Skip to content
  • About
  • Contact
  • Contribute
  • Book
  • Careers
  • Podcast
  • Recommended
  • Speaking
KevinMD
  • All
  • Physician
  • Practice
  • Policy
  • Finance
  • Conditions
  • .edu
  • Patient
  • Meds
  • Tech
  • Social
  • Video
  • All
  • Physician
  • Practice
  • Policy
  • Finance
  • Conditions
  • .edu
  • Patient
  • Meds
  • Tech
  • Social
  • Video
    • All
    • Physician
    • Practice
    • Policy
    • Finance
    • Conditions
    • .edu
    • Patient
    • Meds
    • Tech
    • Social
    • Video
    • About
    • Contact
    • Contribute
    • Book
    • Careers
    • Podcast
    • Recommended
    • Speaking
KevinMD
  • All
  • Physician
  • Practice
  • Policy
  • Finance
  • Conditions
  • .edu
  • Patient
  • Meds
  • Tech
  • Social
  • Video
    • All
    • Physician
    • Practice
    • Policy
    • Finance
    • Conditions
    • .edu
    • Patient
    • Meds
    • Tech
    • Social
    • Video
    • About
    • Contact
    • Contribute
    • Book
    • Careers
    • Podcast
    • Recommended
    • Speaking
  • About KevinMD | Kevin Pho, MD
  • Be heard on social media’s leading physician voice
  • Contact Kevin
  • Discounted enhanced author page
  • DMCA Policy
  • Establishing, Managing, and Protecting Your Online Reputation: A Social Media Guide for Physicians and Medical Practices
  • Group vs. individual disability insurance for doctors: pros and cons
  • KevinMD influencer opportunities
  • Opinion and commentary by KevinMD
  • Physician burnout speakers to keynote your conference
  • Physician Coaching by KevinMD
  • Physician keynote speaker: Kevin Pho, MD
  • Physician Speaking by KevinMD: a boutique speakers bureau
  • Primary care physician in Nashua, NH | Kevin Pho, MD
  • Privacy Policy
  • Recommended services by KevinMD
  • Terms of Use Agreement
  • Thank you for subscribing to KevinMD
  • Thank you for upgrading to the KevinMD enhanced author page
  • The biggest mistake doctors make when purchasing disability insurance
  • The doctor’s guide to disability insurance: short-term vs. long-term
  • The KevinMD ToolKit
  • Upgrade to the KevinMD enhanced author page
  • Why own-occupation disability insurance is a must for doctors

What keeps a hospital CIO up at night

John Halamka, MD
Tech
April 28, 2012
Share
Tweet
Share

Earlier this year, my team presented a list of risks to the Compliance, Audit and Risk Committee at BIDMC.   Here’s my list of top risks for 2012:

1. Old Internet browsers. Many vended clinical applications require specific versions of older browsers such as Internet Explorer 6, which are known to have security flaws.  We’ve worked diligently to eliminate, upgrade or replace applications with browser specificity.   At this point we are 96% Internet Explorer 8/Firefox 7/Safari 5 minimizing our risks to the extent possible.

2. Local Administrative rights. Of our 18,000 devices on the network, a few thousand are devices that require the user to have local administrative rights to run their niche applications (often the research community doing cutting edge research with open source or self developed software).   We have done everything possible to eliminate Local Administrative rights on our managed devices.

3. Outbound transmissions. Security has historically focused on blocking evil actors from the internet.   Given the current challenges of malware and infections brought in from the outside, it’s equally critical to block unexpected outbound activity.

4. Public facing websites. Any machine that touches the internet has the potential to be targeted for attack.  We’ve implemented proxy servers/web application firewalls on most public websites.

5. Identity and Access management. Managing the ever changing roles and rights of individuals in a large complex organization with many partners/affiliates is challenging.  If an affiliate asks for access to an application, how do you automatically deactivate accounts when users leave an affiliate, given the lack of direct employment relationships?

6. Anti-virus. The best anti-virus applications only catch about 50% of malware.  Thus, a multi-layered defense is required.  However, adding all those layers impacts performance and can result in false positives.   Balancing security, reliability, and performance is challenging.

7. Security awareness. When that phishing email arrives asking users for their username/password, social security number, and a DNA sample, some people still fall for it.   Many users surf sites that are known virus distribution sites.   Even social networking is a vector for malware.

8. Keystroke loggers and screen scrapers. Mobile devices and home computers beyond IT control may contain keystroke loggers that capture user credentials, bypassing encryption, VPNs, and other layers of security.

9. Forensics. Increasingly sophisticated security infrastructure implies more events to research which requires additional staff that are challenging to find, recruit and retain.

10. Third party desktop software. It’s no longer the operating system that presents the greatest risk, but security holes in Java and Adobe products such as Flash.

Security is journey and you’ll never be done.  The hope is that your risk profile improves over time as more  of the environment is locked down, creating a restrictive rather than permissive infrastructure which makes services available by exception to the minimum extent necessary while balancing security and ease of use.   As I’ve said before, this is a Cold War at a time when Meaningful Use encourages more data sharing and breach reporting/regulatory penalties are increasingly severe.   All you can do is your best, given fixed resources and time.   And try to get some sleep.

John Halamka is Chief Information Officer of Beth Israel Deaconess Medical Center and blogs at Life as a Healthcare CIO.

Submit a guest post and be heard on social media’s leading physician voice.

Prev

Every emergency medicine shift teaches something

April 28, 2012 Kevin 5
…
Next

Where do our wasted health dollars go to?

April 29, 2012 Kevin 6
…

Tagged as: Health IT

< Previous Post
Every emergency medicine shift teaches something
Next Post >
Where do our wasted health dollars go to?

