CISA Cyber Performance Goals: Third-Party & Supply Chain Requirements

The Cybersecurity and Infrastructure Security Agency (CISA) has been hinting for weeks about a pending announcement on cybersecurity for the nation’s critical infrastructure including healthcare. That update has arrived in the form of a major publication titled CPG: Cross-Sector Cybersecurity Performance Goals.[1]The CPGs provide a mechanism for healthcare organizations and other critical sector entities to prioritize their implementation of the most effective and essential security controls required to defend against emerging cyberattacks. This blog provides an overview of the CPGs and delves into the CPGs that are dedicated to supply chain and third-party vendor risk management. We also discuss the history and genesis of the CPGs, definitions and components, and practical applications for the CPGs for healthcare organizations. Read More

Keep Up with CORL: Vendor Breach Digest, 10/11/22

Our Vendor Breach Digest provides a summary roll-up of major breach events for third-party vendors operating within the healthcare supply chain. Breaches covered in this release: Okta & Microsoft, SummaCare, Healthplex, Inc, GitHub, Arcare, American Dental Association, T-Mobile, Mental Health Center of Greater Manchester, Mountain Area Health Education Center, The State Bar of Georgia, McCarter & English, Kaiser Foundation, Health Plan, Touchstone Imaging, DialAmerica Marketing, Block, Parker Hannifin Corporation, MailChimp, HubSpot, Cytometry Specialists, Palo Alto Networks, Globant, and Gainwell Technologies. Read More

TPRM is Broken: Healthcare’s Unsustainable Approach to Third-Party Vendor Risk Management

CORL and HITRUST specialize in delivering cybersecurity assurance products and services for the healthcare industry including Third-Party Risk Management (TPRM) programs. Our companies have been listening attentively to our clients and colleagues and one message has come across loud and clear: TPRM is broken and we need to collaborate as an industry to fix it. This blog provides a summary of the feedback and perspectives from cybersecurity and risk leaders charged with managing healthcare TPRM programs. Read More

Cloud Security Alliance Weighs in on Third-Party Risk Management in Healthcare

Cloud Security Alliance (CSA) recently released new guidance on managing third-party cyber security risk in healthcare that offers some practical and useful tips for defenders to consider. The report comes on the heels of a new industry report from IBM that cites healthcare as the highest sector for breach costs. The IBM report also notes that 45% of breaches were cloud-based and almost one fifth of breaches occurred because of a compromise at a third-party business partner. Read More

Healthcare Vendors Sharing PHI with Facebook: Analysis & Recommendations

A bombshell news report was issued by The Markup on June 16 in their publication, Facebook Is Receiving Sensitive Medical Information from Hospital Websites. Specifically, the report claims that healthcare organizations across the country have installed Meta Facebook’s Meta Pixel tracking tool on patient portals and other patient-facing websites. The Meta Pixel platform reportedly sends Facebook Protected Health Information (PHI) including patient names, IP addresses, names of doctors, appointment information, prescription details, and more for many of the nation’s hospitals. Read More