Five worthy reads is a regular column on five noteworthy items we discovered while researching trending and timeless topics. In this weeks edition, lets explore the role of HIPAA compliance in the cybersecurity era.
HIPAA stands for the Health Insurance Portability and Accountability Act, a federal statue in the United States which mandates data protection by anyone or any organization that creates, stores, transmits or uses an individualsprotected health information (PHI). This privacy rule ensures each individuals rights over their own health information. A lot of PHI is stored on endpoints like local drives, hard disks, cloud storage and USBs. Protecting this sensitive data from attacks is the healthcare industrys biggest challenge. PHI identifiers include any demographic information like name, photos, Social Security number, birth date, contact number, email address, medical records number, biometric elements, which are used to identify an individual.
There are two entities in HIPAA that needs to be compliant; one is covered entities, and the other is business associates. Covered entities are healthcare providers, health insurance plans, and healthcare clearing houses that are directly involved in the creation of PHI. Business associate is any organization that is hired by the covered entity or another business associate to handle the PHI, which commonly include MSPs, EHRs, medical billing services, cloud storage providers, and shredding services.
HIPAA trainings are widely mandated in companies that deal with PHIs. It provides the necessary guidance on the permitted uses and disclosure of PHI, how to protect it, and what to do when its breached. Even with mandated HIPAA trainings, annual assessments and audits, and data protected by todays heavy encryption methods, does the 25-year-old HIPAA keep up modern cybersecurity trends? Are HIPAA regulations sufficient to prevent the data leakage and attacks?
Arecent industry studystates that 82% of healthcare organizations globally have endured an IoT cyberattack during the past 1 1/2 years and there was a40% increasein average weekly cyberattacks on all organizations globally from 2021, compared to 2020. HIPAA laws were established in 1996 and these old guidelines can reduce the cybersecurity attacks, but might not be sufficient to provide the best safeguards. While some regulation revisions have been enacted, the HIPAA rules have not keep pace with whats required from a technology perspective. When the 2009 HITECH Act became law, four years passed before the 2013 HIPAA Omnibus Rule became effective and it has been more than seven years since the next major update. OnJanuary 5, 2021, a new law was signed amending the HITECH Act. The HIPAA Safe Harbor Bill will incentivize organizations to voluntarily adopt best cybersecurity practices.
Here are five interesting reads on the role of HIPAA compliance in the cybersecurity era.
Why HIPAA Compliance is the Key to Preventing Cyber Attacks
Being HIPAA compliant not only saves your organization from hefty fines from the federal government, it strengthens your network security and protects sensitive data from unwelcome eyes. There are three parts to HIPAA compliance process; first is the documentation process that involves a risk assessment to identify what changes need to be performed, second is conducting annual training for your employees on both HIPAA and the organizations security policies and procedures, and third, is implementation.
Is HIPAA Compliance Enough? What You Need To Know About Cybersecurity
In the digital era data breaches are always on the rise which clearly states just being HIPAA compliant is not enough. HIPAA sets the minimum standards for security but it doesnt guarantee protection against hacks and breaches. Healthcare organizations must invest in blooming technologies like cloud-based environments, taking control of assets and limiting access, enforcing a risk management protocol and a robust security policy.
HIPAA Compliance and the Protection of Cybersecurity
In the cybersecurity era, sensitive patient data is saved and maintained digitally and protected from hackers, identity thieves, and spammers. With the growing threat, healthcare organizations are investing highly in cybersecurity and hiring cybersecurity experts whose role is to keep the data protected and make sure it is available only to authorized personnel. The HIPAA privacy rule might help with security, but it seems to meet only the minimum standards. Organizations must take actions beyond basic HIPAA compliance to ensure their security is protected from an increasing number of threat actors. The National Institute of Standards and Technology (NIST) publishes the guidelines and framework for the organizations. Together, the HIPAA security rule and NISTs framework help organizations reduce cybersecurity risks.
Cybersecurity and HIPAA Compliance Go Hand in Hand: Heres Why
At the core of HIPAA is a security rule, also known as the Security Standards for the Protection of Electronic Protected Health Information, that discusses safeguards that need to be in place for organizations to best handle electronic protected health information. This is best understood in conjunction with the privacy rule, also known as the Standards for Privacy of Individually Identifiable Health Information, created to make national standards that ensure that confidential health data is properly protected. This article addresses insider threats and personnel training as two strategies to increase healthcare cybersecurity. Crucial for maintaining HIPAA compliance, cybersecurity requires organizations to look at insider threats as much as external threats and educate individuals on the best ways to detect and report it.
