Thursday, March 20, 2025

 

                            Designed by Freepik



As the CIO for a nonprofit, community-based healthcare center, I interact with vendors a lot. Probably 25% or more of my week involves dealing with vendors on new project proposals, renewals, research, or getting support. With that experience, here are a couple of things that I would like you, all of the IT vendors out there who want a nonprofit’s business, to know about how to do business with a nonprofit and have more understanding of the people across the table from you.

1. Nonprofit organizations are way different from for-profit organizations. That should be obvious, but let me explain how this should play into how you interact with or understand a nonprofit organization:

a. Most nonprofit organizations, especially those of us relying on federal funding to serve vulnerable populations, have to fight for every dollar we get, therefore, it is imperative to make sure that we are good stewards of those dollars and get the most value for every dollar spent that we can.

b.  This means that we are going to ask more questions, move more slowly to make decisions, maybe consider more options, and certainly push on you for more information than maybe a for-profit customer might.

2. I am going to ask you for a nonprofit discount or special pricing every day, all day long. Your competitors offer this, and I will expect you to as well if you want to do business with me!

3. If you are a VAR representing multiple vendors, we are really going to lean on you to make sure that you are living up to the value-added component of our relationship. For the reasons stated above in item 1b, you might have to spend more time and effort to make a sale to us for a specific product or service. Please understand this before agreeing to enter into a relationship with us. We are going to bring you problems and look for you to help provide us with solutions.

a.  Just because we don’t buy today doesn't mean that we won’t in the future. You may present us with a great solution that we just can’t afford today, however, we will be continually working to find a way to swing that purchase in the future so your working on putting together solutions and proposals for us should be seen as an investment in future business even if you don’t immediately make a sale.

4. Due to lean staffing models, we are always in firefighting mode. Anything you can do to help us become more proactive is appreciated and will be reciprocated in the form of referrals to other colleagues. I personally speak to many of my colleagues in other nonprofit organizations and we frequently discuss our vendor experiences. I always highlight those vendors that I feel have gone above and beyond for us and make strong recommendations advocating for those vendors. Understand that the reverse is also true.

5. We generally want to establish a relationship and have trust in our vendors. We are going to be hesitant when we first start to do business with a new vendor, and it is incumbent on that vendor to build trust with us. While we are always price-sensitive, we also look to the value of the service offered. I don’t mind spending a little more money on a service if it helps me scale to the point where we can do more without adding more FTEs. I am always looking for that value beyond just the bottom-line cost. 
That being said, if you sell me on that value, you had better deliver or else any trust or goodwill will quickly evaporate and your opportunity to do business with us in the future will be greatly hampered.

In conclusion, the relationship between IT vendors and nonprofit organizations is built on understanding, trust, and mutual respect. Vendors who take the time to comprehend the unique challenges faced by nonprofits and offer tailored solutions, discounts, and unwavering support will find loyal and long-term partners. By recognizing the value in each interaction and seeing beyond immediate sales, IT vendors can foster strong, lasting relationships that benefit both parties and ultimately serve the greater good of the community.

Tuesday, March 11, 2025

No Project Management or Bad Project Management: Which is Worse?

Designed by Freepik 

Over the last few years, I have gone back in forth on my opinion of whether it is worse to have no formal project management in place or to have some project management in place that is somewhat ineffective. Previously, I had always leaned toward having some project management in place being better as at least there was something to start from and it could hopefully get better. I have recently changed my opinion on that though after witnessing firsthand what ineffective or bad project management can do to an organization. Here is how I arrived at this change of opinion:

 Initial Belief: Bad project management is a starting point that could be improved upon.

Actual Observations: Bad project management rarely gets better. Individuals who are part of the “bad” process typically don’t want to change and don’t want to recognize what they are doing wrong.  This is basically like trying to get rid of a bad habit in your personal life, which we all know how that is to do. When bad project management habits become entrenched in an organization, they are very difficult to get rid of. Furthermore, leadership “thinks” that they have project management in place because they have individuals with the title of project manager in the organization so making change in this area becomes less of a priority.

