The National Cybersecurity Center of Excellence (NCCoE) has released for public comment the draft of NIST Cybersecurity White Paper (CSWP) 34, Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration.
The public comment period for this draft has been extended until 11:59 p.m. EST on January 21, 2025. All comments that are received will be reviewed and adjudicated to inform the final publication.
About the White Paper
Hospital-at-Home (HaH) is a form of telehealth where patients receive in-patient care, including clinical care and monitoring, at their place of residence. Healthcare systems have begun incorporating communications interfaces, patient monitors, and other medical devices into the patient’s residence to provide advice and perform clinical care while leveraging the advantages associated with patients receiving treatment in an amenable location. HaH offers several benefits to healthcare delivery organizations (HDOs), including improving patient outcomes, alleviating in-patient bed capacity limits, and providing safety for patients and care team members in infectious scenarios.
While these are desirable benefits, HaH introduces privacy and cybersecurity risks by introducing medical-grade equipment and information systems into environments the hospital does not control. This paper examines risks found in HaH deployments when using smart speakers as a representative IoT device and provides recommended steps to address these risks. This paper also describes applying controls that include access control, authentication, continuous monitoring, data security, governance, and network segmentation.
We Want to Hear from You!
The public comment period for this draft is open until 11:59 p.m. EST on January 21, 2025. You can view the publication and submit comments by visiting the NCCoE project page. If you have any questions, please email our team at [email protected].