Dont sleep on HIPAA and cybersecurity
The healthcare sector is a prime target for cybercriminals. Unlike in banking and other sectors,medical identity theft might not be immediately identified and stopped by the patients or healthcare providers, often giving cybercriminals years to milk the identity of a patients credentials. This makes medical data 50 times more valuable to cybercriminals than credit card information. Healthcare organizations can take advantage of the new HIPAA Safe Harbor law enacted that takes into account that cyberattacks are not always preventable and hefty fines are not a solution or remedy. This law amends the HITECH Act and requires the US Department of Health and Human Services to recognize the existing good cybersecurity practices that an organization has in place when investigating a data breach and to be more lenient with penalties, as appropriate.
The post Five worthy reads: HIPAA compliance in the age of cybersecurity appeared first on ManageEngine Blog.
*** This is a Security Bloggers Network syndicated blog from ManageEngine Blog authored by Sree Ram. Read the original post at: https://blogs.manageengine.com/corporate/general/2021/12/03/five-worthy-reads-hipaa-compliance-in-the-age-of-cybersecurity.html
Read more:
Five worthy reads: HIPAA compliance in the age of cybersecurity - Security Boulevard
- CTERA Networks Partners with SYNNEX Corporation to Drive Market Demand for Hybrid Cloud Storage, Collaboration and ... [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Cloud storage exempt from Ninefold's uptime boost [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Virsto Named Finalist of 2012 Storage Virtualization & Cloud Awards [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Innovative Hybrid Cloud Storage Solutions Now Available From PROMISE Technology [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Box Talks Integration with BlackBerry 10 and Cloud Storage for Business - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- AG112's Weekly Technology Tutorials Ep.7 Cloud Storage - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Cloud Storage - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Google Cloud Storage Office Hours - 9/5/2012 - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- IBM Cloud Storage -- Future Directions - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Working with best FREE Cloud storage solution - MediaFire - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Best Cloud Storage | How Nate Made $450 His First Hour... - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Cloud Storage Services: Comparison - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Top 10 Free Cloud Storage Services of 2012 - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Cloud Storage Wars - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Secure and Comprehensive Cloud Storage for Health IT - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Free Cloud Storage! - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Microsoft SkyDrive Cloud Storage - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Top 16 Android Cloud Storage Apps Quick Breakdown - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Up to 48GB of FREE Cloud Storage, 14GB Guaranteed - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Nasuni's CEO To Speak At Interop On The Secure Use Of Cloud Storage [Last Updated On: October 6th, 2012] [Originally Added On: October 6th, 2012]
- Oracle vs Amazon Cloud Storage: OpenWorld 2012 - Video [Last Updated On: October 6th, 2012] [Originally Added On: October 6th, 2012]
- Apple extends iCloud storage for another year [Last Updated On: October 7th, 2012] [Originally Added On: October 7th, 2012]
- Interush Introduces Convenient Cloud-Based Storage Service with Release of PHYTTER DOCK Application [Last Updated On: October 9th, 2012] [Originally Added On: October 9th, 2012]
- Get a free 15GB cloud-storage account from 4Sync [Last Updated On: October 9th, 2012] [Originally Added On: October 9th, 2012]
- Cloud Solutions Increase Customer Engagement and Retention [Last Updated On: October 9th, 2012] [Originally Added On: October 9th, 2012]
- Pogoplug offering 100GB of cloud storage to UK users for just £19.99 a year [Last Updated On: October 10th, 2012] [Originally Added On: October 10th, 2012]
- New vFoglight Storage 2.0 Provides Integrated Application to Disk Performance Monitoring [Last Updated On: October 10th, 2012] [Originally Added On: October 10th, 2012]
- Lunacloud Deploys Cloudian® To Grow Business, Offer S3 Compatible Cloud Storage [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- New Cloud Storage Company, ZapDrive, Launches Today Offering 100 GB for $19.99/year. [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- Otixo Adds Ubuntu One to Aggregated Cloud Storage Lineup [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- Cloud Storage Reviews Announcement Video - Video [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- Cloud storage outage strikes Macquarie Telecom [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- Online-Storage.com is Now SIO.CO [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- C2C Maximizes eMail Archiving Flexibility and Control With Support for the Hybrid Cloud [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- OwnCloud: Build your own or manage your public cloud storage services [Last Updated On: October 12th, 2012] [Originally Added On: October 12th, 2012]
