Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: HIPAA and the Internet of Things

The Internet of Things, most commonly referred to as IoT, are devices that may be used in healthcare environments. Some examples include:

  • Remote patient monitoring
  • Blood glucose monitoring
  • Heart rate monitors
  • Ingestible sensors
  • Connected inhalers
  • Connected contact lenses
  • Depression and mood monitoring
  • Hearing aids

IoT devices can store patient data or connect to networks with access to PHI– of course HIPAA (and the HITECH regulations) would apply to this data and become likely targets for hackers and threat actors.

Covered Entities must take necessary steps to secure and manage IoT devices effectively. These include the following:

  • · Unique user authentication for each individual accessing the resources that would contain PHI – and could be modified – must be in place.
  • · Software and firmware for IoT devices must be maintained and updated as needed. Change device default settings immediately to ensure security gaps are addressed.
  • · Covered Entities and Business Associates must implement audit controls to track and record system and user events for ongoing security monitoring and forensic activity.
  • · Whenever possible install encryption on IoT devices. In the event the device is hacked the data will only be available in
  • algorithms, leaving the threat actor with no decipherable data.
  • · Treat all devices containing PHI just as the organization would with servers, workstations, or laptops onsite. Maintain a documented inventory list and securely store when not in use.

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


Author: Dawn Meglino

HIPAA Compliance Specialist, CHPSE, CCSA, CCAP