Q&A: The Hard Hit Health Care Industry Ramps Up Cybersecurity Efforts
Why is health care a target? According to Baker & Hostetler health care attorney Lynn Sessions, 'Are they attacked more or do they report it more? The answer is both.'
April 12, 2019 at 01:00 AM
6 minute read
The original version of this story was published on Corporate Counsel
A recent study on data privacy and security revealed that health care companies, primarily hospitals, report one-fourth of all U.S. cyberattacks—making health care the No. 1 industry impacted by data breaches.
Health care attorney Lynn Sessions, a partner in the Houston office of Baker & Hostetler, wasn't surprised by the numbers in the fifth annual Data Security Incident Response Report by her law firm. In her 20-plus years of working with health care clients, Sessions has handled more than 550 industry data breaches, including several of the largest reported.
Sessions, a former in-house attorney at Texas Children's Hospital in Houston from 2004 to 2011, spoke with Corporate Counsel this week about the cybersecurity trends she is seeing and what general counsel can do about them. Here are excerpts from that interview, which has been edited for clarity and brevity.
Corporate Counsel: Tell us what trends you are seeing in the health care industry in terms of privacy and security.
Lynn Sessions: The answer is twofold. The first trend is that health care continues to be under attack, both from outside sources such as hackers, primarily through phishing emails sent to employees, as well as through some inside jobs. Because HIPAA [Health Insurance Portability and Accountability Act] is the overarching law in this space, it sets a low threshold for notification purposes. We find a lot of companies having to do breach assessments and notifications.
We handled more breach incidents last year across all industries—from 600 in 2017 to 750 in 2018—and the health care piece of that continues to grow year on year too.
What is the second key trend?
The other trend I see is health care organizations ramping up their cybersecurity efforts. As more of these organizations use electronic medical records, they are amassing large volumes of health care data for really good reasons and for a long time. So it has become a necessity to create a position high up in the organization to oversee the security function. When I was an in-house health attorney here in Houston, I didn't really see any chief information security officers. But we have seen the advent of that in last few years, and it's a good trend for the industry.
Are these officers hard to find, and to whom do they usually report?
Not necessarily. Hospitals compete for the talent with companies in all industries. It can be a sizable outlay to hire someone competent and good. A lot of them are lawyers who have compliance backgrounds.
There are a few models in in which the chief information security officer reports to the general counsel. But the most common model has the CISO reporting to the chief executive or the chief of information technology, which means competing for the IT dollars. When the CISO reports to the general counsel and the chief compliance officer, the organization has a very good, compliance focused program.
In your conversations with health care general counsel, what concerns do they voice most frequently about privacy and cybersecurity?
There is a concern about what appears to be uneven enforcement by the Office for Civil Rights [in the U.S. Department of Health and Human Services], which investigates HIPAA complaints. We're hearing from a lot of general counsel about it. They're saying, 'We have to have electronic health care records, we have to be able to communicate health information across our teams, we know we are under attack, and the Office for Civil Rights continues to enforce these multimillion-dollar penalties, even though we know there is little chance of harm coming to individuals due to a breach.”
The way HIPAA is written, the organization has to overcome a presumption of harm due to the breach. There is no reasonableness standard [for likelihood of harm]. Explaining that to nonlawyer executives and board members, and explaining why we have to notify patients, isn't easy. A breach hurts their reputation and their relationship with their community.
Is ransomware a problem in the health care industry?
Yes. Sometimes health care organizations have really good backups and do not pay the ransom. I had one call today from client who did that.
When the Office for Civil Rights looks at ransomware issues, they are not looking just at whether the data was acquired or not, but at whether a patient was impacted by the attack. So you need to look at the integrity of the data, and if it is intact—and at the availability of the data—how quickly did you get back up and running? How did it affect the patients? What are you doing to report that and to prevent it in future?
As in other industries, is email phishing a major problem?
Yes, phishing is the No. 1 way bad guys get into systems. The other thing you see in health care is employee snooping into medical records. The Office of Civil Rights takes employee snooping very seriously. I see about one case a month involving it. You have to educate your staff, and a bad acting employee has to be sanctioned, up to firing, depending on the case.
