Why Identity and Access Management Is Weak in Healthcare

Why Identity and Access Management Is Weak in Healthcare

3rd Party Risk Management , Business Continuity Management / Disaster Recovery , Critical Infrastructure Security

Cybersecurity and Privacy Expert Lee Kim of HIMSS Discusses Sector's Top Challenges Marianne Kolbasuk McGee (HealthInfoSec) • March 11, 2022    
Lee Kim, senior principal of cybersecurity and privacy, HIMSS

Despite the drum beat that began about a decade ago for healthcare entities to bolster their identity and access management, it is still an "incredibly weak" area for far too many, says Lee Kim, senior principal of cybersecurity and privacy at the Healthcare Information and Management Systems Society.


See Also: The Ransomware Files, Episode 3: Critical Infrastructure


"It behooves all healthcare organizations of all sizes and types to have really strong identity and access management," she says in a video interview with Information Security Media Group ahead of the HIMSS 2022 conference taking place in Orlando, Florida on March 14-18.


"If there's anything that needs to be assessed and addressed more, it is a heightened assurance that the individual or entity that is accessing systems or networks is really who they claim to be," she says.


For instance, "tight provisioning of accounts might seem trivial, but many healthcare entities have contractors, employees and others that are constantly flowing in and out of the organization because they may be visiting and/or their roles may change," she says.


HIMSS' recent
Support the originator by clicking the read the rest link below.