HIPAA Tip: Reminders for Cybersecurity Awareness
- Carefully inspect links and attachments in emails before taking action. When in doubt contact the sender directly (phone call). Always look for the “Red Flags” to determine an email phish.
- Keep business (and personal) devices and apps up to date. Computers, whether a workstation, laptop or cell phone, are easy targets for hackers when the security measures are out-of-date, or no longer exist when a device is end-of-life and not supported by the manufacturer.
- Be wary of unfamiliar social media requests and use strict privacy and security settings. Before posting on sites think about the information being divulged. Would this be a violation of the organization’s privacy policy? Is the information personally identifiable information (your home address, kids’ names, medical procedures that you had done, traveling and leaving your home empty)?
- Follow organizational policies and procedures regarding security and cybersecurity awareness: do not conduct personal business on a company computer, do not download any applications unless authorized to do so by management. Contact IT or the Security/Compliance Officer immediately if you have suspicious activity on your business device.
- Never share personal or organization information with AI chatbots. Be extremely careful when using AI especially if there is a possibility of including ePHI or sensitive data.
- Report suspicious behavior. Never wait to contact the Security Officer or the IT team if you believe your business device has been compromised.
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.
Author:
Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP