OR Manager November/December 2021 - 28

Technology
Continued from page 27
International Medical Device Regulators
Forum published a detailed manual
titled " Principles and Practices for
Medical Device Cybersecurity. " The
document recognizes that cybersecurity
is the responsibility of many
stakeholders-including hospitals.
port also lists several actions that leadership
can take to prepare for and prevent
cybersecurity events (sidebar, The
Joint Commission's " Quick Safety " ).
It is critical for hospitals to be ready
for
IoMT cybersecurity challenges to
address patient safety, protection of
finances, and meet future accreditation
standards.
Quick Safety: The Joint Commission's report
on organization-wide cybersecurity
The " human firewall " concept, as described
by The Joint Commission's Quick Safety
report, is where all staff at the organization
work together to help prevent cybersecurity
attacks in a " top-down organizational
approach. " The report breaks down
The Joint Commission's recommended
safety actions into four categories: leadership,
staff education/training, emergency
management, and IT resources.
Some of the recommended actions include:
➤ Create a culture of cybersecurity that
is top-down;
➤ Make sensitivity to cyberthreats part of
the organization's daily workflow;
➤ Recognize that cybersecurity threats
are always evolving, and threats are
organization-wide;
➤ Teach cybersecurity awareness and
The Centers for Medicare and Medicaid
Services (CMS) and its accreditation
organizations do not yet include requirements
for networked device cybersecurity.
The Office of Inspector General put
forth a new recommendation in June
2021 for CMS to see to this discrepancy
and present a plan for addressing
cybersecurity for quality oversight of
hospitals.
In October 2021, The Joint Commission
issued the " Organization-wide cybersecurity:
Creating a culture of defense "
report,
Reference
The Joint Commission. Quick Safety 62.
Organization-wide cybersecurity:
Creating a culture of defense. October
2021. https://www.jointcommission.
org/resources/news-and-multimedia/
newsletters/newsletters/quick-safety/
quick-safety-issue-62/.
Where can perioperative leaders
begin when trying to facilitate greater
patient safety through cybersecurity
measures? The following tips are
gleaned from several sources, including
Bruemmer's presentation at the OR
Business Management Conference in
September 2021:
* Start with an assessment and list of
all programs and connected devices;
* Assess each one on a standardized
risk scale-there are many of them
readily available;
in which it encourages
the " human firewall " concept. The re28
OR
Manager | Nov/Dec 2021
* Collaboratively decide what the organization's
minimum standards are;
* Decide how to intelligently monitor
those devices that do not meet the
agreed on minimum standards;
* Integrate cybersecurity risk measurements
into procurement processes;
* Re-evaluate over time, because
device security can " drift " as it becomes
older and not as supported;
* Establish monthly standardized reporting
and accountability within your
organization.
vulnerabilities at all levels of the
organization;
➤ Recognize cybersecurity as part of
patient care;
➤ Designate a chief information security
officer, accountable for coordinating
these efforts;
➤ Develop a robust business continuity
plan that can bring the organization
back to an operational level in a timely
fashion.
These steps will not happen overnight,
and one person alone will not
successfully put them in place. But
every step taken by leadership to make
their facilities more secure is a step in
the right direction. Collaborative work on
cybersecurity is a step towards making
patients safer in your care. ✥
-Karen Stockdale, MBA, BSN, RN
References
Bischoff P. Ransomware Attacks on
US Healthcare Organizations Cost
$20.8Bn in 2020. Updated March
10, 2021. Comparitech. https://
www.comparitech.com/blog/
information-security/ransomwareattacks-hospitals-data/#How_
much_did_these_ransomware_attacks_cost_healthcare_organizations_in_2020.
Bruemmer
D. Mayo Clinic cybersecurity
resilience program. OR Business
Management Conference. 2021.
https://www.orbusinessmanagementconference.com/speakers/.
Ponemon
Institute. The impact of
ransomware on healthcare during
COVID-19 and beyond. September
2021. https://www.censinet.com/
ponemon-report-covid-impact-ransomware/.
Cimpanu
C. First death reported following
a ransomware attack on a German
hospital. ZDNet. September
17, 2020. https://www.zdnet.com/
article/first-death-reported-followinga-ransomware-attack-on-a-germanhospital/.
Continued
on page 31
www.ormanager.com
https://www.comparitech.com/blog/information-security/ransomware-attacks-hospitals-data/#How_much_did_these_ransomware_attacks_cost_healthcare_organizations_in_2020 https://www.jointcommission.org/resources/news-and-multimedia/newsletters/newsletters/quick-safety/quick-safety-issue-62 https://www.orbusinessmanagementconference.com/speakers https://www.censinet.com/ponemon-report-covid-impact-ransomware https://www.zdnet.com/article/first-death-reported-following-a-ransomware-attack-on-a-german-hospital http://www.ormanager.com

