PHI Security Emphasized
Congressman Tim Murphy chaired a recent hearing on the HHS cybersecurity role. The hearing included a review of two reports that HHS was required to submit to Congress, following the implementation of the Cybersecurity Information Sharing Act (CISA) of 2015. The reports outline the department’s internal cybersecurity processes and industry recommendations for what the federal government and industry can do to improve cybersecurity efforts in the health care sector. The backdrop to the hearing was the “WannaCry” ransomware attack that has hit countries around the world. As with other cyberattacks, ransomware spreads through a phishing attack, which involves tricking email recipients into installing malicious software that encrypts the system and causes users to lose access to their documents. The user is then prompted to pay a ransom in order to have his or her system restored. For health care providers, concern involves not only the business, but also the risk of breaches of protected health information (PHI).
Discussions during the hearing included the creation of the Health Cybersecurity and Communications Integration Center (HCCIC) and the Health Care Industry Cybersecurity Task Force. Both have identified areas in which HHS can and should help improve the nation’s cybersecurity. One of the major challenges is maintaining security across unique platforms and devices needed to provide appropriate and timely patient care. Although the health care and public health sectors have both improved their ability to manage cybersecurity events, maintaining the balance between securing important data and protecting patient privacy needs continuous evaluation and adjustment. The Task Force identified six imperatives:
- Define and streamline governance and expectations for cybersecurity;
- Increase the security of medical devices;
- Create the workforce capacity necessary to prioritize cybersecurity awareness;
- Increase readiness via cybersecurity awareness and education;
- Find ways to protect R&D efforts and intellectual property from attacks; and
- Improve information sharing of threats and weaknesses.
Connect With A Health Care Compliance Expert.Contact Us Today
Health care organizations should consider the following in protecting themselves against data breaches, malware, and ransomware.
- Don’t assign responsibility for cybersecurity to someone at a low level in the organization.
- Ensure software products are up to date with the most recent patches at all times.
- Establish an aggressive patching schedule for all software.
- Implement policies and procedures for precautions against malware.
- Train employees to not click on suspicious email links or attachments, or to respond to phishing inquiries.
- Regularly test users to make sure they are on alert for potential cybersecurity threats.
- Configure email servers to block zip or other files that are likely to be malicious.
- Restrict permissions for database and network access as needed.
- Grant access to systems on a need to know standard.
- Limit employee access to files on a single server to prevent the potential spread of viruses.
- Focus security efforts on those files that are most critical, such as patient records.
- Conduct a risk analysis to identify ePHI vulnerabilities and ways to mitigate them.
- Maintain frequent data backups to permit restoring of lost data in case of an attack.
- Regularly take full snapshots of data and store them offline.
- Monitor email carefully and do not open email attachments from unknown parties.
- Conduct regular systems tests to flag vulnerabilities before a hacker can gain access.
- Develop a business continuity plan to prevent downtime.
- Maintain disaster recovery and emergency operation plans.
- Prevent spread of attacks by disconnecting infected systems from a network, disabling Wi-Fi, and removing USB sticks or connected external hard drives.
- Establish real-time data backups to permit work to continue.
Have Compliance Questions? Contact Our Experts
Strategic Management Services has healthcare compliance experts with years of experience evaluating compliance programs. If you have questions regarding how to protect against cybersecurity attacks or about your compliance program, give us a call at (703) 683-9600 or contact us online.Subscribe to blog