Showing posts with label cyber security. Show all posts
Showing posts with label cyber security. Show all posts

Friday, March 13, 2020

Top two cybersecurity threats facing physician practices

There were 3,139 data breaches reported to the U.S. Department of Health and Human Services between 2009 and 2020. Guanglan Zhan, PhD, professor of computer science and coordinator of the health informatics program at Boston University, highlights four themes among the data breaches. These include:

Data breaches are trending upward. There were 511 breaches in 2019, 371 in 2018, and 358 in 2017.
With 335 data breaches between 2009 and 2020, California is hardest hit. It’s followed by Texas with 276 data breaches and Florida with 192.
Hacking/IT incidents is the top reason for a data breach. There were 941 such data breaches. Theft (at 893 breaches) and unauthorized access/disclosure (at 875 breaches) are second and third, respectively.

While the vast majority of breaches were committed by healthcare providers (2,287), 430 were caused by business associates.

“Small- to medium-size physician practices are vulnerable to cyberattacks as they often have less expertise in IT technology and limited resources in place,” says Zhan. “Large healthcare organizations often have an IT team, while physician practices might have one IT employee who works part time. Despite this, [practices] need to comply with the same set of rules, [namely,] HIPAA privacy and security rules and state regulations, to safeguard protected health information.”


Here are two of the top cybersecurity threats facing physician practices and advice on safeguarding the practice and patient information:



1. Ransomware attacks from external parties
The financial cost of ransomware attacks, in particular, is steep, says Gary Salman, CEO of Katonah, N.Y.-based Black Talon Security, which consults with physician practices on cybersecurity matters. UC Berkeley defines ransomware as malicious software that infects a computer and restricts users’ access to it until a ransom is paid to unlock it.

Salman says most ransomware payments for a single physician average $30,000. In addition, practices need to account for the cost of systems that are down for two to six weeks as they’re being rebuilt and data is recovered.

IT support companies contracted by physician practices are also targeted for ransomware attacks. In fact, some of Salman’s clients have been shut down for weeks as a result of attacks by hackers on the practice’s IT provider, he says. “In many of these attacks, the hackers hit the doctor’s IT company and used the IT company’s remote-access tools to deploy the ransomware to every computer and server they manage in a [physician’s] office.”


This presents a double-challenge to physician practices impacted by the data breach, since their IT provider can’t support the practice because their own business has been hit. “Most IT companies are relatively small and can’t support an attack like this simply because they don’t have enough manpower...to fix thousands of computers that were hit in the strike,” says Salman.

Thus, penetration testing is essential. According to the National Institute of Standards and Technology, penetration testing is used to circumvent the security function of a system to assess its vulnerabilities. Physician practices must do penetration testing, since hackers are testing physician practices’ networks constantly with the explicit intention of gaining access to them, explains Salman.

Billing insurance companies for services provided to patients is one immediate concern with a ransomware attack, says Michael Morgan, JD, a cybersecurity and data-privacy lawyer with Chicago-based McDermott Will & Emery. Without access to its billing software, due to a ransomware attack, the practice can’t send out bills.



2. Employee-related cybersecurity threats
Physician practices can also fall prey to cybersecurity threats by disgruntled employees. This could be an employee who believes they were treated poorly or didn’t get the promotion they wanted, explains Jay Wolfson, DrPH, JD, who teaches health law at University of Florida. As a result, the employee is angry with their supervisor and wants to steal data from the practice.

Limiting access to patients’ clinical information is one proactive strategy for addressing this problem, advises Wolfson. For example, the receptionist and the billing employee don’t need access to patients’ clinical data. Continually reinforcing this policy in quarterly meetings among the leadership team is essential, he says. That’s in addition to educating new managers at the practice during the new employee onboarding process.

The human resources team also has a role to play, advises Jiban Khuntia, PhD, who teaches about information systems and health administration at University of Colorado Denver. Human resources should encourage staff members to communicate about conflict in the workplace so that their anger doesn’t manifest in a negative event for the practice.
Khuntia advises practices to deploy cyber-surveillance software to monitor the behavior of all employees once it has decided to terminate an employee. This strategy can help prevent data breaches when the employee is terminated, he says.

