3 Steps to Become HIPAA Compliant

Watch to learn how to start your Risk Analysis and Risk Management Plan and how to get HIPAA compliant in 3 steps.

Updated:  
November 22, 2021

Having issues accessing the video above? Watch the video here.

HIPAA Security Rule Best Practices

In this webinar, SecurityMetrics HIPAA Fulfillment Manager Ryan Marshall, HCISPP, covers:

  • Tips to start your Risk Analysis and Risk Management Plan
  • How to get HIPAA compliant in 3 steps
  • HIPAA compliance best practices

This webinar was given on October 19th, 2016.

3 Steps to Become HIPAA Compliant Transcript

Alright. We're gonna go ahead and get started.

Thanks again for everyone's attendance today. We're excited to be talking to you today about HIPAA compliance.

The webinar today is three steps to become HIPAA compliant.

Our presenter will be Ryan Marshall, who is a HCISPP, which is a health care information security and privacy practitioner, and he's our HIPAA fulfillment manager here at Security Metrics.

Ryan's been working at Security Metrics for eight years and has a lot of experience helping organizations of all sizes, technical knowledge, general needs. So we should be able to get a lot of great information from him from his experience.

Before we get started, a little bit about security metrics. We've been helping organizations comply with mandates, avoid security breaches, and recover from data theft since two thousand. So we've been around a long time. We've been in different industries, helped a lot of different companies, and really have been involved in creating even some of these guidelines and best practices.

Before we before I go into the agenda, just a few housekeeping items. We get asked a lot. Will a recording be made available? Can we get the slide deck? We will be sending out the recording in the next few days as well as the slide deck for your review or to share internally or with anyone else. So we get that question a lot. I just wanna make it clear that we will be sending that out.

And we will also be leaving some time for q and a at the end end of this. So if you have questions throughout the webinar, please just chat in your questions, and we'll address as many as we can at the end. If we're unable to get to any questions, we can reach out to you on an individual basis after.

So today, the agenda is the importance of HIPAA compliance, how to get HIPAA compliant in three steps, and HIPAA compliance best practices.

So with that said, I'm gonna turn the time over to Ryan and get into the presentation.

Thank you, Colin.

So I'd like to start off with doing a little bit of background.

HIPAA is thrown around a lot, but we generally think of it as this massive piece of government legislation.

And and sometimes the intent of what it's for and what its purpose is is is misunderstood.

So the the primary intent of HIPAA is to just create interoperability among systems, create unified code sets, national provider identifiers so that the health care can exchange information freely, health care entities can exchange information freely for treatment and payment purposes.

What we generally think of, with HIPAA is the privacy and security portions, which is just one small piece of HIPAA. It's in title two in the administrative simplification provisions.

So I'd just like to break it up into a few pieces because we're only gonna talk about a couple of them today.

So HIPAA is is obviously overseen by health and human services and enforced by the office for civil rights.

In the, in the privacy and security portions, which most people associate with HIPAA and what we're gonna talk about today, it's broken into four pieces. The the four pieces of the privacy and security portions are the privacy rule, which was implemented in in two thousand, was kind of the start of everything, and established the groundwork. And then the, security rule was was, established in two thousand and three, then the breach notification rule in two thousand nine, and then finally, the omnibus rule in twenty thirteen.

This this portion or the this presentation is mainly focused on the security rule.

But I wanna go over a little bit of what entails, some of the other things.

One of the common questions I I get, from people when they start in their HIPAA compliance activities is what is HIPAA? How many requirements are there? What how many of them apply to me?

To answer that question, in the privacy and security portions of HIPAA, there's a hundred and fifty seven total requirements. There's, seventy five of those are the security rule requirements, ten are breach notification rule requirements, and seventy two of them are privacy rule requirements.

The omnibus rule didn't really add any new requirements. It just changed some key definitions and modified some of the existing requirements.

Since since my presentation is gonna be focused on security, I do wanna take a little bit of time to separate privacy from security, because they are different approaches to protecting patient data. I kind of look at security as the security rule is a way in an electronic environment to make sure that the privacy rule is actually upheld.

In my experience, most most entities haven't separated, security from privacy. Most of the people that I deal with actually don't know that the security rule even exists.

They their HIPAA compliance activities are usually, confined only to the privacy rule.

So I wanna just explain the differences between the two a little bit.

The privacy rule established what patient's rights are and what, covered entities responsibilities are in handling data. What a patient has the right to do with their data, what they have the right to request, how they can access it, and what the covered entity is supposed to do in in regards of keeping that private, who they can disclose it to and for what purposes.

And it it primarily deals with, with physical and verbal matters.

The security rule strictly deals only with electronic protected health information, and the security rule is basically the way the way to apply standards to protect the data. So, we talked about these generalized rules and the privacy rule of how data needs to be kept private. The security rule in an electronic environment is how to actually accomplish that.

