Having issues accessing the video above? Watch the video here.
How to Prioritize HIPAA Compliance
In this webinar, Brand Barney, Security Analyst at SecurityMetrics, covers:
- A three-step prioritized approach to achieve HIPAA compliance
- The benefit of a thorough risk analysis
- How to simplify job responsibilities and increase practice security
This webinar was given on May 13th, 2015.
How to Prioritize HIPAA Compliance Transcript
Alright. Good morning, guys, or afternoon, depending on where you're at. My name is Brand Barney, and I'm gonna be hosting your HIPAA webinar today. So let's go ahead and get started. If you guys have any questions, throughout the webinar, please use your chat box to chat them in. And, towards the end of this, HIPAA webinar, we'll try and get all your questions answered. But let's go ahead and get started.
So, like I said, my name is Brand Barney. I work for Security Metrics. I'm one of the, senior HIPAA assessors here, so HIPAA auditors.
And I'm gonna be talking about how to prioritize your compliance efforts.
Now here's the deal with HIPAA.
Like I said, I'm a HIPAA auditor, and so I know a lot about HIPAA, both on the privacy and the security side.
Now when I talk with many entities, the the reality, covered entities or business associates, when I talk with entities about HIPAA or any compliance mandate for that matter, I hear a, a collective sigh. And there's usually a reason for it because HIPAA typically isn't very fun. And there's a lot of reasons for for that, and we'll get we'll go through that throughout this presentation.
But HIPAA has a, a long history, has has a big history through it. And what today through this presentation, I wanna help you to prioritize your compliance efforts.
As I visited many entities, as I've done audits, I've seen a lot of entities put a lot of different, compliant a lot of their efforts into many different areas. And sometimes those areas have been, well, maybe not the wrong area of compliance, but sometimes an an area that didn't get them a lot of a lot of bang for their buck, if you will. It got them a lot of stress. It got them a lot of, maybe even they spent a lot of money, but they just didn't feel like they got a lot of compliance.
Or on on the flip side, a lot of people will tell me that they feel like they're compliant. But here's another reality.
We are today seeing more HIPAA breaches, more, more breaches in the health care space, I should say, more more breaches than ever. So people are losing more protected health information than ever. Now we're also seeing more breaches of credit card information than ever. So I would say as a whole in many different industries, we're seeing breaches, and there's a reason for that.
It's because people, or entities, I should say, are trying to avoid compliance.
They're not really getting compliant, and they're not getting secure. So I'm gonna help you with that. I'm gonna talk about how to prioritize your compliance efforts. And not just prioritize your compliance efforts, but how to get yourself secure. Now, like I said before at the beginning of this presentation, there are two types of auditors.
So there's a type of auditor like myself who you'd work with somebody like SecurityMetrics that comes out and helps you get secure, that kinda has a, a good bedside manner, if you will. So if you're not doing the things that you should be to to secure your patient data, if you're not, if maybe you're neglecting some of your the the security requirements or the privacy requirements or maybe you're just not up to date, they're gonna help you to work through those requirements. They can help you get secure. Well, the second type of auditor is a type of auditor that comes out, from OCR, and they come out after you've had a breach or you've had a a complaint.
And that type of auditor is gonna be really no different than an auditor like myself. He's gonna have the same type of, certifications. He's gonna have the same type of education.
And he's gonna point out the exact same things that are wrong with your your organization, with your compliance and your security. But at the end of that audit, you're gonna find that you're gonna have, you're not you're not gonna be any less compliant than you are today, but you're gonna find that you're gonna be, assessed a penalty. So that's what I wanna help you to avoid. So let's get started with that.
Let's get off the first slide, and let's get started with it. So a little bit about SecurityMetrics, who we are, what we do. So SecurityMetrics has been around since two thousand, and we help organizations comply with mandates. Now that's that's not just HIPAA compliance, but that's also PCI compliance, helping you to protect, your payment card data as well.
And then we do that through avoiding security breaches and preventing data theft. Now there are many many entities out there, many, security companies that will help you to focus on, getting your, compliance up to date. Now they do that through checkbox compliance. We'll talk about that throughout this presentation.
But security metrics, our our our main focus is security. We believe that you can get compliant, but you're gonna do that through securing your data by avoiding a data breach and by avoiding data theft.
So how do we do that? That's what I get asked all the time. When I go out and talk with, you know, entities, maybe it's a small covered entity, maybe it's up to a large hospital, Maybe I'm out of a data encryption business associate, or down to just a pharmacist. You know, they range in in in in their their their business types. But they're all taking patient data or they're protecting patient data. And they say, well, how do you really help us protect ourselves? And it's through a prioritized approach.
Here's what I know about about you and your your business. And this is a broad paint paint paint stroke here.
But it's not about finding time for you because the reality is, I'm gonna guess, you probably don't have a ton of time in your organization. Most people don't.
But it's about maximizing the little time that you have. So we're gonna show you how to do that in your organization.
So we're gonna do that through a three step prioritized approach. Now through this webinar, we have just the space of an hour to talk.
I could obviously sit and hold a a HIPAA class, which would be extremely dry and cumbersome.
But now I could talk about the privacy rule. I could talk about the security rule. I could talk about the HIPAA omnibus. I talk about high-tech. I could talk about lots of dates and things like that, which would bore you to tears.
I might enjoy it because, you know, it's what I specialize in, and I'm very good at, but you might not enjoy it. But the three step prioritized approach really has to do with the security rule because that's where we're really losing, many entities are losing their patient information, their protected health information, PHI, and ePHI specifically.
So the three step prior types approach is a risk analysis, a risk management plan, and then a plan implementation. So risk analysis, to kinda give you a high level, overview of what that is, what that means.
Risk analysis is to identify the risks, the threats, and the vulnerabilities to your patient data, to your organization, and to your systems.
So once we've done that, we need to come up with a risk management plan. So once we've identified the risks, threats, and vulnerabilities to all the patient data, the organization, and to our systems, maybe even processes in in the middle of there. We'll talk about that throughout this presentation. We have to come up with a plan to fix those.
