Information security for healthcare
A healthcare organisation carries two requirements that pull in different directions: the information must be protected to the highest standard, but it must also be instantly available to whoever is treating a patient. A clinic that loses access to its records is not experiencing an IT fault — it stops providing care. Recovery time therefore matters here as much as preventing the leak.
What is at stake
- Medical records and test results
- Patient management and scheduling systems
- Network-connected equipment and systems
- Interfaces to health funds and laboratories
The incidents that matter here
- Ransomware that halts clinical systems and stops treatment, not merely encrypts files
- Unauthorised access to medical records — information that cannot be replaced once it leaks
- Medical equipment or legacy systems that are network-connected and cannot be patched
- Intrusion through an external interface to a laboratory or funding body
Obligations that shape the work
Medical information is classed as specially sensitive under Israeli privacy law, and Amendment 13 tightened the security and reporting duties around it. In practice a healthcare organisation must both protect that information to an unusually high standard and keep it available for treatment — two requirements that have to be designed together rather than separately.
This is general information, not legal or regulatory advice. The obligations that apply to a particular organisation depend on its activity and its regulator.
How we approach it
- Monitoring of record access and of the systems that must not go down
- Incident response that starts from the question of what has to work again first
- A risk assessment that also maps legacy systems and equipment that cannot be patched, and what to do about them
- Training for clinical staff in the language of their daily work rather than a technical one
// next step
Not sure what the right next step is?
Use the short assessment to identify the areas worth reviewing, or tell us what changed and we will start from there.
Do not send passwords, credentials, API keys, logs or sensitive incident material through the web form.