enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Global Product Security & Services Officer for Royal Philips

Multi-Factor Authentication and the Future of Connected Care

Michael McNeil, Global Product Security & Services Officer for Royal Philips

Data breaches in healthcare cost an average of $6.45 million each, with an average of over 25,000 records affected, according to IBM’s 2019 Cost of Data Breach report. Manufacturers like Philips design medical devices and software solutions to meet customer needs, provide the best care to patients, and to be as secure as possible, we are well aware that today’s cyber-threats may pale in comparison to tomorrow’s.

We also know that the best way to deal with a cyber-attack is to prevent it in the first place. Among other prevention efforts, two-factor and multi-factor authentication protocols, which require two or more steps to verify an individual’s credentials before gaining access to sensitive data, provides one of the most straightforward methods in which a healthcare system can safeguard patient data and hospital networks. It is, however, just one step in a holistic cybersecurity program to encourage the highest levels of cyber safety throughout a healthcare network.

Philips systemically implements and deploys two-factor and multi-factor authentication to a number of digital environments, as well as for a number of different categories of end-users – whether clinicians, patients, administrative staff, or support staff. These use cases include secure customer networks where Philips field service engineers require remote access to provide ongoing support, as well as Philips-managed services – whether deployed at customer sites, or hosted by Philips. Additionally, and no less importantly, multi-factor authentication is also deployed in customer-based Philips products and solutions as well.

A prime example of this type of security feature deployment is found in the Philips HealthSuite Digital Platform, where multi-factor authentication is incorporated along with end-to-end encryption and access monitoring, where all access attempts are logged and audited.

"To understand the importance of data security, we need to understand the value of the data itself."

Ultimately, to understand the importance of data security, we need to understand the value of the data itself. Multiple reports can be cited that show healthcare data is the most valuable, that healthcare cyber-attacks are the most expensive, and that healthcare cyber vulnerabilities often prove most susceptible to attacks. Manufacturers and their customers must promote a culture of security and privacy, to help maintain an environment where every employee understands the value of the data with which they interact.

In addition to this, implementing a robust privacy program is also vital to limit how much data is collected, maintaining transparency in sharing with individuals how and why the organization is collecting the data, designing devices and hardware that is compliant with security procedures and requirements, and implementing the right security protocols for those who access that data.

Philips has long been an advocate of the view that manufacturers and customers must begin instilling security from the earliest phases of the design process. From design to deployment, the collection, use, and ultimately the disposal of data must be protected and respected at the highest levels – which lends itself to two-factor and multi-factor authentication. Treating data and access to data as a vitally important dimension of a manufacturer’s product development is good business, as well as a key part of compliance with ethical, legal and regulatory obligations governing medical device data.

By utilizing Philips’ secure cloud-based solutions, managed services, and products, as well as executing extensive security training, two-factor and multi-factor identification, along with creating a culture around security – healthcare providers can improve care, convenience, and simplify operations safely and effectively. Multi-factor identification is just one tool available to healthcare professionals. While effective in many ways, a tool is only as capable as the people using it, which is why we advocate focusing on culture, training, and maintaining complimentary tools that reinforce cyber security at every stage of development in a product’s lifecycle.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.