After that, we have to come up with a plan and implementation. We have to actually start fixing them. So the way I kind of look at this is kind of a to draw it back in a simple way to look at it is if you were to go to to your doctor today, and this works for health care. Right?
But if you were to go to your doctor and your doctor were to do just a general health checkup, your doctor would start to identify risks, threats, and vulnerabilities to you. So maybe let's say you weren't eating so healthy or you weren't, you know, exercising. He would start do you know, identifying risks, threats, and vulnerabilities to your body, to your to your systems, to you. And then if if he identified risks, threats, and vulnerabilities to your life, to your health, he would come up with a plan, and then you need to, yeah, implement that plan.
So maybe that plan is just to simply exercise.
This works the same thing on our business, with our systems, to our organizations, to our patient information. So let's kinda think about it when we go down this road. And this is, to to keep in mind, this is a, security rule requirement. So this isn't something that's optional.
We'll talk about that. When I talk with entities, when I talk in the phone or I'm and I'm sitting with them face to face, many of them say, well, jeez. Brand, where do I start? And I say, first first things first.
Where we've oftentimes failed is we haven't created any created any real goals. So we don't have a goal for ourselves. So how can we start? So I oftentimes will give a couple of bullet points.
I'll say, first things first. The first goal that I would have for you is you need to ask yourself, when do you want to complete your risk analysis?
Now there are some entities that have completed a risk analysis, which is great.
If you have completed a risk analysis, that's good. We need to do that annually.
If you haven't completed a risk analysis, you need to be doing that, and you need to start doing that immediately because that is what tells us what risk, threats, and vulnerabilities we have.
After we've completed a risk analysis, we need to get a risk management plan started at right after. It does us no good to identify risks, threats, and vulnerabilities if we don't come up with a plan to to remediate those or to fix those.
After that, we we should have discussion, and it's an interesting question. Have you ever asked yourself, what is an acceptable risk for your organization?
Do you know what's acceptable?
For many organizations, as we see, they're starting to lose a lot of data. So many many entities, many organizations, hospitals, small clinics all over, they're accepting all of the risk. They're saying, we just choose to ignore it and then accepting the risk and losing a lot of data.
Or maybe they're just accepting the high risk and saying we we don't have the money or the time. We'll talk about that.
When do you plan to train your employees? Now I've done a lot of audits for a lot of organizations. And when I sit down and I do these audits, many people are really proud because they do train their employees. So I can't fault you there.
But the problem with training employees is sometimes we don't actually train our employees on the right things, the correct things to train our employees on. Or maybe we train them when we we when we onboard them or we hire them. So we might train them, annually or we train them, on, like, how to properly, you know, put a patient in a in a waiting room or different many different things. But are we training them on security, on how to protect patient data?
So when do we wanna start training them on the proper things?
So one of the things that, you know, is very interesting with with HIPAA and and especially HIPAA's this HIPAA security rule is demonstrable progress is key. You know, in security metrics, we have one a very unique insight into to HIPAA and and even into the government. The OCR has stated specifically that they will go and so OCR is the the Office of Civil Rights, the the the entity that will actually come out and audit you should you be found, noncompliant or should you have, one of the entities that will come out and audit you if you've, had a complaint.
But OCR is very invested.
They've stated that they will go much easier on any entity that can show two things two things, documentation and progress. So documentation isn't just your your privacy policies that you can, you know, you know, smack down on a desk and say, look. We bought our privacy policies. We're good to go. Our security policies are here.
You know, we we read them once and we're we're good. We had our employees sign them. That is not doc. That is documentation. That's not proper documentation.
Documentation would be are you working towards HIPAA compliance? Are you doing what you should be doing?
And are you doing it regularly?
Progress would be, you know, have you updated your systems? Are you working towards knocking down the risks, the threats, and the vulnerabilities that have been identified?
They they will go easier on you if you can show those things.
They really, what I need you to be able to do and what you need to be able to do is create an evidence of good faith compliance. This is very important. And the way that you can do this is through a risk analysis, like we've talked about and we'll continue to talk about.
Now when we think of a risk analysis, one of the things that I want you to to remember is that your your organization is physical. So as we sit here on during this webinar and we're talking, your organization is just like you and I. It is a living, breathing entity. It is collecting data. It's transmitting data, and it's maintaining data. So it is living and breathing.
And we need to make sure that we're protecting data. So it has risks, threats, and vulnerabilities just like we do.
It, it starts to to, it starts to become, weak over a period of time. It starts to have new weaknesses introduced into it all the time, And, an attacker will look for weaknesses as as we go on. Remember, the risk analysis is not optional for any entity, no matter what your size is, no matter what type of entity you are. So if you're a small covered entity, if you're a large covered entity, if you're a business associate, if somebody else is helping you, risk analysis isn't optional nor is HIPAA, so privacy or security.
Now, like I mentioned, there are checklists out there at the beginning of this presentation. There are lots of checklists. And I gotta be completely honest with you. Many of them are a really good starting point.
But I have to be on on the flip side of that, we have to be honest in in in our presentation here. They are not sufficient when it comes to security. So when we start finding ourselves just checking boxes saying, I think we're doing that or, you know, I think we've done that, a checklist is just that. It's a checklist.
You're not really doing a lot. And so when we go back to, you know, when we go back to the OCR, we'll go easier on those that can show documentation and progress.
If you've done just a checklist, the the OCR is not gonna go easier on those that haven't shown real security, those that aren't protecting their patient data. So I want you to keep that in mind.
What we need to be doing, if you haven't already done so, is place somebody in charge. You need to have a privacy and security, official in charge today.
What I would encourage you to do is involve a trained security professional. Now it doesn't have to be, somebody awesome with a tie there on the right hand side, although I do recommend it.
But what we need to keep in mind is that security, is a lot like health care.
