Teleport Named an Overall Leader in Zero Trust Platforms by KuppingerCole Analysts
Read now
Background image

Streamlining HIPAA Compliance for Modern IT Infrastructure

Published: September 5, 2024

Streamlining HIPAA Compliance for Modern IT Infrastructure

Achieving HIPAA compliance for cloud infrastructure is a complex process requiring stringent controls and systematic adherence to regulatory guidelines. In this webinar, we will explore how Teleport simplifies compliance for healthcare technology companies by providing robust security measures and automated processes.

We will cover how Teleport's solutions help you assess your infrastructure for vulnerabilities, implement rigorous access controls, encrypt sensitive data, and monitor activities to ensure compliance. Additionally, we will demonstrate how health tech companies can surpass the minimum HIPAA requirements with Teleport’s built-in security controls, such as multi-factor authentication, role-based access controls, and session recording. Our experts will showcase the continuous monitoring capabilities of Teleport, providing a comprehensive record of all user activities and ensuring compliance with HIPAA technical safeguards.

Key Highlights:

  • Security and Compliance Risks: Explore the increased complexity and risk introduced by modern IT resources and why traditional solutions fall short.
  • Teleport’s Comprehensive Solution: Discover how Teleport addresses these challenges by offering secure, on-demand, least privileged access with cryptographic identity and zero trust foundations.
  • Healthcare-Specific Benefits: Gain insights into how adopting Teleport can accelerate the shift to a digital-first future in healthcare while reducing security risks and improving developer productivity.

Who Should Attend:

  • Healthcare IT and Security professionals
  • Compliance Officers
  • Infrastructure and IT Security professionals
  • CISOs and CIOs
  • Network Security Architects

Takeaway: Equip your organization with advanced strategies to ensure HIPAA compliance in the era of modern IT infrastructure. Gain actionable insights into leveraging Teleport’s features to create a secure, compliant, and efficient environment.

Learn more about Streamlining HIPAA Compliance for Modern IT Infrastructure

Transcript - Streamlining HIPAA Compliance for Modern IT Infrastructure

Introduction

Eddie: Hello, my name is Eddie Glenn. I'm the Director of Product Marketing here at Teleport. I'm excited to talk to you today about how to secure infrastructure and healthcare. And specifically, we'll cover how we can do that to reduce breaches as well as increase resiliency of our infrastructure. I'm going to touch on a few topics. I think we need to start off with just taking a quick look at how the healthcare landscape has changed in the last few years. It's changed pretty drastically. And then it's also important to talk about how cyberattacks are increasing within healthcare systems. And then I want to review five best practices that Teleport suggests for how you can secure your infrastructure, and then just briefly talk about what Teleport can do to help you with that. Before I get started, though, some of you may not be familiar with us. Teleport provides on-demand, least privileged access to infrastructure. We do that on a foundation of cryptographic identity and zero trust. And we do that with built-in identity and policy governance. So the healthcare landscape is changing, and we've seen a lot of changes in the last few years. AI has been a pretty drastic change in how we handle healthcare.

Current healthcare landscape

Eddie: But there's also been changes around the increase of telehealth, electric medical records, wearables, and then operating rooms are now digital. Patient rooms are digital. Doctor's offices are digital. So all this has had a significant impact on the infrastructure for healthcare. And it's really made the infrastructure become a massive digital undertaking for most organizations. And the other thing that's happened is a lot of these services and these technologies rely on cloud-native infrastructure. And then, of course, there's always compliance and regulations to be concerned with. And then pressures to reduce operational costs as well as reduce time to market for those that are developing healthcare systems. And then, as I mentioned earlier, issues around artificial intelligence. So it's pretty concerning when you look at the news that healthcare's cyber-attacks are on the rise. Just in the last year alone, there was 128% increase in ransomware attacks on healthcare systems in the United States alone. And that's nearly doubled over the previous year. And one of the incidents that happened just recently was with a Children's Hospital in Chicago where it impacted all of their systems, and they were shut down for quite a few weeks. And in fact, what I read is that it took months for them to recover from that particular attack.


