Webinar On Demand
Elevating Healthcare RCM Security: Insider Insights on Cyber Preparedness
Hi. My name is Jonathan Wick. I'm the vice president of health insights at FinThrive, and I'm joined by mister Greg Surla, the senior vice president and chief information security officer at FinThrive. And we're gonna talk to you today about RCM security and cyber preparedness.
This is a mini webinar. It's part of a series. You'll see some QR codes as we go through those here in a little bit that you could click on. If you like what you saw or, wanna pass a little on to others, let us know.
We also have a, cybersecurity council, which Greg will talk about, and there's a way to get ahold of him, in there as well. And and, you can just email us. Our information will be on the last slide there, but I'll go ahead and get started. And welcome, Greg.
Thank you. Thank you, Jonathan.
You bet. Let's talk about cyberattacks. I think, you know, you're hearing them more and more. It seems like I think this graph's gonna look a lot different when the year gets out.
We're we're seeing quite a bit of these things happen. Ascension was kind of the last big one. We had the CrowdStrike thing happen, I believe, last month, which was an operational impact more necessarily than just a data breach. It really crippled, I'd say, probably about a half of hospitals that I talked to anyway, just operational.
A lot of their systems were frozen, and they weren't able to transact, many of their Outlook applications that they used to communicate to one another, and other things. So that was a really big deal, and I think it was an eye opener as well.
This graph showing just the number of attacks, and it's been, you know, kinda following this hockey stick profile, I would call it. And, the PHI, I don't think a lot of people talk about that. The I'll bet you know somebody who got a breach letter, though. I was out in Phoenix last week visiting our friends at banner and, or this week actually, and and I saw a couple of relatives of mine when I was out there as well, and they had gotten a letter.
And I I think about one in three of us probably have some interaction with the clearing house when the change event happened, and and those letters are starting to drop. But a lot of it's not known about what data was taken and where that was spent. I wanna talk about redundancy for a minute too to switching gears here. I worked at a hospital for about twenty five years, and they're a lot like the military in that they have redundancy for redundant systems just to make sure that they can't close.
Because the fact of the matter is a hospital can't close. It's gotta be open twenty four seven. I like to say that a hospital's a a physician's clinic, a restaurant, and a hotel all rolled into one, and it absolutely has never ever closed and has to have levels of redundancy for its clinical operations. Those are backup generators for power, backup water lines, backup Ethernet lines, backup chillers, and those types of things.
And as you're thinking about backups, revenue cycle, I think, has not been a area where there's been a lot of redundancy put into place, like having two clearing houses or two eligibility centers, or two EHRs for that matter, has not really been a a standard. There's been backups and cutovers and downtimes, but not nearly there. But given the events that I talked about and the skyrocketing, area that were there, Greg and I today are gonna talk to you about how important it is to have, one, be prepared, in in your in your in your in your positioning with your operations in terms of cyber, resilience.
And then secondarily, just the level of redundancy in your systems that are required, and we're gonna talk about something called standby claims and standby eligibility here.
Business continuity was a huge impact of the latest out outage with change. It averaged anywhere between seventeen percent of the claims inventory.
You know, you take, you know, one in five of your claims and and have to run those manually. That starts to really add up from an overtime, cash flow standpoint. Twenty percent of your cash flow is getting held up for two two to three months. That's a really big deal. And hospitals that had a lot of reserves and were were able to operate with a fairly resilient, you know, redundancy plan or others did not get as impacted as those that were fragile. You start getting into ambulatory and physician clinics. They were, you know, taking out loans, I'm told, to keep their financial operations going.
Eligibility is one of those areas that I think is table stakes these days in terms of making sure your patients and the consumers that are coming in, their insurance is being verified to where your funding mechanisms are established before care is delivered. Best practices to do that in the pre access intake center. You know, I know hospitals run tens of thousands of these transactions a day, be it for eligibility. We'll talk about insurance discovery here in a minute as well. But it's important that that when that goes down, I think, you know, the other options are to go to a a portal, like like Navinet or or some of these other ones or the or the payer directly. Or I even heard of some hospitals pick up the phone, which, oh my goodness, that's, you know, nineteen eighty five.
