A ‘Defence-in-Depth’ Strategy Protegrity’s Response to the Public Report of The Committee of Inquiry into the Cyber Attack on Singapore Health Services Private Limited’s Patient Database
A ‘Defence-in-Depth’ Strategy
FOREWORD 3
OVERVIEW
4
THE RECOMMENDATIONS
7
RECOMMENDATION 9
8
DATA-CENTRIC SECURITY
10
PROTECTION OF DATA ITSELF
11
A SECURE FOUNDATION
12
HOW PROTEGRITY WILL HELP
14
CONCLUSION
16
APPENDIX 1
WHY COMPANIES ARE MOVING TO DE-IDENTIFY DATA
18
APPENDIX 2
METHODS OF DATA PROTECTION
19
APPENDIX 3
RECOMMENDATION 9 ‘IN-DEPTH’
2 | Surpassing Obligations to Protecting Patient Privacy
Today’s healthcare is immensely effective and dramatically improving the quality of life. And it is also getting more data-centric as healthcare instances use this data to enhance daily care and even discover new ways to cure diseases. However, this does burden the organisations involved with not only taking care of the physical patients but also protecting their digital identity. In this paper Protegrity gives healthcare organisations an approach that can be compared with the way healthcare providers have worked for centuries – by following a (medical) guideline. As far as I’m concerned this is the best way to deal with this new challenge – using these evidence-based recommendations as a new guideline. These recommendations are not only applicable to healthcare providers but to ALL organisations responsible for large repositories of personal information. They will help the organisations not only by identifying the most important questions related to data protection but also by providing possible decision options and their outcomes. Learn it, know it and apply it – just like with any other guideline for primary care! Barbara Peruskovic Author of The Hitchhiker’s Guide to Privacy by Design, a comprehensive look at balancing regulation and data-driven innovation, Barbara has been working and teaching in the field of information architecture for over 30 years. She specialises in Privacy by Design, Data & Analytics and Ethical Data Governance and is also Head of Data & IT at Vibe Group.
A ‘Defence-in-Depth’ Strategy
OVERVIEW Organisations globally are increasingly coming to terms with how vulnerable they are to malicious attacks and take steps to reduce their exposure to risk and meet their obligations as custodians of private and valuable information, but as the Public Report of the Committee of Inquiry (COI) into the Cyber Attack on Singapore Health Services Private Limited’s Patient Database shows, there is always more that can be done. Cybersecurity threats are constantly evolving and continue to increase in sophistication, intensity, and scale. While this means that organisations should adopt an ‘assume breach’ mindset, the COI recognises that the transition to a ‘defencein-depth’ strategy cannot happen overnight; senior management must constantly deliberate cybersecurity issues and renew, review, and refresh their security structures, technology, and readiness accordingly. The COI makes 16 recommendations to strengthen the collective security of all organisations responsible for large databases of personal data. These do not uniquely apply to Integrated Health Information Systems and SingHealth. Taking a data-centric approach to protecting sensitive information goes beyond adopting just one of the COI’s recommendations, to instead provide a security foundation that strengthens the efficacy of all recommendations made.
“Given the importance and sensitivity of the PII contained in EMR, it is important to have a comprehensive policy document that applies to the protection of EMR. This policy must document and make clear the measures that are in place to protect the EMR.” P355, 1028. PUBLIC REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBER ATTACK ON SINGAPORE HEALTH SERVICES PRIVATE LIMITED’S PATIENT DATABASE
Organisations worldwide trust Protegrity to reduce risk to personal and sensitive data, by protecting it without compromising its value or their freedom to innovate with it, regardless of where it comes from or where it flows.
