Inside This Article

Telemedicine has seen a massive rise in popularity since 2019. But with its rise in popularity amongst patients came more security incidents and breaches, as this new technology became a major target for threat actors.

In fact, with the recent rise in telehealth services, healthcare providers have seen a 117% increase in website/IP security alerts due to malware, along with a 56% increase in endpoint vulnerabilities that enable data theft.

Why such a change? Traditionally, patient care was provided within a healthcare facility, where the equipment used for treatments was physically located on-site. In this controlled environment, frameworks like HITRUST could be used to protect patient data.

However, in the case of telemedicine, healthcare delivery organizations (HDOs) are relying on telehealth and remote patient monitoring (RPM) capabilities to treat patients at home. These devices need to use a third-party internet connection and most likely work through the use of a third-party video conferencing platform as well.

Without adequate privacy and cybersecurity measures for this new normal, unauthorized individuals may expose sensitive data or disrupt patient monitoring services. Even with heightened security concerns, telehealth providers are not able to physically enter the homes of all of their patients to make sure they are using adequate cybersecurity measures. 

This is why organizations offering telehealth services will greatly benefit from the new NIST (National Institute of Standards and Technology) publication.

The Release of the New NIST SP 1800-30

While HDOs do not manage and deploy privacy and cybersecurity controls unilaterally, they are responsible for ensuring that appropriate controls and risk mitigation are applied.

For the last two years, the National Cybersecurity Center of Excellence (NCCoE), a division of NIST, has been working on providing guidance to the industry on ensuring the confidentiality, integrity, and availability of patient data. In February of this year, the final version of NIST Special Publication 1800-30 (NIST SP 1800-30), Securing Telehealth Remote Patient Monitoring Ecosystem, was released.

NCCoE developed NIST SP 1800-30 to form a reference architecture that demonstrates how organizations can adopt a standard-based approach to their telehealth protocol and use it alongside commercially available cybersecurity tools. Made in collaboration with leading healthcare, technology, and telehealth partners, the overarching goal is to improve privacy and security within the telehealth ecosystem. 

This is a big win for the industry because NIST SP 1800-30 will help achieve two major objectives:

  1. Adding additional support for provider organizations  
  2. Providing guidance on deploying and implementing platforms

Added Support to Provider Organizations

Due to the rapid rise in the popularity of telemedicine services, HDOs have consistently lacked support when it comes to keeping sensitive information safe.  
NIST SP 1800-30 will help provider organizations keep telehealth and RPM systems secured by teaching them how to deploy the most effective cybersecurity and privacy controls. The framework updates security policies and procedures, providing more insight into how HDOs can select the right technology vendor to help deliver their telehealth services.

Guidance on Deploying and Implementing Platforms 

Coming as a relief to many, NIST SP 1800-30 gives platforms, applications, cloud providers, and other third-party internet organizations guidance on deploying and implementing technologies. These platforms will also make it easier for telehealth organizations to augment the safeguards of data communications.   

For the IT professionals who want to implement NIST SP 1800-30, NCCoE has created detailed how-to guides available for download. These guides provide specific product installation, configuration, and integration instructions for building the example implementation shown in the documentation.

Additionally, NIST SP 1800-30 informs HDOs of both technical and nontechnical supporting capabilities of medical device cybersecurity, as stipulated within the NIST Cybersecurity for Internet of Things Standards. 

What Organizations Should Do Now 

If you are a healthcare provider that uses telehealth to provide care to patients or a technology company supporting telehealth infrastructure, make sure you are working with your security and privacy consultants to help implement the NIST SP 1800-30 standard across your organization.

As a top cybersecurity compliance assessment organization, A-LIGN can help your organization ensure that patient data remains secure. Our experts understand the nuances of NIST control elements and can help you navigate through NIST SP 1800-30.

Contact A-LIGN today to learn more about cybersecurity tools specifically for organizations offering telehealth services.


Blaise Wabo
Blaise Wabo

HITRUST i1 is a gamechanger for the compliance industry — it fills a crucial market gap for businesses that want a highly reliable security certification for moderate risk assurance. Because security is an ongoing process of continuous improvement, the fact that this assessment is frequently updated to maintain continuous relevance is highly appealing. If you’re seeking guidance on HITRUST, A-LIGN is here for you. We have helped hundreds of clients achieve HITRUST certification and can make your HITRUST journey as smooth and efficient as possible.

