Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: You Can Run But You Can’t Hide

Ever hear industry experts say “It’s not IF you have a cyber/ransomware attack, it’s WHEN.” No truer words have been spoken.

Why do we run in the opposite direction from information and tools that can help better secure our healthcare organization?

  • It’s Too Expensive. Some of the best security measures do not have significant costs associated with them, or no cost at all: lengthen passwords in systems and applications containing ePHI; regular (not just annual) cybersecurity and security awareness training; purge patient data that is no longer needed, either in paper (storage facilities) or electronic form (locally stored on computers in desktops, documents, downloads).
  • I Don’t Understand the Security Solutions. Enlist your IT experts to explain the best security tools for your organization. There is never a one size fits all – this is why the HIPAA Rules were created to be flexible, so small and medium sized organizations can still support a rigorous security platform on a limited budget.
  • My Organization is Too Small for a Cyber Attack. Threat actors want patient data – if it’s quick and easy, they’ll take it. Systems that have not been patched, end of life operating systems with no security measures, remote access into networks with no layered security (2FA/MFA) are easy targets for hackers.

Cyber Safety is Patient Safety!

Health Sector Coordinating Council Cybersecurity Working Group

Health-ISAC Collaborating for Resilience in Health

Compliance Is Ongoing

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.