Surpassing Obligations to Protecting Patient Privacy | 3
A ‘Defence-in-Depth’ Strategy
THE RECOMMENDATIONS Based on prevention, vigilance, detection, response, governance and people development, the COI’s recommendations are for improving organisations’ ability to deter, detect, respond to, and recover from IT security incidents. PEOPLE DEVELOPMENT
GOVERNANCE
DATA-CENTRIC SECURITY
PREVENTION
RESPONSE 4 | Surpassing Obligations to Protecting Patient Privacy
VIGILANCE
DETECTION
A ‘Defence-in-Depth’ Strategy
PRIORITY RECOMMENDATIONS 1
An enhanced security structure and readiness must be adopted by IHiS and Public Health Institutions
2
The cyber stack must be reviewed to assess if it is adequate to defend and respond to advanced threats
3
Staff awareness on cybersecurity must be improved, to enhance capacity to prevent, detect, and respond to security incidents
4
Enhanced security checks must be performed, especially on CII systems
5
Privileged administrator accounts must be subject to tighter control and greater monitoring
6
Incident response processes must be improved for more effective response to cyber attacks
7
Partnerships between industry and government to achieve a higher level of collective security
ADDITIONAL RECOMMENDATIONS 8
IT security risk assessments and audit processes must be treated seriously and carried out regularly
9
Enhanced safeguards must be put in place to protect electronic medical records
10 Domain controllers must be better secured against attack 11 A robust patch management process must be implemented to address security vulnerabilities 12 A software upgrade policy with focus on security must be implemented to increase cyber resilience 13 An internet access strategy that minimises exposure to external threats should be implemented 14 Incident response plans must more clearly state when and how a security incident is to be reported 15 Competence of computer security incident response personnel must be significantly improved 16 A post-breach independent forensic review of the network, all endpoints, and the SCM system should be considered
Surpassing Obligations to Protecting Patient Privacy | 5
A ‘Defence-in-Depth’ Strategy Given the high degree of digitalisation and interconnectivity in Singapore, and the risks at the national level, it is Protegrity’s belief that adopting Recommendation 9 – Enhanced safeguards must be put in place to protect electronic medical records – is critical for ensuring the enduring successful adoption of all other recommendations.
6 | Surpassing Obligations to Protecting Patient Privacy
A ‘Defence-in-Depth’ Strategy
RECOMMENDATION 9 “The crown jewels of the SingHealth network are the patient electronic medical records contained in the SingHealth Sunrise Clinical Manager (“SCM”) database.” P1, 2. PUBLIC REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBER ATTACK ON SINGAPORE HEALTH SERVICES PRIVATE LIMITED’S PATIENT DATABASE
All organisations maintain critical operational and analytical systems that could be classified as their ‘crown jewels’. The private information held in these systems is not only of high-value to organisations and their customers, it is also the bounty sought by cybercriminals and malicious insiders; it is these records which the COI’s recommendations are designed to protect.
“The amount of data that is being generated daily continues to increase exponentially. Given the rapid pace of development of cyber attacks, data-centric security measures must be deployed. These measures include safeguarding the data itself as it resides in repositories such as databases.” P363, 1055. PUBLIC REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBER ATTACK ON SINGAPORE HEALTH SERVICES PRIVATE LIMITED’S PATIENT DATABASE
Surpassing Obligations to Protecting Patient Privacy | 7
A ‘Defence-in-Depth’ Strategy
DATA-CENTRIC SECURITY According to Gartner:
“The exponential growth in data generation and usage across multiple data silos is rendering current data security methods obsolete, requiring significant changes in both architecture and product selection approaches.” Silo-oriented security only renders the data container unreadable in situ; once the data is moved for consumption or use, it is dependent on the new environment for protection. Data-centric security is the concept of protecting personal information itself, throughout an organisation, by finding it, protecting it, then controlling and logging access attempts to it according to centrally managed security policies.
With security policies that follow the principle of least privilege – access based on the specific job requirements of an authorised and authenticated user – and the most appropriate method of data protection for each use case, organisations are able to ensure the confidentiality and integrity of their most sensitive and valuable data, in line with the COI’s recommendations.
DATA-CENTRIC AUDIT AND PROTECTION CAPABILITIES • Classification and discovery • Security policy management • Monitoring user privileges and access • Auditing and reporting of access • Behaviour analysis, alerting and blocking • Data protection
8 | Surpassing Obligations to Protecting Patient Privacy
A ‘Defence-in-Depth’ Strategy “In short, the policy should follow the principle of least access – that is, staff should have access only to the resources they need to perform their daily tasks, and no more. Access to confidential data should be on a strict, needto-know basis. Further, there should be no general access to patient data – staff should only be able to access the data when they need it for a specific purpose, and the scope of the data accessed should be tightly controlled to include only data essential to the completion of the task.” P356, 1031. PUBLIC REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBER ATTACK ON SINGAPORE HEALTH SERVICES PRIVATE LIMITED’S PATIENT DATABASE
Outside Threat
Data Security
Application Security
Endpoint Security
DATA
Network Security
Perimeter Security
Surpassing Obligations to Protecting Patient Privacy | 9
A ‘Defence-in-Depth’ Strategy
PROTECTION OF DATA ITSELF The COI’s recommendations include using reversible encryption and tokenisation to protect patient data itself, but it is important to understand that each method of data protection (see Appendix 2) has its own distinct advantages depending on the use case in which it is applied.
Tokenisation, which either fully or partially substitutes a sensitive data element with a random, non-sensitive equivalent of no value in the event of a breach, has become the protection method of choice for sensitive data in transactional and analytic environments and for processing personal information in legacy systems where encryption would necessitate modifications. The COI acknowledges that both methods of protection may have some impact in terms of performance but stresses that:
ENCRYPTION
TOKENISATION INCREASING DATA SENSITIVITY / RISK
Encryption mathematically renders personal data unintelligible to any person who is not authorised to access it, and is typically used to protect data in bulk at rest.
NRIC CCN Medical records
X-Ray, HIV-Pos, Diagnosis report
Patient ID Customer ID Address Last name Phone number
First name
More fine-grained (‘structured’) Less need for access in the clear
DOB
Less fine-grained (‘unstructured’) More need for access in the clear
“adverse impact should not be presumed… security should not be sacrificed merely for convenience, given the high-threat environment that exists today.”
“All the measures we have proposed including encryption and tokenisation apply with particular urgency to such sensitive data.”
P364, 1057. PUBLIC REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBER ATTACK ON SINGAPORE HEALTH SERVICES PRIVATE LIMITED’S PATIENT DATABASE
P367, 1069. PUBLIC REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBER ATTACK ON SINGAPORE HEALTH SERVICES PRIVATE LIMITED’S PATIENT DATABASE
10 | Surpassing Obligations to Protecting Patient Privacy
A ‘Defence-in-Depth’ Strategy
A SECURE FOUNDATION The COI recognises that by protecting the sensitive data itself, organisations can add a further, last line of defence should any of the layers of security process or technology within their cyber stack be compromised:
“Protecting the perimeter proved insufficient against the attacker in this case, and in any event, the threat to EMRs may come from malicious insiders. It is recommended that, network security aside, data-centric security measures must be implemented...” P354, 1026. PUBLIC REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBER ATTACK ON SINGAPORE HEALTH SERVICES PRIVATE LIMITED’S PATIENT DATABASE
This philosophy can equally be applied should adoption of any one of the other COI recommendations prove inadequate defence against further cyber attacks.
A ‘Defence-in-Depth’ Strategy
HOW PROTEGRITY WILL HELP Identified by Gartner as the leader in data-centric audit and protection, Protegrity will enable all organisations to confidently implement the COI’s recommendations and secure the confidentiality and integrity of their patients’ personal data without compromising its business value or freedom to innovate.
“Confidentiality means the property that data or information is not made available or disclosed to unauthorised persons or processes.” P355, 1028. PUBLIC REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBER ATTACK ON SINGAPORE HEALTH SERVICES PRIVATE LIMITED’S PATIENT DATABASE
“Integrity means the property that data or information have not been altered or destroyed in an unauthorised manner.” P355, 1028. PUBLIC REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBER ATTACK ON SINGAPORE HEALTH SERVICES PRIVATE LIMITED’S PATIENT DATABASE
12 | Surpassing Obligations to Protecting Patient Privacy
With almost 20 years experience helping the world’s largest organisations comply with industry regulations such as HIPAA and PCI DSS, large enterprises globally can rely on the expertise of Protegrity’s Data Security Professionals to help them balance the trade-offs between the security and operational requirements of a ‘defencein-depth’ approach, as well as address those between security policy and practice. Protegrity not only identifies private information but also automates centrally-enforced, rolebased access controls and security policies, across the enterprise, to protect it according to the principle of least access – at scale, on-premise and in the cloud, in transit, at rest and in use – allowing data security to be truly ‘by design’. With Protegrity’s ability to automate monitoring, logging, auditing and reporting on access attempts to sensitive data in real time, organisations can quickly identify and respond to anomalous behaviour, with the peace of mind that comes from knowing that all sensitive data is protected in a way that makes it no longer personally identifiable (see Appendix), thus reducing risk.