Initial Belief: Bad project management probably at least enlists some elements of a project management discipline.

Actual Observations: This is really a myth. While there might be some aspects that are masquerading as project management discipline, in reality, it is usually just bits and pieces that someone has picked through and selectively implemented or tried to implement, but there is typically no discipline behind them and usually are misused.

Initial Belief: No project management just means chaos.

      Actual Observations: Typically, while not completely organized, there is usually some sort of project management happening at the user level so that they can at least manage their activity even if the overall project is being managed effectively. In my experience, it is easier to take these efforts and organize them into a project management discipline instead of fixing bad project management practice.

How Does This Usually Happen

  • I think we all agree that project management is critical for any organization that regularly has any type of work that involves multiple resources and/or multiple departments with multiple tasks that take place over a period of time. Many organizations make a half-hearted or uneducated stab at implementing a project management discipline. The problem that usually arises from this is that processes aren’t well thought out or established or applied consistently. This can be due to the following reasons:
  • Project management roles aren’t established as full-time, professional jobs within the organization which means that it just becomes another hat that someone who already has a full-time job ends up wearing.
  • Even if project manager roles are established in the organization, they are given to someone without any formal project management training, often someone in a clerical role, who really is just responsible for coordinating project activities. This role often doesn’t have the authority to manage the human resources assigned to particular projects.
  • Project management is distributed across the organization instead of centralized in a single PMO-type function. This leads to varying degrees of implementation and consistency.
  • Not only is project management a professional discipline that, to do well, requires a lot of education and judgement, but it also requires someone who is highly organized and is a master planner. Often, project management roles aren’t recruited for, they are bestowed or dumped on someone, which usually leads to poor results.

How Does This Typically Manifest

The results of poor project management usually are chiefly evident in lack of or poor planning. Poor or missing project planning usually starts right at the beginning of the project with inadequate requirements gathering and scoping. These two elements alone can doom a project. Without adequate requirements, how do you even build or manage a project plan let alone accomplish anything. This usually leads to massive scope creep as requirements get uncovered throughout the project and then are either reworked into the project with an unending timeline or are left out together delivering a failed mess of a project. Occasionally, requirements get missed, even on the best planned projects, but knowing how to deal with them makes all of the difference in the world. Being able to assess the impact on the project of addressing the new requirements as a scope change vs. adding them to a second phase of the project where initial requirements are delivered and the new requirements are then slotted into another phase takes training and professional judgement to do successfully, not to mention good communication skills to work with your stakeholders to determine the solution that is best for the project and the organization. Bad project management and managers don’t do this assessment and don’t work with their stakeholders to work out a recovery plan to keep the project on track.

Then there are so-called requirements that come in as change requests that aren’t really requirements but nice to have features that someone dreamed up. Strong project management is needed to sort these through and determine what is necessary to successfully deliver the project vs. what is not and can be negotiated for potential later prioritization or release. If your project management is really only just tracking and coordinating project activities, you lose this vital project management skill.

Requirements gathering and project planning are the foundation of a sound project. Without these, a project is doomed to fail before it even really gets started.

Another way that poor project management manifests itself is in lack of leadership, The inability to assess risks to the project and communicate those risks in a meaningful way so as to facilitate the creation of a mitigation strategy is key. This takes leadership and experience.

Lack of communication is also a hallmark of poor project management. Project managers are the glue that hold the project together. The only way to do this is by being a good communicator and facilitator. That means staying engaged with the project team and stakeholders, watching for signs of trouble or risk, communicating often and early when issues arise and making sure that everyone involved understands their role and responsibilities to the project and is held accountable.

Conclusion

While I would wholeheartedly agree that no project management in an organization is a bad thing, I have come to realize that bad project management is even worse as it can create confusion and lead to misunderstandings, lead to ineffective requirements gathering and planning and usually leads to unending scope creep and/or project failure.

As this blog was mainly an opinion piece, I would be curious to hear your opinions or experiences around lack of or bad project management and which you think is worse.

 


Friday, February 28, 2025

Teaching Leadership How to Interview and Hire Candidates

 

Image by storyset on Freepik

In my conversations and coaching as a thought leader with other leaders and, even in my experience as a job candidate over the years, I have noticed that many of us as leaders don’t really know how to effectively screen and interview candidates. This is a key skill, as not hiring the right individuals to build out your teams, taking too long to fill a position or failing to conduct a proper interview and turning down good candidates because you failed to interview them correctly are hugely costly mistakes. As a result, I thought that I would go through some of what I see as areas that many of us as leaders can improve on to make sure that we are filling our roles as efficiently and effectively as possible.

·         Not really understanding what you are looking for or need

o   I was made aware of a Midwest healthcare organization that has been looking for a Chief Information Officer for at least two years!

§  This is not a pipeline problem as my source that relayed this story to me stated that they had plenty of highly qualified candidates who have gone on to be very successful in CIO positions elsewhere after they were turned down by this organization.

§  Without being on the inside and knowing exactly what is going on, this seems to be a situation where the organization doesn’t really even know what they need or the hiring team can’t agree on what characteristics are a priority and, therefore, can’t come to agreement on a candidate. This is where the CEO as the leader needs to step up and be a leader and make a decision in the absence of complete agreement of their hiring team. This situation reflects poorly on the organization as a whole as it makes them really look incompetent.

·       Hiring managers/executives making interviews too much about themselves and not enough about the candidate

o   Interviews, by definition, are to find out about and get to know the candidate to assess their fit in the position and organization. Yes, there is an aspect of the interview where the candidate gets background information on the organization and the position, the interview should resist talking too much about themselves unless the candidate asks specific questions.

§  I actually heard of one leader who made the statement during an interview that he had forgotten more information about his industry than most people had ever known.

·       This can come off as arrogant and sets a very awkward tone and may cause you to lose a valuable candidate because they are put off by this.

·        Remember, the candidate is interviewing you as well

o   Be sure that you are listening to the candidate and what they are actually saying. If they are being too verbose or you would prefer the question to be answered in a certain way, be sure to let the candidate know that. Remember, the candidate has never met you before and doesn’t know exactly how you expect them to interact with them. This becomes even more complicated for the candidate if this is a phone or virtual interview as body language that would normally serve as cues is nonexistent.

§  Everyone is different, this includes interviewers, so set your expectations during the interview for how you expect the interview to go. Some leaders are more casual and want the interview to be more conversational. That is okay, just let the candidate know that upfront.              

§  Be open-minded. You never know when you are going to be pleasantly surprised!

·      Stay away from questions asking how the candidate would implement something or to assess issues with your organization.

o   The candidate only has the information about your organization that is publicly available. They don’t know what the needs or pain points of your organization are. Furthermore, it is unfair to expect them to solve those in the course of an interview even if you tell them what they are!

o   Instead, ask how they would come into your organization and assess needs. What is the process they would use to learn about deficiencies or opportunities, how they would go about prioritizing them, how would they confirm these with stakeholders, etc. The process and thinking behind that will tell you much more about the candidate than you could ever get from them solving a problem for you.

·        Be okay with “I don’t know” as an answer

o   Rarely is any candidate going to check all of the boxes. A candidate who is willing to be upfront and tell you that they know don’t something should be a positive sign rather than one who will try to bluff their way through the answer.

·       Make sure that your job description is updated for the current needs of the business and not just what the incumbent did. It is very likely that your business has changed since you hired the previous person in that role. This is the opportunity to incorporate those changes into the job description. Avoid falling into the trap of just trying to find the same person that you previously had.


