Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: ‘Tis the Season!

It’s the most wonderful time of the year; however, could there be more to do?! Here’s why you need to stay ever-vigilant: threat actors are doing exactly the same, especially knowing targets are well-distracted during the holiday season.

How is that any different than other times of the year? Think about these areas:

  • We are rushing through to make sure we complete tasks either because it is now end-of-year and crunch time, or we may be taking some time off and need to get our work done. In cutting corners, have we forgotten to look for the Red Flags in an email phish? Did we leave papers containing PHI out so we don’t forget to finish our work, and in doing so, we have violated the Clean Desk Policy for our organization? Or worse, we have not logged out of systems containing ePHI that may have a long time-out or no time-out at all?
  • Internet surfing is common, but it soars during the holiday season. Unfortunately, shopping, checking out recipes, looking up restaurants and their reviews happens all too often on business devices. Moving through a site can sometimes lead to clicking on something that may have nothing to do with the particular site and may redirect a user to a malicious site where a malware could potentially be installed.
  • Annual Security Risk Analysis (SRA) must be conducted/completed. Without updating the SRA the organization sits in waiting for a threat actor to take advantage of the vulnerabilities within the environment. Have you recently looked at the HIPAA “Wall of Shame” to see how many breaches have occurred just in the month of December? Not a list you want to join.

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


Author: Dawn Meglino

HIPAA Compliance Specialist, CHPSE, CCSA, CCAP