ADVERTISEMENT

More by John Halamka, MD

  • The future of EHR: Here are 5 predictions

    John Halamka, MD
  • 10 crucial guidelines for health care IT

    John Halamka, MD
  • 5 health care IT tips for President Trump

    John Halamka, MD

More in Tech

  • Navigating the cybersecurity challenges of artificial intelligence in medicine

    Francisco M. Torres, MD & Purab Patel
  • AI in clinical documentation: the hidden risk of automation bias

    Gagandeep Rai
  • Can AI scribes give clinicians time to teach again?

    Lynn McComas, DNP, ANP-C
  • Health care cyberattacks expose a critical national security failure

    Kristen Cline, BSN, RN
  • AI agents in health care: What they say when we aren’t listening

    Alp Köksal
  • The hidden risks and rewards of AI scribes in medicine

    Arthur Lazarus, MD, MBA
  • Most Popular

  • Past Week

    • Politics and fear have replaced science in U.S. pain management [PODCAST]

      The Podcast by KevinMD | Podcast
    • Evidence-based medicine vs. clinical judgment: a medical student’s perspective

      Jay Pendyala | Education
    • The controversy over Maintenance of Certification for grandfathered physicians

      Bernard Leo Remakus, MD | Physician
    • When side effects are actually a cry for help with medication costs

      Shuchita Gupta, MD | Physician
    • The hidden math behind physician hiring costs and recruitment

      Timothy Lesaca, MD | Physician
    • The Schism of Time: Bridging the generational gap in the workplace

      Seleipiri Akobo, MD, MPH, MBA | Physician
  • Past 6 Months

    • The dangers of vertical integration in health care

      Stephanie Waggel, MD | Policy
    • Why does sex work seem like a more viable path than medicine in 2026?

      Corina Fratila, MD | Physician
    • The 9 laws of health care quality: Why metrics miss the point

      Constantine Ioannou, MD | Physician
    • Politics and fear have replaced science in U.S. pain management [PODCAST]

      The Podcast by KevinMD | Podcast
    • From Singapore to Canada: a blueprint for primary care transformation

      Ivy Oandasan, MD | Policy
    • How board certification fuels the physician shortage crisis

      Brian Hudes, MD | Physician
  • Recent Posts

    • Institutional distrust in health care: Why a doctor lost faith

      Joshua Mirrer, MD | Physician
    • Communicating health to children: a pediatrician’s guide for parents

      Joey Skelton, MD | Conditions
    • Insulin resistance is a survival mechanism, not a broken system [PODCAST]

      The Podcast by KevinMD | Podcast
    • Debunking 4 myths about fertility treatments for women of color

      Ilana Ressler, MD | Physician
    • Whole-body MRI screening: a radiologist’s guide to preventive scans

      Amit Newatia, MD | Physician
    • How competency-based education is driving medical education reform

      Ben Reinking, MD | Physician

Subscribe to KevinMD and never miss a story!

Get free updates delivered free to your inbox.


Find jobs at
Careers by KevinMD.com

Search thousands of physician, PA, NP, and CRNA jobs now.

Learn more

Leave a Comment

Founded in 2004 by Kevin Pho, MD, KevinMD.com is the web’s leading platform where physicians, advanced practitioners, nurses, medical students, and patients share their insight and tell their stories.

Social

  • Like on Facebook
  • Follow on Twitter
  • Connect on Linkedin
  • Subscribe on Youtube
  • Instagram

ADVERTISEMENT

  • Most Popular

  • Past Week

    • Politics and fear have replaced science in U.S. pain management [PODCAST]

      The Podcast by KevinMD | Podcast
    • Evidence-based medicine vs. clinical judgment: a medical student’s perspective

      Jay Pendyala | Education
    • The controversy over Maintenance of Certification for grandfathered physicians

      Bernard Leo Remakus, MD | Physician
    • When side effects are actually a cry for help with medication costs

      Shuchita Gupta, MD | Physician
    • The hidden math behind physician hiring costs and recruitment

      Timothy Lesaca, MD | Physician
    • The Schism of Time: Bridging the generational gap in the workplace

      Seleipiri Akobo, MD, MPH, MBA | Physician
  • Past 6 Months

    • The dangers of vertical integration in health care

      Stephanie Waggel, MD | Policy
    • Why does sex work seem like a more viable path than medicine in 2026?

      Corina Fratila, MD | Physician
    • The 9 laws of health care quality: Why metrics miss the point

      Constantine Ioannou, MD | Physician
    • Politics and fear have replaced science in U.S. pain management [PODCAST]

      The Podcast by KevinMD | Podcast
    • From Singapore to Canada: a blueprint for primary care transformation

      Ivy Oandasan, MD | Policy
    • How board certification fuels the physician shortage crisis

      Brian Hudes, MD | Physician
  • Recent Posts

    • Institutional distrust in health care: Why a doctor lost faith

      Joshua Mirrer, MD | Physician
    • Communicating health to children: a pediatrician’s guide for parents

      Joey Skelton, MD | Conditions
    • Insulin resistance is a survival mechanism, not a broken system [PODCAST]

      The Podcast by KevinMD | Podcast
    • Debunking 4 myths about fertility treatments for women of color

      Ilana Ressler, MD | Physician
    • Whole-body MRI screening: a radiologist’s guide to preventive scans

      Amit Newatia, MD | Physician
    • How competency-based education is driving medical education reform

      Ben Reinking, MD | Physician

MedPage Today Professional

An Everyday Health Property Medpage Today

Copyright © 2026 KevinMD.com | Powered by Astra WordPress Theme

  • Terms of Use | Disclaimer
  • Privacy Policy
  • DMCA Policy
All Content © KevinMD, LLC
Site by Outthink Group

Leave a Comment

Comments are moderated before they are published. Please read the comment policy.

Loading Comments...