HIPAA Tip: Strengthen Your Staff’s Security Posture
One of the greatest risks to a healthcare organization is the lack of cybersecurity and security awareness training. The responsibility of training lies with each organization, strengthening this “weak link in the chain”. The unfortunate reality is training only happens once a year, the training material is outdated or reused over and over again, or worse, no training is conducted at all.
Healthcare organizations must prioritize regular training sessions covering the most pertinent information – password management, data and privacy protection, email phishing, secure remote work practices – and in doing so – reinforce the organizational policies and procedures that have been put in place and are expected to be followed.
Understand and communicate intentional and unintentional threats. Consider a disgruntled employee looking for revenge or financial gain by purposely exposing PHI or confidential data. Accidental human error happens all too often with an employee falling for a phishing or smishing attack, or even due to recycled passwords.
However small or large your organization is, enlist coworkers to support and execute regular training sessions. Security updates can be added to staff meetings, email blasts to all team members or even reminders posted in employee kitchens and lounges.
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.
Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP