HIPAA Tip: Time to Set Goals!
As we move into 2025, more than ever, it’s time to assess the security and compliance of your organization. Every day an article is in the news about the latest hacking, ransomware attack or HIPAA Breach. This is not an “event” you want to go through unless you have plenty of time on your hands and lots of money that isn’t needed to run a successful business. Don’t you think you’ve been lucky to dodge this bullet so far?
Going back to the basics:
- Long and complex passwords for all operating systems and applications containing ePHI. An eight-character password (or lower) is no longer secure and easily hacked.
- All staff logging into systems containing ePHI must have a unique ID. NO shared user accounts including the Windows Operating System. Do shared drives contain a plethora of ePHI and do all users have access whether they have the privileges to or not? Think minimum necessary.
- HIPAA, Security Awareness and Cybersecurity training needs to be conducted regularly so all staff are educated in the signs of a cybersecurity attack (email phishing, unusual activity on computers). Best practices the organization has put in place need to be followed by all. Your staff is your best defense against threat actors.
- Multi-factor authentication (MFA) should be enabled whenever possible, adding a critical layer of security. Think of accounts accessed on the internet (EMR, PM, billing), remote access to the organization’s network directly, and emails outside the business environment.
- Incident Response Plans, Disaster Recovery, Contingency Plans are a necessity, and should not be something that was written three or more years ago to satisfy the HIPAA Security
Rule requirements, and never updated or tested to ensure preparedness by the organization.
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.
Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP