La période de renouvellement de l’accès au contenu d’HL7 Canada pour 2025-2026 est commencée. Veuillez renouveler votre accès d’ici le 1 avril 2025. En savoir plus >

Partager :

Le contenu créé par les communautés et les groupes de travail est accessible dans la version originale seulement.

Cybersecurity


Security experts working in healthcare or health solution providers sharing knowledge, information, and resources to promote security in healthcare, and safeguard Canadians’ personal health information.

À propos de nous

Scope

Canada Health Infoway is working closely with the provinces and territories (P/Ts) in support of the accelerated deployment or scaling of virtual care solutions. COVID-19 has created the impetus for moving quickly to virtual care solutions. Now, more than ever, Canadians want virtual and digital health solutions that enhance access to care.

Among the key common requirements are the need for well defined Security policies and tools that can be readily adopted to ensure that the virtual care investments made across the country maintain the safety and security of Canadians’ health information.

What are the common challenges facing Cybersecurity leaders?

  • Healthcare organizations are "feeling” that cyber threats are increasing, and security is getting more complex. Healthcare providers are trying to keep up vs. focusing on delivery of patient care
  • As more applications are moving to cloud, healthcare organizations are assessing a multitude of cloud services and their security and privacy processes
  • There is a shortage of skilled cybersecurity experts to meet the workforce's needs, so leaders depend more on collaboration with others in their industry
  • COVID-19 had led to organizations dealing with security risks associated with a remote work force, and supporting patients without bringing them into the clinical setting
  • Service providers are challenged by differing security requirements across jurisdictions, even when implementing solutions with Pan-Canadian reach

Participation

This community welcomes participation by Security leaders from:

  • Healthcare delivery organizations
  • Members of Federal, Provincial and Territorial Governments (P/Ts), Jurisdictions,
  • Private sector digital health service and product vendors who wish to work with jurisdictions and health delivery organizations

Value Proposition

Canada Health Infoway can help enable health delivery organizations to share in economies of scale and private sector businesses to efficiently and effectively interact with health organizations across Canada.

  • Standard Security Requirements and evaluation criteria for use in procurement processes, including security architecture and testing requirements. (Targeting Summer 2021)
  • Templates for Security Policies and Standards - customizable for specific uses and shared with Participants as an open Cybersecurity resource. (Targeting Fall 2021)

Key Resources

The following is a directory of resources that are free or not-for-profit serving Cybersecurity in the Healthcare sector

Leader

Ann-Marie Westgate, Director of Security, Canada Health Infoway

Activité

Anne-Marie Taylor s'est joint(e) à un groupe

Cybersecurity Logo
Security experts working in healthcare or health solution providers sharing knowledge, information, and resources to promote security in healthcare, and safeguard Canadians’ personal health information.

Katherine McMillan a répondu au cours d'une discussion dans le groupe Cybersecurity

Hi Kodian, One of my favourite articles on Medium.com is about red-teaming LLMs: https://medium.com/ai-in-plain-english/llm-jailbreak-comparing-drattack-artprompt-and-morse-code-17acb0f18be8 I would be considered on the anti-LLM/AI takeover side, although I am a big fan of algorithms. -Katie

David Cumming a répondu au cours d'une discussion dans le groupe Cybersecurity

I used AI to help generate this response to please don't quote the text - only use it as a guide to identify points of research.

David Cumming a répondu au cours d'une discussion dans le groupe Cybersecurity

Good question, and thanks for sparking the discussion! Here are a few recommendations tailored to a Canadian context, building on points already mentioned: Risk Assessment & Vendor Transparency As Matt noted, verify if vendors provide security details (independent audits, regular penetration tests, timely patch updates). For legacy systems, especially if support has ended, assess whether the risk is acceptable or if extra security controls are needed. System Modernization & Interoperability Evaluate if the outdated software integrates well with modern electronic health records (EHRs) and other systems. If not, consider upgrading to newer platforms that are fully supported, ensuring compliance with Canadian standards such as PIPEDA and any relevant provincial regulations (PHIPA in Ontario, etc.). Enhanced Cybersecurity Controls for Legacy Systems If replacing the outdated system isn’t immediately feasible, apply additional safeguards: Limit network access to the system through segmentation. Restrict unnecessary internet connectivity. Use application whitelisting and other compensating controls to reduce risk. User Training & Awareness Ensure that dietitians and other staff are aware of the specific risks that come with using outdated software. Regular training on recognizing phishing attempts and other cyber threats is critical, particularly when using unsupported systems. Regulatory & Compliance Considerations Compliance with Canadian privacy laws, like PIPEDA, is key. Ensure that data managed by these systems is secured according to current standards and that your organization has a clear plan for managing legacy systems under Canadian cybersecurity guidelines.

