MATTERFORM | Healthcare risk analysis, assessment, and management plan experts. https://matterform.com Matterform provides robust risk assessments for healthcare organizations. Wed, 28 Feb 2024 23:08:13 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.5 /wp-content/uploads/2020/12/matterform-logo-final-01-favicon-01-150x150.png MATTERFORM | Healthcare risk analysis, assessment, and management plan experts. https://matterform.com 32 32 Lessons from the 23andMe data breach /lessons-from-the-23andme-data-breach/?utm_source=rss&utm_medium=rss&utm_campaign=lessons-from-the-23andme-data-breach Wed, 28 Feb 2024 23:01:17 +0000 /?p=2363 Lessons from the 23andMe breach Consumer genetics testing company 23andMe suffered a devastating data breach in late 2023. Criminals stole records from 6.9 million customers. How can your health and wellness software company avoid being the next big headline for cybersecurity failures? * indicates required Email Address *

The post Lessons from the 23andMe data breach first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>

Lessons from the 23andMe breach

Consumer genetics testing company 23andMe suffered a devastating data breach in late 2023. Criminals stole records from 6.9 million customers. How can your health and wellness software company avoid being the next big headline for cybersecurity failures?

* indicates required

The post Lessons from the 23andMe data breach first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>
Social engineering /social-engineering/?utm_source=rss&utm_medium=rss&utm_campaign=social-engineering Wed, 13 Apr 2022 15:24:16 +0000 /?p=2344 Social engineering is what we call the intent of obtaining a company’s personal or private information through its employees or the people that have access to that company’s information. It uses psychological manipulation to mislead users into committing security mistakes, or giving away private information. Most common example is an email that promises a prize […]

The post Social engineering first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>

Social engineering is what we call the intent of obtaining a company’s personal or private information through its employees or the people that have access to that company’s information. It uses psychological manipulation to mislead users into committing security mistakes, or giving away private information. Most common example is an email that promises a prize in exchange for an email or, your bank asking for your credit card’s PIN number.

Some types of social engineering attacks include: Phishing, Vishing and Smishing, Pretexting, Baiting, and some others.  Attackers get more creative as time passes.

According to webtribunal.net  Cybercriminals use social engineering in 98% of attacks

 

We are having a free webinar on April 27th at 1pm CST. Please register here: 

https://my.demio.com/ref/oGhMhsiV1MeHaet5

The post Social engineering first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>
HIPAA secure text messaging /hipaa-secure-text-messaging/?utm_source=rss&utm_medium=rss&utm_campaign=hipaa-secure-text-messaging Tue, 22 Mar 2022 18:18:11 +0000 /?p=2338 93% of hospitals have patient portal 10% of patients want a portal 20% would like to communicate by text. It’s important to remember that everybody wants to communicate by text, and that it is possible that every text related to a healthcare provider or healthcare professional can be considered PHI. Reasonable and Appropriate Security Controls […]

The post HIPAA secure text messaging first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>
93% of hospitals have patient portal

10% of patients want a portal

20% would like to communicate by text.

It’s important to remember that everybody wants to communicate by text, and that it is possible that every text related to a healthcare provider or healthcare professional can be considered PHI.

Reasonable and Appropriate Security Controls

  • Document patient consent to receive SMS
  • We have duty to warn patient that SMS may be less secure
  • Make other, more secure methods available whenever feasible
  • Always apply Minimum Necessary Data Standard 
  • We are not responsible for securing messages on patient’s phone
  • Identify at-risk patients who may have trouble keeping their communications private

Please do not forget to register to our free webinar on HIPAA secure text messaging on March 30th at 1pm Central

Register here: https://my.demio.com/ref/yraSxmZdHtAblttt

 

The post HIPAA secure text messaging first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>
BYOD: Bring your own device, or Bring your own disaster? /byod-bring-your-own-device-or-bring-your-own-disaster/?utm_source=rss&utm_medium=rss&utm_campaign=byod-bring-your-own-device-or-bring-your-own-disaster Wed, 05 Jan 2022 20:22:46 +0000 /?p=2285 67% percent of the people that own a smartphone, use it for job related activities.  The most popular pin used to protect those smartphones is: 1-2-3-4* *https://www.pocket-lint.com/phones/news/148224-these-are-the-20-most-common-phone-pins-is-your-device-vulnerable Your employees are already using their personal phones to: Check their email Schedule meetings and appointments Edit patient data in your EHR (Electronic Health Records) Access confidential company […]

The post BYOD: Bring your own device, or Bring your own disaster? first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>
67% percent of the people that own a smartphone, use it for job related activities. 

