Saturday, February 14, 2015

Ways To Strengthen Healthcare Security

Real safeguards and policy implementations, however, speak louder than any number of crisis meetings. Securing any healthcare organization -- from a solo practice to multi-location hospital systems -- takes measured planning, technical expertise, and business knowledge. It's the only way security professionals can balance their quest for impenetrable devices and software against medical users' demand for easy, accessible data and tools.

New regulations tied to the Affordable Care Act are now in effect regarding protected health information and electronic health records, which only underscores the need for data security to ensure privacy among patients.  Healthcare providers recognize that data security is of vital importance to their business.

Healthcare organizations are particularly vulnerable. They house personal health, payment information, and intellectual property -- all lucrative targets for hackers. But most employees want to heal people, not become technologists, and might view technology protections as healthcare speed bumps. As providers, payers, employees, patients, and partners become increasingly intertwined through shared data, transparency, and analytics, the opportunities for loss, error, or theft grow exponentially.

Healthcare had the highest percentage of incidents from theft or loss, the study found, suggesting room for improvement.  But employees don't deserve all the blame. Outsiders -- such as business associates, contractors, and suppliers -- accounted for 68% of the top 10 miscellaneous errors.

Education and regular checks and balances decrease the frequency of incidents. Technologies such as data-loss-prevention software monitor emails and faxes, while mandating that IT alone disposes of equipment helps ensure fewer data-laden devices end up marked for recycling, eBay, or the trash.

Policies are critical to ensuring that an organization's security message permeates departments and shifts. It is one reason a growing number of healthcare organizations are hiring chief security officers (CSOs) or chief information security officers (CISOs) to oversee and govern all areas of protection.  

These technology professionals play an important role; security knowledge is vital, but they also require business expertise in healthcare.






Tuesday, January 27, 2015

Preventing Social Media Blunders In Healthcare Settings


Many healthcare organizations are looking for innovative ways to use social media to improve patient care and communications. But first, they must take some essential steps to address the risks involved. 

Here are three steps to take to minimize social media risks - and avoid the publicity that comes with missteps.

1. Define types of information never be posted to social media sites.
One problem that I've heard over and over is that those who inappropriately posted information, images, comments, etc., to social media sites did not think the information was patient information, or that it was not protected by HIPAA.

Take the case from the first example above. The doctor posting the images and unflattering remarks to Facebook and Instagram was a physician from that hospital who was asked to be present but was not the attending physician. He was also an acquaintance of the patient. There was speculation that he felt the images were not protected health information since he was taking them as a friend and not as the primary physician.
All personnel must clearly understand the types of information that is considered to be PHI. They must understand that PHI remains PHI even if the employees think they can use it in other ways as friends or family. They must also realize that protections for PHI are still required even if the patients or insureds have posted similar information or images online themselves.

Suggested Actions:
  • Clearly define and document the PHI collected, stored, processed or otherwise accessed within your organization;
  • Explain to employees that the PHI must never be posted to social media sites without the clear and documented consent of the associated individuals, following the policies and procedures that you create;
  • Provide real-life examples to reinforce understanding.
2. Establish clear and comprehensive policies
Given the exponential growth in social media use, and the increasing numbers of breaches resulting from inappropriate posts to social media sites, every covered entity and business associate needs to have a documented social media policy, with supporting procedures. The policies and procedures need to include clear direction on what is appropriate and inappropriate to post to social media sites.

Suggested Actions:
  • Meet with key stakeholders to determine the actions that are acceptable and not acceptable, based upon associated risks, with regard to posting information and images to social media sites;
  • Be sure to clearly indicate that even when employees are away from work or using their own personally owned computing devices, PHI must never be inappropriately posted online;
  • Give an individual or team responsibility for monitoring social media policy compliance.
3. Provide training and ongoing awareness communications.
In many, perhaps most, of the incidents involving inappropriate posting of patient information on social media sites, those doing the posting stated they didn't think they had done anything against their organization's policies - or that they didn't have any social media policies. Most organizations do not provide regular training on their policies, or the training they provide is ineffective. And they don't send regular reminders to keep employees aware. Providing effective social media training and ongoing awareness reminders is an essential step toward preventing social media breaches.

Suggested Actions:
  • Create social media training to support your policies and procedures. Or, use existing training that aligns with your policies. I've found classroom training or online live webinar training works best because these approaches allow for interaction and questions.
  • Create and use case studies for interactive discussion to see how learners would react to different types of situations involving social media.
  • Send ongoing awareness communications to remind personnel of appropriate uses of social media and policies on posting PHI or other types of personal information.


