IT risks that health care firms can overlook
Health care companies have to consider the Healthcare Insurance Portability and Accountability Act (HIPAA) as well as the Health Information Technology for
While managing sensitive patient data, three important factors need to be considered by all health care businesses: physical, network and process security procedures.
While the physical security procedures might seem more apparent or Intuitive, It's the network security procedures that either inhibit or aid those with criminal minds trying to access PHI and ePHI. Here are some of the network safeguards that should be considered and/or put Into place to prevent unlawful hands getting access to confidential Information.
* Patching: Patching your servers and PCs with automated security updates is a critical security control that is all too easy to overlook as it often happens in the background and without the user's knowledge. Many cybercriminals will look for unpatched vulnerabilities to exploit and gain access to systems. This Is often the method used to Infect users who visit a website with malicious code embedded in an ad.
A solution is to use an automated patching tool or service to ensure security updates for operating systems and common applications are updated on a regular basis.
* Backup: Backup of your data has taken on more Importance than ever with new threats like ransomware. Be sure your backups are running and secured off-site. Not only do you need to protect data from a hardware failure loss or natural disaster, but you also need to protect It from a cyberattack, which could encrypt that data. Your options are to restore from a good backup or pay the ransom which Is now escalating into extortion.
A solution Is to use a business class backup, not a USB drive, for example, and regularly check to ensure the backup is working. Also be sure that backups are stored off site In an encrypted format to minimize risk of a data breach due to lost or stolen backup media.
* Unsupported OS: In the past two years,
A solution Is to upgrade to a currently supported OS, like Windows 8.1 or 10 for desktop PCs. Alternatively, evaluate If your Windows 2003 servers' current function could be better achieved with a cloud solution like Office 365 before upgrading to Windows Server 2008 or 2012.
* Firewall: Another critical IT asset that are oftentimes forgotten because they're hidden In a computer room or closet. Despite the fact that they continue to work seamlessly, regularly evaluate what you have and whether It's up to compliance standards. Most firewalls have two components - hardware and software licensing. If you have had a firewall for more than five years, ask yourself if the hardware is still supported by the manufacturer and if the licensing Is current. If not, you and your network are open to unnecessary risk.
Part of annual IT planning should be understanding the age and licensing requirements of critical network components like your firewall. If you don't know how to manage, check with your firewall vendor. A lot has changed In the past five years and It might be time to obtain a more capable and current firewall.
* Email: There is a growing requirement to encrypt emails containing sensitive personal and identifiable information as well as personal health Information (PHI) from state laws to federal regulations like HIPAA.
A common data breach occurs when an email containing personal information is accidentally sent unencrypted or to the wrong party. An additional risk Is being out of compliance with state laws related to securing consumer information.
If you regularly work with such Information, you need to implement an email encryption solution. The best approach is to have a solution in place which will scan for the Information, thereby forcing encryption.



Report: EPA Lacks Control Over Site Cleanup Programs
Advisor News
- Retirement is increasingly defined by a secure income stream
- Addressing the ‘menopause tax:’ A guide for advisors with female clients
- Alternative investments in 401(k)s: What advisors must know
- The modern advisor: Merging income, insurance, and investments
- Financial shocks, caregiving gaps and inflation pressures persist
More Advisor NewsAnnuity News
- Retirement is increasingly defined by a secure income stream
- Beyond the S&P 500: The case for RILA diversification
- Globe Life Inc. (NYSE: GL) Making Surprising Moves in Monday Session
- Aspida Life and WealthVest Offer a Powerful New Guaranteed Income Product with the WealthLock® Income Builder
- Lack of digital tools drives wedge between insurers, advisors
More Annuity NewsHealth/Employee Benefits News
- Rethinking the ways employers manage benefits risk
- PARENTS FIGHT INSURANCE CAPS ON HOME NURSING CARE IN COMMERCE CONFERENCE COMMITTEE
- CONGRESSMAN CARTER INTRODUCES BILL TO HELP LOUISIANIANS KEEP THEIR MEDICAID COVERAGE
- GLP1s weight-loss drugs may soon be covered by health insurance under new Washington court ruling
- Baystate, Mercy advocate takeover as public worries about ER waits, delivery rooms, Medicare
More Health/Employee Benefits NewsLife Insurance News
- Symetra Names Jeff Sealey Vice President, Stop Loss Captives
- 3 ways AI can help close the gap for women’s insurance coverage
- Best’s Market Segment Report: AM Best Revises Outlook on Italy’s Life Insurance Segment to Stable From Negative
- Globe Life Inc. (NYSE: GL) Making Surprising Moves in Monday Session
- Dan Scholz to receive NAIFA’s Terry Headley Lifetime Defender Award
More Life Insurance News