The most popular pin used to protect those smartphones is: 1-2-3-4* *https://www.pocket-lint.com/phones/news/148224-these-are-the-20-most-common-phone-pins-is-your-device-vulnerable

Your employees are already using their personal phones to:

Check their email

Schedule meetings and appointments

Edit patient data in your EHR (Electronic Health Records)

Access confidential company data in your intranet

Access financial data in your accounting software

Store their passwords for other sensitive company systems

And that’s not even the scary stuff. One infected employee smartphone could be how a ransomware attack takes down your entire company!

If you got scared by these numbers and facts, and you should be, then you know you need to do something about it. A very good first step is to attend our free webinar, 

“Employee smartphones: How to create a secure BYOD policy”

Join us on January 27th at 1pm central time by registering here:

https://my.demio.com/ref/kegDKXirhi96NiYi 

Don’t let unsecured employee smartphones expose your company to cybersecurity attacks or HIPAA fines. Learn how to create a BYOD security policy that protects your company and helps your employees work the way they want to work. The book includes model policy language you can copy to create a complete, HIPAA-compliant smartphone security policy for your company.

Better cybersecurity is worth it. The effort you invest in your company’s cybersecurity program will pay off by making your company more secure, more resilient, and ultimately, more valuable.

Getting a handle on employee smartphones is one of the easiest and most cost-effective ways to improve cybersecurity at your company. You already have all the technology you need to secure smartphones at your company. All you need is some guidance about what really works.

More good news: help is available, you can email me any time, and I’ll also show you how to get help from your own team. You will need to enlist all your employees and all your vendors to help protect your company. Cybersecurity is a team sport and you can’t do it alone. 

Policies and procedures are hard work, but fines are much, much, worse. We at Matterform can do all the heavy lifting for you, all you need is to schedule a 20 minute call.

The post BYOD: Bring your own device, or Bring your own disaster? first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>
Multi-Factor Authentication for Healthcare /multi-factor-authentication-for-healthcare/?utm_source=rss&utm_medium=rss&utm_campaign=multi-factor-authentication-for-healthcare Wed, 22 Dec 2021 22:30:09 +0000 /?p=2277     Multi-factor authentication, sometimes called two-factor authentication or MFA, is one of the most effective security controls you can implement at your healthcare organization. Multi-factor authentication makes security and business sense at any organization but is especially important for those handling ePHI. Multi-factor authentication can further protect accounts where the only line of defense […]

The post Multi-Factor Authentication for Healthcare first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>
 

 

Multi-factor authentication, sometimes called two-factor authentication or MFA, is one of the most effective security controls you can implement at your healthcare organization. Multi-factor authentication makes security and business sense at any organization but is especially important for those handling ePHI. Multi-factor authentication can further protect accounts where the only line of defense is a password. We talk a lot about secure passwords at Matterform, but threats like social engineering require us to further protect accounts which are accessible from the internet.

Where to prioritize multi-factor authentication

We recommend that any internet accessible account that stores, transmits, or accesses ePHI be protected by multi-factor authentication. Sometimes, business realities get in the way of this goal. Implementing MFA takes time and money, so we have to prioritize which systems are highest risk.

Email: you may think that there is no PHI in your email but we can guarantee there is some. PHI is like an oil slick: it gets everywhere. Email is also a high risk system because it’s vulnerable to social engineering attacks and often is an access point to a larger cloud environment. Any enterprise email service will also allow you to roll out MFA one account at a time, so focus on high risk accounts like your leadership and providers.

VPN: If your healthcare organization has a more traditional infrastructure where you host email on-premises, then chances are you also have a VPN. Protecting your VPN with two-factor authentication means the rest of your on-premises services will inherit those same protections whenever staff is accessing your systems remotely.

FAQs

If multi-factor authentication is so important, why doesn’t HIPAA mention it?

