HIPAA Tip: You Can Run But You Can’t Hide
Ever hear industry experts say “It’s not IF you have a cyber/ransomware attack, it’s WHEN.” No truer words have been spoken.
Why do we run in the opposite direction from information and tools that can help better secure our healthcare organization?
- It’s Too Expensive. Some of the best security measures do not have significant costs associated with them, or no cost at all: lengthen passwords in systems and applications containing ePHI; regular (not just annual) cybersecurity and security awareness training; purge patient data that is no longer needed, either in paper (storage facilities) or electronic form (locally stored on computers in desktops, documents, downloads).
- I Don’t Understand the Security Solutions. Enlist your IT experts to explain the best security tools for your organization. There is never a one size fits all – this is why the HIPAA Rules were created to be flexible, so small and medium sized organizations can still support a rigorous security platform on a limited budget.
- My Organization is Too Small for a Cyber Attack. Threat actors want patient data – if it’s quick and easy, they’ll take it. Systems that have not been patched, end of life operating systems with no security measures, remote access into networks with no layered security (2FA/MFA) are easy targets for hackers.
Cyber Safety is Patient Safety!
Health Sector Coordinating Council Cybersecurity Working Group
Health-ISAC Collaborating for Resilience in Health
Compliance Is Ongoing
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.