Cutting over to a standby eligibility platform, can happen in in a matter of hours, and and it can be set up if you've never had a secondary eligibility system in a in a matter of days. So it's something to think about, and it's it's not a large expense, and it really saves on some of those labor cost and cash flow risks as we're looking. It is a best practice now, I would call it. I'm talking to several health systems, and they are very closely evaluating having a secondary clearing house if if not already installed one.
They'd back up every fifteen minutes, make sure that those payer mnemonics and mappings are all there. And then if the system fails, as I mentioned, you know, they could switch over within a day, at the most, and and those data and and and and other things are synchronized across that group.
Claims are probably the biggest impact we have at the latest event, and that is a big deal. And and I think it it it magnifies itself in that. Once you are down and you're trying to communicate with the payer, that becomes a key key or manually keystroke type of process, which immediately cripples an organization processing maybe ten to twenty thousand claims a day. Right? That automatically kind of dropped and were built through the EHR and whatever your claims clearing house was in terms of getting those out in the right format on that UBO four, you know, out to the payers through that two seventy six, two seventy seven transaction and and and and two seventy eight for that matter. Understanding, you know, what is happening and and why that that outage caused such a large, impact to cash flow is important to understand as you're evaluating having a secondary clearing house. This is is a no brainer these days, I think.
You know, claims must go to get paid. And, also, if if your claim system is down for any exterior period of time, you have to kinda finish out the payment of that process, you know, in that format. So if you call by phone or you fax something or you went to the portal, that's how your remittances are gonna come, and then you're filing paper checks and all that stuff, later, which can be very, very difficult. These are the benefits of having standby eligibility and claims. I'm not gonna go into a super huge detail because Greg and I only have fifteen minutes with you today, but take a look at this and just understand that denials and your follow-up and your clean clean rape and all of those things are very, very important as you're, evaluating a standby solution.
And, I'm gonna turn it over to Greg now, and he's gonna talk a lot about cybersecurity, and then we'll open it up for questions at the end if we have any time. But thank you so much.
Alright. Yeah. Thank you, Jonathan. Appreciate it. Hey. So, so with cybersecurity, you know, if you're a cybersecurity person, you probably know, you know, that we are the health care industry is under attack.
As a CISO here at FinThrive, we see a lot of, a lot of activity, a lot of ransomware attacks on on, customers, on peers, and on many others. And so, it's unprecedented.
It's only gonna get worse. Jonathan had mentioned or had a slide up in the very beginning that talked about number of ransomware events or number of events, for twenty twenty four.
I strongly suspect that number is gonna be a lot higher this year. But, for for FinThrive, just speaking of FinThrive, you know, we aren't checking the box.
And if you're, you know, if you're in if you're in security, you know not to check boxes. You know that, there's there's a lot more. We're we're running into, threats that are faster than the speed of AI, the speed of bots. And so with FinThrive, we've taken the approach of, you know, security first.
It's the culture that goes all the way up from the board to the CEO to, to everyone at the company. And and we do a lot of things, specifically the security team here. You know, we have a security ops ops team there twenty four by seven monitoring. We have our engineering team.
We have our app sec team that, not only looks at the code, but they're conducting, pen testing and red team exercise red team exercises, which means that they're attacking our software as well as as though they were an outsider and trying to exploit those fools that are out there. We wanna catch them before anyone else catches them, if they exist. And then our risk management team is looking at everything from, our vendors, to our, critical, you know, critical environments, our our, business continuity. I'm sorry.
Business continuity, we have information assurance. You if if you work with, FinThrive, and you send a questionnaire over to us, we have our information assurance team that is addressing that. We also have a a a new as of a couple of months ago, we have a FinThrive, trust center where if you wanna look at what we're doing in terms of security, our policies, you know, the things that we're doing to protect your data, feel free to to drop into that FinThrive, customer, trust center. You could find that on the FinThrive homepage.
Go to about us and then security. Alright. Jonathan, let's move on to the next one, Please.
