keeping ehrss safe in time of covid19 | 在2019冠狀病毒病的疫 …

30
Keeping Safe in the time of COVID19 EHRSS CYBER SECURITY AWARENESS SEMINAR 2020-08-12

Upload: others

Post on 08-Jun-2022

5 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Keeping Safe in the time of COVID19EHRSS CYBER SECURITY AWARENESS SEMINAR 2020-08-12

Page 2: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

LESSON LEARN FROM COVID-19

Page 3: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Impact of COVID-19

GlobalContagious Disruptive

Enduring Intractable Costly

20M confirmed740K deaths

USD 15.8 Trillion

213 countriesIn 6 months

Page 4: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Impact of COVID-19 to Healthcare

Overloaded Healthcare System

Paralyzed Supply Chains

Disrupted patient care

Page 5: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Cyber Threats are equality devastating

Global Contagious Disruptive

Enduring Intractable CostlyUSD 9.5M per attack

Page 6: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Impact of Cyber Attacks to business

Destroy + Financial loss

Reputational damage + Disgrace

Legal consequence

• Distributed Denial of Service (DDoS)

• Defacing

• Ransomware• Viruses / Worms

• Data Theft via scam/ social engineering

• Data breach

Page 7: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Cyber attack increased by 200+ % targeting even Healthcare sectors

Coronas virus malware / scams increased by 400% world wide

New risk exposure due to Remote Access, Work-From-Home arrangement

Opportunistic threats during time of COVID19

Page 8: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …
Page 9: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

LESSON LEARN from COVID-19

It can strike at anytime

Adapt fast sweeping change

Individual behavior matters

Be vigilant, be prepared

Hopefully, the worst is over…..

Page 10: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Same Lesson applies to Cyber threats

It can strike at anytime

Adapt fast sweeping change

Individual behavior matters

Be vigilant, be prepared

Cyber threats / computer viruses evolves constantly – the worst has yet to come !

Page 11: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Roles of EHRSS during Pandemic

Page 12: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

eHRSS Participation

Page 13: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Roles of EHRSS during Pandemic"Patients participating in our Community Interim Medication Refill Scheme (CIMRS) pilot are those with chronic illnesses who require long term medication. The outbreak of the Coronavirus Disease 2019 (COVID-19) has unexpectedly disrupted their scheduled follow-up and medication refill at the Hospital Authority (HA).

With the objective to bridge this service gap leveraging community resources and inspired by the use of the Electronic Health Record Sharing System (eHRSS), we and our collaborators sparked off this pilot scheme with the aim to contribute to the continuity of care for patients at the community level, as well as to help release precious resources in the public healthcare sector at this critical time to fight against the pandemic."

https://www.ehealth.gov.hk/en/publicity_promotion/ehealth_news_20/cimrs.html

Page 14: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …
Page 15: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Public Private Partnership Programmes introduced during COVID-19

Page 16: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

District Health Center

地區為本,公私合營,医社合作

Page 17: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Lab/Radi Centres

Hospital Authority

Department of Health

Doctors / Nurses

Private Clinics

Patient

Other Health Care Professionals

Private Hospitals

Electronic Health Records Sharing System (eHRSS)

Elderly Home

Social welfare

Voluntary Participation

(except mandatory for Department of Health &Hospital Authority)

Page 18: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Keeping EHRSS Safe in the time of COVID-19

Page 19: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Role-based Access Control

Personal Data (Privacy) Ordinance (Cap 486) (PDPO)

Code of Practice for Using Electronic Health Record for

Healthcare (COP)

Stringent Technical Requirements

Electronic Health Record Sharing System Ordinance

(Cap 625) (eHRSSO)

• Obtain consent from HCR• Need-to-know” & “Patient-

Under-Care”

Protecting Security and Privacy of Personal Data in eHRSS

Sharing Restriction

Page 20: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

System Controls for viewing of EHRSS Records

22/11/20173.Sharing Consent to HCPs

4. Access patient records on Need-to-know & Patient-under-care basis

Health care professional must have valid registration with respective boards or councils

6. SMS Notification

5. 2FA Logon + Role Based Access Control

Page 21: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Ordinary attacks can be blocked by perimeter defenses

Advanced attacks / insider attacks can only be stopped by application security design and continuous monitoring practices

Page 22: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Enhance 2FA Using Mobile Phone

Page 23: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Enhance Sharing Consent Management via eHealth Mobile App

Page 24: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Be vigilant when using

video conference

Use Antivirus software

Mindful of where you

keep sensitive /

work documents

Back up your data & test your

backup

Avoid software

of unknown

origin

Keep your devices /

PC updated

Use strong password + 2FA, Don’t

share password

Beware of unsecure

WiFi / network

Secure privacy

with VPN

Beware of phishing / Covid19 -

scams

Don’t share sensitive

information on social

media

Stay Safe when Work From Home

Page 25: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Stay Safe with Healthcare IoT

• Evaluate security risk before use

• Avoid upload sensitive data to Cloud (eg. patient id)

• Use strong encryption• Separate network for IoT• Don’t use same password• Regularly update firmware

Page 26: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

Cyber Security Tips for Healthcare Providers

https://www.ehealth.gov.hk/en/healthcare_provider/cyber_security/index.html

Page 27: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …
Page 28: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …
Page 29: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …
Page 30: Keeping EHRSS Safe in time of COVID19 | 在2019冠狀病毒病的疫 …

THANK YOU

Stay Safe, Stay Healthy,

Fight COVID-19 together,Keep EHRSS safe together !