Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Nashville General staff report stronger cybersecurity controls, partial device encryption
Summary
Hospital IT told the compliance committee it enforces multifactor authentication, role‑based Cerner access, daily desktop patches and endpoint protection; 87.26% of devices are encrypted and the Microsoft security score is 76.14%, though training completion was reported at 51% year‑to‑date.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Nashville General Hospital information‑technology staff told the Hospital Authority Compliance Committee they have tightened controls for patient data and system access, including multifactor authentication for remote connections, role‑based user assignments in Cerner and routine patching.
"We have multifactor authentication for a lot of our sensitive data," Miss Thomas said, describing daily desktop patching, monthly server and network updates, endpoint protection and an encryption rate of 87.26% for devices. She reported a Microsoft security score of 76.14% and that 51% of users have completed year‑to‑date cybersecurity training.
Miss Thomas said off‑site access requires VPN plus multifactor verification and that user access in Cerner is now strictly role‑based so staff receive only the permissions their job requires. She described simulated phishing campaigns that place users who click on test messages into immediate remediation training.
Board members pressed for clarifications about the remaining unencrypted devices and the program’s timeline. Miss Thomas said the devices not yet encrypted were mainly older PCs (some up to seven to ten years old) scheduled for replacement as part of the Cerner implementation work, and she expected rapid progress toward full encryption as those machines are retired.
The chair also reminded the committee that recent investments in security software were an intentional response to a recent breach; Miss Thomas and IT staff framed those purchases as key to preventing recurrence and to supporting audits that verify appropriate access to patient records.
Next steps: IT will continue scheduled patch cycles, pursue remaining device replacements, and report back on training‑completion improvements as the security program matures.

