Manage risk before a breach
Of course, there is plenty that practices can do to prevent – and protect themselves from – a health data breach before it happens. Providing employee awareness training is an important step, said Craig Musgrave, chief information officer of the Doctors Company. Institute a training program for staff at all levels and go over the basics, such as refraining from opening emails from senders they don’t know, Mr. Musgrave wrote in a recent column. Updating all software regularly and backing up data is also essential. And Mr. Musgrave emphasizes the importance of “whitelisting.”
“Health care systems are fragmented in their management of systems and data,” Mr. Musgrave wrote in his column. “Their ability to patch legacy systems and employ cybersecurity staff varies enormously. Therefore, application whitelisting is essential. Rather than blacklisting known malicious software, an application whitelist prevents the launching of any executable program (known or unknown) that does not have explicit authorization. This, in combination with strong firewalls and network segmentation tools like micro-segmentation, provides stronger security.”
In addition, consider implementing data security policies and incident response protocols as well as employee training on securing patient data, ProAssurance’s Ms. Tullos said.
“A breach can also occur within a third-party vendors system and infiltrate the physician’s records, so it is important to discuss cybersecurity with those vendors and all parties should purchase cyberliability insurance,” she said.