So why should people care about HIPAA?

There are a lot of scare tactics, in this industry. I'm sure that everybody that's listening to this has been told how they're gonna be breached and told how they're gonna be fined, and the OCR is gonna come and get you. And I know that that probably wears a little thin hearing that drumbeat beat so much, but I but I think the reason that it is beat so much is because there's a lot of denial, in this industry when it comes to HIPAA. I I think that, the environment has changed in the past fifteen years, and I don't think people understand what risks they're running.

So people try and use the scare tactics, to create motivation for becoming compliant. But there is other reasons as to why it's important to become HIPAA compliant. And the reason I always like to focus on is, health care in general is a is a philanthropic endeavor. I don't think anybody gets into health care specifically just to make money.

There's a lot of easier ways to make money. I think they do it because they wanna help people.

Even take an oath and the Hippocratic oath to do no harm to your patients. And I just think that there's a a misunderstanding that compromising someone's data does cause a great deal of harm to the patients. So I think we should care about HIPAA for the same reason that we care about patient health care, and then we care about the types of service you're providing your patients. No health care provider I've ever talked to would ever perform, or provide treatment that was going to, either by negligence or by intent, harm their patient. They would do everything in their power to avoid that. I think it's just time that we see HIPAA as as a part of that.

So now that I've explained the other part, I have to get into a little bit of the scare tactics.

Only because I think that there there's a misconception of I I hear all the time, I've never been breached. I've been in business for twenty years, and I've never been breached.

First of all, that's probably untrue. The Pointe Mon Institute did a study that found that ninety four percent of practices have suffered some form of breach, in their lifetime, and forty five percent of those had suffered more than five breaches in the last two years. I think that this misunderstanding comes from a misunderstanding of what the term breach actually means.

To have a breach doesn't necessarily mean that someone hacked your network or that you lost a device, which is what most people would associate it with. But any unauthorized disclosure of protected health information is constituted as a breach.

Sending a letter to the wrong address with billing information or any kind of medical charts could could be constituted as a breach. So this the the scope is much larger, I think, than most people think. And then the other part of it is in in the last, excuse me, in the last five years alone, there's been an exponential increase in the desire to breach health care information. It's becoming increasingly more valuable. So whereas maybe in the early two thousands or late nineties, people weren't looking to compromise health care data in the same way that they are now. The it far outpaces financial information as the as the highest value target for data thieves.

Also, if you if you are ever breached, they are very expensive.

Once again, I don't think the primary purpose for being HIPAA compliant should be to avoid breaches or penalties. I think it should be to protect your patient's data.

But I just wanted to spell some myths with this.

We hear about breaches and we hear about the wall of shame, OCR's wall of shame, and those are generally larger entities. And the ones that get publicized are almost always large entities, and it creates this line of thinking that that can't happen to me. Those astronomical fines can't happen to me. But health care records are the most have the highest breach related cost per record of any type of data in the world.

It's about three hundred and sixty dollars per record is the average cost for a breach. So if you do the math on that, if you have five hundred records that get breached, which almost everybody I've ever talked to has five hundred records. If you have five hundred records that get breached, that could easily cost you two hundred thousand dollars. So it it is expensive on top of the unforeseen fact that about studies are showing about forty percent of your patients will walk away from your practice and never come back, if if a breach happens.

So the long term effects can be damaging. The Ponemon Institute averaged it. The, breach related cost to an entity over two years is around two million dollars.

So, there's a little bit of, motivation to avoid that type of stuff as well.

So now that I've gone through the, scare tactics and hopefully you're sufficiently motivated and scared, we can talk about what you can do to get compliant.

We have this title, this three steps.

I I do wanna make it clear that there is a lot more than three steps to to getting HIPAA compliant. So don't think that this is just a a one, two, three, ten minutes and you're done thing. But as far as complying with the security rule, there are three basic pieces of it that you need, to to enact, and each one of these pieces will contain multiple steps inside of them. It is a a fairly extensive process, but I don't think it's as hard as as most people think.

Excuse me. The three steps are you need to conduct a risk analysis. You need to use that risk analysis to develop a risk management or risk mitigation plan, and then you need to put that plan into action. So I wanna talk a little bit more about each one of these three pieces and, some important parts of of how to implement them and what they are.

So first, let's go over a risk analysis. A risk analysis is the foundation of any data security process.

If you look at at NIST standards or anything, a risk assessment procedure is is the foundation of data security.

And while a lot of HIPAA is very vague and and general and ambiguous, risk analysis and the requirements for them are not. They are very specifically spelled out in HIPAA that you must conduct a risk assessment process annually, at least annually.