Tuesday, February 4, 2025

Leveraging Business Intelligence for a Data-Driven Healthcare Future

 

Image by pch.vector on Freepik

Coming up through the ranks in information technology (IT) as a database administrator and with a previous background in auditing and financial analysis, I found a special passion for business intelligence (BI). BI has an important ability to provide a competitive advantage by taking raw data (potentially from multiple, disparate sources) and putting context around it by organizing and aggregating data around descriptive attributes that can be used to filter and provide granular context around the data. This provides a competitive advantage in that the data is fresh (not necessarily real-time) and not at least 30 days old like financial statements and provides a decision maker with data that allows them to zoom in and make business-critical decisions quickly without having to search through myriad reports that may or may not give them the detail or context they need to make a decision. This can provide a business with the opportunity to identify trends and pivot before their competitors.

Specifically looking at today’s rapidly evolving healthcare landscape, organizations must harness the power of data to remain competitive, improve patient outcomes, and streamline operations. BI has emerged as a critical tool in transforming raw data into actionable insights that drive strategic decision-making. For healthcare organization, the ability to extract meaningful intelligence from vast amounts of data can lead to improved efficiency, enhanced patient experiences, and a more resilient business model.

The Growing Importance of BI in Healthcare

The healthcare industry generates an immense amount of data daily—from patient records and claims processing to provider performance metrics and financial transactions. Without a robust BI strategy, this wealth of information remains underutilized, limiting an organization's ability to optimize processes and enhance service delivery.

BI tools consolidate disparate data sources, enabling leaders to gain a holistic view of operations. By leveraging data visualization, predictive analytics, and AI-driven insights, healthcare organizations can make data-informed decisions that lead to greater efficiency and improved care quality.

Key Benefits of BI for Healthcare Organizations

  1. Enhanced Decision-Making
    BI enables healthcare leaders to analyze trends, forecast demand, and allocate resources more effectively. By identifying patterns in claims processing, patient behavior, and operational workflows, organizations can refine their strategies to improve outcomes. Additionally, this data can be used to look at the feasibility of offering additional (new) services or product lines.
  2. Improving Patient Experience
    By analyzing patient interactions, feedback, and service utilization, BI tools help organizations personalize patient engagement. Tailored communication and proactive care recommendations improve patient satisfaction and loyalty.
  3. Fraud Detection and Risk Mitigation
    Advanced analytics can help detect anomalies in claims and billing processes, identifying fraudulent activities before they escalate. This proactive approach reduces financial risks and ensures regulatory compliance.
  4. Optimizing Operational Efficiency
    BI streamlines workflows by providing real-time insights into system performance, staffing needs, and service bottlenecks. Automated reporting eliminates manual processes, allowing staff to focus on more strategic initiatives.
  5. Driving AI and Predictive Analytics
    The integration of AI with BI platforms enhances predictive modeling capabilities. This allows organizations to anticipate patient needs, optimize provider networks, and improve population health management.

Implementing a BI Strategy: Best Practices

  1. Define Key Performance Indicators (KPIs)
    Establish clear metrics aligned with organizational goals, such as claims processing speed, provider network performance, and patient satisfaction scores.
  2. Leverage AI-Driven Insights
    Integrate AI to enhance data analysis, enabling automated trend detection and decision support for leadership teams.
  3. Ensure Data Accuracy and Security
    Implement robust data governance frameworks to maintain data integrity and comply with industry regulations such as HIPAA.
  4. Foster a Data-Driven Culture
    Encourage cross-functional teams to use BI tools for decision-making, ensuring that data insights are leveraged across the organization.

Conclusion

As the healthcare industry continues to evolve, organizations must embrace Business Intelligence to stay ahead. By leveraging BI tools effectively, healthcare organizations can drive innovation, improve patient experiences, and ensure operational excellence. Investing in BI is not just about collecting data, it’s about transforming data into strategic advantage for a healthier, more efficient future.