A ‘Defence-in-Depth’ Strategy Role
Name
DOB
City
Phone Number
Default (protected)
0YFPi VXSthG
1553-01-16
xKsuO
0044692376501
Database Admin
0YFPi VXSthG
1553-01-16
xKsuO
0044692376501
Analyst
0YFPi VXSthG
1994-04-05
London
0044692376501
Customer Service
John Smith
1553-01-16
London
0044######570
Protegrity’s comprehensive suite of platform-agnostic data protection capabilities – including discovery, encryption and tokenisation – ensures that any shortfall in the cyber stacks of these organisations, as well as the consequences of human error will be mitigated. By ensuring that only those who have real need to access private information in the clear can do so, the scope of a data breach’s impact is significantly reduced.
“The EMR system must document and keep up-to-date logs and maintain an audit trail of authorised access to the system by users. This means it must record how medical records are accessed, by whom, what information was accessed, and when. That way, security personnel can quickly investigate if they suspect an insider was involved in a data breach. As shown in the Cyber Attack, an external actor can also obtain credentials and masquerade as an authorised insider. Logging of access to the EMR from the front-end client can also therefore be essential to investigating unauthorised access by external attackers.” P357, 1034. PUBLIC REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBER ATTACK ON SINGAPORE HEALTH SERVICES PRIVATE LIMITED’S PATIENT DATABASE Surpassing Obligations to Protecting Patient Privacy | 13
A ‘Defence-in-Depth’ Strategy
CONCLUSION Collectively, the COI’s 16 recommendations serve to build a culture of security, secure particular aspects of the system, improve incident response capabilities, improve post-incident recovery capabilities, and promote collective security. Making the organisational culture, mindset, and structure changes necessary to implement these recommendations will clearly require strong executive leadership – and the right technology to support their governance. To discuss further please get in touch with: Lee Chay Lip Account Executive – Asia Pacific T: +65 9147 9384 E: chaylip.lee@protegrity.com Protegrity Singapore
14 | Surpassing Obligations to Protecting Patient Privacy
Surpassing Obligations to Protecting Patient Privacy | 15
A ‘Defence-in-Depth’ Strategy
APPENDIX 1
WHY COMPANIES ARE MOVING TO DE-IDENTIFY DATA MAXIMISE ROI, LOWER RISK, AND INCREASE THE AGILITY OF YOUR DATA Companies today are choosing to meet the rigorous regulatory, privacy, and corporate requirements for data protection using data de-identification. Data de-identification differs from traditional security approaches enabling complete protection of data across the most diverse and complex environments while allowing the protected data to be fully utilised without risk (e.g. analytics). Original Data
KEY BENEFITS • Protect sensitive data across all environments on premises or in the cloud seamlessly without change or modification • Enable safe consumption and analytics of data without divulging identities • Meet all regulatory requirements governing data protection and privacy • Quick deployments via flexible bundles to protect data across all platforms with services and expertise included
First Name
Last Name
SSN / NID
Account Balance
Credit Limit
DOB
Jason
Watson
392-11-4442
$400,000
$801,840
10/30/65
Unhindered Analytics with De-Identified Data
Kate
Harris
240-02-0023
$381,116
$279,128
12/28/47
Performing analytics produces identical results from both Original Data and De-Identified Data.