OR Manager November/December 2021

Table of Contents for the Digital Edition of OR Manager November/December 2021

OR Manager November/December 2021 - 1
OR Manager November/December 2021 - 2
OR Manager November/December 2021 - 3
OR Manager November/December 2021 - 4
OR Manager November/December 2021 - 5
OR Manager November/December 2021 - 6
OR Manager November/December 2021 - 7
OR Manager November/December 2021 - 8
OR Manager November/December 2021 - 9
OR Manager November/December 2021 - 10
OR Manager November/December 2021 - 11
OR Manager November/December 2021 - 12
OR Manager November/December 2021 - 13
OR Manager November/December 2021 - 14
OR Manager November/December 2021 - 15
OR Manager November/December 2021 - 16
OR Manager November/December 2021 - 17
OR Manager November/December 2021 - 18
OR Manager November/December 2021 - 19
OR Manager November/December 2021 - 20
OR Manager November/December 2021 - 21
OR Manager November/December 2021 - 22
OR Manager November/December 2021 - 23
OR Manager November/December 2021 - 24
OR Manager November/December 2021 - 25
OR Manager November/December 2021 - 26
OR Manager November/December 2021 - 27
OR Manager November/December 2021 - 28
OR Manager November/December 2021 - 29
OR Manager November/December 2021 - 30
OR Manager November/December 2021 - 31
OR Manager November/December 2021 - 32
OR Manager November/December 2021 - 33
OR Manager November/December 2021 - 34
OR Manager November/December 2021 - 35
OR Manager November/December 2021 - 36
https://www.nxtbook.com/accessintelligence/ORManager/orm_mar_apr-2025
https://www.nxtbook.com/accessintelligence/ORManager/orm-orbmc_feb-2025
https://www.nxtbook.com/accessintelligence/ORManager/orm_jan_feb-2025
https://www.nxtbook.com/accessintelligence/ORManager/orm_november-2024
https://www.nxtbook.com/accessintelligence/ORManager/orm_asc_october-2024
https://www.nxtbook.com/accessintelligence/ORManager/orm_october-2024
https://www.nxtbook.com/accessintelligence/ORManager/orm_september-2024
https://www.nxtbook.com/accessintelligence/ORManager/orm_august-2024
https://www.nxtbook.com/accessintelligence/ORManager/orm_july-2024
https://www.nxtbook.com/accessintelligence/ORManager/orm_june-2024
https://www.nxtbook.com/accessintelligence/ORManager/orm_may-2024
https://www.nxtbook.com/accessintelligence/ORManager/ormc_brochure_march-2024
https://www.nxtbook.com/accessintelligence/ORManager/orm_april-2024
https://www.nxtbook.com/accessintelligence/ORManager/orm_asc_march-2024
https://www.nxtbook.com/accessintelligence/ORManager/orm_march-2024
https://www.nxtbook.com/accessintelligence/ORManager/orm_february-2024
https://www.nxtbook.com/accessintelligence/ORManager/orm_january-2024
https://www.nxtbook.com/accessintelligence/ORManager/orm_november-2023
https://www.nxtbook.com/accessintelligence/ORManager/orm_october-2023
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-september-2023
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-august-2023
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-july-2023
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-june-2023
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-may-2023
https://www.nxtbook.com/accessintelligence/ORManager/ormc-brochure-march-2023
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-april-2023
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-march-2023
https://www.nxtbook.com/accessintelligence/ORManager/orm-february-2023
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-january-2023
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-november-december-2022
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-october-2022
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-september-2022
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-august-2022
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-july-2022
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-june-2022
https://www.nxtbook.com/accessintelligence/ORManager/ormc-brochure-may-2022
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-may-2022
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-april-2022
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-march-2022
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-february-2022
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-january-2022
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-november-december-2021
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-october-2021
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-september-2021
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-august-2021
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-july-2021
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-june-2021
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-may-2021
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-April-2021
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-march-2021
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-february-2021
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-january-2021
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-december-2020
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-october-2020
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-september-2020
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-august-2020
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-july-2020
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-june-2020
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-may-2020
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-april-2020
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-march-2020
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-february-2020
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-january-2020
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-december-2019
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-november-2019
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-october-2019
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-september-2019
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-august-2019
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-july-2019
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-june-2019
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-may-2019
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-april-2019
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-march-2019
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-february-2019
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-january-2019
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-december-2018
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-november-2018
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-october-2018
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-september-2018
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-august-2018
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-july-2018
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-june-2018
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-may-2018
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-april-2018
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-march-2018
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-february-2018
https://www.nxtbook.com/accessintelligence/ORManager/or-manager-january-2018
https://www.nxtbookmedia.com