

user guidance coupled with

presence of PHI on mobile devices

Page 9: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

Defense In Depth Safeguards

9

TECHNOLOGY

PEOPLE PROCESS

Technology

Process

People

Page 10: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

R1: “Unauthorised disclosure of PHI due to re-provisioned or lost/stolen device containing Vidyo Mobile Logs” Safeguard

No PHI Anonymized PHI

Pseudonymized PHI Explicit PHI

Do not leave your mobile device unattended

Page 11: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

R1: “Unauthorised disclosure of PHI due to re-provisioned or lost/stolen device containing

Vidyo Mobile Logs” Safeguard

Use passphrases

Page 12: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

R2: “Inadvertent exposure and unauthorised access to PCVC sessions” Safeguard

Do not leave your mobile device unattended

Page 13: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

R2: “Inadvertent exposure and unauthorised access to PCVC sessions” Safeguard

Do not share your account credentials

Page 14: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

Risk 3 “Breach of physician privacy due to lack of end user guidance” Safeguard

14

Awareness Training EducationAttribute What? How? Why?

Imparts Information Knowledge Insight

Method Media•Video

•Newsletters•Posters

Practical Instruction•Lectures

•Case Study•Hands-on practice

Theoretical Instruction

•Seminar and discussion

•Reading and studyImpact Time-Frame Short-Term Medium-Term Long-Term

Regularly

Create best practise guidelines for HIC users

Page 15: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

Risk 4 “Limitations and Complexity within Policies” Safeguard

Create simplified and friendly terms of services

Page 16: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

Risk “Increased external attacks…”

Page 17: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

Risk “Increased external attacks” Safeguard

Harden devices and applications

Page 18: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

Risk “Increased external attacks…” Safeguard

Separate corporate from consumer environments

Page 19: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

Circles of Trust

International

Federal

Provincial

OTN Local

Page 20: Exposing the Data Risks and Offering the Recommendations for the Secure Consumerization of e-Health Jason Lin, Corporate Security Officer Tuesday, May

Questions and Answers

Thank You

http://otn.ca/en/services/pcvc