Third-party security threats are one of the most critical risks facing the healthcare sector. Increasing use of artificial intelligence by vendors adds a new layer of third-party concerns, said independent consultant Rick Doten, former CISO of a large managed healthcare firm.
Vendors in the healthcare sector that handle HIPAA protected health information should be scrutinized by their healthcare sector clients on how these firms use AI models, what data they collect and how AI-based agents interact with sensitive systems and accounts, Doten said.
“What AI models are you using? Are they public? Are they private? Are you using platforms that are leveraging AI? Are you doing this for analytics?” are among the questions that healthcare sector entities should ask third-party contractors, he said.
“It’s not just the protection of data, but the appropriate use of the data,” he said. “Is the AI collecting PHI that it shouldn’t? Are you using agents to be able to do processes that may be logging or using accounts or have access to information that may not be needed for the process, but just as kind of brought in in the fishnet of all the things that it’s doing,” he said.
In the audio interview with Information Security Media Group (see audio link below photo), Doten also discussed:
- Dealing with vendors in disruptive security incidents;
- Resources to help smaller hospitals and other healthcare providers better manage their overall cybersecurity risk;
- Why HIPAA security risk analysis is so difficult to perform for many regulated entities.
Doten is the former CISO and vice president of information security at Centene Corp. He has also previously worked as a virtual CISO supporting international companies. He is on the Cloud Security Alliance CXO Trust Advisory Council, as well as the boards of his local Charlotte ISC2 and CSA Chapters. He works with several venture capital and go-to-market firms reviewing security technology, as well as on the board of advisers for several startups.