So I've heard a lot of, attempts to scope themselves out of this requirement. Like, you know, we don't do we don't do business with a clearing house, so we don't we don't have to do a risk analysis. We don't use any business associates, or we don't email any patient data. One thing I wanna make clear is that if you handle patient data in an electronic format in any way, and I wanna format in any way, and I wanna expand the the definition of protected health information isn't just medical records.

It isn't just social security numbers. It is first name, last name. It is their address. It is any identifying number that could be associated with them.

There's eighteen components that could make it up. So almost any piece of information about an individual is considered protected health information. If that is housed in an electronic system for scheduling, billing, for any purpose, then you are subject to the security rule and you are required to take a risk and or to complete a risk analysis annually.

When you start off doing a risk analysis, I think the first step is to just scope yourself. You need to understand what types of PHI you have, how much of it you have, where it's stored, where it's, transmitted, what systems are interacting with it, what personnel are interacting with it, in what way. You just need to get a broad overview of, you know, how you're handling PHI and using it within your organization. And that's the first step to start to identify what what activities that are involved in that are high risk, low risk, or or need to be addressed.

One of the most valuable parts of this is to interview personnel. If you're in an organization, no one person really knows all the ins and outs of every piece of of happenings and goings on in an organization.

If you talk to people in different roles and different, responsibilities, they can give you a a good insight as to how they interact with PHI, what systems they're using, who they're sharing it with, who they're sending it to, who they're getting it from. It can give you a a a much clearer picture of the role of information inside your organization and your daily functions.

Once you have established your scope and and and and know how you're using PHI and and what types of it you have, you need to identify threats, risks, and vulnerabilities.

To put it simply, I guess, a vulnerability is a is a flaw in a system or a component or even in a person that could be exploited or triggered in order to, corrupt data, to corrupt the confidentiality, integrity, or availability of data.

A threat is a person or thing that could trigger a vulnerability, and a risk is the probable is the combination of the two. It's the probability that any particular threat will, trigger any particular vulnerability and what the impact of that could be.

When you're when you're identifying, threats and risks in your environment, some tools that you can that you can use to help you is external and internal vulnerability scans.

A lot of people view these as some type of hacking tool, but they're they're nonmalicious. They are just diagnostic.

They will check thousands and thousands of configurations and software programs, check your hardware, see if you have open services that shouldn't be there, out of date software versions. A lot of things that, to do manually would take a long time. A penetration test is is basically a vulnerability scan on steroids, and it includes an actual white hat hacker, which will try and exploit vulnerabilities in a non malicious way, to to execute them and make sure that they exist in your system.

And then, virus scanning is also very important.

And while I'm here talking about virus scanning, I there's three things I always address with with people when they're engaging in their HIPAA compliance activities for the first time, and that I call them the three easy wins of HIPAA.

A lot of people will have varying ideas of what their compliance level is, what they currently already have in place. But there seems to be three things that almost everybody I've talked to always thinks that they have in place and that they're good on. They don't wanna go over those because we're solid here. I'm not worried about that. And the first one is is antivirus.

And the reason I bring that up is because I've almost I've rarely talked to somebody who if they if they they have antivirus, everybody does, but they generally don't have a commercial grade version of antivirus that is updated regularly. If they do have a commercial grade version, they're not running the scans daily. And if they are running the scans daily, they're not doing anything with the reports. So, all three of those things need to be in place to have adequate antivirus that you're actually utilizing properly.

Sorry. That was a little sidebar.

Once you've determined, or identified what risks and threats there are, you need to prioritize them based on some type of level, and that's a combination of what the probability that the risk could be triggered and what the impact could be. As a security professional, I always look at this strictly from, from risk level. If if it's a high risk behavior that's a high probability of being exposed and could have, some pretty critical impact if it is, I place that in high priority, but I don't take into account the financial impact of actually mitigating the risk. So if you're doing an internal risk assessment process, the organization, you can factor that in on on what it's going to cost. And I know that that budgetary concerns are going to be a a real world factor in what risks get dealt with and and what don't.

Once once you've assigned a risk level and you identified all your risks and completed your risk analysis, you need to make sure that it gets done at least annually. And when I say at least annually, I mean that no matter what, you have to do it once a year, but you also need to review it and update it if any significant changes occur in the environment. Any new systems are added to the network, any personnel changes or process or procedure changes that need to be accounted for and identified in your risk analysis to see if that changes your risk profile.

Then you move on to the the risk management plan. And a risk analysis is there's no recommendations on treatment. It's just it's simply just identifying problems. These are the problems.

These are how bad they they are. A risk management plan is the part where you start to get in and and develop a plan on how you're going to deal with or handle that risk. It, also is very specifically defined, in the security rule that you need to conduct a risk management process. The specific verbiage is on the slide here.

