Cybersecurity is a serious concern for everyone today. Data breaches are far too common, and to some extent, we have become accustomed to them.
But that’s not acceptable, particularly as more and more of our personal information lives online. We must take steps to protect our own data and the data of the people we serve.
For Nurse Practitioners in private practice, that means safeguarding patient data.
If you read last week’s post, you know that the goal of Senate Bill 3315 is to tighten Cybersecurity across all healthcare organizations.
Up to now, organizations were expected to make “reasonable efforts” to protect data.
However, if the pending legislation passes, a defined level of cybersecurity must be implemented and proven with documentation, logs, testing results, and audits.
While this will create short-term inconvenience and disruption for organizations, keeping data safer will be worth it in the long term.
Where to Start?
Perhaps you’re wondering whether you should wait and see if the proposed legislation becomes law, or get started now?
I think it’s best to get ahead of the curve and start now.
It’s in your best interest to do all you can to protect the data you’ve been entrusted with, along with yours.
Besides…
Updates to the current security standards are sure to come, even though they may differ from the proposed standards.
The suggested legislation is complex and would require all HIPAA-regulated entities to implement minimum cybersecurity standards, including:
- MFA (Multi Factor Authentication)
- Data Protection (Encrypt all ePHI, at rest and during transit).
- Security Testing (Conduct audits and penetration testing).
- Framework (Alignment with established standards, like the NIST)
If you’re thinking that implementing these requirements is too much to ask of small practices, you are not alone!
As overwhelming as it may seem, I believe that with a detailed implementation plan and adequate time on your side, you can implement greater security for your organization.
I suggest you start tightening security in your office as soon as possible.
So, let’s start at the beginning, with one of the most important and overlooked areas of cybersecurity, your asset inventory.
If you don’t know what you have, how it connects, and who has access to it, you can’t secure it, yet everything else, including MFA, encryption, and monitoring, depends on it.
Why an Asset Inventory Matters
Creating and maintaining an up-to-date inventory is the foundation for assessing security risks.
A current and up-to-date inventory:
- Lets you know where all ePHI resides and how it flows through your office.
- Reduces the risk of a data breach due to “shadow devices,” forgotten and unmonitored devices that may become entry points for attackers.
- Allows you to respond faster to incidents by quickly isolating affected devices and systems.
- Creates an audit trail, along with internal documentation for systems maintenance.
Keep in mind, many data breaches happen because of outdated, forgotten, or unattended software.
Hackers exploit this, along with weak passwords. They steal credentials and seek to exploit every security weakness they can find.
And don’t make the mistake of thinking small practices are not worth the trouble for hackers.
On the contrary, hackers assume that small practices are lax in their security and easy to take advantage of.
A small practice is a perfect target for hackers…
Let’s prove them wrong!
Your Inventory: What to Include?
Every device and piece of software your office uses to access and transfer data is a potential entry point for hackers and should be part of your inventory. Include the following:
Hardware, all devices used to access data:
- Desktop computers
- Laptops
- Tablets and phones
- Printers, scanners, fax machines
- Routers and network equipment
- Software-enabled medical devices
- Servers (on-site or cloud-connected)
- Include all personal devices used for work
Software, everything used in your practice:
- EHR/EMR systems
- Scheduling software
- Billing and claims systems
- Cloud storage (Dropbox, Google Drive, etc.)
- Telehealth platforms
- Email programs
- Antivirus security programs
- Any additional applications installed on computers
Software is where data resides. Outdated or unauthorized software is one of the most common causes of data breaches and hacks.
Vendors & Third Parties:
- Billing companies
- IT service providers
- EHR vendors
- Cloud service providers
- Payment processors
- Telehealth platforms
- Any business that handles patient data (directly or indirectly)
Your risk is not limited to you alone; it includes everyone connected to you or anyone you connect to. Therefore, if a vendor is compromised, your data may be compromised too.
Who has Access?
This step is critical…
Determine and document who has access to what.
For every device, software system, and vendor, you must know who has access to it.
Account for:
- Employees
- Contractors
- Vendors
- Former staff (this is a high-risk area)
Frequently, data breaches and hacks happen not because someone had access, but because access was never removed!
Keep track of prior access and when and how it was revoked.
How to Keep Track
The simplest way to keep track of this information is with a spreadsheet, using MS Excel or Google Sheets.
A centralized spreadsheet is accessible, simple to create, and easy to maintain.
I suggest you create a master spreadsheet for everything; include as much detail as possible:
- Sheet 1 contains all hardware information
- Sheet 2 contains all software information
- Sheet 3 contains all vendor and 3rd party data
- Sheet 4 lists access, the role, access level, and start/end date
View your spreadsheet as a living document. Start with a simple spreadsheet and refine it as you go. Review it often and keep it up to date.
Utilize this spreadsheet as you bring on new employees and as others leave your practice.
Update it as new software is installed and more devices are added.
Use it to clean up any unused or outdated software and to revoke access of former employees.
Utilize it to troubleshoot and evaluate vendors you’re working with or consider working with. And of course, use it as you prepare for an audit.
To Sum Up …
Creating a comprehensive inventory spreadsheet pays off…
You will be safer against hackers and data breaches, and you will have more control over your practice.
Let’s face it, you cannot protect what you can’t see, no more than you can hit a target you can’t see.
Creating and maintaining an inventory of devices, software, and vendors, and documenting who has access to each, is one of the highest-impact actions you can take in your practice today.
And it doesn’t take a high level of technical knowledge.
What it takes is the willingness to set aside time to document how your office handles patient data from start to finish.
And in the new, proposed regulatory environment, that may be the difference between a manageable incident and a catastrophic one.
We’ll cover how to implement the new requirements in subsequent articles. And, we’ll keep you up to date on changes to the legislation as soon as information becomes available.
Do you know how patient data flows through your office? Do you know which device is an access point, and who has direct access to the data?
Let us know what you think in the comments below…
By Johanna Hofmann, MBA, MAc., EAMP; regular contributor to the NPBusiness blog.
