HIPAA Tip: User Access Audits

Healthcare cyber attacks - HIPAA security and data protection

Auditing active user accounts in all systems and applications containing ePHI for healthcare organizations is crucial in order to maintain data security and regulatory compliance. This includes reviewing user activity logs, access permissions and system configurations to identify potential security risks and policy violations. User access reviews examine availability to systems’ sensitive data and ensures…

Read More

HIPAA Tip: General Compliance Program Guidance

Healthcare cyber attacks - HIPAA security and data protection

General Compliance Program Guidance, or GCPG is a program created from Office of the Inspector General (OIG) and Health and Human Services (HHS). The GCPG is a reference guide for the health care compliance community and other health care stakeholders. The GCPG provides information about relevant Federal laws, compliance program infrastructure, OIG resources, and other…

Read More

HIPAA Tip: Artificial Intelligence Poisoning Attacks

Healthcare cyber attacks - HIPAA security and data protection

Artificial Intelligence or AI Poisoning Attacks take two significant forms: Data Poisoning and Model Poisoning. Data Poisoning is classified into two categories: targeted data poisoning and non-targeted data poisoning. Targeted attacks occur when an adversary attempts to manipulate the model’s behavior with respect to a specific situation. An example would be a cybercriminal introducing poisoned…

Read More

HIPAA Tip: You Can Run But You Can’t Hide

Healthcare cyber attacks - HIPAA security and data protection

Ever hear industry experts say “It’s not IF you have a cyber/ransomware attack, it’s WHEN.” No truer words have been spoken. Why do we run in the opposite direction from information and tools that can help better secure our healthcare organization? It’s Too Expensive. Some of the best security measures do not have significant costs…

Read More

HIPAA Tip: Is Your Electronic Medical Records Team Pulling Their Weight?

Healthcare cyber attacks - HIPAA security and data protection

OR, is it your organization that is not stepping up? Have you recently reviewed the security measures and password policies in place for systems and applications containing ePHI, whether this is scheduling software, billing, Practice Management (PM), or the Electronic Medical Records (EMR)? Are the measures up to the standards of HIPAA, NIST, CISA, for…

Read More

HIPAA Tip: What Does Security Mean to You?

Healthcare cyber attacks - HIPAA security and data protection

Is it having locks on all doors, or is it an alarm system and security cameras? When you think of security for your home and your personal possessions, do you assess the organization’s security with the same standards? Security for a healthcare organization goes beyond physical security, and the best way to look at a…

Read More

HIPAA Tip: Model Notices of Privacy Practices

Healthcare cyber attacks - HIPAA security and data protection

The HIPAA Privacy Rule requires health plans and covered health care providers to develop and distribute a notice that provides a clear, user friendly explanation of individuals’ rights with respect to their personal health information and the privacy practices of health plans and health care providers. As of February 16, 2026, these HIPAA covered entities…

Read More

HIPAA Tip: Cybersecurity Attacks

Healthcare cyber attacks - HIPAA security and data protection

Getting tired of opening emails or articles and reading about another cybersecurity attack on a healthcare organization? Afraid your business might be next? Then do something about it! Cybersecurity and Infrastructure Security Agency (CISA) offers the healthcare sector numerous tools and resources to protect networks from cyberattacks: 4 Things You Can Do To Keep Yourself…

Read More

HIPAA Tip: HIPAA Checklist – Volume 1

Healthcare cyber attacks - HIPAA security and data protection

The following HIPAA Checklists (more to come!) are intended to serve as reminders and quick references. Additionally, these lists are HIPAA requirements and not to be ignored. Audit active users in all systems and applications containing ePHI Review users’ roles and privileges in systems and applications to ensure least privileged access/minimum necessary Check to see…

Read More

HIPAA Tip: Disaster Recovery Plan Testing

Healthcare cyber attacks - HIPAA security and data protection

How many times have you heard from your compliance expert or IT team that you must conduct Disaster Recovery Plan (DRP) testing? And you think – are they nuts? On the contrary, one of the most important areas to focus on with cybersecurity is testing (at least bi-annually) your DRP. The last place you want…

Read More