Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Federal Register of Proposed Rule by the Health and Human Services Department

Directly from the Executive Summary in the Notice of Proposed Rulemaking, Federal Register:

The Security Rule was initially published in 2003 and most recently revised in 2013. Since its publication, there have been significant changes to the environment in which health care is provided and how the health care industry operates. Today, cybersecurity is a concern that touches nearly every facet of modern health care, certainly more than it did in 2003 or even 2013. Almost every stage of modern health care relies on stable and secure computer and network technologies, including, but not limited to, the following: appointment scheduling, prescription orders, telehealth visits, medical devices, patient records, medical and pharmacy claims submissions and billing, insurance coverage verifications, payroll, facilities access and management, internal and external communications, and clinician resources. These tools and technologies are an integral part of the modern health care system, but they also present opportunities for bad actors to cause harm through hacking, ransomware, and other means. Covered Entities and Business Associates may also experience malfunctions and inadvertent errors that threaten the confidentiality, integrity, or availability of ePHI. Thus, cyberattacks, malfunctions, and inadvertent errors can negatively affect the provision of health care, as well as the efficiency and effectiveness of the health care system.

Please take heed: EVERY aspect of a healthcare environment most likely will contain ePHI or sensitive data. Proactively address vulnerabilities within your organization and increase security measures.

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


Author: Dawn Meglino

HIPAA Compliance Specialist, CHPSE, CCSA, CCAP