Blog
We know you have a lot of questions. That’s why our team has curated top-notch resources to help you along your healthcare cybersecurity and compliance journey.
Business Impact Analysis: A Critical Process to Improve Resiliency in Wake of a Cyberattack
On the heels of a major wave of ransomware activity in late 2019, this week healthcare organizations find ...
Making Cyber Risk Management an Ongoing Process
With new changes in technology, organizations must consider new threats and vulnerabilities as they are discovered.
OCR Re-Affirms Enterprisewide Risk Analysis is the “Most Important Thing You Can Do to Protect Yourself” Against a Cyber Attack
“Attacks are now more sophisticated and more targeted,” Office for Civil Rights Director Roger Severino said. “The single most important thing you can do to protect yourself is to conduct a risk analysis.”
Developing a More Secure PACS Ecosystem
The security of medical images took center stage this past week as Senator Mark Warner of Virginia demanded that TridentUSA and its affiliate MobileXUSA outline their cybersecurity practices after ProPublica reported the imaging firms left millions of medical records and patient data exposed online.
What the New York SHIELD Act Means for Healthcare Organizations
On July 25, 2019 the Governor of New York signed into law the “Stop Hacks and Improve Electronic Data Security Act” (SHIELD ACT) effective March 21, 2020.
The Rise of Enterprise Cyber Risk Management Software
The digital transformation of healthcare is rapidly driving the adoption of new technology and information systems to support key business initiatives. We are experiencing a veritable explosion in health care data, systems and devices.
Understanding What Constitutes OCR-Quality Risk Analysis®
In the first half of 2019, there were 223 reported breaches affecting 10.2 million individuals, an increase of 167% over the same period in 2018. These figures do not include the widely publicized American Medical Collections Agency breach, which is estimated to have affected at least 22 million individuals on its own.
Understanding the True Cost of a Data Breach
In the case of American Medical Collection Agency’s (AMCA) highly publicized data breach, the cost proved unrecoverable as the 42-year-old parent company Retrieval-Masters Credit Bureau filed for bankruptcy just weeks after disclosing the breach.
Organizations should calculate the risk of a data breach, not only for covered entities but also for their business associates. A breach of your patient data will affect your organization, even if it’s by a business associate.
State Attorney General HIPAA Enforcement Ramps Up, Value of an OCR-Quality Risk Analysis® Has Never Been Higher
Many Chief Information Security Officers and Chief Compliance Officers often express concern to us about the potential disruption and cost that can come from an Office for Civil Rights (OCR) investigation, not to mention the reputational damage that will result from a settlement or monetary penalty. An appearance on the wall of shame is a mere blemish compared to the negative publicity of an OCR fine or settlement. However, the possibility of a State Attorney General (AG) action is often underestimated and overlooked. If a State AG enforcement is not top of mind for you and your board, it should be.
Key Takeaways From Breakfast & Breaches® | D.C.
Clearwater’s recent Breakfast & Breaches event in Washington, DC brought together an outstanding group of leaders with unique insight on the growing problem of how to keep protected health information secure. Drawing on their combined decades of experience working across the compliance spectrum, our panelists and moderator challenged the audience’s thinking with regard to how their organizations analyze and manage risks.
Managing Third-Party Information Security Risk
Clinical laboratory provider Quest Diagnostics recently acknowledged that a billings collections vendor it works with suffered a data breach on its web payment system that may have exposed information of nearly 12 million of Quest’s patients. The third-party company, Elmsford, N.Y.-based American Medical Collection Agency (AMCA), is contracted with Optum360 LLC, which in turn provides payment services to Quest.
NIST and Telehealth: Securing the Remote Patient Monitoring Ecosystem
We are living in an exhilarating time in the world of healthcare. A common theme among many healthcare related stories and articles we come across today is that things which were once thought to be a matter of science fiction are now moving closer to becoming a reality. A Feb 27, 2019, article from Forbes Magazine, entitled, “Telemedicine: The Latest Futuristic Tech Prediction from The Jetsons To Come True,” brought up a cartoon show from 1962, “The Jetsons,” in which depicted patients video conferencing physicians for diagnosis and treatment as being something commonplace.
Newsletter
Sign up for our monthly newsletter discussing hot topics and access to invaluable resources.
Featured Resource
Protecting PHI: The Buck Stops Here for BAs
Introduction
With both increased OCR investigations and ...