David Cumming a répondu au cours d'une discussion dans le groupe Cybersecurity

Cybersecurity Recommendations for Dental Clinics in Canada Cybersecurity is a critical concern for dental clinics, especially with threats like data breaches, ransomware, and insider attacks. Below are practical recommendations, tailored for Canadian clinics. 1. Aligning with Canadian Privacy and Security Regulations Understand PIPEDA Compliance: Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) applies to most private dental clinics handling patient health data. Provincial Health Privacy Laws: Some provinces have their own health data regulations, such as PHIPA (Ontario), HIA (Alberta), and PIPA (British Columbia). Regulatory Guidance: Consult the Canadian Dental Association (CDA) and provincial regulatory bodies for security and privacy guidelines. 2. Preventing Data Breaches Encrypt Patient Data: Protect data at rest (stored) and in transit (transferred online) using encryption. Backup and Disaster Recovery: Follow the 3-2-1 backup rule—keep three copies of data, on two types of storage, with one copy offsite. Role-Based Access Control (RBAC): Restrict data access based on job roles. Maintain audit logs of who accessed records. Patch and Update Software: Keep operating systems, dental practice software, and security tools updated to prevent vulnerabilities. 3. Ransomware Protection Use Endpoint Protection: Install reputable antivirus and anti-ransomware solutions with real-time protection. Separate Network Access: Keep patient records on a private network and guest Wi-Fi on a separate network. Least Privilege Access: Give each staff member only the access they need to perform their job. Incident Response Plan: Have a clear plan on how to respond to ransomware, including IT support contacts and steps to restore backups. 4. Preventing Insider Threats Onboarding and Offboarding Protocols: Revoke access to systems immediately when an employee leaves. Security Awareness Training: Train staff regularly on phishing, data security, and safe browsing practices. Monitor Access Logs: Track privileged account activity and regularly review login attempts. Whistleblower Policy: Encourage staff to report security concerns confidentially. 5. Additional Canadian-Specific Security Considerations Enable Multi-Factor Authentication (MFA): Require MFA for system logins and remote access. Use Email and Web Security Filters: Protect against phishing and spam emails with filtering tools. Regular Security Assessments: Consider hiring a cybersecurity firm for vulnerability testing. Cyber Liability Insurance: Ensure your insurance covers data breaches and ransomware attacks. Maintain Compliance Documentation: Keep records of security practices in case of an audit by the Office of the Privacy Commissioner of Canada. 6. Key Resources for Canadian Clinics Office of the Privacy Commissioner of Canada (OPC): www.priv.gc.ca Canadian Centre for Cyber Security (CCCS): cyber.gc.ca Ontario PHIPA: www.ontario.ca/laws/statute/04p03 Alberta HIA: www.alberta.ca/health-information-act.aspx BC PIPA: www.oipc.bc.ca/about/legislation/ Canadian Dental Association (CDA): www.cda-adc.ca National Cyber Security Strategy: www.publicsafety.gc.ca/cnt/rsrcs/pblctns/ntnl-cbr-scrt-strtg/index-en.aspx By following these best practices and aligning with Canadian regulations, dental clinics can reduce the risks of data breaches, ransomware attacks, and insider threats.

Katherine McMillan a lancé une nouvelle discussion dans le groupe Cybersecurity

One of the scariest cybersecurity threats/attacks that can be faced in healthcare, or in general, is called a "Man in the Middle" attack. This form of attack can happen when a 'threat actor' gets access to the middle of communications or systems, and can see, delete, disable or distort them, without the other parties knowing that anything has occurred. This can be particularly detrimental for communications/relationships where there are factors (such as an NDA investigation, lack of public transportation, distance, low income, etc.) preventing or interfering with direct contact. These can occur with very little technical ability, but with a lot of wit/motivation/time. I draw your attention to Shelly Chartier and her particular crimes (I like to provide a Canadian example where I can). Some call her a catfish, but I see her as a Woman in the Middle. I would just like to add that Shelly Chartier has served her punishment and should not continue to be seen as a criminal or bullied in any way as she has done her time. Is anyone working on anything involving Women in the Middle?

Événements



Événements à venir :

Aucun événement

Forum

Cybersecurity in Dental Clinics 02/26/25

Hi Kodian, One of my favourite articles on Medium.com is about red-teaming LLMs: https://medium.com/ai-in-plain-english/llm-jailbreak-comparing-drattack-artprompt-and-morse-code-17acb0f18be8 I would be considered on the anti-LLM/AI takeover sid...

Cybersecurity in Dental Clinics 02/26/25

I used AI to help generate this response to please don't quote the text - only use it as a guide to identify points of research.

Dietitians using Outdated Software and Systems 02/26/25

Good question, and thanks for sparking the discussion! Here are a few recommendations tailored to a Canadian context, building on points already mentioned: Risk Assessment & Vendor Transparency As Matt noted, verify if vendors provide security de...

Cybersecurity in Dental Clinics 02/26/25

Cybersecurity Recommendations for Dental Clinics in Canada Cybersecurity is a critical concern for dental clinics, especially with threats like data breaches, ransomware, and insider attacks. Below are practical recommendations, tailored for Canad...

"Man in the Middle" (MitM) Attacks 02/26/25

One of the scariest cybersecurity threats/attacks that can be faced in healthcare, or in general, is called a "Man in the Middle" attack. This form of attack can happen when a 'threat actor' gets access to the middle of communications or systems, an...

