THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our Healthcare Tech Outlook Advisory Board.



VillageCare, an ACAP member, is a community-based, not-for-profit organization that has served the New York City community for over 40 years, providing community health plans, managed long-term care services, and post-acute healthcare services. ACAP members serve over 20 million people in the United States who live in lower-income communities and have significant health needs.
It is a healthcare sector that is suffering cyberattacks at the same scale and frequency as hospitals and large healthcare systems. The shift to a remote workforce and rapid adoption of cloud computing have created a nebulous computing environment, expanding and complicating the attack surface that already lean security teams must safeguard.
Before the pandemic, VillageCare already had a sizeable remote workforce and had shifted many of its work processes to the cloud. Security tools such as MFA, EDR, and CASB are part of the organization’s security portfolio. The security model, however, was built for a pre-pandemic world.
The results of an independent risk analysis and internal threat assessment identified risks that required VillageCare to perform a comprehensive review of its security model, security stack, and security tool portfolio.
We analyzed user login activity and network traffic patterns and discovered that VillageCare’s remote workforce was no longer confined to the New York metropolitan area. We saw login and network activity from the South and Midwest, Eastern and Western Europe, and the Caribbean. VillageCare had become a community-based organization with a global workforce.
We also discovered that some U.S. internet service providers (ISPs) issue customers cable modems with no network address translation features. A small number of VillageCare staff that connected their VillageCare laptop directly to their cable modem received a public IP address, making it publicly discoverable. Although many of our security controls reduced the risk of compromise, the laptops could potentially be targets of brute-force attacks and exposed to exploitation of zero-day vulnerabilities. We don’t know if foreign ISPs also offer their residential customers similar home network devices. Our immediate action was to ensure that our laptops had the most current operating system patches.
While our security tool portfolio includes EDR, MFA, CASB, secure email and web gateway services, there is a heavy administrative burden. Adding more security vendors risks creating security tool sprawl. We feel we need a more efficient and manageable security stack suitable for a small security team. Integrating our security stack is one of our goals.
"The shift to a remote workforce and rapid adoption of cloud computing has created a nebulous computing environment, expanding and complicating the attack surface that already lean security teams must safeguard"
Peer and industry networks are essential resources. We spoke to several peers in our industry sector, many of whom were also struggling with similar challenges. Some had only one or two people managing security, sharing security duties with IT service teams (who had different service mandates and approach security problems differently). The impact of a remote workforce and cloud adoption varied. A few were contemplating testing Desktop as a Service for remote staff, but still needed to calculate the total cost of ownership. Cloud security posture management was another emerging need.
We also met with security vendors and resellers and learned many of our tools can be integrated with each other, but at varying levels. We also learned that we weren’t taking advantage of some existing features. These features were zeitgeists, not the prophylactic measures necessary against the type of network and identity attacks we were now encountering.
We have embraced the concept of zero trust, but security vendors have different models and visions for implementing it. Our guide is the zero-trust model originally conceived by Forrester’s John Kindervag in 2010. We also leaned on the published work from Evan Gilman, Doug Barth, and Betsy Beyer who influenced the model’s evolution. We particularly took to heart two of Gilman and Barth’s fundamental assertions:
• Every device, user, and network flow are authenticated and authorized.
• Network locality is not sufficient for deciding trust in a network.
To fully implement a zero-trust model requires additional security investments. This includes adding features to some of our security tools and getting help with integration and management. We also need to be fluent in our security tools’ capabilities and limitations. However, we are mindful to not assume more than we can handle. We learned this the hard way with previous security projects. Planning and patience are important for success.
Hackers are ingenious creatures, conceiving novel ways of conspicuously peeling or piercing security layers and identifying and exploiting vulnerabilities. They relentlessly gnaw at healthcare organizations’ cybersecurity defenses or outright clamp their jaws around its throats. VillageCare’s response is to seek more opportunities to collaborate with our security peers and industry groups, develop closer partnerships with our security vendors and resellers, integrate our security stack, have a comprehensive understanding of our security tools, and institute continuous risk and threat assessments. But one step at a time.