Healthcare cyberattacks and other challenges

Eddie: And then another report that I saw that I found really interesting is that for every successful attack, cost on average for a healthcare provider, $1.85 million to recover from that incident. I think with the ones that we see here, the examples, it was probably more than that because of the number of patient records that were involved. So what are some of the impacts from a successful cyber-attack on healthcare systems? The one that's most obvious is a breach of patient records. And we can look at just a few examples over the past few years. Lori Children's system had 800,000 patient records breached. Bay Care Health had 500,000 reached. Community Health had 1 million patient records breached. And then when we look at the impact from a regulatory fines perspective, back in 2018, Anthem was fined $16 million. Humira was fined $7 million, and Exodus Health was fined $5.1 million. And then there's also the consideration of disruption of operations. I've already mentioned the hospital that was down for several months, but this happens throughout. If there is a breach, different institutions will be down for multiple months at a time as they recover from that particular attack. So these attacks are extremely expensive from different perspectives. And what do they have in common? Well, there's a key attack vector, and that is credential theft and identity-based exploit of standing privileges.

Eddie: So what do I mean by that? It's unprotected username, password. Someone's able to log in with an employee's credentials, and then they're able to from there get access to maybe systems that they shouldn't have had access to because that employee happened to have access to that system. Also, another tactic is social engineering and phishing accounts for about 35% of this kind of identity-related breaches. And I saw another really interesting statistic. The average number of identity-based attacks that any organization is going to experience in a year is 43. So that is quite a few attacks. Obviously, not always successful, but definitely bad actors are out trying to breach healthcare assistance. And what do we need to help prevent this? It's basically better infrastructure access control. So we really cannot any longer rely on just ensuring that an employee is going to do the right thing by having a hard-to-guess password or not fall for a phishing attempt. We have to do more to protect our infrastructure.

Eddie: So I've talked about some of the external challenges, but we also have some internal challenges as well. And this ties back to how the landscape has changed. And that's why I wanted to talk about that change and change the landscape. And that is technologies that are used by healthcare systems are very, very diverse. Some newer modern technology using cloud-native architectures. Others might still be using on-prem technologies with Linux or Windows servers. And there's lots of different software packages, different databases. And all of these resources that are needed by healthcare systems — they have their own access control infrastructure and they're siloed. So it makes it really hard for an organization to control everything from a single place. And this leads to a couple of things. One is it's high risk. These things rely on secrets. So either usernames and passwords — maybe it's a key that is used to access a system from it —would be like an SSH key. It's prone to human mistakes. So someone uses a weak password or someone writes your password down or it's found through a phishing attempt. And it makes it high risk. A lot of the security systems that organizations have in place are not necessarily friendly and work well with cloud-native platforms.

Eddie: So that's why we frequently see a siloed effect where groups that are using cloud-native technologies use their own set of technologies and people that are using more on-prem technologies are using more traditional security systems. And also, these more traditional security systems are frequently disliked by engineers because it slows them down. And then there's the cost of all of this because if all of these are being handled in a siloed way, that means there's going to be duplication of costs. So this creates another challenge for healthcare organizations. So what's needed to help address this? Well, from a Teleport standpoint, we call it modern access control. There's a set of things that need to be done to help ensure that infrastructure is protected. With us, it starts with a cryptographic identity. So we want to get rid of usernames and passwords and replace it with a short-lived cryptographic certificate that can be used for any device, any software service, cloud native services, on-prem services, machines. And the benefit of this is that it's going to be phishing and theft resistant. The next thing is we need to ensure that there is zero trust networking techniques being used. And what this means is that for application and workloads that we only are providing credentials that are needed at the time that they're needed and that everything checks for a credential when it needs to be accessed. Then we need to provide secretless authentication and ephemeral privileges. So one aspect of that is utilizing biometrics.


Five best practices to secure healthcare infrastructure

Eddie: So we know that not every service or every database or every cloud-native platform offers a way to log in with biometric data, but Teleport wants to be able to provide a service that offers that to any kind of resource that you're using. And finally, we want to build in security intelligence, which means building in identity and policy governance. So this means identity locking as well as being able to visibly check to see what patterns of access one has within their infrastructure. So let's now talk about specifically what are five best practices that you can use to harden your healthcare infrastructure. And this is a defense-in-depth strategy, basically. So the first one is using ephemeral privileges for administrators. Administrative roles should be requested, then get approved and assigned, and only to authorize users for the required time that they need to do that particular kind of operation. And then once that operation is finished, that access goes away. That way, if a particular user gets compromised, the bad actor does not have access to admin privileges. The next thing that's important is requiring MFA for every administrative action. So again, as I said earlier, some devices might have support or some resources might have support for MFA, but not all of them do.

