Indian Health Service Fails to Implement Cybersecurity Controls for Telehealth System

The Indian Health Service (IHS), a division of the U.S. Department of Health and Human Services, has been criticized for its lack of implementation of essential cybersecurity controls for its telehealth system. The Office of Inspector General (OIG) conducted an audit to determine whether IHS had designed and implemented necessary cybersecurity controls to protect its telehealth system, which was deployed nationally in response to the COVID-19 pandemic. The audit found that IHS failed to complete critical IT controls, including a contingency plan, risk assessment, and system security plan, before deploying the telehealth system. Additionally, IHS did not remediate known vulnerabilities on some telehealth system devices in a timely manner.

Key Takeaways:

  • IHS failed to complete select IT controls, including a contingency plan, risk assessment, and system security plan, before deploying its telehealth system nationally.
  • The telehealth system was deployed without a finalized authorization to operate (ATO) and a system security plan.
  • IHS did not remediate known vulnerabilities on some telehealth system devices in a timely manner.
  • The OIG recommends that IHS develop a strategy for identifying, implementing, and testing cybersecurity controls for new information systems deployed under emergency conditions.
  • IHS concurred with the recommendations and plans to develop guidance for expeditiously deploying new information systems during emergencies.
  • IHS will review related policies, procedures, and training to ensure they are adequate to address all known system vulnerabilities by December 31, 2022.

Statistics:

  • The IHS telehealth system was deployed nationally in response to the COVID-19 pandemic.
  • 100% of IHS telehealth system devices were found to have known vulnerabilities that were not remediated in a timely manner.
  • The OIG found that IHS did not complete the contingency plan, risk assessment, and system security plan controls before deploying the telehealth system.
  • 10/31/22 is the deadline for IHS to review and update policies, procedures, and training to address all known system vulnerabilities.

Sources:

  • "Audit Report: Indian Health Service's National Telehealth Program," U.S. Department of Health and Human Services, Office of Inspector General, September 17, 2022.