HIPAA Tip: Fight Back!
For those of you who know me, you’ve heard me say probably more than once, we are all patients somewhere. And as patients we want to be treated with importance and feel confident knowing our medical information is private with those providing our care and secure from a hacking incident, ransomware attack or data breach.
How we handle and protect patient data is paramount – that’s our business, so let’s start fighting back against threat actors with some of the basics.
- Cybersecurity and security awareness training must be completed as often as possible, for ALL team members (no exclusions!). Include training in staff meetings, newsletters; add posters and HIPAA TIPS in the lunchroom and have all staff sign off on these being read.
- Systems and applications containing ePHI must have an auto-lock/timeout after 10-15 minutes of inactivity – not just a screen going dark! If necessary lengthen auto-lock in procedure rooms, but do NOT extend this to hours. Thought to remember: why do we lock our homes when leaving or our autos in public?
- Lengthen passwords: minimum of 12-16 characters for systems and applications containing ePHI or sensitive data; do NOT use the same password for all accounts! A hacker gets into one of your accounts you can bet they will try another with the same password.
- Review users in all systems containing ePHI regularly (quarterly) to ensure staff no longer employed have been disabled. Always review roles and privileges at the same time: minimum necessary, least privileged access.
Compliance Is Ongoing
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.