By Michael Hill
Correspondent
Joe Carr welcomes the state and health care industry partnership to protect the 200-plus members of his New Jersey Hospital Association against cyber threats and hacking.
“That kind of support is really important for us,” said Carr, chief information officer for the New Jersey Hospital Association.
The newly formed New Jersey Cybersecurity and Communications Integration Cell — called NJ CICC — is the state’s one-stop shop for cyber threats, attacks, analysis and incident reporting. It’s under the state Homeland Security Department. It has 19 states and hundreds of public and private partners with which it shares information.
Today, it reached out to an industry that analysts have said has been slow to adapt to new security technologies: hospitals and health care. So it’s partnered with the National Health Information Sharing and Analysis Center.
What are the capabilities and how quickly can it track down a hacking? “We have automated intelligence and information sharing. If we see something hitting our networks here in the state we can on an immediate basis share that tactical information with our members,” said New Jersey Office of Homeland Security and Preparedness Director Chris Rodriguez.
The goal here is that through information sharing they can detect cyber threats and thwart them and ultimately prevent them.
Rodriguez says it takes more than 200 days for a company to realize it’s been hacked and two-thirds of all cyber breaches target patients’ and relatives’ personal information in medical and health care records.
“As the health care sector is also digitizing a lot of patient information and putting the information increasingly on different mobile devices, in order to connect and for cost efficiencies, the health care sector’s attack surface is increasing,” Rodriguez said.
The state says NJ CICC has no interest in collecting anyone’s personal information or any company’s proprietary information.
“We’re interested in cyber threat indicators, very technical oftentimes, indicators of compromise that identifies how attackers are actually defeating security controls or exploiting vulnerabilities in your technology,” said NJ OHSP Cybersecurity Director Dave Weinstein.
The acting state health department commissioner says the partnership is imperative.
“It’s always a concern and we do want to be very cognizant that the techniques and utilization of different types of information can be evolving and that’s why things like the NJ CICC make so much sense,” said New Jersey Department of Health Acting Commissioner Cathleen Bennett.
Carr says considering what’s at stake, it takes a team to tackle it.
“You’re on an island, right? So the more minds you can get who are in a similar boat as you that have expertise that can all bring something to the table and that have same expertise at a higher level, at state government, who’s not only seeing it for health care, but other sectors. That’s amazing,” he said.
NJ CICC’s message: hackers beware.