Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Cybersecurity Awareness Key Points

While attending a recent Cybersecurity Conference some basic “key” points came up:

  • Our daily lives are filled with lots of business, whether the job at the office, kids’ activities, organizations we work with and spend time assisting, or just personal business. The more we are plugged in digitally, the quicker we move. In other words, how often do you find yourself “multi-tasking” and not thoroughly thinking through what is being completed or tasked? In our haste we may very well do exactly what we tell our staff NOT to do, and click on an attachment or a link without stepping back and saying, “was I really supposed to receive that?” Is the computer “acting up” but you need to complete your project so you ignore a potential malicious malware that is now in your computer and running through the rest of the company’s network?
  • Threat actors have specific specialized areas of expertise. In Advanced Persistent Threat (APT) groups there are collectives of threat actors usually supported by a nation state. One malicious actor will carry out a specific task while another has proficiency in completing another area of the attack. As an example, “Script Kiddie” is a novice hacker using existing scripts and software to carry out a cyberattack.
  • Whenever possible segment networks in a business environment, especially with ePHI, PII and sensitive data present. Network segmentation is a cybersecurity technique that divides a network into smaller subnetworks to limit access to ePHI, may prevent security breaches and limit the impact of cyber attacks.

We all need to be vigilant and do our parts. Your team/staff is one of the biggest contributors to the organization’s success against cyber attacks. Keep everyone educated and in the know!