You need to create security measures sufficient to reduce risks and vulnerabilities. That's straight from the security rule.

When you're doing a risk analysis or risk management plan, it's just a process of creating action items, milestones, tracking your completion dates, and your progress for how you're dealing with or handling the risks that were found in your risk analysis.

When you are coordinating or coming up with a plan for for how you're gonna deal with each risk, you need to develop a strategy. And there's there's four generally accepted strategies for treating risk. And I'll go over each one and just give you a little bit of an explanation on on each one.

The first and the best one is called risk avoidance.

Risk avoidance is the only way to eliminate all presence of risk, and that's because you eliminate the action that caused the risk in the first place.

So if you were, you know, emailing PHI and then you just decided that you didn't actually need to email any PHI and you didn't need to send those emails to patients or to anyone, then you could just eliminate that activity, and that eliminates all of the risk, involved with that activity.

Risk avoidance can't be practiced, most of the time. Only in certain situations can it be implemented, but it is the most effective way to deal with risk because it completely eliminates risk.

The second is risk reduction or some people call it risk mitigation, which is saying, okay. This risk exists. The activity has to be there. We need to do that, but we want to lower the risk to the minimum amount possible.

This is the most common, risk treatment strategy that people employ because especially in health care, because of the saturation of data through the network and the interchange of data. There's just a lot of risk that has to that has to be present. So risk reduction is probably the main, strategy to employ for most things. And then you have risk sharing, which is sometimes is what we use business associates for.

If you don't wanna deal with the risks of backing up and encrypting, or or dealing with data backups and and encrypting those and making sure that's secure, you can hire a company to do that for you. However, it's important to note that, in a risk sharing or transfer its process, all risk can never be transferred onto a business associate. You can transfer some of the financial risks by executing, proper business associate agreements, but you will always hold the reputational risk yourself because you are the data owner. As the data owner, you always are the ultimate responsible party for what's going to happen to that data.

And then the fourth and the least common, utilized strategy is called the risk acceptance or retention.

And that's where you just say, I know this risks, is present, and I'm not going to do anything about it. There's there's very few incidents where this is an appropriate strategy.

And if you had a a website that was just informational only, gave your office hours and some background information on the clinicians that work there and the staff, and treatments and or services that are provided. But it had no protected health information, and it had, you know, an SSL certificate vulnerability on the website. That would be something that you could employ risk acceptance for. You say, okay. There's no impact to PHI. We understand it's not the best practice, but we're just gonna leave that be because financially, it just doesn't make sense to fix that.

So the the other three are are gonna be the main three that you you should employ for most risks.

And you need to figure out which one of these strategies is going to be best to treat each risk.

It's important that you that you track this in some sort of documentation.

You can use a lot of people just use spreadsheets, but any way that you can document your risk management process, what the risk is, what your what your strategy is. You'll also wanna document any milestones and achievements that you have.

Even when people are involved in pretty heavily in compliance activities, one of the one of the common mistakes that gets made is that they don't document their progress, which, you know, engaging in in the risk management process is the way to make your your business more secure.

But the documentation is the way that you prove, to interested or invested parties that you have actually done it. So it's it's important to to make sure that you don't do one without doing the other.

In a risk management process, it's very important to designate, stakeholders and people that are responsible for it. So there's going to be time. There's going to possibly be money and resources and personnel that are going to be involved in this. It's important to identify who needs to be involved in it, and assign them the responsibilities, for implementing the tasks that are identified in the risk management process.

So once you get through with all of the hypothetical, parts of this, you actually need to put the plan into action. And the first step of putting any plan into action is to assign someone to be in charge of it, and this is going to be the security officer. It's also a specific HIPAA requirement that you need to have both a privacy officer and a security officer. They they can be the same person, but their duties are separate.

And a lot of the the common mistake I I see in this with organizations is that they'll assign their IT guy to be their security officer, but most of them don't have in house IT. They're using a third party, IT company.

And if you're using a third party IT company, the IT person should never be your security officer. While they may be, play an integral role in implementing a lot of the items, because of their knowledge and skill set, they should not be the overall responsible person for security because they only deal with one aspect of it. They can't control policies and personnel changes and things like that. So it needs to be an internal person, usually a a manage, somebody in a managerial role. That should be the security officer. Now the security officer doesn't need to be the person that implements every item, but they do need to be the person that is overseeing the implementation of items and setting out assignments to other personnel.

IT guys also, as a side note, and I people always view this like I'm bashing on IT guys, and I'm and I'm really not. They play a very important role in this, but IT, professionals are not security experts. They have a very vested conflict of interest that that stops them fulfilling that role most of the time, and their main role is to make sure that the network functions and that your systems function and that they're efficient, and and people can use them. And sometimes security will run directly contradictory to that.

