Tuesday, February 21, 2017
What healthcare agencies require hearing from their Chief Information Security Officers?
That initiates with educating other executives about breaches—why they occur in the first place, the significance of discussing the technology behind breaches, but most significantly, the procedures and failures that cause breaches.
Chief Information Security Officers (CISOs) should talk about the cyber atmosphere using non-biased sources from firms like Gartner, Ponemon and health insurers to report to coworkers on trends and emerging threats. And Chief Information Security Officers (CISOs) require insisting that the agency join cyber threat sharing initiatives across their region and the industry.
Information security must be tied to 2 enterprise levels—information systems and the organization strategy, Parker stressed. “Metrics need to concentrate on augmenting and supporting the overall strategy,” he adds.
Parker recommended adopting the Lean methodology for improving security performance, as the program is all about process improvements and asking why less than optimal processes continue to exist. And workers responsible for information security, regardless of where in the agency, should be told that they require understanding Lean.
Moreover, Lean should be utilized to design and maintain systems covering business customers, enterprise architecture, legal contracting, compliance, supply chain and enterprise risk scoring, making sure that several teams are on the same page with security.
This is grunt work, Parker cautioned: “You cannot buy your way into this.”
If an agency decides to purchase cyber insurance, it must understand the requirement to complete a comprehensive risk assessment that includes pointed queries to determine the strength of the security program. Not merely are insurers looking for that assessment, but so also is the HHS Office for Civil Rights, which enforces the HIPAA privacy, security and breach notification rules.
Good information security, Parker claimed, has its hooks in clinical risk management, insurance, emergency preparedness, privacy, corporate compliance, supply chain, revenue cycle, information management and Joint Commission requirements, among others.
To be victorious with this laundry list, an agency must embrace change management in an overall enterprise model, Parker advised. “If one player claims, ‘I do my own change management,’ it will not work. Either there is one change management program or there is none.”
Thursday, November 24, 2016
Indiana University Health appoints new CISO
Indiana University Health, the greatest healthcare system in the state, has named Mitch Parker as executive director of Information Security and Compliance.
Parker comes to IU Health from Temple Health, where he was appointed as chief information security officer for 8 years
At IU Health, Parker, who assumed the position in the month of September, leads a team within Information Services committed to protecting the systems and data of organization. He reports to Chief Information Officer Mark Lantzy.
IU Health has fifteen affiliated hospitals and nearly 30,000 workers. It also partners with Indiana University School of Medicine.
Parker has a BS in the field of computer science from the institute of Bloomsburg University of Pennsylvania, an MS in the department of information technology leadership from LaSalle University and an MBA from the Fox School of Business, Temple University.
He is an adjunct professor with the IT and Cyber Security program at the Fox School of Business at the institute of Temple University, as well he as a famous presenter at professional conferences and webinars.





