RadiantLogic-Cisco-Dashboard-Reporting-Hero

What It Actually Takes: Identity Management & Defense from a Healthcare Practitioner


Speakers:

Paul Dant, Sr. Solutions Consultant, Radiant Logic
Kristin Hoppe, Director, Identity Access Management, Baylor Scott & White

Knowing how attackers operate is half the battle. Kristin Hoppe joins Paul Dant for a practitioner’s view of identity management and defense inside a major health system: the real constraints, the tradeoffs, and the decisions that hold up under clinical pressure.

Read the transcript

Brooke Vixamar:
Welcome, everyone. My name is Brooke Vixamar. I’m the senior director of product marketing here at Radiant Logic, and I am so excited that we have part two of this two-part health care webinar series.

In part one, we shared some sobering realities facing health care organizations. We talked about health care being a prime target, as I’m sure everyone on this call already knows. Ninety three percent of health care organizations have had at least one breach in the last year, And the average ransom payment we’ve seen in health care is 1,150,000, which is the highest of any industry. So it’s certainly a big pressing concern, and so that’s why we wanted to bring this topic to the audience today.

In part one, Paul Dant shared some real life examples of his background in red teaming to share how the attackers are not just breaking down walls. They’re actually using identity to walk in the front door.

Really sobering reality, lots of interesting stories. If you missed part one, by all means, go back and listen to Paul’s stories. Today, I’m particularly excited. We’re pivoting, and we brought on Kristin Hoppe. She’s going to be sharing some real life practitioners perspective from her experience as the head of identity at Baylor Scott and White. Baylor Scott and White is the largest not for profit healthcare system in Texas and one of the largest in The United States.

Today, Baylor Scott and White includes 48 hospitals, more than 1,000 patient care sites, more than 9,600 active physicians, and over 48,000 employees in the Scott and White health plan. So certainly a large number of identities that she’s managing. And so we’re really excited to have her share her insights and expertise to all of us today. Paul, Kristin, thank you both so much for being here.

Paul Dant:
My pleasure. Thanks for having me.

Kristin Hoppe:
No, absolutely. Thank you for having me.

Brooke Vixamar:
I’m going to turn off our screen because this is really going to be a conversation today. We’re really excited to really just dig in and have an open conversation. As we kick things off, Paul, I thought maybe we could start with you and you could kind of revisit a little bit from part one on how was it that you got in? And then we’ll we’ll pivot back to Kristin and say, hey. This is your building. How would you think about closing it? So let’s start with you on just kind of giving us a little bit of a flavor of what we talked about in part one.

Paul Dant:
Sure, sure. Thanks, Brooke. So one of the key things that we talked about when it comes to identity is that good intentions often lead to bad outcomes. And what we really mean by that is traditionally as we’ve built identity programs, we’ve managed identity, it’s been built more for success and operational efficiency, not so much around security and understanding risks. We’re bringing that sort of mentality to identity in much more recent times.

And I think really what we talked about from a what’s missing perspective is the overall idea that identity data is strewn all throughout the enterprise. And when we talk about healthcare specifically, we have so many different types of attributes related to identity that grant us access to so many different systems and applications. It’s incredibly challenging to bring all of that together into a unified view. And that’s really where one of the things that we left off in our last webinar was part one was about how does the attacker ultimately get in?

Why is healthcare seemingly so vulnerable to these attacks as the media reports would tell us and what can we do about it? So, as you mentioned, I’ve spent quite a bit of time as a, we’ll say an offensive security researcher, forty years in fact, and hospitals and other healthcare facilities have been part of some of the targets that I’ve led coordinated attacks around from a research perspective. So one of the things that I’ll kind of just throw out there that I think is very unique and specific to healthcare is in particular within facilities, wow, excuse me, the susceptibility of someone gaining initial access onto a network and then finding their way through lateral movement to all of the really important things.

And of course, plays a critical role in controlling what an attacker can do once an identity is compromised.

And I think that’s really where we break into part two here is understanding from a practitioner and defender perspective, what does that look like? So I’ll hand it back over to you, Brooke.