In the health care space, we have trained securities or not trained security, excuse me. In the health care space, we have, people that specialize is what I meant to say, people that specialize all the time. So for instance, you would never have your neurosurgeon perform a coronary artery bypass grafting. That would just be weird.
But we would have a heart surgeon that does that because the heart surgeon has specialized. Now both the heart surgeon and the neurosurgeon, they've both gone to medical school. And I would trust both of them to tell me if I don't smoke. But if I were a smoker, I would trust both of them to tell me that smoking is bad for my health. So just like in in the IT world, an IT professional, and both the IT professional and myself can set up your network.
But an IT professional and myself, and a networking guy and I, it's a little different. So your IT professional in your in your business is a separate discipline than security. So we always recommend that you get a security professional that can come in and look at it, because it is dis it is a separate discipline from IT.
So this is something that you can do today. This is something that, needs to be done and should be done as part of your your your risk analysis.
You should be documenting your PHI flow. You should know where your protected health information comes into your business, where it leaves your business, and where it's being maintained, where it's being stored, main maintained means meaning storage.
So this is a really fun exercise and one that I love to do when I'm gonna come out and do do audits. But you can really do this on your own.
So what you need to do is you could sit down after we get off after we get off this webinar, and you could sit down with your the the key members of each department. Or if you're a small enough organization, you could sit down with your entire team. That does take a little bit of time. But what we do is we would sit down with everybody or sit down with the key the key department heads, and we start to identify, the areas where protected health information is coming in, where it's being transmitted, where it's leaving our organization, and where it's being stored.
Now here's the deal. Oftentimes, as I talk to many entities, they will tell me that they believe they already know where these this is taking place. They know where the the data comes in. They know where the data is being sent or how it's being sent, and they know where the data is being stored.
But let me give you a couple of examples, and we'll try to do this as briefly as possible. But you might, for example, sit down with the front desk, or or or or or or or guy and say, let's talk about how you receive protected health information.
And they say, okay. Well, I receive protected health information via the phone. You say, okay. So patients call you?
I say, yes. Patients call me and schedule appointments, reschedule appointments, cancel appointments. They might say, patients call with a, question for a doctor. Again, Broadpaint Circle, because I don't know what all of your businesses do.
But they so you say, okay. And you write down everything that they're telling you. Some of these, again, you may already know, but it's important to document all this. Remember, documentation is key.
So you're documenting all the flow.
So let's talk about, do you receive any emails?
So ways we receive protected information. They say, yes. We receive email. And then you say, okay.
Well, our process is we should receive that through our exchange through exchange, and they say, yes. And they say, well, I also received it through Gmail as well. You go, oh, you receive, email, protected health information through Gmail? And they say, yes.
And you find out that was not part of your process. You should not be receiving the email through Gmail. So you write that down. Then they say that they get it on a little form.
So you write down all these these ways that you receive it. Then we go to the ways that we transmit. So maybe you go back to the billing area, and they're talking about ways that they transmit data. So they're sending data out through, a covered entity or not through a covered entity, through a business associate.
So there there's lots of business associates. Associates. And so you write down who are who are all of our business associates, and we would just document every single business associate. We also find that they're sending, data through Gmail because it turns out exchange was running slow and IT guys may be face palming when that happens.
But they're sending email to Gmail and you document that, and that's second time we've heard that.
As we go back and we we we're talking with, the nursing staff or maybe the doctor, The doctor says or we we find out that storage of data. So the the front desk gal said she was writing down patient questions on a piece of paper, and she takes it back to the doctor because she doesn't wanna interrupt him. She goes back and takes the piece of paper to the doctor. We find out he's putting it just in a in a bin that's not being logged.
So we there were three processes that that we were supposed to identify, how patient data came in, how patient data left, and where it was being stored. Now we found a couple of problems here. The fourth piece of information is we observe the data flows coming in. The fourth piece of information is where data was leaking.
Now ID, obviously, as a as an auditor would see a lot of these things, but we're gonna see data leaking. We're gonna see that, obviously, the Gmail was a process that shouldn't happen and and is not supposed to be we shouldn't be using that. We're gonna see that, we have pieces of paper, with patient information that should have been shredded and that are sitting in a drawer that's not locked. We're gonna see that maybe we have a couple of business associates that we're sharing data with that weren't documented.
We might even see further stuff. So this is a very important thing that you can do today. As we do this, we should gather all the data that we document. So this will include lists of hardware, all the software that we use to dot that that we we send data out, that that we receive the data on, and that we store.
So all the data storage locations included. And then maybe an up to and including, any encryption algorithms that were deployed and that we use. So anywhere which we we store data and any way we transmit data. So if we're transmitting data, that should be encrypted.
So you can identify documents and systems. This is just a couple of examples, and I did duplicate some of these here. But servers, workstations, network medical devices. You know, I was just recently doing an audit where I saw somebody, they were swallowing a pill, that send data over RFID. So that you know, people don't think that that can have a risk, risk threats and vulnerabilities, but it can.
Laptops, your operating systems, mobile phones, can be connected to your network and and maybe even staff from home can connect those. Your EHR and your EMR, you know, I oftentimes will hear, we're compliant because our EHR vendor told us we're compliant. That's just one small piece to the pie. Right?
So that's one small piece of the pie. And maybe they are compliant, but that doesn't make you compliant. Because as you can see, you we were using Gmail. We had data that wasn't being shredded.
We had staff that were doing things they shouldn't have been doing in all different types of processes as it was leaking out. So even if your EHR is truly compliant, which they may or may not be, that doesn't make you as an organization compliant, but we still need to document it.
It. Now there are risk analysis tools that you can use, and they're excellent. Security metrics offers us, several of these.
So vulnerability scans, both internal and external. Now external scan would be like a, a tool that you would implement into your internal network and would scan your internal network for for risks, threats, and vulnerabilities, vulnerability specifically.
But, external vulnerability scanning is something that you should be doing, and you should be doing on a quarterly basis and after any time you change anything on your on your network.