De-Identified (Protected) Data De-identified data only changes the identifiers – not the values. First Name
Last Name
SSN / NID
Account Balance
Credit Limit
DOB
sjjya
fksyek
372-72-2064
$400,000
$801,840
09/17/91
ldeu
fleoah
214-03-9200
$381,116
$279,128
10/22/86
16 | Surpassing Obligations to Protecting Patient Privacy
Credit Limit
Account Balance
Original Data
Credit Limit
Account Balance
De-Identified Data
A ‘Defence-in-Depth’ Strategy
APPENDIX 1
Why De-Identification is Better Data Protection
Protection Across All Environments
• Meets stringent compliance, privacy, and regulatory requirements including GDPR, PCI, PHI, HIPAA, and PII mandates
Protegrity provides seamless, centralised enterprise data security, including policy management, monitoring, and reporting across every environment. Data is transparently tokenised/encrypted or detokenised/decrypted across any of Protegrity’s Protectors spanning databases, applications, mainframe, Big Data, and the Cloud. The data remains interoperable and protected across environments to ensure that authorised users can view protected data wherever it is used while unauthorised users cannot.
• Data is protected 100% of the time even if it travels outside a protected environment (e.g. laptop, cloud, USB stick) • Enable privacy preserved analytics and other business applications without divulging identities or risk of breach. • Compatible with all existing and future applications on premises or in the cloud without modification to any code or databases Multiple Protection Methods for De-Identifying Data Sensitive data is de-identified using either tokenisation or encryption technologies. Protegrity Vaultless Tokenization (PVT) is the most advanced and secure tokenisation technology on the market. PVT is Protegrity’s patented tokenisation solution, which substitutes sensitive data with randomly generated values while preserving the original data type and length. Standards-based AES format preserving encryption (FPE) is also available to de-identify data. These different choices provide latitude for organisations to choose technologies based on standards or performance preferences.
Why Protegrity Committed to the success of our customers, Protegrity introduced Protegrity Prime, the industry’s first customer-first subscription model that bundles its software, support and consulting services into flexible tiers based on how much sensitive data is protected. Protegrity Prime allows clients to protect their sensitive data wherever it resides using every product of the Protegrity portfolio in one simple package. Protegrity end-to-end data security includes a highly skilled Professional Security Services team to establish a corporate data protection strategy, followed by optimised deployment and implementation. Protegrity’s continuous protection, and impeccable Support and Customer Enablement Services teams maintain the highest level of data security after implementation. Surpassing Obligations to Protecting Patient Privacy | 17
A ‘Defence-in-Depth’ Strategy
APPENDIX 2
METHODS OF DATA PROTECTION FULLY FLEXIBLE PROTECTION OPTIONS John Snow 4472-8302-9115-3562
John h5siP
#JYhak@osj@H^ !@#$J%a^/&*Bi0)..2,;,+5ea’@?a>
TOKENISATION
ENCRYPTION
Protegrity provides an elegant and efficient Vaultless Tokenisation solution that uses small, static token tables to create unique random token values without the need for a dynamic lookup table. The result is highly scalable, flexible and powerful protection.
Uses mathematical algorithms and cryptographic keys to alter data into binary ciphertext. Reversible only with correct key with the algorithm.
18 | Surpassing Obligations to Protecting Patient Privacy
4001-7642-6031-8836
****-****-****-3562 OR ************
FORMAT PRESERVING ENCRYPTION
DYNAMIC DATA MASKING
Combines the benefits of encryption and tokenisation, but requires more CPU cycles.
Dynamic Data Masking does not alter cleartext data at rest. Views mask all or part of the data when displayed to the user.
A ‘Defence-in-Depth’ Strategy
APPENDIX 3
RECOMMENDATION 9 ‘IN-DEPTH’ QUESTION
PROTEGRITY RESPONSE
“1026. Protecting the perimeter proved insufficient against the attacker in this case, and in any event, the threat to EMRs may come from malicious insiders. It is recommended that, network security aside, data-centric security measures must be implemented to:”
Three key concepts are built into the Protegrity product suite: Data Security Policy, Consistent Deployment across all protection methods and Separation of Duties. Data Security Policy The foundation for protecting sensitive data in the enterprise is the data security policy each organisation creates within the Protegrity Enterprise Security Administrator (ESA), based on their relevant regulations, and circumstances. The purpose of the policy is to enable the Security Officer to determine, specify and enforce the following data security rules: - What type(s) of sensitive data shall be protected? -W hich method(s) will be used to protect the sensitive data? - Who shall have access to the sensitive data? -W here in the enterprise shall the policy be enforced? -A udit of access and process attempts by whom, to what data, where and when.