Sometimes security is inconvenient, and it will upset people because it makes processes less efficient. There needs to be somebody that can play the bad cop and say, no. This needs to be done for security purposes. And sometimes the the IT person is not is not able to fill that role.

So it is important to have those duties separated. Security is a separate discipline from IT, although they are dependent upon each other, I would say.

Implementing a risk management plan or mitigating risk is going to look different. It's very dynamic depending on what is already in place, what the environment consists of. And so I just wanna kind of spend the rest of the presentation going over some best practices on things that I wouldn't call them necessarily the the minimum things that you would have, that you would wanna make sure that you have as far as security goes, but they are definitely some of the higher bang for your buck items, things that are not, incredibly difficult or expensive to implement that you get a lot of, increased security and reduced risk out of.

The first is, protecting PHI when you are not around. The the way that you do this is with screensavers, and and lockouts.

So most people are are familiar with using screen savers, and and do it pretty good. You make sure wanna make sure that you set those to lock the the screens on workstations and computers no more than about fifteen minutes is what I generally advise.

But the second layer that goes behind that is account lockouts. And that's if you're using a a practice management system or an electronic health record system or any kind of technology, you don't want those accounts to just stay active forever. You wanna set a lockout period so that if someone isn't using it, that it locks them out. If they it it's just creating a second layer of security if someone does forget to lock their screen and and is away from their computer for a little bit, someone would have to authenticate, also with with the secondary program on the account to access PHI.

Strengthening physical security. A lot of times, we just associate physical security with, you know, locks, and and that is a part of it, making sure someone can't break into a building. But most commercial buildings have pretty good physical security measures as far as as locks on the doors and cameras and security systems.

The one part that gets overlooked is personnel security.

I'm gonna go over social engineering here in a little bit, later, but one of the main components of social engineering is to pose as someone.

So being able to represent yourself as someone that you're not and being granted physical access to an area that that they shouldn't have is a is a way to easily bypass any technological safeguards that you have in place. You have the most secure robust system and firewalls, and security systems in the world. But if you let me into your server room, I can bypass all of that. So it's important to keep visitors logs, know exactly who people are before you allow them into secure areas. If you it's it's sometimes it's looked at as being impolite, but that's okay.

It's not impolite to just verify who someone is before you allow them access and to also make sure that your public areas are separate from areas where sensitive data is being handled on workstations or in a hard copy format, or where, you know, server rooms or main control rooms are housed.

Another thing that you need to do is ongoing security assessment. I talked a little about this with antivirus. You need to run antivirus scans every single day. You need to run vulnerability scans. I would say quarterly is is best security practice.

But to have some type of ongoing effort to continue to identify possible threats and vulnerabilities in a system in order to to correct them. One of the most common forms of this is, updates and patches.

A lot of times, everybody's familiar with the operating system updates that you get. Every system, including networked medical devices sometimes have firmware updates. You know, if you have an X-ray machine or a digital imaging machine, a lot of times those will have firmware updates that need to be applied as well too.

A lot of times, updates are just bug fixes where they have some cool design feature or, you know, increase efficiency of use. But a lot of times, they have critical security patches that are involved in those too. So if you do have the option to set auto updates on your antivirus on your operating systems or or common systems that have auto update features, that's the easiest way to do it. But there needs to be some type of oversight process to make sure that's being done regularly.

Training staff is another big one, and this is the second easy win of HIPAA that I go over with people. Everybody that I've ever talked to holds some sort of training, for for HIPAA, but they generally just do it once a year, and they generally only do privacy training. Security awareness training is fairly rare. I wouldn't say extremely rare, but fairly rare, in the medical field, and it's never done often enough. Doing anything once a year is not enough to reinforce it, and it definitely doesn't create a mindset or a culture information because your employees can bypass all of your security measures since they have access.

So training is extremely important. It doesn't need to be some long, hour long boring diatribe about HIPAA like like maybe this is.

But it can just be five, ten minute quick training sessions once a month to discuss one area of security. You can talk about phishing. You can talk about making sure that you verify people's identity before you allow them in. You can talk about just little teeny aspects of security that reinforce, and create a mindset in your staff that, hey. I need to be pay attention paying attention to these things. And then more than just making sure patients sign a notice of privacy practices or sign an authorization form or making sure that I I know the party is authorized before talking to them about patient data. There's there's more that goes into an employee's responsibility in securing data than just those things.

Phishing is an example of social engineering, and I I will go over other forms of social engineering in the next slide. But phishing is by far the most prevalent and common form of social engineering and will be encountered by employees, by far the most. And so I felt like it deserved its own discussion.

Phishing is a source of aggravation for me because it is one of the easiest things to avoid. I I I it's the cons that go on in phishing scams are not even good. They're not well thought out. They're usually done by a bot. It's it just involves not letting people act on their own senses. You need to have policies and phishing training with employees, and and this can be easily avoided.