- Ubuntu's cloud storage service hits Mac in beta, with 5GB free [Last Updated On: October 12th, 2012] [Originally Added On: October 12th, 2012]
- Akitio Cloud Hybrid Review: Convenient NAS and USB Storage in One [Last Updated On: October 13th, 2012] [Originally Added On: October 13th, 2012]
- Symform Hires Senior Sales Executive to Build Global Partnerships as Distributed Cloud Storage Network Surpasses 5.5 ... [Last Updated On: October 15th, 2012] [Originally Added On: October 15th, 2012]
- Get an extra 25GB of storage in the Dropbox Great Space Race [Last Updated On: October 16th, 2012] [Originally Added On: October 16th, 2012]
- Microsoft Acquires StorSimple To Increase Cloud Storage Capabilities [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Inktank-Metacloud Partnership Enhances Fully Managed Private Cloud Solution With Enterprise-Class Storage [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Citrix and NetApp Collaborate to Simplify Cloud Storage [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Microsoft Acquires Leader In Cloud-integrated Storage [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Microsoft Buys StorSimple for Enterprise Cloud Storage [Last Updated On: October 18th, 2012] [Originally Added On: October 18th, 2012]
- FreedomPACS, Radiology PACS and Cloud Image Storage Provider, Releases Results of County Hospital Case Study ... [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Nirvanix Selects Brocade as Networking Backbone for Global Cloud Expansion [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Pogoplug offers unlimited cloud storage for $5 a month [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- NTT Communications Chooses Cloudian® S3 compatible Object Storage Platform for Multi Petabyte Cloud Storage as a Service [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- TwinStrata and Google to Host "Beyond Disaster Recovery: Integrating Cloud Storage into Your IT Strategy" Seminar [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud Storage Reviews Outlines "How SugarSync Works" In Latest Guide [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Symform Challenges Users to Think Beyond Centralized Data Centers With Its 'Byte Me' Promotion [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Avere to tart up FTX with cloud storage gateway, mutterings foretell [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Deals WD My Book Live Personal Cloud Storage 2 TB Network Attached Best Price 2012 - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Create and Manage Your Own Cloud Storage Free - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Free Cloud Space 100GB - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- DuraCloud Brown Bag Series: How DuraCloud is Different From Amazon - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- PocketCloud Explore - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Free 1TB Cloud storage - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Store your files on WEB for free - Unlimited and better than dropbox - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- CloudBackupNow - Retention Policy (with audio) - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- CloudBackupNow - Retention Policy - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- CloudBackupNow - Primer II - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- ERP Data Capture animation - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cash rains DOWN on the Cloud - Nasuni trousers $20m [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- My PC Backup Review The Cloud Storage Service For You - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Samsung ATIV S Review - Phones 4u - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Trust Me mv - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Product Webinar: Collaborating and Exchanging Large Data at Distance with Faspex 3.0 - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- DT Daily: Facebook takes aim at Craigslist, Halo 4 reviews a - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- 2 MCSE Private Cloud Storage Basics - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Gladinet Cloud Enterprise Quick Start Guide - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Installing OfficeDrop Mac File Sync - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- OfficeDrop Mac File Sync - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Secure Cloud Storage - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Windows Phone 8: Lenese integrates apps in the camera app - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Graphic Video on Wuala Secure Cloud Storage from Paula Hansen and Chart Magic - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Hurricane Sandy Cheat Meal Run to Tastee Diner - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Cloud Zow Review - Cloudzow Review | Marketing Secret Revealed - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- What is Cloud Storage? - Video [Last Updated On: November 4th, 2012] [Originally Added On: November 4th, 2012]
- Perfume - Chocolate Disco [ hide@BSB Battle In Feb. Remix ] - Video [Last Updated On: November 4th, 2012] [Originally Added On: November 4th, 2012]