Here’s the approach Khuntia recommends if an employee must be fired: Approximately one week before the employee is fired, the practice should deploy surveillance software that monitors the activity of every team member, not just the employee who is being let go. In addition, all logins and passwords must be changed before the employee is terminated. The best place to house the login and password information is in a physical binder, he advises.

In addition, Salman says practices have to continually train employees about the risk of clicking on links and attachments in emails. When the hacker is successful, they’ll have access to the practice’s network and can compromise the employee’s username and password associated with a device or server.



Embrace paper to prepare for system downtime

Clyde Hewitt, executive advisor at Austin, Tex.-based cybersecurity consulting firm CynergisTek also has some low-tech advice if a cyberattack occurs. Practices need to be prepared to open the office and have none of the technology working. That involves printing the schedule for the several days or weeks, which will inform staff about the patients expected each day.

Depending on the type of practice, access to static data, such as allergies and prior medications, can be helpful, adds Hewitt. “Finally, don’t panic, as physicians and clinicians have been treating patients for centuries before computers. Ensure your staff hasn’t forgotten how.”

15% Off Medical Practice Supplies


VIEW ALL



Manual Prescription Pad (Large - Yellow)


Manual Prescription Pad (Large - Pink)

Manual Prescription Pads (Bright Orange)

Manual Prescription Pads (Light Pink)

Manual Prescription Pads (Light Yellow)

Manual Prescription Pad (Large - Blue)

Manual Prescription Pad (Large - White)

VIEW ALL

Saturday, December 17, 2016

Private Cyber Insurance Capable of Managing Most Risks

PRESS RELEASE

 
WASHINGTON – Cyber vulnerability is a growing source of significant risk for both the public and private sectors that has prompted a market for insurance products capable of managing the overwhelming majority of cyber-attacks firms might face, according to a new policy study from the R Street Institute.
 
The study by R Street Senior Fellow Ian Adams finds the market is growing at a rate of 26 to 50 percent per year. The U.S. insurance industry collected $2.75 billion in cyber insurance premiums in 2015, a total that is expected to grow to $7.5 billion by 2020. Overall industry capacity is currently estimated to be about $500 million.
 
“Encouragingly, to date, policies with $50 million limits would be able to cover roughly 92 percent of cyber-event claims,” Adams writes.
 
However, the study acknowledges that some models place the likelihood of a major cyber event that causes between $250 billion and $1 trillion in damage at some point in the next decade to be between 10 and 20 percent. Given the potential for this sort of “black swan” event, some have proposed a government backstop or reinsurance facility to manage the nation’s cyber exposure.
 
Adams warns policymakers to be cautious about any plan that could dampen development of private solutions or displace private coverage, particularly given the tendency of government insurance programs to inculcate moral hazard, channel funds through inefficient and unpredictable processes, and unnecessarily delay recovery.
 
“What can be assessed for certain is that the cyber insurance market is growing rapidly and that it already has sufficient capacity to cover the overwhelming bulk of events the market already has faced,” Adams writes. “It is also the case that businesses report they are satisfied with their existing cyber coverages. Unlike in the case of terrorism in the early 2000s, there is no evidence that insureds are requesting coverage limits that insurers and/or reinsurers have been unable or unwilling to fulfill.”
 
 
R Street is a nonprofit, nonpartisan public policy research organization whose mission is to promote free markets and limited, effective government. It has headquarters in Washington, D.C. and five regional offices across the country. Its website is www.rstreet.org.

Business Cards

20% Off All Orders!

Linen Business Card w/Logo

Tuesday, December 1, 2015

How to Stop Security Breaches Before They Cost You

 

Image courtesy of (Stuart Miles) / FreeDigitalPhotos.net
 

Too many employees have unnecessary access to high-level data; that is the conclusion drawn by Charles S. Clark in Two-Thirds of Federal IT Managers Fear a Security Breach from Colleagues. (It seems we should have learned this from the Edward Snowden leaks, but apparently not.)

According to sources quoted by Clark: “As many as 63 percent of respondents said they view other employees as the greatest security risk, while fully 92 percent said general employees have access to more information than is necessary.”