Surpassing Obligations to Protecting Patient Privacy | 19
A ‘Defence-in-Depth’ Strategy
APPENDIX 3
Policy Deployment Once the policy is determined and set in ESA, it is deployed to Protegrity Data Protectors for: Separation of Duties (SoD) The term ‘Separation of Duties’ refers to the separation or segregation of the security officers, who have control over the data security policy (including granting access to sensitive data), from systems administrators who work with or manage environments containing sensitive data, and who may or may not require access to the data. Security officers control access to sensitive data through the data security policy set in ESA, preventing unauthorised access to sensitive data in the clear such as DBAs, programmers, system engineers and outside parties. Security officers can also be prevented in viewing the data in clear as part of SoD objective. “(a) Ensure the confidentiality91 and integrity92 of medical records.”
Confidentiality means the property that data or information is not made available or disclosed to unauthorised persons or processes. Once installed and configured only those allowed to view sensitive data in the clear will be allowed to see the unprotected form of that data.
“(b) Protect against any reasonably anticipated threats or hazards to the security or integrity of such information.”
Integrity means the property that data or information have not been altered or destroyed in an unauthorised manner.
20 | Surpassing Obligations to Protecting Patient Privacy
A ‘Defence-in-Depth’ Strategy
APPENDIX 3
Protecting data at rest or in transit will require replacement of the data in the clear with protected data. This will ensure any direct access to the data by deliberate bypassing of the Protegrity protection will only result in protected values being obtained. Configuration of High Availability Protection, support for Disaster Recovery requirements and features for backups of policy and keys from ESA allows clients to always be able to access their data in the clear. “(c) Protect against any reasonably anticipated use or disclosure of such information.”
Security Standards of the U.S. Health Insurance Portability and Accountability Act of 1996 (HIPAA), mandates data privacy and security provisions for safeguarding medical information. Protegrity currently has HIPAA regulated clients in the Health Care industry protecting their patients’ data. While the use of Protegrity does provide a means for protecting sensitive data, full compliance with these types of standard does require organisations to have defined policies and procedures in place outside of just data protection.
“1028. Given the importance and sensitivity of the PII contained in EMR, it is important to have a comprehensive policy document that applies to the protection of EMR. This policy must document and make clear the measures that are in place to protect the EMR. We elaborate on some key measures that should be addressed in the policy, in the following sections.”
An organisation’s data security policy is used to configure the policies within Protegrity’s ESA in order to satisfy the data protection requirements of such a corporate policy.
Surpassing Obligations to Protecting Patient Privacy | 21
A ‘Defence-in-Depth’ Strategy
APPENDIX 3
“1030. The policy must establish clear access controls including:
Protegrity supports Enterprise-wide role-based access control (RBAC) through the following features:
(a) Role-based security that restricts access to information based on pre-established categories of patients, duties and documents based on specific job requirements of the user; and
a) Centrally managed enterprise-level crossplatform independent RBAC.
(b) Tagging of sensitive data with status indicators that enable restriction of identified patients and encounters to only those with permissions to access such data.“
Protegrity customers define, grant and revoke enterprise wide access to data from a single interface in a pure cross-platform way. There is no need to know particularities and properties of underlying systems. b) Centralised cross-platform policy design and management. Part of the RBAC definition is a policy design. Protegrity customers will be able to define data access policies in a cross-platform way from a central location. c) Cross-platform policy enforcement on all platforms. Agents enforce data protection policies in a cross-platform way according to capabilities of underlying OSes and technologies. d) Comprehensive segregation of duties. Neither root, systems administrators, DBA nor DBC level admins can view protected data in the clear. There is nothing that can be modified on the system to grant an access. All endpoints are accessible by everyone, only authorised users get meaningful results. Walking out of the data centre with a Protegrityprotected dataset and privileged credentials will not result in exposure of protected data.