 


Friday, January 31, 2025

The Ever-Evolving Role of the CIO in Healthcare

 


It seems that few roles have evolved over the years as much as the role of the Chief Information Officer (CIO) in healthcare. Gone are the days when the CIO was just the person who was responsible for the computer systems and nothing else. . I remember back in the early 2000s when I worked at University Medical Center in Tucson, AZ that the IT team, including the CIO, were stashed in a 40+ year old portable building behind the hospital next to what we called the clinical equipment graveyard where old hospital beds and miscellaneous furniture went to die. In those days, IT was out of sight and out of mind. Flash forward to today and the healthcare CIO is now a trusted advisor, business consultant and valued member of the organization’s executive team. A lot has changed in the last 20+ years!

So, what is the role of the modern healthcare CIO? Let’s break this down a little bit:

Business Process Expert

A healthcare CIO should have a good understanding of how to develop, document and analyze business processes. You can’t add technology to a business process that doesn’t exist, isn’t standardized or even well understood. Well, actually you can, I guess, but what you get is a bigger, more complicated mess.

The CIO needs to be able to facilitate sessions to understand and map current business processes and help the functional area determine what is working and what isn’t and then formulate problem statements for the areas that aren’t working so that requirements for a solution can then start to be collected. The thing to keep in mind here is that the solution may not always be one that involves technology even though the CIO or their delegate is leading the process to identify and help implement a solution. Many times, without going through this process, you don’t know what the right solution is. Organizations that don’t take this approach can throw money and technology at a problem hoping to solve it, but if you haven’t accurately defined the problem and what it would take to functionally solve it, you are really just shooting in the dark.

This function of the CIO relies on the CIO’s business skills and acumen which in today’s healthcare environment are just as important for the CIO to have as knowledge of technology and technical trends.

Security Expert

Healthcare is one of the most highly regulated industries and also one of the most targeted industries by threat actors. Because of this, today’s healthcare CIO needs to be well-versed in threat landscape and how to mitigate potential threats to protect the privacy and safety of patient data and the organization’s systems. The threat landscape is ever evolving and shifting, requiring the CIO to always be researching and understanding these changes in a way that can be easily communicated back to the rest of the executive team and the board. The CIO needs to be able to accurately assess and communicate the risks to the organization and provide a strategy that is tailored to the organization and makes sense. This is a very time-consuming aspect of the CIO’s job and one that shouldn’t be taken lightly by the organization’s leadership.

Change Agent

There are probably few areas that introduce as much change through the organization as the IT department. While these changes are rarely true IT initiatives, most are led by IT on behalf of a functional area, IT is the one who generally leads and manages these changes. As a result, it typically falls on the CIO to come up with a change management strategy to help the organization’s workforce adapt to these changes with as little disruption and displeasure as possible. This role calls on the CIO to be an excellent planner, leader and psychologist. That last attribute is not one that you will find in any CIO job description, but an understanding of the psychology of change and how change is viewed and ultimately accepted is critical to ensure the success of any large project. This requires the CIO to have a strong understanding of the organization’s culture and be highly visible during the change process, actively listening and evolving the change strategy to help the workforce successfully adapt to the change.

Governance

A successful CIO needs to be able to organize and lead the governance process as it relates to technology. This process can take several forms and while not all organizations have all forms of governance, it should be the direction that the CIO is pushing for. The types of governance, as I would recommend them, are outlined below:

IT Governance

It is important that there is some sort of governance structure that loops together leaders of the organization and the board to vet long-term IT strategy and prioritize IT initiatives. Part of the chart of this governance structure should be to always make sure that the work and projects that IT takes on always align with the broader goals and objectives of the organization. This is usually chaired (or facilitated) by the CIO and includes leaders from the key areas of the organization to help provide visibility and context into the needs of the organization.

Project Governance

This could be done through a Project Management Office (PMO) and/or a Project Steering Committee. The purpose of this governance structure is to oversee the intake process for prospective projects, lead the analysis and vetting of those projects and formulate recommendations on projects that should be undertaken. Once projects are approved, the reporting and management of those projects and the organization’s overall project portfolio should go through this governance structure. This usually falls under the supervision of the CIO.

