The Maine House of Representatives has voted unanimously to advance a bill that seeks to strengthen cybersecurity at Maine hospitals to prevent cyberattacks and ensure continuity of care following cyber intrusions. The bill faces further votes in the House and Senate in the coming days.
The bill was proposed by Rep. Julie McCabe (D-Lewiston), a member of the Health and Human Services Committee, following two cyberattacks last year that impacted five Maine hospitals – Covenant Health’s St. Mary’s Hospital in Lewiston, St. Joseph’s Hospital in Bangor, and Central Maine Medical Center’s hospitals in Lewiston, Bridgton, and Rumford. The Covenant Health ransomware attack alone affected 478,188 individuals, and along with the cyberattack on Central Maine Medical Center, around one-third of state residents were affected.
Those cyberattacks had a negative impact on patient care, crippling basic communication services, exposing serious breakdowns in hospitals’ protocols, and causing major disruption to patient care that lasted for weeks, including disruptions to preventative care and cancer care. “Cyberattacks pose a serious risk to our already-fragile health care system,” said McCabe. “We’ve already seen how a cyberattack can impact Maine hospitals and leave patients in dire straits. This legislation will help ensure that our hospitals are prepared to deal with these types of incidents, respond promptly and effectively to patient needs, and protect sensitive information.”
The bill – LD 2103 – requires hospitals to adopt measures to prevent and respond to cybersecurity incidents, and also includes provisions requiring workplace safety measures to protect patients, visitors, and employees from aggressive and violent behavior. According to the Occupational Safety and Health Administration (OSHA), healthcare workers are 4-5 times as likely to suffer injuries due to violence as employees in all other sectors. The bill requires hospitals to have a process in place to receive and record incidents and threats of violence and prohibits representatives or employees of a hospital from interfering with a person making a report.
All hospitals will be required to have a cybersecurity plan consistent with cybersecurity best practices established by the U.S. Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), Department of Commerce, National Institute of Standards and Technology (NIST), and the Healthcare and Public Health Sector Coordinating Council (HSCC).
The cybersecurity plan must be consistent with HIPAA and be reviewed at least annually. At a minimum, the plan must include provisions to ensure timely notifications to law enforcement, state regulators, patients, and employees about cybersecurity intrusions. All hospitals must have a backup communication response provision to ensure continuity of care for patients in the event of a disruption of hospital computer systems due to a cybersecurity intrusion. That includes a compliant process for patients who experience challenges accessing medical care, a system to triage patients within 48 hours of submitting a complaint about emergent symptoms, and timely management of complaints related to prescriptions.
There is a provision to ensure the triage of all hospital services in the event of disruption to computer systems, including procedures for diverting hospital services, and written agreements with other hospitals to facilitate the continuity of care for patients during any disruption due to a cybersecurity incident. Hospitals must have a written security incident response plan documenting how hospital employees are to report suspected or known security incidents, including how the hospital will respond clinically, and provisions for internal and external communications. Hospitals must also have a system for ensuring that all manually charted medical information is incorporated into electronic medical records in a timely manner.
Cybersecurity training for hospital employees and board members is required at least annually, and incident response and downtime procedures must be reviewed, tested, and updated, as necessary, at least once a year. Further, following any cybersecurity incident, hospitals are required to review the response and take steps to improve procedures for responding to future cybersecurity incidents.
The post Maine House Unanimously Passes Bill to Strengthen Cybersecurity at Maine Hospitals appeared first on The HIPAA Journal.