Brooke Vixamar:
Absolutely, great. Thank you for setting the stage on that.

Kristin, we’ll put you in the hot seat for a minute. I want to start with a little bit of the elephant in the room. I feel like health care is such a highly regulated industry.

I thought, as someone leading identity for such a highly regulated industry, where do you start? How do you decide your priorities and programs and what you put in place? How do you kind of approach it from that highly regulated industry standpoint?

Kristin Hoppe:
Yeah, absolutely. So starting from a regulated identity perspective, when you’re in an industry that requires that, you really have to understand the regulations themselves. So you actually should be reading them, understanding them, forming relationships with your privacy and your compliance and your legal entities within your organization.

Baylor Scott and White’s unique. We have a couple of different umbrellas that are on the same infrastructure. We have a health plan. We have We have a digital health office. We have a developer area.

We have joint ventures. So we have a number of different arms within our organization, and each of those has competing priorities. And each have competing regulations.

Some must be SOC compliant, others do not at that point. So you really have to regulate, or sorry, you have to build your program to defend the regulations that you’re responsible for, and not at the sake of end user function and ease of use either. I mean, as Paul already talked about in his intro, that’s a key component. So you need to make sure that your experience is as frictionless for your end user across any different persona, across any different regulation or branch that they’re working in within your organization, but your security is always in the background, and it’s always layered.

Brooke Vixamar:
That, across all of these personas, across all of these different departments, I think that kind of opens up the conversation around I think you’ve called them the unicorns in the past, the multi persona challenge that is really big in health care. You have someone who is legitimately three or four or five different people, they’re a clinician, a surgeon, a professor, a researcher. How do you manage that complexity?

Kristin Hoppe:
That is, it’s a complexity that never goes away. So even if you’ve developed a program, and we we have actually developed a very successful program at Baylor Scott and White, it still never goes away. You’re always gonna have these people. You’re always gonna have a person that is a student, but also as an employee, but also as a volunteer.

And then they’re going to change one of those personas, keep the other two throughout the duration of their time. They’re going to shift from employee to a contractor or contractor, better way to say that, to a contractor and then back again.

One of the best ways to do that is truly having a unified identity, but also having a global unique identifier. If you’ve assigned an identity so that Brooke Vixamer is who she is across all platforms, across any persona that she enters, then you’ve succeeded because you’re eliminating duplicate accounts. You’re eliminating the need for merging. You understand the access layers that that persona has depending on the role that they’re in.

That’s a big lift. It’s taken over two years for me to get that program up and running, and it is now finally running and working really well.

Brooke Vixamar:
I assume that also would be helpful for things like the contractors, the traveling nurses, the Yes. All of those pieces. Yes. Just having something that’s unique to them regardless of how they’re coming in and out of the system.

Kristin Hoppe:
100%.

Brooke Vixamar:
One of the particular challenges we see facing health care also is there’s a lot of legacy technology, and there’s a lot of operational technology that you can’t just ignore it. It’s important, but it’s very hard to manage.

So these are devices that are a little outdated and you can’t really patch them.

So if you can’t fix the device, what do you do instead?

Kristin Hoppe:
Yeah, absolutely. I think that’s to me.

From a practitioner side, sometimes that’s not an identity issue so much as you’re going to work with your partners across infrastructure and you’re going to

Brooke Vixamar:
work with your partners across security itself.

And you’re going to isolate it.

You’re going to put it

Kristin Hoppe:
on its own network segment.

You’re going to put boundaries and foxes around that with different technological layers than just identity. Now, one of the key things with identity is just, I mean, even establishing your standard and creating buy in and having everybody speak the language that is new applications are coming in, or they’re looking at replacement, or you’re talking to the operational stakeholders about what it means to be on a modern technology, just having them understand base words like SSO and SAML or OIDC, having them be able to be your advocate as they’re going into these rooms that you’re not in is key, and that’s something that we do really well in my program as we teach all of our practitioners, all of our partners across our IT departments that as they’re onboarding new or they’re replacing old or they have old, that we have to defend that. And that’s and that’s the way we’ve done that by giving them a common language.