Data Governance

While most electronic data is managed by the IT department, it is important to remember that the IT department doesn’t really own this data or even completely understands how data is used in its entirety across the organization. This is where data governance comes into play. Data governance entails identifying all the various types of data as it is used throughout the organization as well as identifying data stewards for each type of data. Data stewards are individuals who are subject matter experts with regard to the data under their stewardship and can be looked to for decisions regarding who needs access to the data, retention requirements for the data and would be part of any integration discussions where the data may be transferred or exchanged. This function is important as it takes decisions around data out of the hands of the IT department and assigns ownership of it to those who actually use and understand it, with the advice and consultation of the CIO and the IT department.

EHR or Health IT Systems Governance

This governance model usually involves the leadership of the Chief Medical Information Officer (CMIO) along with the CIO to take changes and optimizations requested by the users of the various health IT systems and evaluates them for need, scope, difficulty or feasibility, and impact. This usually involves a committee structure made up of representatives of the systems’ stakeholders who, under the leadership of the CMIO with the support of the CIO, meet and discuss system change requests and then either approve or deny them and subsequently prioritize them for scheduling. This committee also receives reports back on the status and progress of requested changes.

Finance Manager

The assets, capital and operating budgets under the management of the CIO are typically some of the largest in the organization. This requires the CIO to be a keen financial manager who can project and budget for the organization’s needs and then effectively manage within that budget. To do this, the CIO must be a strong negotiator, both with internal stakeholders and vendors, and must be adept at vendor management to ensure that the organization always receives the highest value for the dollars spent. In some organizations, this also means vetting vendors to make sure that their values align with the organization's.

This role may require the creation or input into the creation of RFPs and evaluating responses as well as the subsequent negotiation of a contract for services.

Communicator

Last, but not least, is the role of communicator. The CIO needs to be constantly communicating to a large number of constituents. They are expected to communicate recommendations, risk assessments and progress reports to the executive team and the board; they communicate upcoming changes, either in person, by email or virtually, to the workforce and are available to take questions and concerns; they should be constantly communicating with the entire organization about potential security risks, educating them on how to avoid them and protect themselves and the organization; they communicate with external partners, establishing and maintaining relationships that benefit their organization; they may be responsible for communication with auditor or regulatory bodies regarding compliance with regulations and internal controls. Additionally, a good CIO is always in touch with the staff, understanding what they see and hear, their concerns and needs and is available to advocate for them to enable them to do their jobs to the best of their ability.

Conclusion

As you can see, today’s healthcare CIO has evolved way beyond the traditional technology role and is a key player in the operations and decisions across the entire organization. The role of the CIO today is a respected member and advisor to the executive team and C-suite and is required to wear many hats and have expertise far beyond that of the technology stack.


Wednesday, December 11, 2024

Bridging the Gap: Strengthening Cybersecurity for Nonprofit and Rural Healthcare Providers

 

In my previous article (that article can be read here, I introduced the issue facing many nonprofit and/or rural healthcare organizations as it pertains to keeping up with cybersecurity needs both from a regulatory perspective and from an active threat perspective. The biggest challenge facing these organizations is funding. Healthcare is very expensive to deliver especially when you depend largely on grants and donations. Unfortunately, cybersecurity is also very expensive and most nonprofit healthcare organizations just don’t have the funding to keep up with increased threats and increased security regulation.

At the end of that article, I committed to following up with a set of recommendations that I feel could assist with this challenge faced by these healthcare organizations. So, as promised, here is my laundry list of recommendations.

Addressing the challenges of cybersecurity for nonprofit and rural healthcare organizations requires a combination of targeted funding, policy changes, public-private partnerships, and tailored resources. Below are specific recommendations to tackle these issues effectively:

 

1. Increase Federal and State Funding for Cybersecurity

  • Establish Dedicated Grants: Create cybersecurity-specific grants for nonprofit and rural healthcare providers, similar to the Health Center Program administered by HRSA, to fund technology upgrades, training, and security measures.
  • Provide Matching Funds: Encourage states to provide matching funds for federal grants to incentivize investment in cybersecurity infrastructure.
  • Subsidize Cyber Insurance: Offer subsidies or tax incentives to help small healthcare organizations afford cyber insurance, which can mitigate financial risks from breaches.

