Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Is Your Electronic Medical Records Team Pulling Their Weight?

OR, is it your organization that is not stepping up?

Have you recently reviewed the security measures and password policies in place for systems and applications containing ePHI, whether this is scheduling software, billing, Practice Management (PM), or the Electronic Medical Records (EMR)? Are the measures up to the standards of HIPAA, NIST, CISA, for securing sensitive data and ePHI?

If the password length for your EMR is eight characters or less this is not good enough. Forget that it’s called a “complex” password:  an eight-character password can be cracked by a hacker or threat actor from minutes to under an hour.

How many failed login attempts to these systems before a user is locked out? This one is huge – if there is no account lockout policy in place a threat actor can brute force the password over and over and over again until they gain access.

Restriction on the reuse of the last several passwords is important, as it forces users to create new passwords. I can’t tell you the amount of times I’ve heard from clients how much they hate to have to reset passwords after 60-90 days. Then I ask the question on whether I can reuse the last password and I’m told same password can be used?! So I was just told that I don’t have to reset my password – I can continue using the same one!

What is the auto-lock/time-out policy, and I’m not talking about the computer screen going dark until the mouse is wiggled? Most users will not lock their computers when they leave their desks, leaving the EMR or other systems containing ePHI wide-open. If your organization requires some computers to remain unlocked longer (OR, procedure rooms), this should not apply to all PCs in the organization. Billing, front desk users need to auto-lock much more quickly.

If your systems and applications containing ePHI do not have these security measures in place contact your vendors and demand that the level of security be increased. Do not make excuses or concede to staff/users that it’s impossible for them to do their work when systems are locked down to secure the organization’s PHI. Each of us as patients (somewhere) want to know our medical data is secure and accessible to only those who need it.

Compliance Is Ongoing

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.