Phishing scams are usually have something that's odd about them. If you receive a phishing email, it usually will have an incorrect URL. It will usually contain some type of unsolicited request for information, have attachments that where there just shouldn't be an attachment, come from people that you definitely don't know. They'll want you to click on URLs or or do things that a a trusted person that you deal with in business, whether it be a customer or a business associate, just generally doesn't engage in those activities. So if it seems suspicious, reply back to them. You you can't inst you're not gonna install malware or a virus just by simply replying back to the sender to request more information. If somebody sends you an attachment, and you don't know what it's for, don't open the attachment.

Email them back and say, why are you sending us an attachment? What is this in regards to? And the the honest part about phishing scams is most of the time, they won't reply. If they do reply, a lot of them originate from other countries of origin, and they don't have English as their first language, so there will be dialectical differences.

And the more that you engage, a phishing scam, through email, the more that they'll expose themselves if they even respond at all. So this is the most easy thing to avoid. I personally dealt with a customer who, installed, the CryptoLocker virus, if anybody's heard of of ransomware, and called us asking what they should do. And they were left with a choice between paying twelve hundred dollars to a criminal who had infected their system and encrypted their entire server under the hopes that they would be honest and give them the encryption key and give them access to their system back or restoring it from backups.

And what they eventually ended up doing was deleting their entire system and restoring from backup, which shut them down for five days. It was a very stressful, and time consuming process. And the person that did this was not a criminal. It was an employee in the organization that just didn't know to not open an attachment from, from an unknown center.

So there's my diatribe on fishing.

Other forms of social engineering, I've gone over posers, and another one is just info gathering through through phone calls. One of the most famous social engineers in history is is Kevin Mitnick. He used to do phone freaking with AT and T, back in the eighties. He was the first person to ever be federally prosecuted for hacking.

One of the one of the most common things that he did, and this is something that nobody ever realizes, but if somebody either comes into a business physically or calls over the phone and is starting to ask for information about the business or ask about employees, don't answer them. Ask them what their purpose is in wanting that information, and then be a little bit of be scrutinized about it. Social engineers always play on people's, tendency and wanting to be courteous.

We can still be courteous while maintaining common sense at the same time. And a lot of times when people are asking for Kevin Minnick said his favorite piece of information to ask people for was employee directories. If you gave him an employee directory, he could get anything he wanted after that because it allows him to say keywords that build trust. They can once they know the employees that work in an organization, they can make other phone calls and say, hey. I'm just calling in for Barbara.

I'm she just told me that I needed this piece of information.

That combined with other innocuous pieces of information, can build trust. So once again, always verify who you're talking to and what their purpose is. If somebody's claiming especially if they're claiming, to be somebody that should be trusted, like an IT person that's coming in to do maintenance, or if they're wanting access to either data or to areas that contain data. They always need to just take a moment and verify who they are.

We talked about physical security a little bit previously, and the only thing I wanted to rehash with this is that whatever physical security measures are in place, whether they be door locks or locked filing cabinets or locked server room, nothing is impenetrable, obviously, but they need to be able to stand up to at least a first wave of attack.

Right? People shouldn't be able to kick a door in, easily. They shouldn't be able to pick it with, they call it, you know, the cheap butter knife or things like that. And then another form of physical security that I didn't cover that is often overlooked is destruction of physical data.

Dumpster diving is a really easy way to bypass security measures. So if you do have physical data, make sure that that's being crosscut, shredded, burned, or pulled before it is disposed of.

And then also tailgating, employ physical security measures where people that have access to secure restricted areas have either a key or an RFID badge or some token that will allow them access and that visitors are assigned temporary badges, and then there's a process for that.

At my company, we use we use RFID badges, and sometimes I'll come in. We have our elevators are secured. Sometimes I'll come in and people will just say, hey. I I need to ride up to the third floor. Can you just badge me in? And I always say no. I'm not going to tell you, and they always give me a weird look.

But, that's just once again, it's not being discourteous to employ good security practices. It's just your job and what you're supposed to be doing.

Everybody needs to have individual user accounts. I come across a lot of times, especially with the HR programs where people are using, shared access and shared accounts. It is incredibly important to have individual accounts both for accountability purposes and for auditing and logging purposes.

I'll go user based and role based access also is dependent upon each user having their own account. I'll go into that in the next slide a little bit more.

But credentials are only secure. If you're using a username combined with a password, to authenticate yourself, that's only secure if only one person knows it. And if another every every other person that you add into that equation that knows that information makes that authentication, information exponentially less secure.

So each person needs to have their own user account for that, plus you wanna be able to track what employees are doing, what types of access to systems they have, what are they doing with that access.

