HITRUST Backs ‘Community Defense’ Approach to Health Care Cyber-Security

Published: Nov 14, 2012
Updated: Feb 2, 2021
3 minute read
HITRUST Backs ‘Community Defense’ Approach to Health Care Cyber-Security
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

As Congress reportedly prepares to push through a cyber-security bill next week that stalled this past summer, the Health Information Trust Alliance (HITRUST) has responded to a letter from Sen. Jay Rockefeller (D-W. Va.) on how to proceed with cyber-security.

HITRUST is a group of health care business, technology and information security leaders that provides guidance on risk management and protecting patient health information.

After the Cyber-Security Act of 2012 failed to pass, Rockefeller sent a letter on Sept. 19 to 500 CEOs, including many from health care organizations, to suggest that they conduct an audit of their level of preparedness for cyber-attacks. He inquired about what best practices companies are adopting to deal with cyber-threats.

HITRUST responded with a letter to Rockefeller that discussed the steps the health care industry has taken to guard against cyber-attacks.

“We wanted to make sure Sen. Rockefeller was aware that there already was a fair degree of collaboration,” HITRUST CEO Dan Nutkis told eWEEK.

HITRUST launched the Cyber Threat Analysis Service (C-TAS) July 24 to provide intelligence on computer network threats facing the health care industry.

Rockefeller had called for government oversight of critical networks and a presidential executive order on cyber-security.

However, one solution won’t solve the problem of cyber-security, according to Nutkis.

“For us, the key isn’t one size fits all,” said Nutkis. “Every industry believes that they’ve got specific circumstances; health care is no different.”

In its letter to Rockefeller, HITRUST discussed how it was working on a “community defense model” for sharing cyber-threat intelligence, coordinated incident response and exchanging best practices.

“This ‘community defense’ model provides a trusted platform for health care organizations to share threat intelligence and best practices with each other and the government with certain anonymity and without undue scrutiny or liability,” Nutkis wrote in his letter to Rockefeller.

“The [HITRUST Cyber Threat Intelligence and Incident Coordination] Center has established the legal and operating structure to ensure that only relevant information is shared with the Center and that information shared by the Center is done without identification of submitter or victim, facilitating increased willingness to participate.”

Advertisement

For the community defense model, HITRUST partnered with BMC Software and runs its application on the Force.com cloud platform. It provides a platform for health care organizations to report data breaches, share information access about incidents instantaneously and coordinate with HITRUST personnel, said Nutkis.

Under the community defense model, “information gleaned from cyber-attacks becomes proactive information for others to learn from,” according to Nutkis. “One person’s incident becomes another organization’s defense and prevents organizations from undergoing the same type of breach.”

In dealing with cyber-threats, the health care industry is unique because of its mix of medical devices, electronic health records and advanced clinical systems that organizations must secure, said Nutkis.

Critical infrastructures also require easy access for patients and medical staff, he said.

“Health care, unlike other critical infrastructure sectors such as banking and finance and the defense industrial base, however, faces unique challenges when it comes to cyber-security,” Nutkis wrote in his letter.

“The vast majority of the assets are privately owned and operated, highly interconnected with many points of entry, and represent a diverse range of companies, from Fortune 500 organizations down to small businesses, which number in the hundreds of thousands with inconsistent practices and varying levels of skills relating to information security,” he wrote.

Brian T. Horowitz

Brian T. Horowitz is a technology and health writer as well as a copy editor. Brian has worked on the tech beat since 1996 and covered health care IT and rugged mobile computing for eWEEK since 2010. He has contributed to more than 20 publications, including Computer Shopper, Fast Company, FOXNews.com, More, NYSE Magazine, Parents, ScientificAmerican.com, USA Weekend and Womansday.com, as well as other consumer and trade publications.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。