One year into the coronavirus (COVID-19) pandemic, phishing attacks against healthcare organizations remain a chief concern. Threat actors are constantly finding new vulnerabilities to exploit. It’s like a game of whack-a-mole: When healthcare organizations swat away one problem, another pops up.
Q: If we work with a business associate (BA) that enters into agreements with BA subcontractors, are we required to obtain copies of these agreements and review them?
Q: Are we allowed to use case studies involving real incidents that occurred at our facility as part of our HIPAA training? We’ve always been told that real-life examples will resonate with staff, but wouldn’t this be a HIPAA violation?
Q: We are coming up on our annual HIPAA training for staff. We have used the same training program for several years—it covers the basics and places a strong emphasis on recognizing phishing and other cyberattack tactics. Given the events of the past year, are there any other security trends we should be sure to highlight during our training session?
Q: As we look forward to 2021, we’re looking to utilize the most up-to-date HIPAA training strategies. I am responsible for training clinical and clerical staff annually. Do you have any recommendations for job-specific HIPAA training?
Welcome to the brave, not-so-new world of compliance and cybersecurity! News of cybercrime seems to be constantly in the headlines, and healthcare is one of the key industries being targeted.