Multi-Factor authentication is nowhere to be found in the HIPAA implementable specifications, but other high value security controls like encryption are. As a result, some compliance officers overlook MFA, but this is a mistake. Remember, HIPAA is technology neutral. HIPAA is also old. It predates Wi-Fi, which wasn’t widely used until 1997. The threat landscape to healthcare is constantly evolving and it would be impossible for HIPAA to keep up. This is why it’s so important to incorporate not only HIPAA standards but NIST standards into your annual security risk assessment. NIST 800-63B, a great reference for cyber security best practices, recommends MFA as a security control.

Not all my staff have organization-issued smartphones. How can I get a second factor of authentication?

An inexpensive and secure way to implement MFA without buying your whole staff smartphones is by purchasing USB authenticators, small USB drives which act as a second factor (something you have) along with a password (something you know).  These authenticators can be kept on a key chain or a building badge. You can also have users authenticate using their personal smartphones but you should ensure you have a Bring Your Own Device (BYOD) Policy first. Matterform has model language for a BYOD policy that you can deploy within 30 days, just contact us to learn more.

What if the VPN implementations I’ve looked at are too expensive?

Many commercial implementations for MFA on your VPN can be prohibitively expensive and may cause you to write off MFA entirely. There are other inexpensive solutions, such as cryptographic enrollment of workstations with a unique certificate. At Matterform, we are happy to look at any quote you may have and see if you’re getting a fair deal.

But my organization has shared accounts. How do we implement multi-factor authentication on those?

You may have a shared email for admin staff or maybe all your medical assistants log into the same EHR account to handle medication refills. Remember, HIPAA requires that all users have unique accounts so you should get rid of any shared accounts right away. In the meantimethere are some things you can do: For your email system, implement MFA selectively on non-shared accounts first. For your EHR, consider buying more licenses.

But what if the second factor is breached?

It’s unlikely, but it could happen. Just because you have more than one factor of authentication doesn’t mean your account is 100% secure, and not all second factors are created equal. Multi-factor authentication is not perfect and could be breached, but it’s one of the best controls we have.

Takeaways

Multi-factor authentication improves your cyber security by adding an extra layer of protection to a sensitive online account. The National Institute of Standards and Technology recommends MFA, you can implement MFA without organization-owned smartphones, and you can implement MFA cheaply. Focus on email and VPN first.

Watch this video in our HIPAA for Humans series to hear our founder and senior risk analyst Michael Herrick discuss Multi-factor authentication.

The post Multi-Factor Authentication for Healthcare first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>
Cannabis dispensaries /cannabis-dispensaries/?utm_source=rss&utm_medium=rss&utm_campaign=cannabis-dispensaries Tue, 07 Dec 2021 19:30:38 +0000 /?p=2267 If you run a cannabis dispensary  in Illinois you will be required by law to observe certain sections of the Health Insurance Portability and Accountability Act (HIPAA). This means a lot of things, but the first step, and probably the most important one is that you have to conduct a HIPAA risk assessment. A risk […]

The post Cannabis dispensaries first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>

If you run a cannabis dispensary  in Illinois you will be required by law to observe certain sections of the Health Insurance Portability and Accountability Act (HIPAA). 

This means a lot of things, but the first step, and probably the most important one is that you have to conduct a HIPAA risk assessment.

A risk assessment is more than a checklist, more than a network scan. It needs to cover all your business processes, not just IT, and it needs to offer specific guidance to improve security.

The Matterform process will save your staff hundreds of hours of work and you’ll feel confident that your HIPAA strategy is on a sure foundation, with a solid plan for moving forward to manage risk. When you work with Matterform, our experts will interview your management and technology staff in person to:

1.-Inventory all systems, from your EHR to your paper files to your staff training

2.-Review policies and procedures, check business associate agreements

3.-Identify technical and non-technical process vulnerabilities

4.-Conduct a vulnerability scan of your local computer network

5.-Deliver specific, action-oriented recommendations aligned to your strategic goals

Here are some resources for you to get started right away:

Full one hour Webinars:

How to conduct an effective HIPAA risk assessment

Vendor Management

Our HIPAA for humans video series:

HIPAA 3 business goals 

HIPAA setting priorities with your risk assessment

 

And check our blogs at www.matterform.com

 

Starting a business is hard. Do not put it at risk, or do not risk the chance of fines. Especially when you have a solution right at your fingertips.