Subscribed
Lynne purchased a subscription.
Subscribed
Leighton purchased a subscription.
Subscribed
Jorge purchased a subscription.
Subscribed
Vanessa purchased a subscription.
Subscribed
Ali purchased a subscription.
Subscribed
Mike purchased a subscription.
Subscribed
THOMAS purchased a subscription.
Subscribed
Pam purchased a subscription.
Subscribed
Virginia purchased a subscription.
Subscribed
Sam purchased a subscription.
Subscribed
Tim purchased a subscription.
Subscribed
Ross purchased a subscription.
Subscribed
Ritu purchased a subscription.
Subscribed
Debra purchased a subscription.
Subscribed
Amy purchased a subscription.
Subscribed
Cole purchased a subscription.
Subscribed
Kevin purchased a subscription.
Subscribed
SURYA purchased a subscription.
Subscribed
Wendy purchased a subscription.
Subscribed
Katie purchased a subscription.
Subscribed
Amy purchased a subscription.
Subscribed
Amanda purchased a subscription.
Subscribed
Anna purchased a subscription.
Subscribed
Joseph purchased a subscription.
Subscribed
Joseph purchased a subscription.
Subscribed
Michael purchased a subscription.
Subscribed
Regan purchased a subscription.
Subscribed
Donna purchased a subscription.
Subscribed
PATRICIA purchased a subscription.
Subscribed
Jennifer purchased a subscription.
Subscribed
Tyler purchased a subscription.
Subscribed
Dawn purchased a subscription.
Subscribed
Amanda purchased a subscription.
Subscribed
Miguel purchased a subscription.
Subscribed
Jessica purchased a subscription.
Subscribed
Erin purchased a subscription.
Subscribed
Kandis purchased a subscription.
Subscribed
Engin purchased a subscription.
Subscribed
Grace purchased a subscription.
Subscribed
kharisma D Edwards purchased a subscription.
Subscribed
LeAnn purchased a subscription.
Subscribed
Louis purchased a subscription.
Subscribed
Hanna purchased a subscription.
Subscribed
David purchased a subscription.
Subscribed
Michael purchased a subscription.
Subscribed
Anshul purchased a subscription.
Subscribed
Mital purchased a subscription.
Subscribed
Donna purchased a subscription.
Subscribed
Si Kam purchased a subscription.
Subscribed
JOSEPH purchased a subscription.
Subscribed
Denise purchased a subscription.
Subscribed
Cinda purchased a subscription.
Subscribed
David purchased a subscription.
Subscribed
Gregory purchased a subscription.
Subscribed
Nicholas purchased a subscription.
Subscribed
David purchased a subscription.
Subscribed
Diane purchased a subscription.
Subscribed
Irina purchased a subscription.
Subscribed
Robyn purchased a subscription.
Subscribed
Charlotte purchased a subscription.
Subscribed
Mei purchased a subscription.
Subscribed
Micki purchased a subscription.
Subscribed
Lisa purchased a subscription.
Subscribed
GREGORY purchased a subscription.
Subscribed
WILLIAM purchased a subscription.
Subscribed
Tom purchased a subscription.
Subscribed
Qiao purchased a subscription.
Subscribed
Jeff purchased a subscription.
Subscribed
Veronica purchased a subscription.
Subscribed
Lisa purchased a subscription.
Subscribed
Jesu Christie purchased a subscription.
Subscribed
Tony purchased a subscription.
Subscribed
Takumi purchased a subscription.
Subscribed
May purchased a subscription.
Subscribed
William purchased a subscription.
Subscribed
Samuel Jones purchased a subscription.
Subscribed
Eric purchased a subscription.
Subscribed
WILLIAM purchased a subscription.
Subscribed
James purchased a subscription.
Subscribed
Brian purchased a subscription.
Subscribed
Marie purchased a subscription.
Subscribed
Youssouf purchased a subscription.
Subscribed
Kijaun purchased a subscription.
Subscribed
STUART purchased a subscription.
Subscribed
Blake purchased a subscription.
Subscribed
David purchased a subscription.
Subscribed
Kemper purchased a subscription.
Subscribed
Herschel purchased a subscription.
Subscribed
Bari purchased a subscription.
Subscribed
Kelly R. purchased a subscription.
Subscribed
Brenda purchased a subscription.
Subscribed
Rajachitra purchased a subscription.
Subscribed
Carina Iona purchased a subscription.
Subscribed
Kevin purchased a subscription.
Subscribed
Junko purchased a subscription.
Subscribed
Nancy purchased a subscription.
Subscribed
Diane purchased a subscription.
Subscribed
Beth purchased a subscription.
Subscribed
Antonio purchased a subscription.
Subscribed
Steve purchased a subscription.