NIST Risk Assessment Lifecycle Implementation
Our evaluation systematically transitioned from raw breach data extraction to quantitative threat likelihood scoring, vulnerability correlation, and actionable mitigation roadmaps aligned with federal compliance mandates.
The Vulnerability of U.S. Healthcare Infrastructure
The healthcare sector represents one of the most targeted critical infrastructure sectors in the United States. Under HIPAA requirements, covered entities and business associates must report breaches affecting 500 or more individuals to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR).
Healthcare organizations handle deeply sensitive Protected Health Information (PHI) while frequently operating on fragmented electronic health record (EHR) platforms, legacy medical devices, and decentralized vendor supply chains. Our team was tasked with examining empirical HHS breach records to diagnose root cause vulnerabilities and deliver prioritized mitigation strategies.
Data Cleaning & Quantitative Analysis in Excel
Using advanced Microsoft Excel functionalities — including pivot tables, multi-parameter conditional lookups, and categorical aggregation — our team cleansed and parsed historical HHS breach records:
- Categorization by Breach Type: Segmented incidents into Hacking/IT Incidents, Unauthorized Access/Disclosure, Theft, Loss, and Improper Disposal.
- Location of Breached Information: Mapped breaches across Network Servers, Email Accounts, Electronic Medical Records (EMR), Laptops, and Paper/Films.
- Entity Profiling: Differentiated breach trends among Healthcare Providers, Business Associates, Health Plans, and Healthcare Clearinghouses.
Most Prominent Attack Vectors Discovered
Network Server Ransomware
Hacking incidents targeting centralized network servers and EMR databases represented the vast majority of exposed patient records and operational paralysis.
Email Phishing & Credential Theft
Compromised employee credentials via spear-phishing served as the predominant entry point into corporate networks and clinical communication systems.
Third-Party Business Associates
Vendor supply chain vulnerabilities exposed massive quantities of aggregated PHI when billing, claims processing, or IT contractors suffered security failures.
Unencrypted Portable Endpoints
Laptops, storage drives, and medical devices lacking mandatory full-disk encryption frequently contributed to non-compliance disclosures upon theft or loss.
Proposed Risk Mitigation Strategies
Applying defensive controls recommended in NIST publications, our team designed an actionable remediation strategy prioritizing low-overhead, high-impact defense mechanisms:
Mandate phishing-resistant Multi-Factor Authentication (MFA) across all email and network portals, utilizing conditional access policies (e.g., Azure Entra ID) and strict least-privilege role boundaries.
Isolate clinical IoT devices and patient monitoring systems from general staff networks to prevent lateral movement during ransomware outbreaks, backed by automated Endpoint Detection & Response.
Establish offline, immutable backup repositories to guarantee prompt system restoration without capitulating to extortion attempts.
Implement recurring phishing simulations and role-tailored security awareness education for clinical and administrative staff.
Formal Presentation & Stakeholder Briefing
Our team synthesized these analytical insights into a formal executive presentation delivered to course faculty and fellow students at LSU's E.J. Ourso College of Business. The presentation emphasized translating complex cyber telemetry into quantifiable financial and patient safety risk metrics that hospital boardrooms can prioritize.
More Projects by Benjamin
Car Dealership Data Modeling
Designed an ERD model, Relational Data Model, and SQL schema for an automotive dealership database, including full metadata and data dictionary.
Static Website Creation
Built a responsive static website using VS Code, GitHub, Anaconda Prompt, and Zurb templates, configured with Cloudflare DNS & security routing.