So, again, these are a relatively cheap way to to start identifying, things that a hacker would start looking for, on your external network and even on your website. So if you're not doing vulnerability scans, while that doesn't complete and is doesn't fulfill your your entire risk analysis, you should absolutely start looking at vulnerability scans. Because I can tell you, I've seen many organizations, many health care organizations and non health care organizations lose their sensitive data because a hacker identified a vulnerability in their network or on their website that you that that they could have easily identified, just as easily as the hacker did, and could have resolved. So if you're not using a vulnerability scan, you probably should do that immediately.
Now a penetration test, a penetration test is slightly different, and more costly. A penetration test is an ethical hacker. That is somebody who comes in and actually looks at all of the the weaknesses and the vulnerabilities to your systems.
This is a very awesome way to start identifying, many of the vulnerabilities that you have. Now, again, that is a little more pricey option, but one that is open to you. And nmap scanning, if your IT professional has not done that, that is something that you should begin doing immediately. That identifies the ports and services that are open.
So let's say, just given, a small example might be, that you have, port three thousand three hundred and six open and available to the public. That's a database port, and that would be a, a concern, for a security professional to see that you had a database port open and available to the public. So an NMAP scan would be something that would be a serious problem, and a security professional would know that you shouldn't have that open. So if you have any questions about NMAP scanning or that how that's done, engage with somebody like, SecurityMetrics to have them help you to to do it.
And nmap scanning is not hard at all. That's you can do that completely free, completely free of charge.
So let's talk about, another part of risk analysis is a bad guy walk through. This is really easy and really, really fun. This is fun to do. So a bad guy walk through can be things that you do as you walk through your organization and an auditor will do as they look for things that a bad guy if he were walking through your organization, they they would look to to steal, things that they would look to see weakness and weaknesses, threats, and vulnerabilities.
So for instance, as I walk through, I might look to see, do we have phones that staff are using? Are they breaking policy?
What can I see from the front desk? What can I hear from the front desk?
As I walk maybe around the perimeter of your organization, what can I see through the windows?
Are are, monitors close to the windows?
You'd be amazed at how many times I've actually gotten right up close to a window, put did did the awkward, put my hands cupped up against the window and looked inside the window on an audit and had nobody stop me, and just watch people as they're entering data into the EHR. So you can do this in your organization just by observing your staff, by observing the things that are doing. It sometimes does take a little bit of security knowledge. So maybe for instance, as we are sitting in our patient area, we might see that we have, open available network ports. That would be a serious problem if if they were open and available. We could have somebody plug into those and start doing some packet sniffing.
So, some observation. And you know what's really amazing? Most of the time, our employees know most of our problems. So just by talking to to our employees, our front desk, our our billing, our nursing, whoever in our organization that's that's handling PHI, that's protecting PHI, they're gonna know where our problems are. So it's really fun.
So we've talked a ton about identifying, our risks. So what are our vulnerabilities? There are gonna be flaws in components, flaws in, you know, in procedures. So we have procedures set up.
There'll be there'll be a lot of those. Flaws in design, sometimes in building designs, designs that you've set up, implementations or internal controls. We're gonna have a lot of threats as well. And a threat will be the potential for a person, a group, or a thing to trigger that vulnerability.
And then the risk will be the probability that particular threat will exercise a particular vulnerability, and the resulting impact will devastate our business.
So we have to do several things here that are important. We need to assess current controls. Now I know it may it may have sounded like all doomsday, and I don't mean it for it to.
But we have current controls.
As I said before, it is important to onboard or to engage a security professional. But your IT guy has set up many things that have that already did have good controls. So I don't want it sound like you don't have controls in place, but we do have weaknesses, threats, and vulnerabilities.
We need to determine the likelihood of the occurrence. So what is the occurrence or the rate of occurrence? Those those things could maybe one of those, threats or vulnerabilities could could detonate and and impact us in a very negative way. What was what would be the potential impact?
So if we lost data, what would be the impact to our business? Would it put us out of business? What would be the fines? What would be the the, brand degradation to us?
What would that do to us? What's the risk? So as we see those nice little little, little TNT there, what would that look like? Would it be the yellow, a low risk, maybe a light orange?
Would that be medium? Or to be extremely high. And if it blew up, it would just ruin us. So we need to identify the security measures, the controls, and mitigations.
Once we've done that, we're gonna come up with a risk management plan. This is where it gets, a lot more fun. I I enjoy all parts, but I think this is where it gets fun. So we're gonna craft a risk management plan.
Now you can do this on your own or, again, if you're, have engaged a security company, they're gonna help you with this. And if you you've engaged an auditor, they'll do that for you. So an, a risk management plan is to, specifically stated by the HHS, is to implement security measures, sufficient to reduce risks and vulnerabilities, remembering that we have to create evidence of good faith compliance, like I said earlier. There are multiple items that need to be included in your risk management plan, and and I've bold pointed them here for you.
You have to have an action item for every single risk. Every risk has to have an action item. We need to have milestones. So you can do break that down into one, you know, two milestones, three milestones, four milestones, but you have to have milestones, things that, you know, are demonstratable progress.
We have to have completion dates for everything, and we should have progress. Now I recommend daily or weekly progress, but you can even do up to monthly progress depending on the risk. So let's talk about our risks. So we have to implement a risk strategy for every risk identified.
Remember that you cannot, you can't just ignore your risk here. So let's talk about the different types of, risk strategies there are. There is, retention or or acceptance.
So for that nice little low risk or that little yellow piece of TNT, or, you know, dynamite there, we can accept some risks. The problem is that everybody well, not everybody, that sounds like worst case scenario, but many people are accepting all their risk. And that is a problem, and OCR will not accept it nor will HHS.
But you can accept some of your low risks.
A security expert will help in that arena. They'll help you to guide you and show you what is acceptable with, with your business.
You can reduce or mitigate your risk, which is what many people choose to do. They choose to resolve the risk and mitigate it. Sharing would be like, an insurance company. So, I have a car.