Why do you think the health care industry is the most attacked industry?
My question is are they attacked more or do they report it more? The answer is both. Again that's because of the broader requirements under HIPAA and under state breach notification laws. There are more scenarios—not just attacks—in health care where there is unauthorized access to or disclosure of data that triggers a notification obligation. While the incidents may be more frequent, the number of individuals involved is often lower than incidents affecting entities in other industries.
Is there anything you'd like to add?
I think the industry has really responded to obligations under HIPAA and state laws, as more state attorneys general, like Florida, California and Massachusetts, are coming in now. Breaches are what keep health care general counsel and their boards up at night. It's smart for general counsel to be engaged on this and to continue to make this a top priority.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllTrending Stories
- 1The Rise and Risks of Merchant Cash Advance Debt Relief Companies
- 2Ill. Class Action Claims Cannabis Companies Sell Products with Excessive THC Content
- 3Suboxone MDL Mostly Survives Initial Preemption Challenge
- 4Paul Hastings Hires Music Industry Practice Chair From Willkie in Los Angeles
- 5Global Software Firm Trying to Jump-Start Growth Hands CLO Post to 3-Time Legal Chief
Who Got The Work
J. Brugh Lower of Gibbons has entered an appearance for industrial equipment supplier Devco Corporation in a pending trademark infringement lawsuit. The suit, accusing the defendant of selling knock-off Graco products, was filed Dec. 18 in New Jersey District Court by Rivkin Radler on behalf of Graco Inc. and Graco Minnesota. The case, assigned to U.S. District Judge Zahid N. Quraishi, is 3:24-cv-11294, Graco Inc. et al v. Devco Corporation.
Who Got The Work
Rebecca Maller-Stein and Kent A. Yalowitz of Arnold & Porter Kaye Scholer have entered their appearances for Hanaco Venture Capital and its executives, Lior Prosor and David Frankel, in a pending securities lawsuit. The action, filed on Dec. 24 in New York Southern District Court by Zell, Aron & Co. on behalf of Goldeneye Advisors, accuses the defendants of negligently and fraudulently managing the plaintiff's $1 million investment. The case, assigned to U.S. District Judge Vernon S. Broderick, is 1:24-cv-09918, Goldeneye Advisors, LLC v. Hanaco Venture Capital, Ltd. et al.
Who Got The Work
Attorneys from A&O Shearman has stepped in as defense counsel for Toronto-Dominion Bank and other defendants in a pending securities class action. The suit, filed Dec. 11 in New York Southern District Court by Bleichmar Fonti & Auld, accuses the defendants of concealing the bank's 'pervasive' deficiencies in regards to its compliance with the Bank Secrecy Act and the quality of its anti-money laundering controls. The case, assigned to U.S. District Judge Arun Subramanian, is 1:24-cv-09445, Gonzalez v. The Toronto-Dominion Bank et al.
Who Got The Work
Crown Castle International, a Pennsylvania company providing shared communications infrastructure, has turned to Luke D. Wolf of Gordon Rees Scully Mansukhani to fend off a pending breach-of-contract lawsuit. The court action, filed Nov. 25 in Michigan Eastern District Court by Hooper Hathaway PC on behalf of The Town Residences LLC, accuses Crown Castle of failing to transfer approximately $30,000 in utility payments from T-Mobile in breach of a roof-top lease and assignment agreement. The case, assigned to U.S. District Judge Susan K. Declercq, is 2:24-cv-13131, The Town Residences LLC v. T-Mobile US, Inc. et al.
Who Got The Work
Wilfred P. Coronato and Daniel M. Schwartz of McCarter & English have stepped in as defense counsel to Electrolux Home Products Inc. in a pending product liability lawsuit. The court action, filed Nov. 26 in New York Eastern District Court by Poulos Lopiccolo PC and Nagel Rice LLP on behalf of David Stern, alleges that the defendant's refrigerators’ drawers and shelving repeatedly break and fall apart within months after purchase. The case, assigned to U.S. District Judge Joan M. Azrack, is 2:24-cv-08204, Stern v. Electrolux Home Products, Inc.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250