22 | Surpassing Obligations to Protecting Patient Privacy
A ‘Defence-in-Depth’ Strategy
APPENDIX 3
e) Protegrity supports integration with all major user directories including Active Directory and LDAP. Protegrity provides a Data Discovery Tool called InsightTM that allows organisations to monitor and track the data stored and evaluate all data for sensitivity and report where potential sensitive data is not protected. “1031. In short, the policy should follow the principle of least access – that is, staff should have access only to the resources they need to perform their daily tasks, and no more. Access to confidential data should be on a strict, need-toknow basis. Further, there should be no general access to patient data – staff should only be able to access the data when they need it for a specific purpose, and the scope of the data accessed should be tightly controlled to include only data essential to the completion of the task”
The Protegrity platform abides with the principle of the least access. Protegrity ensures that personal information is secure by default. Only authorised users have access to the data in the clear. Data access and protection type is defined by a central privacy policy, which varies per role, system, and the context of use.
“1032. Security measures should not only be geared towards external attackers – there is a real risk of patient data being compromised by insiders too. We recommend that the need for administrators, developers and support team to access patient data be reviewed. IHiS should aim for the least number of people possible to have access to the database. To the maximum extent possible, administrators, developers and support team should not be able to view actual patient
The Protegrity platform abides with the principle of the least access. Protegrity ensures that personal information is secure by default. Only authorised users have access to the data in the clear. Data access and protection type is defined by a central privacy policy, which varies per role, system, and the context of use.
Surpassing Obligations to Protecting Patient Privacy | 23
A ‘Defence-in-Depth’ Strategy
APPENDIX 3
data. Currently, IHiS staff such as database administrators are able to access medical records. The only control is that any access by such personnel is logged for audit purposes. This is insufficient, because it does not stop access, and by definition, the logs would only be useful to show that access had already taken place.” “1034. The EMR system must document and keep up-to-date logs and maintain an audit trail of authorised access to the system by users. This means it must record how medical records are accessed, by whom, what information was accessed, and when. That way, security personnel can quickly investigate if they suspect an insider was involved in a data breach. As shown in the Cyber Attack, an external actor can also obtain credentials and masquerade as an authorised insider. Logging of access to the EMR from the front-end client can also therefore be essential to investigating unauthorised access by external attackers.”
Automated audit traits are supported by Protegrity platform, as detailed below:
“1053. In the Cyber Attack, the attacker was able to view the full details of the medical records stored in the SCM database, once he had gained access. This was so as there were no measures in place to secure the data-at-rest in the database.”
Once data at rest is secured with Protegrity’s products, all viewing and copying of the data will be in a meaningless form. Only by authorisation in an ESA policy can someone view the data in the clear once Protegrity’s protection is installed.
24 | Surpassing Obligations to Protecting Patient Privacy
-A ll protection, unprotection and reprotection operations. -O perations of authorised and unauthorised access to protected data are recorded. -A ll administrator activity on Protegrity appliances are logged. This includes administrator login, modifications to the configuration and changes to policy. -U sing the event log configuration within ESA it is possible to stop, pause or initialise the sending of the audit.
A ‘Defence-in-Depth’ Strategy
APPENDIX 3
“1054. Data-at-rest refers to information stored in databases in filesharing servers, in backup tapes etc, and generally includes any data that is not being transmitted through a network (which is known as data-in-motion).”
Protegrity’s suite of protection products can protect data at rest, in transit, and in motion, thus ensuring end-to-end protection of data within an organisation.
“1055. The amount of data that is being generated daily continues to increase exponentially. Given the rapid pace of development of cyber attacks, datacentric security measures must be deployed. These measures include safeguarding the data itself as it resides in repositories such as databases.”
Protegrity’s product suite scales both vertically and horizontally in order to process additional volumes of data as clients may require.