Saturday, November 22, 2014

Employees Expose Sensitive Data Outside the Workplace

Workers expose company data beyond the workplace, including very sensitive information. Typically, the employee has no idea how risky this is. It’s as easy as the crook capturing data, that’s displayed on a screen, with a smartphone camera as he passes by or secretly looks on continuously from nearby.

And there’s little corporate policy in place to guard against this. Many professional employees admitted their company lacked any explicit policy on conducting business in public. Some employers don’t even have a policy on privacy filter use.

Either communication about policies with employees is feeble, or attention to visual policy from the decision makers is lacking.  This proves security awareness training and education are needed as an integral part of information security. 

An increasing number of people are taking their online work to public places, but if they knew that company data was properly protected from roving snoops, they’d be more productive. Companies need to take more seriously the issue of visual privacy and this includes equipping employees with tools of protection. Some employees don’t even know what their employer’s policy was.

Type of Data Handled in Public
  • Internal financials
  • Private HR data
  • Trade secrets
  • Credit card numbers
  • SSNs
  • Medical data

Another factor is that of enlightening workers about the whole issue. An enlightened employee is more likely to conduct public online business securely.

Businesses are sadly lacking in security tactics relating to data that’s stored, transmitted, used and displayed. This is a weak link in the chain of sensitive information is the human. Any effective IT security strategy needs to address this issue and take it right down the line to the last employee.

Monday, October 20, 2014

Why Cyber Security Matters To Everyone

Your cyber hygiene affects others
It’s not unlike public health. One of the reasons health officials urge almost everyone to get a flu shot is because people who are infected are more likely to infect others. And the same is true for cyber security. Infected devices have a way of infecting other devices and compromised systems can make everyone vulnerable. So your cyber hygiene isn’t just about protecting you, it’s about protecting all of us.

Bots or zombie networks are just one example. Bad guys look for vulnerable machines to infect and enlist them into a zombie army that infects other machines, thus greatly amplifying their ability to reach millions of users.

Even bad social networking and email security can be contagious. If your accounts are insecure, it makes it easier for others to go online as you and spread infections or social engineering attacks designed to steal data or money.

What’s in it for you?
But forget altruism for a moment. Having an insecure machine or password can be personally devastating. I’ll spare you the scare tactics, you’ve probably heard them before — but I will remind you that an intrusion into any of your accounts or devices can escalate into a full-scale attack on your financial and reputational well-being.

Even something as basic as inadvertently sending out spam, can be embarrassing, but there is also the risk of identity theft and financial crime that can leave you with an empty bank account.

Shared responsibility
Cyber security is a shared responsibility. Internet companies and brick and mortar merchants can do their part by shoring up the security of their networks and payment systems. Government can educate the public and enforce anti-cyber crime laws. Businesses can make sure that they have strong security processes in place; including making sure their employees use strong passwords and everyone can play an important role by securing our devices and being sure that our passwords are strong and unique.

Kids too

And it’s not just for adult. Just as we teach our kids to lock their bicycles, parents and teachers need to remind them to password-protect their phones and other devices. And kids need to know that some things in life need to be kept secret. Passing on your passwords is not a way of proving that you’re a good friend. If a friend asks for a password you can really be a good friend by reminding them that it’s never a good idea.

Sunday, October 5, 2014

Cybersecurity Awareness Is About Both ‘Knowing’ and ‘Doing’

Ask any IT security professional and you’ll get the same answer. One of the biggest cybersecurity challenges is the human factor, making cybersecurity awareness more vital than ever in our mobilized, interconnected world.

According to the 2014 Cyber Security Intelligence Index, an astounding 95 percent of all security incidents involve human error. The most prevalent mistake? Double clicking on an infected attachment or unsafe URL. Other common errors include lack of patching, using default user names and passwords and easy-to-guess passwords, lost laptops and mobile devices, and inadvertent disclosure of sensitive information by use of an incorrect email address.

All the more reason to support and participate in National Cybersecurity Awareness Month, which is observed in October in the U.S., with similar months or weeks set aside in other countries. Cybersecurity awareness events like these are valuable opportunities to shine a spotlight on what it means to be aware and how to promote not only knowledge, but deliberate, mindful behavior to actively protect valuable data and information in our businesses and communities.

What is cybersecurity awareness? It’s not just knowledge. Knowing isn’t doing. Security awareness is knowledge combined with attitudes and behaviors that serve to protect our information assets. Being cybersecurity aware means you understand what the threats are and you take the right steps to prevent them.

