OCR Offers Advice on Recognizing, Avoiding, and Mitigating Social Engineering Attacks
The majority of healthcare data breaches reported in the past few years are due to hacking incidents but many of these security incidents do not involve the exploitation of vulnerabilities in software and operating systems for initial access. Far more common is the exploitation of human vulnerabilities, where healthcare workers are tricked into providing cyber actors with access to internal systems and sensitive data. According to the Verizon 2024 Data Breach Investigations Report, more than two-thirds of breaches involve the human element rather than the exploitation of weaknesses and vulnerabilities in technology. One of the most common methods used is phishing, where a cyber actor makes contact with a healthcare employee and convinces them to visit a malicious website where they are asked to enter their credentials or are convinced to download a malicious file, both of which give the cyber actor the access they need. With phishing, the initial contact is often via email, although an increasing number of phishing attacks are now occurring via SMS (smishing), instant messaging...
OCR Explains Department’s Key Priorities at HHS-NIST Conference
Last week, the Department of Health and Human Services (HHS) and the National Institute for Standards and Technology (NIST) hosted the Safeguarding Health Information: Building Assurance Through HIPAA Security 2024 conference after a 5-year absence. Attendees learned about the current cybersecurity landscape in healthcare, how compliance with the HIPAA Security Rule can help HIPAA-regulated entities combat cyber threats, and were provided with practical tips and techniques for implementing the requirements of the HIPAA Security Rule. On October 24, 2024, in a keynote speech, OCR Director Melanie Fontes Rainer provided an update on OCR’s main priorities. One of the key priorities is an update to the HIPAA Security Rule to add new cybersecurity requirements. OCR has been working on an update to the HIPAA Security Rule this year and has now finalized its proposed rule. The proposed rule is now being reviewed by the Office of Management and Budget (OMB) and Fontes Rainer anticipates publishing a Notice of Proposed Rulemaking (NPRM) before the end of the year. Fontes Rainer did not...
Healthcare Compliance Teams Stretched Thin Due to Complex Regulations and New Risks
New compliance requirements are on the horizon as the HHS’ Office for Civil Rights (OCR) expects to publish a notice of proposed rulemaking later this year to update the HIPAA Security Rule with new cybersecurity requirements, but healthcare compliance professionals are already struggling to comply with existing regulations, according to a recent report from the Indianapolis, IN-based business law firm Barnes & Thornburg. For its 2025 Healthcare Compliance Outlook Report, the law firm surveyed 120 compliance, risk, and legal leaders at U.S.-based healthcare and life sciences organizations, including health systems, pharma firms, biotech companies, and medical device manufacturers. The survey revealed a majority of the respondents felt stretched thin due to the current complex regulatory landscape and expanding areas of risk, including increasingly sophisticated cyberattacks, the rapid adoption of artificial intelligence (AI) solutions, and increased scrutiny of mergers and acquisitions. Only 31% of surveyed compliance, risk, and legal professionals felt they were very prepared...
More Than 50% of Healthcare Employees Fail a HIPAA Assessment, New Data Reveals
Businesses in the healthcare sector have a responsibility to minimise the risks of HIPAA violations, for the sake of their patients, staff and the organization as a whole. One way in which organizations can mitigate internal breaches is by ensuring that staff receive regular HIPAA training. However the number of internal breaches recorded each year would suggest that more needs to be done to ensure employees are HIPAA compliant. To investigate the standards of HIPAA training in the healthcare sector, The HIPAA Journal researchers have examined HIPAA assessment fail rates, the percentage of staff who have witnessed HIPAA violations, and how frequently training is being conducted in 2023. How many employees working with PHI fail a HIPAA assessment? More than half of employees working in the healthcare sector fail a HIPAA assessment. The data suggests that more than 50% of staff working with PHI do not have a comprehensive understanding of HIPAA regulations, and therefore require more training. Which area of HIPAA training sees the highest fail rates? During a HIPAA assessment in...
HIPAA Compliant Remote Access Software
HIPAA compliant remote access software provides HIPAA-covered entities and their busines associates with a secure way of remotely accessing systems containing electronic protected health information (ePHI) and simplifies the management of remote access. Healthcare organizations can have dozens of vendors who require remote access to servers, applications, and healthcare data, and oftentimes several different methods are used to provide access to vendors. Without a single solution, management of remote access is time consuming, complex, and difficult to carefully control. Healthcare employees also need remote access to applications, files, and ePHI and remote access has become even more important in the COVID-19 era. To reduce the risk of infection and help control the spread of COVID-19, there has been a major expansion of telehealth services. Healthcare professionals are now conducting more visits virtually and need to remotely access applications, EHRs, and files to provide those telehealth services. Windows Remote Desktop Protocol can be used for remote access, but RDP is not...



