Zero Trust Security in Healthcare: Protecting Patient Data

Zero Trust Security in Healthcare: A New Approach to Protect Patient Data

Zero Trust Security in Healthcare: A New Approach to Protect Patient Data

Imagine a breach in a hospital network that was not initiated by any hackers hacking through the firewall from the outside but instead was enabled by a simple theft of employee login credentials and subsequent unauthorised internal movement from system to system: a billing server, then a records database, then even a linked diagnostic machine, without a single internal checkpoint querying whether this access even should occur. It is precisely such breaches that the concept of Zero Trust Security is meant to address, as it assumes that all requests for access to information, whether initiated externally or originating from devices already within the hospital network, must be verified rather than assumed to be genuine. The article below discusses the actual definition of the term, the current state of affairs in India in regard to the issue and the way forward.

Inside the Zero Trust Framework

The Zero Trust Security model is an approach to cybersecurity founded on one fundamental principle that states never trust but always verify. The traditional approaches to network security generally relied on the premise that any element within the network boundary, such as a hospital staff computer or internal server, was, by definition, trustworthy, with a focus on securing the external environment against potential threats to the network. The Zero Trust model completely disregards such a premise and stipulates that all the elements must prove their legitimacy each time they make any request.

There are certain core principles behind the implementation of this concept, including: the least-privilege access, according to which users or systems are provided with the minimum level of access needed for carrying out a particular task; continuous verification, according to which trustworthiness is not something that is obtained once and forever; and micro-segmentation, which involves splitting the network into smaller and more segmented zones.

In terms of securing patient information particularly, this comes into play since the hospital’s network will usually consist of various systems including health care record systems, billing systems, connected diagnostics machines, communications for the staff, among others, and under a conventional model based on perimeter security, this means that after the attacker breaches the perimeter security layer, they can navigate through all of these systems rather easily.

The Threat Landscape Facing Indian Healthcare

Healthcare and pharmaceutical companies have also regularly appeared in reports about being among the industries most under threat from cyber threats to India, due to the valuable nature of the personal data contained therein: while a card number can usually be cancelled and replaced following a data breach, medical records cannot, making them particularly vulnerable to theft for purposes of identity fraud, insurance scams, and blackmail.

The regulatory landscape in India has been considerably altered by the introduction of the Digital Personal Data Protection (DPDP) Act, 2023, which is altering the way in which healthcare providers in India must manage their patients' personal data, and is increasingly being mentioned by security consultancies as a factor driving healthcare providers in India towards Zero Trust.

For many years now, healthcare has been considered the industry that experiences the highest cost per data breach on an average basis, globally, in every annual industry breach cost study that has been undertaken so far, partly because it takes much longer for healthcare companies to detect and mitigate a data breach than in any other industry. Even though there is very little information available regarding India-specific breach cost details, the factors involved are the same in this context too.

It is not some theoretical threats that apply exclusively to Indian hospitals. As recently as November 2022, a ransomware attack against one of the largest Indian government hospitals, AIIMS Delhi, put out of action the centre’s core digital systems for about two weeks as the staff had to deal with registration, admissions, discharges, and record keeping in manual mode while the access was being restored. Even more recently, cybersecurity researchers discovered open files belonging to Apollo Hospitals, one of the largest hospital chains in India, which contained patients' medical information and personal documents; the hospital chain was made aware of that and escalated the situation to India's cybersecurity response organisations. Such cases serve as an example of what these kinds of threats look like when mentioned by security consultancies.

Putting Zero Trust into Practice

Identification and Access Management would be the starting point when implementing Zero Trust Security for any hospital organisation. This involves moving from the existing username/password login process to the adoption of stronger user identification processes such as multi-factor authentication for all users who attempt to access the clinical and administrative systems, regardless of whether they are on the premises or remote.

Network Segmentation is yet another application area of Zero Trust Security within hospitals. In this application area, a hospital's network would be split into various segments such that the connected medical device, billing system, and clinical record database would all be in separate segments as opposed to being on one flat network where a compromised device can compromise the whole network.

Another area where Zero Trust Security can be used is continuous monitoring and device verification, which is important especially in light of the many connected medical devices in hospitals. Under normal circumstances, a connected medical device is trusted once connected to the network, but under Zero Trust Security, the device's behaviour is monitored for any signs of strange behaviour.

What Hospitals Stand to Gain

One of the clearest advantages offered by Zero Trust is that a breach will have less impact, because it won’t be possible for an attacker to spread damage to other systems using one compromised account or device; because the system is continually being assessed and because the network zones are separated from each other, an attacker that succeeds in compromising one login credential or device will not suddenly have access to the whole network.

The second advantage of Zero Trust is its applicability in today’s hospital environment with remote access, cloud services, and many different connected medical devices. Zero Trust is better suited than traditional approaches to protecting information assets in today’s hospital environments.

The third benefit of a Zero Trust architecture in healthcare is compliance. With increasing regulatory pressure to provide detailed and specific control over access to information, Zero Trust provides better assurance of compliance with regulatory requirements.

The Obstacles Slowing the Shift

The implementation difficulty represents another issue that is especially pronounced in the case of those hospitals that possess a combination of more advanced and legacy systems. It should be stated that the concept of Zero Trust, in general, is commonly regarded as a long-term process rather than the purchase of certain software and requires comprehensive knowledge about existing identity flows, device inventories, and access to third parties before the redesign of access controls of a hospital is possible.

Cost and resources represent another issue to be considered in this regard. Specifically, small and medium-sized hospitals that already struggle with tight budgets and a lack of cybersecurity staff in this particular field find it difficult to allocate costs and resources to a lengthy process of security transformation.

Misconfigured cloud settings represent another risk factor related to the implementation of Zero Trust in hospitals due to the fact that, as a result of the digital transformation of hospitals, security analysts state that misconfigured cloud settings become one of the most frequent reasons for breaches.

The Path to Industry-Wide Adoption

The pressure brought to bear by regulatory requirements such as those outlined in the DPDP Act, coupled with the continued cyber-attacks on health care organisations and pharmaceuticals, will likely keep the trend going in terms of driving Zero Trust Security from being an optional upgrade to becoming a standard requirement for hospitals in India over the next few years.

Well-financed larger hospital networks are likely to spearhead this change, due to the inherent expense and difficulty, with smaller hospitals following suit over time, possibly using security services where Zero Trust Security does not need to be implemented in-house properly.

What remains to be seen is whether Zero Trust Security will actually decrease healthcare data breaches in India's hospital system overall, rather than just a few select well-financed hospital systems, and this will be determined not so much by the effectiveness of the security strategy but by its implementation cost-effectiveness.

Stay tuned for more such updates on Digital Health News

Follow us

More Articles By This Author


Show All

Sign In / Sign up