Once an employee is granted security access at any level, it is uncommon to monitor what they do with it. Few realize the enormous vulnerability of big data and the more databases are integrated, the larger that risk grows. Nowhere is that more apparent than in health care.


Health-Care Sector at Greatest Risk
According to the Wombat Security Breach Report: Healthcare Edition (November 2015), the health-care sector reported the largest number of security breaches at 37 percent, triple the amount of the retail sector.

Health-care breaches are also more expensive, with an average per record cost of $363 versus an average per record cost across all other industries globally of $154 or less than half.
Points of vulnerability include local hospitals, doctor’s offices and medical centers, insurance companies, and health-care clearinghouses. Health-care breaches tend to be very large and can result in identity theft.

Of 105 incidents from June to October 2015, the causes in order of frequency are:
  • Unauthorized disclosure or access (42 breaches)
  • Theft (38 breaches)
  • Hacking and IT incidents (16 breaches)
  • Data loss (8)
  • Improper disposal (1)

Human error resulted in 1.5 million patient records — including police reports, Social Security numbers, medical service records, and drug test results — being publicly posted on Amazon Web Services.

It is not a matter of if — but when — any business has a data breach. It is imperative that companies have both a plan for prevention and policies in place for immediately responding to any data breach.


How to Prevent Data Breaches
The first step is better staff training: more than 90 percent of data breaches in the first half of 2014 were preventable. Security personnel should be limiting access to data to only those who need that access and immediately removing it when duties change.

All employees need better training on e-mail, social media, and mobile device usage when it comes to protection from phishing and other hacks. Every employee must know not to click on links in e-mails, or to download apps onto their company computer running on the internal LAN. Controlling what apps employees download onto their Smartphones that contain company data is another challenge.

Does your company have a process all employees and vendors have immediate access to in case of theft of their laptop or mobile device? All training required of employees should also be required of consultants and vendors.

If you walked down the halls and asked each employee to whom they would report security breaches and how would they reach them, would they know? Do you annually survey your employees to ensure they are familiar with security practices?

Do they know not to talk directly to the media and to whom they should refer any media inquiries? Read the link immediately above for 12 specific methods for making employee devices safer.


Use a CDN as a First Line of IT Defense
Regardless of the size of your company or IT staff, putting a Content Delivery Network (CDN) between your online servers and hackers can prevent many issues. Some CDNs have a strong focus on security, watching for and recognizing threats immediately.

Although CDNs have been around for years, most people still are unclear of their benefits or even what they are. Imperva Incapsula has produced a comprehensive CDN Guide to explain what a CDN is, the architecture, and how CDN caching works.

CDNs provide benefits beyond prevention of data loss. They can also ensure a DDoS attack does not make your site unavailable and decrease page load times which can lead to more search engine traffic. A CDN is one of those rare services that has a strong upside immediately rather than only being seen as a preventive expense in case of attack.

All types of sites WordPress blogs, partly because of plugins, are being continually hacked. All businesses should have a blog, and it should be protected by:
  • Keeping WordPress, the theme used, and all plugins continually updated
  • A hidden login page or additional pop-up to guard the login page
  • Only permitting strong passwords
  • WordFence plugin to block fake Google crawlers and comment spam bots

Few realize that so many hackers are running password crackers and crawling blog posts with bots that they can impact the entire server a blog is on. The traffic to most sites today – and especially WordPress blogs is 56 percent to 90-plus percent bots.


Act Immediately to Control a Breach
Response speed is critical because attackers are moving more quickly, exploiting zero day security vulnerabilities before most businesses are even aware they’ve been published.

Highly targeted spear-phishing attacks are on the increase as are Trojanized software updates, making it easier to target specific industries and companies. Read the link immediately above to learn more about sophisticated methods being used, Smartphones, wearable health apps, and how the Internet of Things (IOT) increases security complexity.

Custom Business Cards

20% Off!

Linen Business Card Template (Sky)Appointment Reminder Cards (100 pack-White) Business Card Templates
Linen Business Card TemplatePearl Finish  Business Card Template
Platinum Business Card TemplateGold Finish Business Card
Iridescent Pearl Finish Business Card (Style 4)