2. Develop Tiered Compliance Requirements

  • Adjust Regulations for Smaller Organizations: Mandate cybersecurity standards that are scaled based on the size, resources, and risk profile of healthcare organizations. This prevents overwhelming smaller entities with costly compliance requirements.
  • Offer Grace Periods: Provide extended timelines and guidance for rural and nonprofit healthcare providers to meet new cybersecurity mandates.

3. Leverage Public-Private Partnerships

  • Expand Industry Support Programs: Encourage technology companies to broaden their cybersecurity initiatives to include all vulnerable healthcare providers, not just rural hospitals.
  • Create Shared Cybersecurity Centers: Partner with private sector firms to establish regional cybersecurity resource hubs where small providers can access tools, training, and support.
  • Collaborate on Affordable Solutions: Work with cybersecurity vendors to develop affordable solutions tailored to the needs of nonprofit and rural healthcare organizations.

4. Build Cybersecurity Workforce Capacity

  • Launch Training Programs: Fund cybersecurity training specifically for healthcare IT professionals, focusing on nonprofit and rural settings.
  • Promote Loan Forgiveness for Cybersecurity Professionals: Introduce loan forgiveness programs for cybersecurity experts who work in underserved healthcare organizations for a specified period.
  • Leverage Virtual Support Networks: Create remote cybersecurity support networks, allowing experts to assist multiple small healthcare organizations simultaneously.

5. Enhance Technology Access

  • Subsidize Cloud-Based Security Solutions: Provide financial incentives for nonprofit and rural healthcare providers to adopt cloud-based solutions with built-in security features.
  • Encourage Open-Source Tools: Invest in the development of open-source cybersecurity tools that can be used by resource-constrained healthcare providers.
  • Enable Group Purchasing Power: Form cooperative purchasing programs to allow smaller healthcare providers to collectively negotiate for lower prices on cybersecurity tools and services.

6. Foster Information Sharing

  • Create Regional Cybersecurity Alliances: Establish local or regional alliances where healthcare providers can share threat intelligence and best practices.
  • Improve Government Alerts: Ensure that federal agencies provide timely and actionable cybersecurity alerts specifically tailored to the healthcare sector.
  • Facilitate Incident Response Teams: Develop rapid-response teams that nonprofit and rural providers can call on during a cybersecurity breach.

7. Advocate for Policy Adjustments

  • Integrate Cybersecurity into Rural Health Initiatives: Advocate for existing rural health programs to include cybersecurity as a core component.
  • Require Vendor Accountability: Implement policies that hold software and hardware vendors accountable for providing secure, easily updatable solutions to healthcare organizations.
  • Support Anti-Trust Exemptions for Collaboration: Allow small healthcare providers to collaborate without fear of antitrust violations when sharing resources or negotiating with vendors.

8. Focus on Education and Awareness

  • Launch Awareness Campaigns: Educate healthcare leaders on the critical importance of cybersecurity and how to integrate it into operational priorities.
  • Develop Simple Training Modules: Create low-cost or free cybersecurity training modules tailored for healthcare staff with limited technical expertise.

9. Provide Emergency Relief for Breach Recovery

  • Establish a Cybersecurity Emergency Fund: Offer financial support for nonprofit and rural healthcare providers affected by significant cyberattacks, helping them recover operations without sacrificing patient care.
  • Simplify Federal Aid Access: Streamline the process for healthcare organizations to access emergency funds post-breach.

10. Pilot Programs and Case Studies

  • Launch Pilot Projects: Fund pilot programs in rural areas to test innovative cybersecurity approaches, documenting their effectiveness and scalability.
  • Document Success Stories: Share case studies of organizations that have successfully implemented affordable cybersecurity measures to inspire and guide others.