How to avert DDoS (Distributed Denial of Service) attack in Pharmacy chains 02/25/25

Thank you, Klei, for an insightful reply. The points you mentioned will definitely help me and my team to report on the subject matter. Truly appreciate the help.

Cybersecurity in Dental Clinics 02/25/25

Hi Klei, Thanks for taking the time to read and respond to my post.

Cybersecurity in Dental Clinics 02/25/25

Hi Kodian, Thanks for reaching out! Those are common cybersecurity threats. Some mitigations to consider are: - Employee training and awareness - Having technical controls in place that would alert when something seems off - Strong network sec...

Dietitians using Outdated Software and Systems 02/25/25

Hi Marion, When I ever encounter new software that I'm not familiar with, which is something security staff encounter as part of their work, then I approach the issue by learning as much about the software as possible. Questions I'm looking to an...

How to avert DDoS (Distributed Denial of Service) attack in Pharmacy chains 02/25/25

Hi Darwin, Thank you for reaching out! Here are some things to consider: - DDoS can be prevented using IDS/IPS (Intrusion Detection and Prevention systems) - Services that provide load balancing etc. and cloud hosting providers often have DDoS p...

Dietitians experiencing Phishing Attacks in a hospital setting 02/25/25

Hi Marion, Thanks for reaching out! Here are some things to consider: - Employee training and awareness so that dieticians are informed and aware of what to look for and to distinguish a phishing attack - Having a phishing reporting process in...

Cybersecurity in Dental Clinics 02/25/25

Good day, I am a student doing a project on the topic cybersecurity in dental clinics. As part of the project, we are exploring different cybersecurity issues. We selected data breach, ransomware attacks, and insider threats. As such my qu...

Cybersecurity issues in Dental Clinics 02/25/25

Hi Katie! Thank you for your reply. That topic sounds interesting, and it's the first time I've heard about that specialty group. I'll try to research more about it. Patient data breaches, phishing emails are the most common issues but is there anyth...

Cybersecurity issues in Dental Clinics 02/25/25

Hello Margareth, Awesome topic! There is really something to this. In your research, you have probably seen that specialists called "Odontologists" get involved in certain cases. These specialists can provide really amazing forensic support, and...

Cybersecurity issues in Dental Clinics 02/24/25

Hi! I'm Margareth, a student studying Health Systems Management. Part of my assignment is to research cybersecurity issues in dental clinics. I would appreciate it if you could give me some information on what these issues are and how to mitigate the...

Documents

Cliquez sur « Gérer des documents » pour :

  • voir la liste complète des documents ou les dossiers regroupant les documents
  • téléverser un nouveau document

N. B. : Les membres des groupes ne sont actuellement pas avisés de l'ajout d'un nouveau document. Pour aviser d'autres membres, vous devez en afficher l'adresse électronique dans le forum. (La fonction d'avis de téléversement des nouveaux documents est en préparation.)

Gérer des documents Vous devez peut-être ouvrir une session et/ou être déjà membre du groupe pour accéder à ce contenu.

Vidéo

Ce groupe n'a pas de video.

Membres

Robert Martin
Photo de Robert Martin
Canada Health Infoway
Déconnecté(e)
Personne-ressource
Ann-Marie Westgate
Photo de Ann-Marie Westgate
Canada Health Infoway
Déconnecté(e)
Personne-ressource
Bijiteshwar Aayush
Photo de Bijiteshwar Aayush
Canada Health Infoway
Déconnecté(e)
Admin
Anne-Marie Taylor
Photo de Anne-Marie Taylor
Alberta Health Services
Déconnecté(e)
Membre
Kodian Brooks
Photo de Kodian Brooks
Fanshawe
Déconnecté(e)
Membre
Margareth Languido
Photo de Margareth Languido
n/a
Déconnecté(e)
Membre
Darwin Tanchoco
Photo de Darwin Tanchoco
n/a
Déconnecté(e)
Membre
aarti devi
Photo de aarti devi
fanshawe college
Déconnecté(e)
Membre
Marion Calungsud
Photo de Marion Calungsud
n/a
Déconnecté(e)
Membre
Divya Singh Chauhan
Photo de Divya Singh Chauhan
Fanshawe College
Déconnecté(e)
Membre
Clinton Cabillada
Photo de Clinton Cabillada
n/a
Déconnecté(e)
Membre
Shanoi Chambers
Photo de Shanoi Chambers
n/a
Déconnecté(e)
Membre
David Cumming
Photo de David Cumming
Canada Health Infoway
Déconnecté(e)
Membre
Santiago Riveros
Photo de Santiago Riveros
n/a
Déconnecté(e)
Membre
GUNJAN CHOPRA
Photo de GUNJAN CHOPRA
Eastern College
Déconnecté(e)
Membre
Membres: 108
Personne-ressource: Robert Martin
Administration: Bijiteshwar Aayush
Type: Ouvert
Accès: Public
Security experts working in healthcare or health solution providers sharing knowledge, information, and resources to promote security in healthcare, and safeguard Canadians’ personal health information.

Logo d'InfoCentral

La santé numérique à votre service

 

Transformer les soins de santé au Canada grâce aux technologies de l'information sur la santé.