 

The post Cannabis dispensaries first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>
Webinar: Is Your Telemedicine Practice HIPAA Compliant? /webinar-is-your-telemedicine-practice-hipaa-compliant/?utm_source=rss&utm_medium=rss&utm_campaign=webinar-is-your-telemedicine-practice-hipaa-compliant Mon, 30 Aug 2021 19:42:05 +0000 https://matterformhipp.wpengine.com/?p=2198 On Sept. 1st, the New Mexico Telehealth Alliance will host Founder and CEO of Matterform, Michael Herrick,  for a webinar. With the rise of the Delta Variant, you may be thinking that we will be relying on telehealth more this fall. Are you compliant? Do you have concerns about your platform? Have you been relying on tools […]

The post Webinar: Is Your Telemedicine Practice HIPAA Compliant? first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>

On Sept. 1st, the New Mexico Telehealth Alliance will host Founder and CEO of Matterform, Michael Herrick,  for a webinar. 

With the rise of the Delta Variant, you may be thinking that we will be relying on telehealth more this fall. Are you compliant? Do you have concerns about your platform? Have you been relying on tools that won't be compliant once the public emergency health order ends?

Wednesday, September 1
12p.m. – 1p.m.

The post Webinar: Is Your Telemedicine Practice HIPAA Compliant? first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>
HIPAA Building a Security-First Culture /hipaa-building-a-security-first-culture/?utm_source=rss&utm_medium=rss&utm_campaign=hipaa-building-a-security-first-culture Thu, 26 Aug 2021 15:38:23 +0000 https://matterformhipp.wpengine.com/?p=1794 A client contacted me recently with a really interesting question. Their organization has started using video recordings as part of their EHR training with their staff to demonstrate certain workflows and best practices in their electronic health records application. I am a huge believer in the power of , so I think this is a […]

The post HIPAA Building a Security-First Culture first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>

A client contacted me recently with a really interesting question. Their organization has started using video recordings as part of their EHR training with their staff to demonstrate certain workflows and best practices in their electronic health records application. I am a huge believer in the power of , so I think this is a great idea.

However, these videos contained small amounts of protected health information (PHI), which raised the question of whether there were HIPAA implications that the organization needed to consider. To answer that question requires unpacking the various elements. Are the videos produced locally only? Are cloud servers involved in saving or backing up the files? If so, are the right business associate agreements in place to prevent impermissible disclosure of PHI?

Situations like this are a reminder that people in various departments of an organization can come up with good ideas like this one, but may overlook possible HIPAA implications

Questions like this serve as a reminder of the true purpose of HIPAA. Contrary to what some believe, HIPAA is not meant to be a bunch of red tape and bureaucracy. HIPAA guidelines are simply meant to provide guidance for healthcare providers to honor and respect the privacy of their patients. Situations like this are a reminder that people in various departments of an organization can come up with good ideas like this one, but may overlook possible HIPAA implications before they go off and running. 

PHI disclosed through cloud serviceMeanwhile, a year or more down the road, a disclosure might be made during a risk assessment that an individual or department has inadvertently disclosed PHI to third parties through a cloud service or shadow browser extension. Worse, the improper disclosure might be uncovered during a HIPAA audit.

The take-home lesson is that IT threats are often generated through initiatives created with the best of intentions. Do you have questions about the HIPAA implications of a new program or general questions about your organization’s HIPAA compliance?  Matterform can help you build a security-first cybersecurity program that is HIPAA compliant. Contact us for a free exposure analysis today.

The post HIPAA Building a Security-First Culture first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>
HIPAA Penetration Tests and Vulnerability Scans /hipaa-penetration-tests-and-vulnerability-scans/?utm_source=rss&utm_medium=rss&utm_campaign=hipaa-penetration-tests-and-vulnerability-scans Wed, 28 Jul 2021 21:54:54 +0000 https://matterformhipp.wpengine.com/?p=1782 Medical facilities are understandably concerned with the security of patient data. HIPAA demands that certain safeguards are maintained. In the pursuit of maintaining security, organizations utilize a number of cybersecurity measures. Specifically, they may hire a company to perform a vulnerability scan or a penetration test. These two procedures are very different, and definitely not […]

The post HIPAA Penetration Tests and Vulnerability Scans first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>

Medical facilities are understandably concerned with the security of patient data. HIPAA demands that certain safeguards are maintained. In the pursuit of maintaining security, organizations utilize a number of cybersecurity measures. Specifically, they may hire a company to perform a vulnerability scan or a penetration test. These two procedures are very different, and definitely not interchangeable.

