Author: com-messick0

  • Why IT Cannot Meet HIPAA Requirements

    An Honest Discussion About Security, Compliance, and Responsibilities
    Mike Messick
    President, Deep Forest Security

    While exhibiting at a medical practice trade conference recently, I asked dozens of attendees “Who takes care of security within your practice?” Almost without exception the answer was “Oh, our IT handles it for us.”
    While outsourcing security to IT makes sense from a business perspective, our experience has shown that without exception, Covered Entities (CE) that rely on IT to fulfill their security requirements fall far short of the intended goal. The fundamental issue with this approach is that the proverbial tail ends up wagging the dog, and when a CE is audited by the Office of Civil Rights (OCR) because of a data breach or random audit selection, significant fines and reputational damage are the end result. Here’s why:
    You get what you pay for. IT is a cost center that enables business. As such, IT services are offered at the lowest price possible with the level of support demanded by the organization. Outside of contractual or departmental obligations, the responsibility placed upon IT to ensure business operations automatically defines their role as operationally focused, not security focused.
    Security has multiple meanings. If you ask an IT manager or provider what security related issues they’re responsible for, the answer will likely include firewalls, antivirus, backups, and spam filtering. While these are necessary and critical security components, an overall security management plan that includes executive/owner direction, risk analysis & mitigation, policy development, vulnerability management and other components of a holistic approach to risk-based security will not be mentioned.
    Security must start at the top. Security is so much more than firewalls, antivirus, and other technical controls. It’s a way of thinking, that must be embraced by everyone. An effective security plan must be owned, promoted, and enforced by upper management. It starts with owners making a conscious decision to protect patient data and work towards HIPAA Security Rule compliance. Security is driven downwards from there:


    Without direction, participation, and support from executive management, IT cannot provide a risk-based security management program necessary to adequately protect patient data and satisfy HIPAA Security Rule requirements.
    A better question to ask therefore, might be “Does your organization own its security?” If the answer is not “Yes,” then there may be underlying issues that need to be evaluated; in the eyes of OCR, the Covered Entity is ultimately responsible for all patient data contained therein.

  • About the Founder of Deep Forest Security

    Mike Messick’s Founder’s Note:

    I remember my first hack.  At 11 years old, I successfully bypassed the copy-protection on an Apple-II game.  Not because I was into software-piracy, but because I wanted to see how computer security systems worked.  The rush from breaking a system that was designed to be unbreakable was unbearably addicting. 

    When I graduated high-school, I was hired by an oil-company and was tasked with testing the security of their systems. The rush I felt when I unintentionally crashed the multi-million-dollar mainframe was quite different. I learned very quickly about unintended consequences.

    I also remember my first cyber intrusion. The sense of violation, anger, and frustration at not being able to hit-back at the attackers. I learned what it was like to get compromised. My second cyber-intrusion was much different. As the security officer for an Internet Service Provider, I was able to work with municipal, state, and federal agencies to hunt down the badguys that perpetrated a credit card fraud against our customers. 4 months later, the FBI arrested the perpetrators. The rush from victory over the badguys was the best of all.

    Later on, I would battle much larger foes who were tasked with stealing our country’s economic and industrial secrets. I learned quickly that you will never win the war, but you can absolutely stick it to the badguys in any given battle.

    When I founded this company with two police department cyber-crime detectives, we thought the idea of combining law enforcement with cutting-edge technology and techniques might be fun. We could get paid to do a couple of talks, and maybe earn enough money to pay for our cell phones (which, back then were still somewhat of a novelty). Boy, were we wrong.

    We discovered quickly how badly businesses, hospitals, schools, legal firms, government agencies, and others needed our help. We developed cutting edge monitoring techniques to track foreign reconnaissance against critical infrastructure. We disabled logic bombs, and built timelines of cyber incidents involving malevolent employees. We even got to confiscate credit card machines off of a jet as it opened its doors at the gate. All of these things done in the pursuit of protecting our clients.

    When I became the sole owner of the company in 2016, we added some specific managed services to our offerings to address common security pain points we were seeing across all industries for over 10 years: log monitoring, vulnerability scanning, threat detection and response. These tools are super-hard for most businesses to install and run themselves, but provide visibility into networks critical to mounting an effective cyber-defense, and now, cyber-resilience. I’ve lost count of the number of times we’ve quite literally saved a client from compromise because of these services.

    I still get the rush when we defeat the badguys on the wire. My heart also breaks when I get those phone calls on a Friday afternoon at 5:30pm from a college IT administrator who’s network has just been torched, and school starts Monday. Unfortunately, we’re good at cleaning up the messes, and we can hand out hugs in the hallway to little old ladies who are in tears (true story). But we’d much rather help avoid something bad from happening when the badguys come. And they always do, it’s only a matter of time before they’re at your cyber doorstep, because the Internet is really small even though it spans the globe.

    So if you’ve not had a recent security assessment, you need specific services, or you just have concerns and want to talk, reach out to us today.

    As Elwood Blues famously said, “We’re on a mission from God….”

error: Content is protected !!