I get car insurance, and I share the risk with my, car insurance provider. Again, you're not gonna do that for every single risk, not not with not with your security risks. And avoidance would be, say, for instance, we have, that's kind of, you know, joins, together with, like, a mitigation, reducing or mitigation. But let's say we have a ton of, XP machines or maybe we have an employee that's doing bad things, we avoid it, by getting rid of it altogether.
So we avoid it and get rid of it.
So let's consider some of the risks. And I know we've talked about this, so I don't want to bore you to death, but let's consider you. And I nor do I want to scare you to death either. But let's consider some of the risks. So we have employee actions. Now I've seen, employees all over the nation, in many different types of entities, both large and small, and I've seen employees doing all kinds of things they shouldn't be doing. Sometimes they're malicious, sometimes they're unintentional or all meaning, and sometimes it's just downright neglectful.
Sometimes it's before the breach and and even after the breach. Now malicious, I would say, is the is a very small percentage, but it does happen. So we need to learn as an entity to protect ourselves from our employees.
Unintentional or well meaning is probably shared with that neglectful or negligent, I should say.
So remember, our employee actions are they're a big risk to us. We we we do have employees that will do things, that that can harm us and can harm our patient data. So we have to put controls in place that don't allow for our employees to to hurt our data or hurt to hurt our systems or our business.
Role based access to systems and susceptibility to social engineering, I'm gonna talk about that later in the presentation, so we'll get to that.
Your but your employees, let's talk about and and the employees with, susceptibility to social engineering. We'll talk about how they do that. But your employees, screensavers to protect PHI. You've got to have screensavers on all of your systems.
Your employees will walk away from their systems. Time and time again, I've gone into organizations to audit. And they walk away from their computers and they don't lock anything. And as it's sitting there unlocked, somebody can walk up and start perusing your systems and collecting PHI.
That is a major problem. And as we talked about earlier when we're talking about documenting your PHI flow, as as you can see, you probably start walking through your mind. And as you go through the exercise later, you will start to see paper trails and undocumented flows in storage because it's, you know, your employees are trying just to do their jobs. They don't have a ton of time in their day, but the workflow and the burden of their day just kind of starts to, you know, stack up, they're they're gonna start to have paper trails that start to to leak and undocumented flows in storage that, an attacker will start to take your data because they didn't, they weren't following proper procedure.
Your business associates. Now your business associates are one of your greatest risks to you. Your business associates, remember, but now business I don't mean business associates are bad in any way, shape, or form. But keeping in mind that when you share data, that data is out of your control. You have shared it with somebody else, and you no longer have, a way to safeguard the data, safeguard patient information. So it is time to make sure that we have updated our business associate agreements. We may need to make sure that we review all the vendors that we have and make sure that, we remember that a business associate agreement does not relieve us of liability or responsibility.
I I tell and and and counsel many, covered entities that if you do not have a business associate business associate validation program, you should probably have one. You know, Ponymon Institute in twenty fourteen did a, a study that said that only thirty percent of covered entities were confident that their business associates are properly handling or properly safeguarding their patient information, which is a staggeringly low number. So remember, your business associates are are are losing data, and we're seeing that in the data breaches today. So let's talk a little bit about your systems.
Now I know that I said your IT guys are awesome, and we have some super trooper IT professionals. I love to work with IT professionals.
Some of my best friends are IT professionals.
So when we start to look at the systems and when I come out and I audit, I I do look at your systems. I look at your systems to see how they're configured.
Your systems oftentimes, have a very well, they they are not are not properly configured, so I guess the the nicest way to say it. So we we oftentimes plug the systems in. We need them to start working in a proper manner, and get them up and going as quickly as possible to start doing business. Now your IT guy has many different functions, oftentimes, and one of them is is to configure these things.
But, like, going back to what we said earlier, oftentimes, they don't have a lot of security training. Now if you go and look on many university website websites, on which I don't encourage you to do. But if you were to go look, again, you would see that security is its own subset. So when I start to look at firewalls or I look at servers and workstations and mobile devices, what I see oftentimes is that they are configured to communicate to the other devices in your organizations, and they usually, and and I say usually, do a fairly decent job at doing that.
They are communicating. They are storing data. They're transmitting data, and they're receiving data.
Sometimes we may not we may may have a a printer misbehaving here and there. We may have our EHR that doesn't wanna behave, and so our, IT guy is kind of scrambling all over the place to make sure that those are working. But, what we oftentimes see when we're we're performing an audit is that we see that the firewall, is not properly configured, and we see rules, that allow for data to come in, that shouldn't come in, or traffic, I should say, is probably the more appropriate word. Traffic just to kind of come in that shouldn't come in and traffic to leave your network that shouldn't be allowed to leave your network.
So, again, your systems are not properly configured. Remote access, let's talk about that for just a brief moment. So when we're remoting, so let's talk when we remote outside of your network. So let's say, because again, at the beginning of the presentation, we talked about people being too busy to to well, just to get everything done in a day.
So I know that people are taking their work home. So the doctor takes his work home, office managers are taking their work home, many entities are taking their work home.
So we go home, we plug our, you know, our laptops in our home network and we use things like, log me in or, go to my PC not go to my PC, but we use remote desktop protocol. We use a lot of different tools to to to remote in.
And as we use those tools to remote into our business network, those are oftentimes insecure.
And so we use just a simple password. Well, we we have to have an IP address, of course, but we use a simple password to get in. But when that data is being sent, an attacker can quickly quickly take that data that's being sent across. So we should have what's called two factor authentication.
So something you know, something you have, and something you are.
So an on on screen example here would be pass password one two three. If you're using password one two three as your password, that is a very poor password. Please don't use it. But, obviously, you're not gonna use a fingerprint because it's a remote access, two factor authentication. But you can use a, a key. So oftentimes, you'll see, keys being used, like RSA key or something to the effect, on like Gmail. So what I encourage you to do today, is talk with your IT professionals if you're using remote access to remote into your business outside of your network, let them know that it is a requirement that you do use two factor authentication.
