The updated HIPAA Security Rule, which is now expected to go into effect in mid-2027, shifts several securing measures from optional considerations to mandatory, including network segmentation. David Finkelstein, chief information security officer at St. Luke’s University Health Network in Allentown, Pa., recently spoke with Healthcare Innovation about the benefit of deploying identity-based microsegmentation across 15 hospitals and roughly 85,000 production devices at his organization.
St. Luke’s adopted Elisity’s identity-based microsegmentation and ran it on the network infrastructure they already owned. As Elisity explains it, microsegmentation lets St. Luke’s cybersecurity team wrap a layer of control around a device they could not directly manage, so they could tolerate more clinical capability without taking on more residual risk.
Joining the conversation was Jason Elrod, CISO at MultiCare Health System in Washington state and an executive advisor for Elisity.
HCI: What are some fundamental challenges that have plagued your network for years, and some of the things that have kept you up at night as top concerns?
Finkelstein:For me, one frustration has been that you have biomedical companies that create these really cool tools that do amazing things for the patient. But when you look at the back-end system, it’s built with what I call bubble gum and duct tape. It’s just not fundamentally developed the correct way. The headache is always: how do you allow a system into your network that you know is going to put all your patient data at risk?
Elrod:I’ve been involved in in healthcare for the last 15 years, and the stuff that was old when I started is still there. So if it was old 15 years ago, what do you think it is today? Legacy tech debt is a real thing. You can’t do modern healthcare without modern IT, and you can’t do modern IT without modern security.
HCI: One example I read about at St. Luke’s involved a robotic assisted surgical system that lets a surgeon help with a procedure from afar. But a blog post said that while the clinical upside of that might be enormous, you had to say no to it for quite a while.
Finkelstein: For four years. What these robots can do from a surgery standpoint is incredible. But we had to shut that off for four years because of how the systems are built and the effect that it would have if we let that run on a network like ours. The question was: How do we get that in here while not massively increasing the risk for the rest of the organization? It was a non-trivial effort.
The friction gets significant. I have had blowouts with physicians who said you’re keeping us from taking care of patients. And in reality, they are exactly right. The flip side of that is, you can’t see a patient at all if the hospital doesn’t have IT and is being shut down.
HCI: Could you talk about earlier approaches that involved VLANs and firewalls?
Finkelstein:That got the job done, but it was costly. That’s the problem. The robots cost $35,000 each, and now we’re saying to the business, you need to give us another $100,000 to build you a special environment. That didn’t make sense to them, and it doesn’t make sense to me as an IT professional. But Jason said it. You can’t have modern patient care without modern IT. If you don’t have IT at all, the days of paper and taking X-rays the way that we used to are gone. That doesn’t exist anymore.
HCI: So how does the identity-based microsegmentation you’ve done with Elisity solve that problem?
Finkelstein:Because it allows you to isolate a specific device in a specific environment. For instance, these robots are in six different hospitals, so now I can isolate the robot in each hospital, both at the macro level and the micro level. That’s the beauty of it. If they have to connect to a system that requires some type of patient documentation, we can do that in a way that protects that system, but allows a robot to function exactly the way it used to.
HCI: David, does that allow you to think about ransomware differently, like as more of a containment problem rather than across the whole network?
Finkelstein:Well, ransomware is a juggernaut in and of itself. But what it allows you to do is be more proactive with ransomware, where you can take the headaches that our cyber engineers and our cyber architects are dealing with with ransomware before we had segmentation and focus on other opportunities and other things within our environment to take care of ransomware.
HCI: I read that St. Luke’s has grown through acquisition several times, and that microsegmentation has had an impact on how long that process takes to bring a new hospital on board.
Finkelstein:When I first started, we had a hospital that we acquired two years before I showed up. Five years later, we finally had that hospital shifted. The most recent hospital that we just acquired took us a year, because we were able to make decisions based upon segmentation and say, “OK, we have to bring that system over. It’s not going to pass. It’s going to fail. We only need them for X amount of years or a year. We’ll segment that. That’ll be fine. We keep moving. So it allows us to speed up our ability to get rid of legacy systems — the legacy tech debt that Jason was talking about. It allows us to really restrict tech debt exponentially, rather than taking five to seven years. Now it takes a year to a year and a half.
HCI: One of your employees, Dan Dopsovich, gave a talk at a Gartner event and had some recommendations for picking a vendor. He said to demand a simulation before enforcement. He said, “If a vendor can’t show you what a policy will block before you turn it on, walk away.”
Finkelstein: When we started our segmentation journey about three years ago, a lot of the vendors said, “Oh yeah, we can do it. And once we did the proof of concept, they didn’t even come close. The thing I listen for is when my network architect says, “Wow, this thing really works.”
This is the thing that kills vendors all the time. They have these demos, so it’s a very contained environment. Of course, the demo is always going to work, but they have no idea of the configuration, the system, the architecture of the customer. To Dan’s point, make it work in the environment. If it does, buy it. If it doesn’t, walk away.
HCI: Dan also said, “Get your CIO and network team in the room from day one. He said, “This is not just a security project alone.” Have you learned that lesson of working more closely with your CIO on these things?
Finkelstein: We learned that lesson early on. I’ve been with St. Luke’s for 13 years. I used to do it very siloed. Now I bring my CTO and my CIO to the table initially. It does two things: One, it gets them to buy in, and two, it allows me to see what my CTO and CIO are thinking about from a long-term standpoint, Now it’s not just a security requirement; it’s an IT strategic requirement.
HCI: Jason, one of the things I wanted to ask you about is the implications of the additional time given to implement HIPAA Security Rule changes and what that means for healthcare organizations. What should they should be doing now to prepare for that?
Elrod:What we’ve got now is this runway that says things that were addressable are now required. It’s not a pass to ignore this for the next 12 months and then be surprised by something that’s not surprising. I think anywork being done in this should continue unabated. Chief among them is the idea of microsegmentation. If you haven’t as an organization gotten behind the idea of deploying microsegmentation in a rational sense, you’re not going to be able to deploy it 12 months from now. The resources available for that are going to become more and more constrained, and they’re going to drive the cost up.
HCI: When we see HHS Office for Civil Rights notifications of security breaches and settlements, they almost all include a description of a failure to do an adequate risk assessment. Why is that happening?
Elrod:They’ve done a risk analysis. I call it the re-victimization of the victim here. Let’s say my organization, fingers crossed, gets ransomware. A bad guy does a bad thing against us, and our patients are impacted. Organizationally, we’re impacted. We’re a victim of of a threat actor, and our patients are impacted. Then I have this three-letter agency, OCR, saying we’re going to assign additional blame because you weren’t perfect in your risk analysis. You weren’t perfect in your security controls. You weren’t perfect in your ability to respond and remove the impact from this threat actor.
HCI: Let me switch gears. Everyone’s talking about AI these days. How is AI impacting your thinking on both sides of this — what bad actors would do with it, or in terms of building AI into tools to defend health system networks?
Finkelstein:AI is a double-edged sword. We have no idea how to use AI yet. We think we do, and we all have 1,000 companies saying they can revolutionize what we do with AI in minutes. We don’t know what agents will truly do. The good side of that is, the threat actors don’t really know how good AI is for them yet either.
Elrod: We’re in this race of who can figure it out quicker. The headache is that until we get our headd wrapped around exactly what AI can do and how it functions and how it truly affects security, we’re all chasing our tails.