We work to create a risk-aware culture where employees are educated about the cybersecurity hazards we face and trained to take the right actions to defend against them. Training courses, simulated phishing exercises, awareness campaigns, videos and a steady stream of awareness messaging and social media conversations are some of the ways we work to keep cybersecurity top of the mind.

We encourage staff to visit the StaySafeOnline and Stop.Think.Connect websites to cultivate cyber awareness at home and in their neighborhoods. StaySafeOnline offers tips and resources, including content for teaching cybersecurity to students from kindergarten through college. The Stop.Think.Connect. site offers information on how to protect our digital lives online.


We’re all in this together, and each of us has a stake in reducing human error and encouraging cybersecurity best practices in our workplaces, homes and communities. Help spread the word to promote a safer, more productive digital experience for all of us.

Wednesday, October 1, 2014

Beware of Socially Engineered Phishing Attacks on Facebook

Phishing attacks are one of the most common scams on Facebook. The goal of these scams is to obtain your Facebook user name and password. If successful, the scammers can totally take over your Facebook account and use it to spread more spam and scams to your friends. They can also mine everyone in your network for data they can later use for identity theft or other socially engineered attacks.

Here are some examples of popular phishing schemes on Facebook:

  1. Facebook Lottery – You’re likely to receive an email stating you’ve won a sum of money. These can also be advanced fee scams.
  1. Confirm Your Account – Any messages asking you to confirm your account should be viewed with extreme suspicion. If you receive an email like this, don’t follow any links. A better option is to log in to Facebook directly.
  1. Violated a Policy – Hacked accounts often send messages posing as ‘Facebook Security.’ If you encounter one of these scams, you’ll notice that Facebook Security will be spelled with non-traditional characters. This is done to bypass Facebook’s filters.
  1. Photos & Videos - The scammers attempt to capitalize on our curious nature. You will receive a message from a compromised friend’s account asking you to look at this photo or video. A popular theme is to say the picture is embarrassing or they can’t believe you did that, etc. Other variants of this scam contain files laden with malware.
Most all of these scams direct you to external links to pages designed to look like Facebook. Before logging in to any site, always verify that you are indeed on the main site. Careless and unsuspecting users are often fooled by these tricks.

Saturday, September 20, 2014

The Role of Human Error in Successful Security Attacks

The Threats of Inadvertent Human Error by Insider Mistakes
One of the leading errors made by insiders is sending sensitive documents to unintended recipients. This is relatively easy to solve by deploying security controls to monitor sensitive information being leaked out of the organization. Once considered complex to deploy, these controls have been made considerably easier to implement by vendors in recent years. This has dramatically reduced the level of user involvement required and increased the use of such controls.

These tools can also prevent users from engaging in inappropriate behavior, such as sending documents home via email or placing them on file-sharing sites or removable media such as USB sticks. Lost or stolen mobile devices are also a major concern that is exacerbated by the growing trend toward the use of personal devices.

Human error is also a factor in other security incidents caused by insiders who are the most trusted and highly skilled, such as system and network administrators. Some of the most commonly recorded forms of human error caused by such employees are misconfigured systems, poor patch management practices and the use of default names and passwords.

Successful Security Attacks Exploit Human Interest Factor
The human interest factor is also being exploited by attackers and plays a large part in successful security attacks seen today, but it is not always attributed to mistakes made by insiders. Many of these attacks involve social engineering techniques to lure individually targeted users into making mistakes. Advanced and targeted attacks involved spear-phishing scams with emails containing malicious attachments that can cause malware to be downloaded onto the user’s computing device. This gives attackers a foothold into the organization in search of valuable information, such as intellectual property.   

Today, legitimate websites are increasingly being hacked since they are just the sort of websites that users would routinely trust. However, compromised websites are also being used in attacks that target the interests of specific users or groups. There has also been a particular increase in so-called watering hole attacks.

People, Processes and Technology
It is often said that any successful organization must focus on people, processes and technology in equal order. Technology provides automated safeguards and processes to determine the series of actions to be taken to achieve a particular end. Oftentimes, there is insufficient attention paid to the “people” part of the equation. To stem errors made through social engineering and to raise awareness of the potential caused by carelessness, technology and processes must be combined with employee education. This way, employees are aware of the threats they face and the part they are expected to play in guarding against them. Keeping organizations safe relies on constantly educating employees about identifying suspicious communications and new possible risks.