Now here's the deal. Your servers, your workstation, mobiles, devices, again, if they're not properly configured, to log all acts, to log all of your your patient data, your data, again, is gonna walk right out of your network. So I don't wanna harp too much on that. Let's talk about your physical security.
We we oftentimes talk about we oftentimes think a lot of just the electronic data, but the physical security is really important. As I come in and I start to see, entities, many people will think that their physical security is just the privacy element. So they'll think that, you know, it's it is the privacy rule. Excuse me. So but it really isn't.
It does it does match a little bit in the privacy, but your physical security is also the security rule. So we need to make sure that anywhere that we are storing, that we're transmitting, or that we're receiving data, that we are actually physically securing it. So that any we have visitor and maintenance logs, so to our our network closet, to our server, to anywhere that we're storing our, to to our storing our, our logs, anything.
We need to make sure that we control and limit physical access to those. So we have lock we actually have locks on doors and that the key to those doors are are limited to not get everybody have access to it.
Video cameras to to monitor access to sensitive areas. Now I know that sounds very, onerous.
Obviously, this is gonna depend on on the size of your organization, but you should have, video cameras to monitor access to very sensitive areas. And you need to be able to distinguish visitors from on-site personnel. Now here's the deal with that.
A lot of people give me a lot of, or they don't understand they don't understand this particular requirement.
Because they'll say, well, you know, we are a a small organization. Maybe we're thirty staff. So we're gonna know if somebody got fired, or we're gonna know if somebody, doesn't work here anymore, or or we're gonna know if there's a visitor. But what I tell people all the time is somebody may have just got let go and is coming back into a sensitive area, and you weren't told about it because that is a sensitive thing.
You weren't told about and they just immediately walked back. So having a badge, having a process to be able to tell immediately if that person is supposed to be there, a badge with photo identification name, you're gonna be able to quickly tell if that person is supposed to be there and will help you to avoid that data breach. Because, again, when I go back to that slide, your employees can be your biggest weakness, That does help. So make sure you have you have badges.
So let's talk about tiering your passwords. Now I'm not gonna spend a ton of time because I do have a I do talk about passwords towards the end of the presentation.
But when we install a lot of systems, many systems and many, tools come with vendor supplied defaults. So it is very, very common for me to go in and audit an organization and see those vendor supplied defaults still in. So, again, what we're talking about here is we're identifying, we're fixing in a risk analysis. We're still identifying, some of these, these risks, threats, and vulnerabilities.
So, what are the risks? But vendor supply defaults, you can get on the Internet. Say, let's give you an example, your router. If you're using a Linksys router, or a Netgear router, maybe even in your home.
So just you can do an example. Whatever you use, you can go on and type in Netgear router, default login, and you can find every single password for every single make and model. It is really not hard. And that really is the case for just about any type of, any type of system.
Maybe not every system, but for many systems that are on the market today. Because when they make something like that and somebody wants to get in and they can't remember what the fit the the vendor supply default was, it's available on the Internet. So what I encourage you to do is when you get something, you install it, you need to make sure you you change your vendor supply defaults.
We gotta make sure we'll talk about this in the end, but do not allow your employees to share usernames and passwords. Again, that I think that goes without saying. So let's talk about the risk management process.
So a risk management process really doesn't a lot of people make this much more nebulous than it has to be. But risk management process can be implemented on a tracking sheet or a database.
Again, if you're working with a security company, they're gonna help you do that. They're gonna make that much more easy a much easier streamline process, than than kind of putting on a pen and paper. So but things that you're gonna document would be milestones. So your goals.
What were your goals, and when did you wanna complete them? What were your achievements? You've gotta know what your achievements are. So maybe, an achievement was making sure that we, had unique usernames and unique usernames and passwords for everybody.
That was a goal. We identified the risk. We got it, and we have an achievement. So we gotta we gotta identify that, and we gotta document it.
Maybe we need to designate staff and resources for larger projects.
So oftentimes, we'll go into organizations and we'll see somebody who needs a centralized log server. They just don't have one. Or maybe they need file integrity monitoring or some type of, any of data loss prevention or other tools and and and processes in place. And maybe they may be a little more costly, or may just take time. Now, obviously, like I said in the beginning, you're we we have to have progress, and I don't think that you're gonna become compliant overnight. So you may need to get a project manager.
You may even need to get stakeholder representatives involved.
But you need to document that as well, and you need to come up with dates that you suspect that those will be done by. So, again, document everything. So let's talk about implementing your plan.
So you're you're away from your desk or you're sitting down for a webinar and you're learning about HIPAA. We need to make sure that we protect PHI when you're gone, when your employees are gone. So we have to have automatic lockouts for all computers for every anywhere that we transmit, collect, or or maintain data, which have screensavers on every single computer. You know, I I I look like a a maniac anytime I go out and do an audit because I love to hit the space bar on every single computer.
It looks like an arcade game. But it's oftentimes amazing, how many times, computers will will willingly pop up without without requiring a password, after they've timed out as well, how many times they don't have a screensaver, you'd be shocked at how many times this happens. And this is a simple control that you can just immediately do today. So protect your PHI when you're away from your computers.
Because if you're not, a patient sitting in in a room or, you know, a vendor's walking past or, you know, somebody's not being, escorted like we talked about in physical security, people will take your data. And we should have encryption on all on all of our devices. So we should have an encryption where data is being stored. We should have encryption where data is being transmitted.
And, again, the storage piece also sometimes is, on our mobile devices. So maybe even on our laptops or our backup drives. You know, we had a a fairly large, a data breach, in Utah, where somebody just smashed a a window and took somebody's storage drive. And the the you know, if you have encryption, that helps to reduce reduce your your breach there.
So make sure that you do have encryption on all your devices.
