(781) 916-2284 [email protected]

Back in 1996, Congress passed the Health Insurance Portability and Accountability Act known as HIPAA, which set in motion a variety of changes in the healthcare industry.  This included a set of standards regarding health records as well as security and privacy rules enacted in 2003.  At the core of these rules is securing personal healthcare data, known as Protected Health Information (PHI).   In 2013, with the passing of the Final Omnibus Rule, HIPAA security rules were updated and penalties for violation of PHI privacy requirements were made more severe.

 

For many hospitals, doctors’ offices, and other healthcare providers and insurance companies, addressing security and privacy have been a growing concern.  While many of these practices were new to organizations in the early 2000s, most have developed basic practices that address the rules.  However, over the last decade, security threats have become significantly more prevalent and advanced.  To make things worse, it’s not just the big organizations that are under attack.  Small hospitals, medical groups, and stand-alone practices are also being targeted and getting compromised.

The HIPAA privacy and security rules are enforced by the Health and Human Services (HHS) Office of Civil Rights (OCR) and they issue annual guidance.  Currently, it’s required that all “covered entities” perform an annual Security Risk Assessment (SRA).  There is a lot more information on what is included as part of the privacy and security rules, but that’s probably a topic for another blog. 

 

The fundamental essence of the security and privacy rules is to protect individuals from electronic healthcare information being shared with those that should not be seeing it and that control of that information is decided by the patient.  While poor practices by a medical professional may allow certain people to gain access to records, a greater risk are cyber-attacks, whereby external bad actors gain access to large amounts of data, control or damage information systems, or execute ransomware attacks.

Major breaches, including an increasing amount of ransomware attacks, have been plaguing the healthcare industry. According to IBM’s latest “Cost of a Data Breach Report”, data breaches in healthcare cost organizations an average of $10.1 million each.  Add the fact that over 600 breaches affecting more than 500 people each have been reported so far this year by healthcare organizations, it is a scary realization. The likelihood and impact to you is real and expensive.

 

With the increase in concern over these attacks, the White House has announced they are looking to add minimum-security standards for healthcare organizations.  While the HIPAA and HITECH security and privacy rules already exist, this means additional requirements, higher standards, and increased auditing and penalties are most likely coming soon.

 

Specifically, Anne Neuberger, the deputy national security advisor for cyber and emerging technology in the Biden Administration, stated at a recent Washington Post Live event that the healthcare industry is one of the next three cybersecurity focus areas for the White House.  Neuberger explained that through the HHS there are plans to “put in place minimum cybersecurity guidelines and then further work upcoming thereafter on devices and broader health care as well.”

 

For most organizations, if you are performing a proper security risk assessment at least once a year and addressing your vulnerabilities, you are probably in good shape for what’s next.  The real problem is that many organizations perform an SRA simply meet the requirements as opposed to truly using it to better their organization’s security posture.  For many, it is time to take a more aggressive approach to the organization’s security practices and put in place processes and technology that will achieve much greater protection.

 

With ever-increasing attacks, the requirement to publicly report any and every breach, increasing fines, and the OCR becoming more aggressive on audits, it is time to take healthcare security very seriously and make it a priority for your organization.  The best way to get started is by performing your next SRA and ensuring that it is conducted thoroughly and by security experts to truly move you forward.

 

If you need assistance with your next SRA, contact ClearBridge Technology Group here for a free consultation. 

 

 

 

 

 

 

 

 

 

 

 

New and experienced players alike appreciate Zizobet Casino for its simple navigation, secure payments and fair conditions.
Make your free time more exciting with Vibro Bet, combining a friendly interface with a rich selection of casino entertainment.
For many online casino fans, Lolajack Casino quickly becomes a regular stop during their gaming routine.
Molti giocatori italiani cercano piattaforme affidabili dove poter prelevare le vincite senza attese infinite, e tra le opzioni più apprezzate ci sono i casino non aams prelievi veloci che combinano un catalogo di giochi ampio con tempi di pagamento ridotti.
Regulars who track UK casino welcome packages usually weigh bonus terms, withdrawal turnaround, and the variety of game studios, and Kingdom Casino comes up often in those side-by-side comparisons.
Outside the UKGC framework, ModernGhana Malta online casinos accepting UK players have carved out a niche by combining MGA oversight with payment methods, game catalogues, and promotional structures that feel familiar to British players while sidestepping GamStop restrictions on sign-ups and deposits.
Wie graag af en toe een gokje waagt, weet dat het loont om verschillende aanbieders met elkaar te vergelijken voordat je ergens een account aanmaakt. Een relatief nieuwe naam in het Nederlandse landschap is kiki, waar spelers terecht kunnen voor slots, live tafels en een ruim welkomstpakket. Voor beginners is het verstandig om eerst de bonusvoorwaarden goed door te nemen en te letten op de inzetvereisten, zodat je later niet voor verrassingen komt te staan. Ervaren spelers kijken juist vaak naar de snelheid van uitbetalen en de variatie aan spelproviders, en ook op dat vlak lijkt dit platform behoorlijk competitief te zijn.
Nederlandse gokliefhebbers vergelijken steeds vaker de bonussen en het spelaanbod voordat ze zich ergens registreren, en daarbij valt SpinCHESTER Casino regelmatig op door de snelle uitbetalingen en het brede assortiment aan videoslots.