Thank you. So, certifications, and accreditations. FinThrive is, is constantly going through, SOC two, SOC one, SOC two, HITRUST, DirectTrust. And then most recently, we we've accumulated a Texas ramp, certification. This, as you see here, these are the products that are certified. When you go into that trust center, you can download those reports so that you can see where FinThrive, where we sit in terms of how we've been, how we're securing our environments.
Let's go ahead and move on to the next. So with cyber incident response, same same thing.
We are, strongly focused on incident response. Change Healthcare kinda opened up a lot of people's eyes. It's also opened up some eyes over here. We align with NIST eight hundred sixty, one, rev two, and that's the the life cycle that you see on the right there. Just so you know, we we have, we conduct, tabletop tabletop exercises twice a year, with our technology team, in one part of the year. And then the second part of the year, we conduct it with our executive and leadership teams.
Both sides of the house are directed through this year, we're we're doing a ransomware event similar to what Change Healthcare had done so that everybody understands what their role is and and how to move quickly to protect your data. Let's go ahead and move on.
Alright. So, we talked about, Jonathan talked about redundancy. And so with us, we have, we have a a hybrid approach to our hosting of your data. For some of the products, we have, you know, there it's sitting in Azure. It's also sitting in your data center. But then for others, it's sitting in Azure in our own data centers in Texas and Phoenix, and then we have, one product that is sitting in, AWS.
We do this to make sure that, if there is an event, we can failover, as quickly as possible.
Alright. Let's go ahead and move on. So talking about building cybersecurity, cyber resilience rather. You know, one thing you wanna do and and for those of you that are in, in security, you probably know this already, but, just wanted to, talk about this a little bit. You wanna sign, align with a security framework for FinThrive where, we we align closely with HITRUST, as well as SOC and NIST.
You know, I talked about the incident response plan. We do conduct risk assessments, not just on our products, but on the company as a whole. I have an entire risk assessment team that does that year round, and they are looking at at everything, including the processes as well as the security controls that are in place.
We talked about talked about the culture here.
We have, phishing tests just like I'm sure nearly everyone on the call here has phishing tests. We do them at least once a month.
We're we gamify them. We also provide, just you know, we provide gift cards for those that are reporting in a timely manner. So it's, we we try to make it fun because we all know that phishing training isn't exactly the funniest, the the most fun thing to do, but, we try to make it a little bit better.
Just like you all do with assessing your supply chain with FinThrive, we do the same thing. We're looking at all of our vendors to make sure that if there is a single point of failure, we're gonna try and, identify that and look for alternatives, look for ways to fail over, and, find the best approach to getting back online in case that, supply chain vendor is is compromised. And then finally, we've adopted an assumed breach mindset. What that means is that we assume a breach, has occurred or can occur, and it is our responsibility to find that breach.
That's why we have pen testers. That's why we have, code, application security engineers. That's why we have security engineers, that are looking at our infrastructure and our security operations team. So so we do adopt that assume breach mindset, mindset at FinThrive.
And then let's move on to the next.
Jonathan talked about this earlier about the Finthrive Security Council. This is something we are very excited about. What we are looking to do is build a a, group of peers, where we talk about security issues. This is a group where, you know, what you say stays in the room.
It's, not something that we we're not looking to expose anything. We just we know that, sometimes you're sitting out on an island, in terms of discussing security. So for us, we wanna build that, industry best practices as when it comes to cybersecurity. And so so that security council, we're looking to build.
We just had our first meeting in August. We're doing this quarterly.
Next meeting is in October.
If, and and we may change that to monthly, but we're looking to see how how things are going. But, would love for anybody on this call, to either join or get get members of their cybersecurity team. Or if even if you're not in cybersecurity, we welcome your participation.
Alright. And then you can reach out to me. Yeah. Go ahead. I'm sorry, Jonathan.
That's alright. Go ahead, Greg.
Yeah. So, I knew this was coming up, but, in order to join that, security council, feel free to reach out to me. Send shoot me an email, and we'll get you set up.
Alright.
Alright. Thank you, Greg. Thank you all of you for that quick and dirty, review of, of cyber redundancy and resilience within RCM. I hope you learned about, having standby claims and eligibility and some best practices from both the provider and, business side of, health care. And have a great afternoon, and thank you so much.
Alright. Thank you, everyone.