Now remember to update your systems and your applications. The the deal with, update updating systems is that many, many people believe that, their systems will behave the same way they did when they first installed them, and this just isn't the truth. When we update and when when we install our systems and our applications, it like I said in the beginning of the presentation, it really is a lot like a living, breathing human being. They do not behave the same way they should.
So remember to update them. This is a couple of examples here. Your EHR, antivirus operating systems, firewalls, your medical devices even, and then your intrusion prevention, your file integrity monitoring, your data loss prevention. Now these last bullet points, oftentimes see that many entities do not have those.
If you don't have them, you do need them to help you protect your data. So make sure you're updating them and you're not avoiding when it pops up. Let's talk about phishing training. Now I'm not just talking about I don't mean to, pick on Nigeria or anything, but I'm not talking about, like, receiving an email from the prince of Nigeria here.
So, I'll be I'll be at that is some type of, phishing, and that is to, you know, something that we don't wanna receive and we should never reply to, because you are not gonna receive any money from them. But you should keep and train this is part of training your staff on correct security procedures.
So we see things with email requests that, you know, request sensitive info. So when you get an email from the prince of Nigeria and he says, send me your Social Security number and I will send you one million dollars, please don't reply to that. Please don't click on any links in that. If you see things with, like, incorrect or missing names in an email, that is a surefire surefire way to know that that email is they're fishing for information from you.
You'll oftentimes see a sender email, address that is mismatched. So, if it's like brandon at security metrics dot com, but brandon, dot, you know, brandon dot o n, and you'll see weird stuff. You know, that just doesn't look correct.
Security metrics is spelled with matrix. You'll you'll see things like that. It's like, I know this isn't who it's coming from.
Can you know, it'll oftentimes click contain unsolicited attachments, so things with, like, a dot e x e. Boy, if it's got an executable in there, delete. Make sure that you you get, your IT guy to come in and look at that. And company links don't match legit URLs.
Oftentimes, you can just hover over, a link and see where it's gonna take you. So if it says that it's gonna take you to Facebook and you hover over and it says it's gonna take you to well, I don't know where it's gonna take you, but hover over and it'll tell you where usually, it'll tell you where it's gonna take you. Train your employees on this. You also need to make sure that we're training our employees on social engineering.
People will come in and I the the word poser, I've always sound slightly amusing, but people will come in and pose as somebody that they're not supposed to be. And these are the people that they typically pose as. So janitorial services, IT professionals, public service, professionals, and telecommunications.
And the reason they they, pose as these people is because these are typically the people that are not told no. These are typically the people that can walk in and and go unnoticed. They can take things without being, again, without being told no and without without, really being noticed in your organization. What they'll oftentimes do is they'll start you're not you're oftentimes not shredding your your IT statements.
You're not shredding your your telecommunication statements. You're not shredding your public service statements, your janitorial statements. So they might go through your, your your trash can and see that your IT guy was in last week. He performed he switched out a couple of he switched out a blade server.
He replaced a router, and he had problems with the printer. His guy his name was Steve. So they go through and they look in your trash can. They see Steve was in.
He replaced those things. And they walk in. They dress up. They and they see what company he was from.
So they go and get the same getup. They come in. Maybe they even call you before. They say, hey.
Steve is no longer with the company. We're here.
It looks like there was issues. We're not able to communicate via the remote protocol that you're using because they know what that is. So we're not able to communicate with that server anymore. We are having a faulty router that he replaced. We just need to replace that router.
And maybe you question it, maybe you don't, maybe you're not in for the day, and maybe a staff member lets him write back and and replace things that he shouldn't be doing and shouldn't have access to. And you'd be shocked at how many times people let him in. So, again, train people on it. You should not let any of these people shouldn't let anybody in to any sensitive data, without proper access. So social engineering is very, very easy to do.
Physical security training, I don't wanna harp too much on this one, but remember, tailgating into sensitive areas should not happen, so keep an eye on that. When a door closes, it should you you're you know, you should be the only person that was in in there. Cheap butter knife. This one's awesome.
You can go on the Internet and do a YouTube search for the cheap butter knife hack. You can pretty much get into any door today other than Fort Knox, but you can get into just about any business door with a cheap butter knife, and hackers show how to do that. So keeping up to date with your doors and making sure your doors are actually up to up to date and secure is very, very important. And we check that when we do, an audit.
And then dumpster diving, like I said, making sure you're shredding your your your statements. So we we oftentimes shred, things that are are common shred, but shredding your actual good statements. So telecommunications, IT, janitorial services, etcetera.
So when we talked about individual user accounts, so this is, talking about your your employees again, and and the employee weaknesses. But I don't mean to to to bag on any employees here, but not all workforce members are created equal. So the the front desk staff should not have the same privileges and should not have access to all of the same information that the doctor has access to or that the IT professional has access to. So for instance, a physician's laptop should only be used by a physician, not by any nurses or by any receptionists.
Again, so we we we call those things like, and for instance, on your, like, your network shares.
We should have individual user accounts, and we should have what's called role based access.
So, again, workforce members are not all created equal, and they should not have the same access.
And, again, all staff should have separate user accounts. Now this I'm not talking about just your e e your EHR.
So when they log into the EHR, oftentimes, that will force you to have a separate user account. But your front desk, your exam rooms, oftentimes, those will have, when I go in, I'll see it called front desk one and exam room one, exam room two, exam room three, etcetera. Again, that's not acceptable for for HIPAA. So you have to have separate user accounts for everybody. So if, James, Brandy, and Deborah all have to have separate user accounts. And I know that can be painful sometimes, but that helps you to have what's called accountability for every single workforce member.
Let's talk about changing our passwords. Now changing our passwords is super, super important. This helps us to protect our data down at the at the individual user level. So one, we should never share passwords with anybody.
We should never use default passwords like I mentioned ear earlier because when we use default passwords, it makes it extremely easy for a an attacker to come in and take our data. And then we should change our passwords to a passphrase. So password would be something like, a b c one two three. But a a passphrase would be my favorite foods are pizza, ice ice cream, and fried chicken.
