American Association for Physician Leadership

Operations and Policy

New Laws on Data Privacy and Security Are Coming. Is Your Company Ready?

Andrew Burt

September 27, 2019


Summary:

New laws across the country are beginning to enact basic standards for software used and raise the penalties for privacy or security failures, is your healthcare organization prepared?





Companies today are often not equipped to sell secure software, because they are not incentivized to do so, and because consumers are in no position to demand it. But this market failure won’t last long.

Governments are in the process of passing new laws to ensure higher standards for software security and data privacy. The era in which tech companies inadequately test their software for security and privacy vulnerabilities is coming to an end. Last year, for example, California became the first U.S. state to enact to Brazil . basic standards for software used in the “internet of things.” And v arious p roposed state laws around the country would raise the penalties for privacy or security failures. Similar efforts are ongoing around the world, from India

Software companies and their corporate customers shouldn’t wait to take action. To start with, they should not only gauge their level of security in terms of the patches they install or the incidents they respond to, but also consider the labor-intensive, ongoing processes they devote to preventing privacy and security vulnerabilities. That means that the time devoted to testing software and maintaining it once it is deployed will become central metrics in securing enterprise data.

Companies that create and deploy software can ready themselves by adopting two additional strategies.

First, they must focus on embedding security processes into the software design and deployment life cycle as early and as often as possible. Companies that purchase software should continuously track their attack surface and ensure that the teams appointed to simulate attackers are actively probing company networks and testing security readiness.

Second, companies need to connect the resources they spend on privacy and security to the volume and complexity of the code they seek to protect. As the number of lines of code in any given software system grows, or as its user base expands, organizations will have to increase their efforts to protect the privacy and security of their customers.

Soon, a less than robust software security strategy will become more than a public relations liability; it will become a serious legal vulnerability. It’s best to be prepared.

(Andrew Burt is chief privacy officer and legal engineer at Immuta.)

Copyright 2019 Harvard Business School Publishing Corp. Distributed by The New York Times Syndicate.

Andrew Burt

Andrew Burt is chief privacy officer and legal engineer at Immuta.

Interested in sharing leadership insights? Contribute



For over 45 years.

The American Association for Physician Leadership has helped physicians develop their leadership skills through education, career development, thought leadership and community building.

The American Association for Physician Leadership (AAPL) changed its name from the American College of Physician Executives (ACPE) in 2014. We may have changed our name, but we are the same organization that has been serving physician leaders since 1975.

CONTACT US

Mail Processing Address
PO Box 96503 I BMB 97493
Washington, DC 20090-6503

Payment Remittance Address
PO Box 745725
Atlanta, GA 30374-5725
(800) 562-8088
(813) 287-8993 Fax
customerservice@physicianleaders.org

CONNECT WITH US

LOOKING TO ENGAGE YOUR STAFF?

AAPL providers leadership development programs designed to retain valuable team members and improve patient outcomes.

American Association for Physician Leadership®

formerly known as the American College of Physician Executives (ACPE)