Report / In Depth

Do No Harm 2.0

Electronic Health Record
Shutterstock

Abstract

While this report is ostensibly about cybersecurity in healthcare, we hope it is remembered as yet another contribution to the broader body of patient safety literature in medicine, albeit an unorthodox one. Specifically, we aim to highlight the need to mitigate the risks to patient safety created by the growing integration of information technology and operational technology into healthcare, and to propose ways to mitigate that risk. The report takes as a core premise that there is great benefit to be had from technology adoption, but also that in order to achieve that benefit, action will be required to prevent those same systems—either maliciously or by accident—leading to patient harm. Recognizing that this is a complex systemic challenge, the report offers 17 actionable recommendations which we believe could make a real impact. These recommendations are organized across three pillars: culture, technology and workforce.

Acknowledgments

Special thanks also goes to Gabe Nicholas, whose extensive work in the final stages of this paper aided greatly in creating the finished product you hold today.

The authors would like to thank the countless independent privacy and security experts, healthcare practitioners, executive leaders in healthcare, and experts in artificial intelligence, information technology systems, and workforce development whose work made this report possible. Specific thanks go to those individuals who provided thoughtful commentary throughout the development of this project, including:

Laura Bate, Cybersecurity Policy Fellow, New America

Rear Admiral Susan J. Blumenthal (Ret.), MD, MPA, Senior Fellow in Health Policy, New America

Daniel Bowden, VP and Chief Information Security Officer, Sentara Healthcare

Mark Combs, CIO, Steptoe and Johnson, PLLC

Carlos Cruz, SVP/Chief Compliance Officer, Tri-City Medical Center

J. Michael Daniel, President, Cyber Threat Alliance

Dante Disparte, Founder, Chairman and CEO, Risk Cooperative

Matt Doan, Cybersecurity Policy Fellow, New America

Matt Fisher, Partner, Mirick O’Connell

Michael Fried, CIO, Baltimore City Health Department

Chandresh Harjivan, Partner and Managing Director at the Boston Consulting Group (BCG)

David Holtzman, VP, Compliance Strategies, CynergisTek

Peter James, Founder, Amen Ra Security

Robert Morgus, Cybersecurity Policy Fellow, New America

Dr. David Mussington, Professor, UMD School of Public Policy and Board Director, (ISC)2

Mitchell Parker, Executive Director, Information Security and Compliance, IU Health

Michael Prebil, Program Associate, New America

Joy Pritts, Principal, Pritts Consulting

Lucia Savage, Chief Privacy Officer, Omada Health

John Schwartz, Chief Information Security Officer, Health Quest

Heidi Shey, Principal Analyst, Forrester

Dave Summitt, Chief Information Security Officer, Moffitt Cancer Center

Hussein Syed, Chief Information Security Officer, RWJBarnabas Health

Ian Wallace, Senior Fellow, New America

Beau Woods, Cyber Safety Advocate, I Am The Cavalry

Please Note: The affiliations of the noted individuals in no way indicate organizational endorsement of the recommendations in this report. Each of these individuals has merely provided commentary, insights and enhancements that we are very thankful for.

We also wish to acknowledge the supporters of the New America Cybersecurity Initiative whose support helped make this paper possible, notably the Citi Foundation (through their support to New America’s Millennial Public Policy Fellows Program), Florida International University and the Hewlett Foundation.

More About the Authors

Dillon Roseen
Dillon Roseen
Robert Lord
Robert Lord

Programs/Projects/Initiatives

Topics

Table of Contents

Close