You can identify a lot of high risk behaviors, in in employees or or users on a system and then address those before they actually cause any problems. But if if it's on a shared system, you don't know who is the problem in order to address it.

Also, remote access. This is a a little add on to this slide is remote access is a unique form of access.

There needs to be separate user accounts for the remote access. That's very common. People use a shared remote account.

Remote access is extremely high risk, and not only should they have an individual, user account, but it should be implementing multifactor authentication, with that access as well, either a biometric, authentication method like a retinal scanner or fingerprint or more commonly just using, something you have like a token, a USB drive, a unique code that gets sent to your cell phone, something, to log in to remote accounts. It's if remote accounts or sessions are compromised, it's the keys to the kingdom. So it's a very high risk behavior that can be secured pretty easily if you follow the the appropriate processes.

Role based access. If if anybody has has dove too much into the privacy rule, you've heard about minimum necessary.

Role based access is is is perfectly in keeping with minimum necessary. You should not give more access to a person than what they need to perform their job duties.

Obviously, like I said, this is dependent upon each user having their own account so that you can actually determine and separate their privileges.

And this doesn't need to be done by by each individual, just by roles. Maybe a a a receptionist doesn't need the same level of access as an office manager that doesn't need the same level of access as a doctor.

By reducing access, you can avoid a lot of risk that gets created by them having access that they don't need.

So in conclusion, the takeaways, if you're going to take anything away from this webinar, is, assign somebody to be in charge of your activities and hold them accountable for being responsible for those.

Assess what your risks are at your business, conduct a risk assessment process, then develop a plan on how how you're going to deal with that. And realize that everything doesn't need to be done right now. Just make sure that you're setting targets and completion dates and goals and that you are checking them off as you go through them. Sometimes the compliance process can take up to two years, to complete, and that's there's nothing to be worried about, with that. The only thing that you really need to be worried about demonstrating is good faith compliance, which in essence is just making progress.

Train your employees. They can be a great risk to your organization, but they can also be a great benefit in helping secure patient data if they and I think that employees want to do the right thing. They just need a little bit of prodding sometimes. And then, document, document, document. Also, that's the third easy one of HIPAA. I forgot to bring that up.

The third easy one of HIPAA is that everybody thinks they have policies, but, generally speaking, they only have privacy policies, not security policies. So make sure you have all documents, and then make sure that you have, all the policies associated for all of your activities, not just what your privacy rules or privacy policies are.

So now, we have a little bit of time where we're gonna open it up, for some questions.

Thanks, everyone, for attending. We're gonna move into the q and a. So as some questions come in as we're as we're getting them, I'm just gonna do a reminder as we had it asked a few times.

We will be sending out a recording of the webinar, so be watching for that. We'll just send it to the email address that you used to register for the webinar. So all registrants of the webinar will receive a recording.

So just a reminder of that to watch the next few days.

We're getting a lot of good questions, so I'm just gonna move into those and have Ryan address them. So, Ryan, you talked about privacy and security officers. Are privacy and security offer officers also required for business associates?

Yes.

The omnibus ruling of twenty thirteen expanded the responsibilities of a business associate to be identical to that of a covered entity. The only difference that, comes up with business associate environments is scope. In a covered entity environment, generally, health information is going to be involved in in almost every activity. Whereas in a business associate environment, it can be much more limited. They may only be involved in one aspect of the business function, but you are still required to comply with all all relevant privacy rule regulations and all relevant security rule regulations.

Great. And staying along the officer line, what kind of background should people be looking for in a security officer?

Honestly, there and this is one of the questions that comes up actually quite a bit. Your security officer doesn't necessarily need to be a security professional. You can have them you can hire a a consulting firm to be your security professional. The the most important quality in a security officer in an organization is that they have the power to carry out change and to enforce things.

But they have an overall high level knowledge of how the organization functions, and then they have the power within that organization to affect change to and they don't need to be the top level person, but they need to be in a position to to delegate, things out and implement procedural changes. So they don't need to be a security expert. I know a lot of people like to have, you know, a certification like an HCI, SSP or CHP.

But there is no real requirement there. The main important part is that they they can they can actually make make policy changes and influence change and enforce things at the company, and then they can work with a professional, if they if they lack that type of expertise.

Great. Thank you.

This question is about business associates.

Is there a way to, you know, either force or acquire HIPAA compliance from a non US based company?

That's where it gets really tricky.

Yes. I there's no surefire way to do it. The only protections that US based companies have when dealing with foreign entities is their business associate agreements and exercising the right to audit clause. Using your your, using your your using your power as a customer of theirs is is the most effective way to do it in enforcing your business associate agreements. So, I always tell everybody the most important aspect of any business associate agreement is your right to audit clause, which is where you can you can include in there that anytime you request them, they send you their risk analysis, send you their policies and procedures, how they're handling the data.