A vulnerability scan is an automated process where a technician uses specialized software to scan computer hardware or a network for vulnerabilities, such as outdated operating systems, unpatched software, or open ports on a firewall. It is often the first step before a penetration test is performed. Vulnerability scans are also suitable for companies that are at the beginning stages of establishing a cybersecurity strategy.

Vulnerability scans are also suitable for companies that are at the beginning stages of establishing a cybersecurity strategy.


Penetration tests are used to discover and document specific weaknesses so that corrections can be made. Companies should be aware that some cybersecurity outfits advertise what they call penetration tests, but are in fact just glorified vulnerability scans. A penetration test, unlike a vulnerability scan, is hands-on and very intensive. It is done by an ethical hacker who deliberately attempts to break into a system. These tests are best suited for organizations with a fairly mature cybersecurity program in place.

unencrypted laptop

Both vulnerability scans and penetration tests have their limits. Even the most intensive penetration test will probably not disclose whether staff members are walking around with unencrypted laptops. And a vulnerability scan may discover open firewall ports, but if an organization has multi-factor authentication in place, such openings present minimal risk.

Fortunately, there is a solution that can address the gaps that a vulnerability scan or a penetration test may miss. It’s a risk assessment, which is exactly what we do at Matterform. We perform risk assessments specially designed to meet HIPAA requirements to respect and maintain the privacy of their patient’s records. If you have questions about your organization’s cybersecurity and HIPAA compliance, contact Matterform for a free exposure analysis today. 

The post HIPAA Penetration Tests and Vulnerability Scans first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>
Automate Your Defenses Against Social Engineering /automate-your-defenses-against-social-engineering/?utm_source=rss&utm_medium=rss&utm_campaign=automate-your-defenses-against-social-engineering Tue, 06 Jul 2021 23:42:23 +0000 https://matterformhipp.wpengine.com/?p=1741 It’s widely recognized that social engineering represents one of the biggest threats to healthcare organizations. On the other hand, a lot of IT people throw up their hands in surrender, essentially crossing their fingers and anxiously hoping that the often minimal training offered to staff will be sufficient to keep the organization on the right […]

The post Automate Your Defenses Against Social Engineering first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>

It’s widely recognized that social engineering represents one of the biggest threats to healthcare organizations. On the other hand, a lot of IT people throw up their hands in surrender, essentially crossing their fingers and anxiously hoping that the often minimal training offered to staff will be sufficient to keep the organization on the right side of HIPAA.

HIPAA isn’t a collection of red tape and bureaucracy, lying in wait like a “gotcha” trap

But this approach misses the point. HIPAA isn’t a collection of red tape and bureaucracy, lying in wait like a “gotcha” trap for unwary individuals or organizations. It’s a set of guidelines designed to respect and honor patients as they negotiate the healthcare system.

Another approach is to lean heavily on human-centered training, such as instructing users on how to create good passwords or requiring everyone to change their passwords every 60 or 90 days. This type of strategy makes more sense on a surface level. After all, social engineering threats are often generated by human error – or overt bad acts. Minimizing unsafe practices should also minimize the risk of data breaches.

phishing emailsHowever, relying on human perfection to defend against social engineering-related threats is ultimately doomed to fail. After all, humans are, well, humans. Even when we are diligent and well-intentioned, we miss things. Or we’re misled by deceptive tactics like phishing emails or links to sketchy websites loaded with malware. We get distracted and we get bored. Simple human error can introduce a cascade of disastrous consequences.

A better approach to reducing the threat of social engineering is to combine common sense human strategies with reliable technology. User-friendly technology like VPNs, multi-factor authentication, and password managers can be very effective in defending against phishing attacks, malware, and other security hazards – and more importantly, help to keep your organization HIPAA compliant.

Do you have questions about your organization’s HIPAA compliance? Contact Matterform for a free exposure analysis today. 

The post Automate Your Defenses Against Social Engineering first appeared on MATTERFORM | Healthcare risk analysis, assessment, and management plan experts..]]>