“1056. In general, mechanisms to protect data involve coding data in such a way that access to the data is restricted. This process can generally be referred to as “masking”96 and can occur at the central record repository. Techniques used to mask information in a patient’s medical record include data encryption and tokenisation97. “
Protegrity provides a variety of data protection methods for securing data, including patented Vaultless Tokenization, masking, strong encryption, data-type preserving encryption, and monitoring for anomalous behaviours. Masked or tokenised data embedded with business intelligence allow for secure storage of de-identified personal information and seamless analysis without the need to re-identify the data.
“96 Data masking is the process of hiding original data with random characters or data.”
Protegrity does support masking of data and recommends to our clients that tokenisation be used to ensure the most secure method of protecting the sensitive data.
Surpassing Obligations to Protecting Patient Privacy | 25
A ‘Defence-in-Depth’ Strategy
APPENDIX 3
“97 Tokenisation is the process of substituting a sensitive data element with a non-sensitive equivalent, referred to as a token, that has no exploitable meaning or value. The token is a reference that maps back to the sensitive data through a tokenisation system.”
Protegrity’s Vaultless Tokenization uses a patented process for producing the tokens. No vault is required as codebooks are generated and stored in a protected format within memory and never written to disk or files.
“1057. It is acknowledged that encryption and tokenisation of data may have some impact on the operations of the PHIs, in terms of speed of access to patient records. However, such adverse impact should not be presumed without further study. As before, security should not be sacrificed merely for convenience, given the high-threat environment that exists today. Implementation needs to be carefully handled to minimise disruption to operations. An independent study should be conduct on the feasibility of implementing these measures in the EMR systems of the PHIs.“
The advantage of Protegrity’s Vaultless Tokenization protection method is that protection operations are performed all within memory in fractions of a second. This avoids the need for large token vaults that require additional access and communication time to obtain the required token value for protecting data.
“1069. Similarly, even if encryption and tokenisation cannot be applied to all databases wholesale for performance reasons, steps should nonetheless be taken to encrypt or tokenise sensitive data. This is because such data constitutes an obvious highvalue target for attackers. All the measures we have proposed including encryption and tokenisation apply with particular urgency to such sensitive data.”
Protegrity believes strongly in protecting the values as soon as they are created or enter an organisation’s environment. Protected data will flow through the environment and only be unprotected where approved by management and the client data security team. This will minimise the chance that unprotected data can be obtained within a client environment.
26 | Surpassing Obligations to Protecting Patient Privacy
Protegrity tokenization can be configured to provide the same format of the value to be protected. This makes for a less intrusive application of data security for clients that minimises application and environment changes when tokens are substituted for the real data.
PROVEN EXPERTS IN DATA SECURITY Protegrity has been helping companies for almost 20 years to protect their data as a core business competency. We are used for public cloud environments, including AWS, by leading enterprises in the financial services, healthcare, entertainment, and gaming industries. Each has expansive uses cases for their data that go beyond simply cutting costs and at the same time, involves ensuring that their sensitive customer data is not compromised. Protegrity is the only enterprise data security software platform that leverages scalable, data-centric encryption, tokenisation and masking to help businesses secure sensitive information while maintaining data usability. Built for complex, heterogeneous business environments, the Protegrity Data Security Platform provides unprecedented levels of data security certified across applications, data warehouses, mainframes, big data, and cloud environments. Companies trust Protegrity to help them manage risk, achieve compliance, enable business analytics, and confidently adopt new platforms. Protegrity is headquartered in Stamford, Connecticut USA, with regional offices around the world.
To discuss further please get in touch with: Lee Chay Lip, Account Executive – Asia Pacific T: +65 9147 9384 E: chaylip.lee@protegrity.com Protegrity Singapore, 9 Raffles Place, Level 6 Republic Plaza 1, Singapore, 048619
www.protegrity.com Corporate Headquarters: Protegrity USA, Inc.
Protegrity (Europe)
333 Ludlow Street, South Tower, 8th Floor
Suite 2, First Floor, Braywick House West, Windsor Road
Stamford, CT 06902, USA
Maidenhead, Berkshire SL6 1DN, United Kingdom
Phone: +1.203.326.7200
Phone: +44 1494 857762