You can't really a hundred percent control what they're going to do, and they aren't governed by the same US regulations, that you are. But you can at least exercise due diligence in in checking in on them and and making sure what they're doing is secure and up to your standards. If it's not, dump them and go somewhere else. And at least it may not be a hundred percent way to protect you. It will put you in a strong defensible stance if something were to happen.

Great.

So you talked about documentation a few times and how it's really one of the, you know, top three things with HIPAA compliance.

So is there a good resource or a place for people to go that don't feel confident about how they're writing their documentation or even the way they're organizing it or, you know, a guide to specifically how or what they should be documenting?

So the easy answer is you can buy policies from us, and that takes care of that. But it it's complex. You know? Writing policies, privacy is centered a lot around legal, and so I would absolutely, recommend involving an attorney if you're gonna create your own policies. Sometimes, I'm aware that some types of associations, like if you're a dentist and you're a part of the American Dental Association, I think that they provide some of the policies, and I haven't reviewed any of them to know how good they are.

But sometimes you can get involved in organizations like that, or you can do a security adequate set of policies because there need to be they're going to be need to be created with a combination of a person from your organization, a lawyer, and a a security expert. So, most of the time, it's it's a lot easier to just buy them from from somebody who knows what they're doing that created them.

Great. And if you can touch I know this was primarily focused on the security rule and not to dive deep, but can you touch on breach notification and what, you know, what is the procedure or the process, you know, in general terms to handle an electronic HIPAA breach?

It depends.

So it depends on whether the breach is under or over five hundred individuals, but let's just assume that it's over five hundred individuals, which is probably what I think the question is asking.

In that event, you need to notify the media. You need to notify, the secretary of HHS.

You need to notify all affected individuals, anybody that could possibly, be affected. And, I mean, I could go off on this for ten minutes. But, basically, the the important thing to remember with the breach is those are the the basic notification requirements.

The important thing is if you have five thousand records and you suffer a breach, you need to act as if all five thousand records were breached until you have sure fire evidence that it was less than that. Because it is going to be treated as if all five thousand records were breached until you prove that they weren't.

So when you're doing your notification, especially to individuals, if you don't know if you haven't narrowed down the scope of the breach to exactly how many people were affected, just notify everybody.

This is one of those bad parts about breach because you're gonna there's some reputational damage with letting your customers or patients know that you may have breached their data. But it's better to be safe than sorry to notify more people than not enough.

Great. And if it is a small breach you mentioned earlier that a lot of people don't understand what that term means. Let's say they send an email to a handful of people that was wrong.

What are they required to do there?

So it's not the amount of data that was contained in each record, that they classify size of breach. It's more it's the it's the number of individuals that are affected. So under five hundred individuals affected is a different set of rules. You still do have to report it, but you don't have to do individual notifications. You don't have to do the media notifications.

And, you have sixty days till sixty days after the end of the calendar year to notify the secretary of HHS. So it's a much less expensive involved damaging process if the breach involves less than five hundred or the breach affected less than five hundred individuals.

Perfect.

And going back to the privacy security officer with some of these smaller organizations, I did believe you mentioned the same person can have both those roles, but those roles need to be defined. Is that correct?

Yes. You need to identify both. So most of the people that I talk to, the office manager at small to medium sized practices is generally the person that would be the security officer and the privacy officer.

And they just need to be identified as both, and they need to make sure that they're they're carrying out both, roles effectively.

Great.

And when you mentioned during breach notification that they need to notify someone, is that the HHS, whether it's a small or large breach? You mentioned that they still need to know to be to report it.

Oh, yeah. So sorry.

I guess there's a I'll just I'll separate terms. When I say reporting, I'm always meaning reporting it to HHS. Notification would be notification to the individuals affected. And then, you know, when there are larger breaches, you have to notify.

There's a lot of stuff that either you have to notify through the media. If you don't have current contact information, you may have to put ads in public papers in a certain geographical area. There's a lot of differentiators there. But no matter what in a breach, you have to report it to HHS. The size of it will determine whether you need to do an individual notification to individuals that may be affected.

Great.

Well, it looks like we're, running a little short on time, and we've handled most of the questions. Some of the other questions have been a little more specific to your environment. So I've made note of those so that we can have someone reach out and better understand your environment so we can give you an answer we feel comfortable with. We don't wanna put Ryan on the spot with with little information about your specific environment.

So, I'll give it a minute for more questions to come in so that we can reach out on an individual basis and take care of those. We wanna thank everyone for coming out to the webinar. And just a reminder, we will be sending out the recording in the next few days. So thanks again, and watch out for our next webinar and other educational material to help your hip endeavors.