Conclusion

Addressing these cybersecurity challenges requires a multi-faceted approach that prioritizes equity and sustainability. By leveraging funding, partnerships, and tailored resources, policymakers and industry leaders can help nonprofit and rural healthcare organizations enhance their cybersecurity defenses without compromising patient care. These solutions must be actionable, scalable, and sensitive to the unique constraints these organizations face. 

Obviously, there is no panacea that will immediately solve the cybersecurity issues facing our nonprofit and rural healthcare organizations, however, putting together a thoughtful, coordinated action plan such as the one above involving both public and private resources will greatly help our underfunded nonprofit and rural healthcare organizations who are providing care on a daily basis for the most underserved populations in our society. These are a public health resource that we just cannot afford to lose.

Friday, December 6, 2024

Cybersecurity Requirements May Break the Back of Nonprofit Health Care in the United States

 

Cybersecurity is a huge concern for health care entities as one of the most targeted industries by cyber criminals according to an article by the EC-Council University (https://www.eccu.edu/blog/cybersecurity/top-industries-most-vulnerable-to-cyber-attacks). The health care industry is so targeted in fact, that Congress is now considering a bill, with the backing of HHS, to mandate that health care organizations strengthen their cybersecurity defenses (https://www.finance.senate.gov/imo/media/doc/health_infrastructure_security_and_accountability_act_leg_text.pdf). This is all well and good for those for-profit entities such as United Healthcare, Humana, or CHI who have fairly deep pockets. The big question is where does this leave nonprofit entities struggling to provide safety net services on sliding fee schedules depending on decreasing reimbursements and grant funding to survive?

Microsoft and Google, working with the White House, have come up with a so-called plan to help, consisting of free and discounted cybersecurity resources to assist in enhancing health care cybersecurity. I call this a so-called solution because it only addresses one discrete area of need, rural hospitals. What this completely misses are the over 1,400 Federally Qualified Health Care (FQHC) centers operating at more 15,000 sites serving more than 26.6 million patients per year or the over 5,200 rural health clinics (RHC) serving more than 37.7 million patients per year, both providing integrated outpatient care to those who otherwise would not have access to health care or couldn’t afford it. These organizations survive on shoestring budgets where the goal is to dedicate every penny possible to patient service. With cybersecurity threats increasing in complexity and number almost daily, it is nearly impossible for these organizations to keep up. Yet instead of providing help where it is actually needed, our technology industry and government make superficial efforts to look like they are helping with the problem while Congress seeks to pass more stringent regulations without any assistance in meeting those regulations.

If you have been watching the news lately, you have seen a number of rural and nonprofit health care organizations closing facilities at a breakneck pace because the margins are so low that they cannot survive. When we layer in the hundreds of thousands of dollars or more that each health care organization is going to have spend to keep up with cybersecurity threats, that means we can expect to see even more health care facilities closing in the areas where they are needed most. We aren’t talking about metro areas like Los Angeles or Chicago, we are talking rural, less densely populated areas such as rural areas of Nevada, Utah, Colorado, Arizona, California, and much of the southern United States. On average, these residents tend to be older and potentially require more medical attention than the average person. In an article published in the Journal of the Missouri State Medical Association (https://pmc.ncbi.nlm.nih.gov/articles/PMC6140198/), it was stated that while 20% of Americans live in rural areas, only one-tenth of physicians practice there.

My call to action is this: While we all agree that increased cybersecurity in health care is necessary and we are all tired of reading about the breaches, we need to come up with some real solutions to assist this industry, especially the safety net and rural providers who are hit hardest by the extra costs that these initiatives bring. We need to stop complaining and put together real action plans because our health care industry is already straining and struggling and the added burden of increased costs around cybersecurity is enough to break it where it is needed most. 

In my next post, I will attempt to provide some suggestions as to how we might be able to attempt to solve this problem.


The Growing Role of Artificial Intelligence in Ambulatory Health Care

  Introduction Yesterday, I wrote about the use of Robotic Process Automation (RPA) in health care . Today, I want to discuss the growing ...