Eddie: But it's really important for an organization to require that for every resource, be it a person, a workload, a piece of software, a machine should all to control that access, there should be an MFA required step to access that. There should also be per session phishing-resistant MFAs. So if I log into a database, that database should require an MFA for that particular session that I've logged into. And then access request. And I've mentioned this a few minutes ago, but we want to implement the principle of least privilege. So basically, we leave an attacker with no permanent admins to target, and that drastically reduces attack vectors. And finally, there is this concept of device trust. And this goes back to how we can use MFA from a particular device to say that this device is trusted. So that if a bad actor does get access to the network, if their device has not been marked as being a trusted device, it's not going to have any access to any of the services on your infrastructure.

Teleport Access Platform

Eddie: So I want to now spend a few minutes talking about what the Teleport Access Platform is and how we can help you implement these best practices to secure your healthcare infrastructure. The first part of this is what we call the Teleport Access product as part of the Teleport Access Platform. And it provides three things. It provides a cryptographic identity, and that's for all users within your infrastructure, all machines within your infrastructure, workloads, and dynamic inventories. And for those of you that might not understand the word cryptographic identity, it's basically a certificate that gets randomly generated that identifies a particular user or machine or resource for a short period of time. And then once that period of time expires and a new one gets generated, so we no longer have to keep track of permanent keys or permanent passwords. So that's one aspect of what Teleport Access does.

Eddie: The next is it provides zero trust networking. And it does this through a variety of things, including reverse tunnels and a protocol aware proxy. And then it also provides authorization and audit. So it does this through secretless authentication. So we aren't using secrets. We aren't using SSH keys. We aren't using usernames and passwords. And then it's done in an ephemeral way. So they do disappear once they aren't needed anymore. So that's the first aspect of what the Teleport Access Platform is. The next aspect is around identity and identity governance. So basically, we're providing you a way to do access monitoring and response, access requests, and reviews. So if I'm a user in your infrastructure and I want to access a particular database, there is a way to get that through to the right people to approve the use of that particular database for that duration of time that I've asked for it for. It does identity locking. It does integrations with SAML and OIDC. And then, as I mentioned earlier, it provides the device trust to identify what devices and machines on your network are safe. And finally, the third part of the Teleport Access platform is Teleport Policy. And this is what allows you to do governance of access policy. So are there any patterns of access that shouldn't be allowed?

Eddie: And maybe you don't even realize that those patterns exist. And Teleport Policy is going to report on what those patterns are that maybe I shouldn't have access to a Windows resource. But because I have access to this particular Linux machine and that Linux machine has access to that Windows machine, that indirectly gives me access. So Teleport Policy can help identify those risky patterns and then allow you to remediate those. So infrastructure — it's really important that it's easy to access and it's secure. We can't have one or the other. The system is broken if it's easy to access but not secure, or it's secure but not easy to access. Because after all, we're all people. We need to make sure that the technologies that we use are easy to use, especially from an engineering perspective. So with Teleport Access Platform, we do three main things. We improve productivity of your workforce. We provide that security that's needed to make your infrastructure resistant to bad actors or human error. And then we also, and this is extremely important for healthcare, provide that compliance part that's needed for things like HIPAA. And one of the aspects of HIPAA is that you need to be able to show how you have access controls over all the critical resources that have access to sensitive patient data. And we can do that with their platform.

Wrap-Up

Eddie: So I know this has been short, and I've intentionally wanted to keep it short because I know that you all are extremely busy. So I just wanted to follow up with some conclusions. First one is the landscape has changed. It's continuing to change. We're embracing technology more in healthcare, and that's causing more cyber-attacks to be targeting the healthcare industry. And we're seeing that increase year over year, and it's something that we should not ignore. Teleport provides solutions for healthcare that enhance infrastructure security. It streamlines access, and it helps you ensure compliance, which is very important. We do this by leveraging cryptographic identities for all the users on your infrastructure, all the machines in your infrastructure, and the devices and workloads. And we eliminate the risk associated with stolen credentials, and we further enforce the principle of least privilege access. And doing this allows us to significantly mitigate the threat of identity-based attacks. So thank you so much for your time today. I do want to encourage you to download this white paper. You can snap the QR code here, but it's a very informative white paper that goes into much more detail about what I just talked about for you to learn more about how we can help secure healthcare infrastructure.

Eddie: Thank you so much for your time. Bye-bye.

Join The Teleport Community

Background image

Try Teleport today

In the cloud, self-hosted, or open source

Get StartedView developer docs