Now if that were true, I'm an extremely unhealthy individual. But the passphrase below it would be, well, that passphrase. Now that is an extremely onerous passphrase, and I'm not asking you to have your password passphrase look like that because I don't know that you would remember it.
But that passphrase right there used at blog dot kaspersky dot com slash password check would take five hundred and ninety one centuries to crack with an average home computer. So the computer that I'm actually using right now, which is a fairly upgraded computer, but five hundred and ninety one centuries. Now you could walk to the moon and back at two thousand four hundred and thirteen times. So if we go back and look at it, that's a fairly complex password, and I don't think that anybody is using that password today.
I know I'm surely not. But I am using a passphrase, and I did check my passphrase on this site. Now I obviously don't recommend that you go and check your passwords on this site or your pass phrase on this site. But, I I decided before I started this presentation, I would actually go check one of my passwords against it.
And my password would take ten thousand plus centuries to crack.
Now, obviously, I'm not ever gonna use it again, but a simple passphrase, something that you can remember, can be, can be very effective, against an attacker. So I would encourage you to check it, and I would encourage you to make sure that all of your staff are are using complex passwords. So what are our takeaways today? Now, obviously, we've talked about a a lot of different information. And, obviously, HIPAA is still a a large onerous task to do. But you are you can complete HIPAA, and you can, prioritize your compliance efforts.
So we have a to do list.
Do I don't I wouldn't encourage you to do HIPAA all in one sitting. If you're trying to do HIPAA all in one sitting, I don't believe that HIPAA will be, achievable for you. And I don't believe that HIPAA is gonna be fun, not that HIPAA should is fun for many people, but I don't think that HIPAA will be, will be easy. I think that HIPAA will cause a lot of heartburn for you.
And I think that, that that's one of the ways that many people start to put it on the back burner. They start to let their risk threats and vulnerabilities pile up, and then we start to see breaches. And here's the deal with breaches. We oftentimes see breaches in the media, but a lot of people are having breaches today.
When we go in and we see them as auditors, we see things that, you know, why these people ask, well, if I had a breach, I say, well, I don't know. But I think that you're at a very, very high risk for have have having had a breach. I can't tell you that you have, but it looks like there's a high risk that you have. So, start small and, you know, start having, you know, demonstrable progress.
So the first thing to do is designate a privacy and security officer.
You know, identify, you know, contact, assess your general risk level. You know, get that started immediately.
Begin an internal security risk analysis. If you do anything, start that immediately.
Determine the internal and external resources you need to use. So you are gonna have internal resources that have to be used, and that can be painful for some people, because they don't have a lot of internal resources. So that's where we encourage entities to to engage a security professional, engage external resources. So maybe it's engaging, you know, or doing a risk analysis over the phone with with a company like Security Metrics.
And maybe you do that monthly. Maybe it's fifteen minutes a month. Maybe it's twenty minutes a month. Maybe it's an hour every Friday.
It just depends. Or maybe you say, hey. This risk analysis, we know our risks are huge. We wanna just get the risk analysis out of the way, and I wanna have an auditor come out and look at my risks now. That's something that is available that you can do process. But I would recommend that you do start your risk analysis immediately and determine what your resources are.
I would I would highly recommend that you outline your specific plans with dates and milestones. So know what your dates are. Know what your deliverables need to be and what milestones you'd like to have. Educate and train your employees.
Remember, your employees are one of your greatest weaknesses to you. They're the the the chink in the chain. And they if if if that goes, you're it's kinda like a house of cards. Your data can your data can be lost really quickly.
So train them. Get them excited because they they are part of the process of protecting your data. And they do want to they I I talk to so many employees when I go out and I and I do, when I do audits. And so many of these employees are awesome.
They're stellar, and they want to protect your data. They just often oftentimes aren't empowered to protect data, and they just don't know how. So train them on how to properly protect data. And, boy, above all things, above all things, remember what I said earlier.
The OCR will go so much easier on those entities to document their processes, their findings, and their actions. Remember, it many entities have been breached. Many entities are going to be breached. So if you're do anything, document your processes, your findings and actions, and get started today.
Now we do have a couple of minutes left for questions.
So I'm gonna open up the questions.
You guys just chat those into the chat box, and, we'll try to get as many questions answered as we can.
And I appreciate your time. I'm gonna put us on a a brief, brief hold here while we let the questions roll in. Thanks, guys.
Alright, guys. So looks like we have two good questions here to to answer. We will, answer, individual, questions through through email. But, so we will be sending the presentations out through the the slides, out through through email.
So, yes, we will be doing that. And, another really good question is, so on the the business associate agreements and this one gets asked all the time, so I think this is a a a great question. I appreciate you asking it. But the business associate agreement so the HIPAA omnibus rule, was was updated.
The the final HIPAA omnibus rule was updated in twenty thirteen. So as I mentioned earlier, it is important to update, if you haven't already, I should say. If you haven't already updated your, business associate agreements, it is time to update them. Now you obviously should have, you should have identified all of your business associates today.
So I identify through that the PHI flow. Identify who the vendors are that you're actually sharing data. Now there are gonna be some vendors that it's kind of a gray area. So vendors like your IT professionals, your janitorial staff.
The IT professional where they're actually helping you to protect your data like a third party, I would recommend that you have them, sign a business associate agreement. If they're employed by you and they work for you in in in your business, they would need to sign a BAA. But if it's like a third party coming in, you would want them to sign a BAA. But where the the b the the omnibus rule comes in in twenty thirteen, what that does is that that shares liability between the covered entity and the business associate.
So you would want to update your business associate agreements as soon as possible if you haven't done that since that date. That was September twenty third of twenty thirteen.
So, again, update them, make sure you identify who who they are, and get that done as soon as possible. But that does look like that is all the time we have for today, guys. I really do appreciate you you attending our webinar. If there is any other questions, I will reach out to you via email and answer those questions.
I appreciate your time, and have a wonderful rest of your day. Thanks. Goodbye.
