Archives     Advertise     Editorial Calendar     Subscribe     Contact Us    



NMGMA: Ten Minute Takeaway


 
Jackson Thornton's Nic Cofield shares the devious means criminals use to gain access to PHI.

The second Tuesday of each month, practice managers and healthcare industry service providers gather at KraftCPA headquarters for the monthly Nashville Medical Group Management Association (NMGMA) meeting.

During the June luncheon, Nic Cofield, business development manager for Jackson Thornton Technologies, spoke about the importance of protecting your practice in the age of the healthcare hack.

Cofield helps educate and protect companies and practices against cybersecurity threats. He noted many healthcare organizations have taken significant steps like encryption and installing firewalls to safeguard their practice and protected health information (PHI). While providers have gotten smarter ... so have the bad guys who now target specific information. The biggest weakness facing security for employers, he said, is the education of employees and staff.

"In most situations, incidents caused by employee actions are not the result of malicious intent. Rather, the majority of cases stem from a lack of understanding and an overall sense of complacency," explained Cofield.

The five biggest threats to organization's cybersecurity are phishing, vishing, SMiShing, USB baiting, and impersonation and tailgating.

Phishing is the deceitful practice of sending emails pretending to be from reputable companies in order to compel someone to reveal their personal information, like passwords and credit cards. For example, the email from a prince of a foreign country claiming you've come into a large sum of money if only you'll send your social security number. Of course, criminals have gotten much more sophisticated with the bait the days.

Because newer safeguards are being taken, hackers have evolved to spear-fishing, which is a more targeted way of phishing using social media platforms in order to obtain information like club affiliations and member organizations to personalize and target the attack. A little detective work can make an email seem much more legitimate.

Cofield recommended employees pay extra attention to email URLs and improper grammar, which is often a sign the email has been sent by someone for whom English isn't a native language. He said extra precautions are especially necessary for any message requesting document downloads, requiring quick action after sharing frightening information, or any type of online banking alert.

Vishing, which is similar to phishing, finds the attacker using the phone to impersonate trusted sources or authorized organizations. Vishing most commonly targets areas of highly focused customer interactions, like the front desk or billing.

Sometimes the scam utilizes two calls with the first being reconnaissance and a follow-up caller using the information collected to make an information request seem more legitimate, One example might be the impersonation of IT support with a request of password information to download a software patch or update remotely.

Another threat that is gaining popularity is SMiShing, which utilizes text-based hacks and tricks users to download malicious software onto the device. Typically, the text says action is required and includes a link.

Attackers also utilize in-person methods of hacking through USB baiting and impersonation and tailgating.

USB baiting involves planting a USB device with the goal of having a user find the device and plug it into a computer. For example, a guest might drop a USB device in the lobby or inconspicuously lay it on the edge of the front desk before leaving the building. The hope is that a good Samaritan will plug in the device to see if they can obtain any information about who left it behind in order to return it. When they do this, the hacker is able to encode malicious software into their system.

Finally, hackers are able to utilize impersonation and tailgating to gain access to sensitive information. Social engineers are now posing as technicians, delivery people, and pest control reps amongst other things in order to exploit weak access controls and gain physical access to restricted areas. Cofield said a vishing expedition could uncover the name of a network provider. With a quick internet search, it's easy to download a logo from that company and have a polo shirt made with the emblem on it to look official.

These people can also 'piggyback' off of authorized users in order to gain access by asking for someone to hold the door for them or claiming to have left their access badge at home.

Cofield said the best way to prevent these hacks from occurring is to make sure employees are aware of these situations and know how to react in each scenario. He also suggested training should go beyond basic education and that companies should implement a Security Awareness Program that has a set routine of education and training sessions that can be scored and tracked on an ongoing basis. For those in the medical profession, the HIPAA Security Rule requires the implementation of these programs for all members of the workforce. Employees should be regularly tested on their knowledge to make sure that everything is implemented correctly and to address areas of weakness.

While all of these safeguards are important and should be implemented, Cofield emphasized that it is still crucial to constantly update your system and procedures in order to maintain safety and try to stay a step ahead. "If someone wants to get to you, they'll get to you," he cautioned. "What additional layers can you add? What policies can be put in place?" Cofield questioned.

People make mistakes, he said. Therefore, it's important for organizations to understand the many different ways in which systems can be compromised, create a security awareness program, and then train, test, and retrain employees regularly to try to minimize risks.

For information on upcoming NMGMA events or to learn more about the association, go online to nmgma.com.

WEB:
NMGMA
Jackson Thornton Technologies

 
Share:

Related Articles:


Recent Articles

Post-Flu Risks A Growing Concern For The Elderly

Infectious disease experts are warning that flu can lead to an increased risk of heart attack, stroke and disability in elderly patients for months after they have recovered from their illness.

Read More

Meharry & HCA Join Forces for Training Physicians

Meharry students to train in HCA system.

Read More

Hospital Groups File Lawsuit To Stop Significant Payment Cuts For 340B Hospitals

Today, the American Hospital Association (AHA), the Association of American Medical Colleges (AAMC) and America's Essential Hospitals filed a lawsuit against the U.S. Department of Health and Human Services (HHS) in the U.S. District Court for the District of Columbia to prevent significant Medicare payment cuts for hospitals that participate in the 340B Drug Pricing Program.

Read More

CMS proposes policies to lower the cost of prescription drugs and combat the opioid crisis

The proposed rule eliminates administrative hurdles to providing more affordable prescription drugs and will allow Medicare to combat opioid overprescribing and abuse.

Read More

Tax Reform & Healthcare

Medicare cuts and repeal of the individual mandate are two areas of tax reform directly impacting healthcare.

Read More

Senate HELP Committee Hearing on Gene Editing Technology

On Nov. 14, the Senate health committee held a hearing on the gene editing method CRISPR to learn more about the technology from expert witnesses, which included Dr. Matthew Porteus, associate professor of Pediatrics at Stanford University; Katrine Bosley, CEO and president of Editas Medicine; and Dr. Jeffrey Kahn, director of the Johns Hopkins Berman Institute of Bioethics at Johns Hopkins School of Public Health.

Read More

Nashville Health Care Council Hosts Panel Discussion on Pharma/Provider Collaborations in Health Care

On Nov. 13, the Nashville Health Care Council hosted a panel discussion on collaborations between the pharmaceutical and healthcare provider sectors and how those collaborations can drive change in healthcare.

Read More

Tennessee Health Care Hall of Fame Class of 2017

Six healthcare luminaries were recently inducted into the Tennessee Health Care Hall of Fame.

Read More

NMGMA 10 Minute Takeaway

Nashville Medical News recently had the opportunity to chat with new NMGMA president Joy Testa.

Read More

Tennessee Joins Medical Licensing Compact

A new Tennessee law will make it easier for area physicians to practice across state lines beginning in 2019 as part of the Interstate Medical Licensure Compact.

Read More

Email Print
 
 

 

 


Tags:
Cybersecurity, Hacking, Impersonation, Jackson Thornton Technologies, Nashville Medical Group Management Association, Nic Cofield, NMGMA, PHI, Phishing, Protected Health Information, SMiShing, USB Baiting, Vishing
Powered by Bondware
News Publishing Software

The browser you are using is outdated!

You may not be getting all you can out of your browsing experience
and may be open to security risks!

Consider upgrading to the latest version of your browser or choose on below: