{"id":262,"date":"2018-05-25T07:00:28","date_gmt":"2018-05-25T07:00:28","guid":{"rendered":"https:\/\/advantagehcconsulting.com\/blog\/?p=262"},"modified":"2018-05-21T14:35:39","modified_gmt":"2018-05-21T14:35:39","slug":"hipaa-boost-compliance-by-reviewing-top-10-cybersecurity-terms","status":"publish","type":"post","link":"https:\/\/advantagehcconsulting.com\/blog\/2018\/05\/25\/hipaa-boost-compliance-by-reviewing-top-10-cybersecurity-terms\/","title":{"rendered":"HIPAA: Boost Compliance By Reviewing Top 10 Cybersecurity Terms"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-263\" src=\"https:\/\/advantagehcconsulting.com\/blog\/wp-content\/uploads\/2018\/05\/HIPAA.jpg\" alt=\"\" width=\"846\" height=\"780\" srcset=\"https:\/\/advantagehcconsulting.com\/blog\/wp-content\/uploads\/2018\/05\/HIPAA.jpg 846w, https:\/\/advantagehcconsulting.com\/blog\/wp-content\/uploads\/2018\/05\/HIPAA-300x277.jpg 300w, https:\/\/advantagehcconsulting.com\/blog\/wp-content\/uploads\/2018\/05\/HIPAA-768x708.jpg 768w, https:\/\/advantagehcconsulting.com\/blog\/wp-content\/uploads\/2018\/05\/HIPAA-210x194.jpg 210w\" sizes=\"auto, (max-width: 846px) 100vw, 846px\" \/><\/p>\n<p><span style=\"color: #ffffff;\"><strong><em>What you don\u2019t know may hurt you.<\/em><\/strong><\/span><\/p>\n<p>Failing to keep up to date on important cybersecurity issues can leave you wide open for a HIPAA breach.<\/p>\n<p>Keeping in sync with the hot terms in health IT allows your agency to prepare for and be part of healthcare\u2019s security conversation \u2014 and protect your organization in the process. Keep your team members knowledgeable and IT lexicon current with these 10 cybersecurity must-knows:<\/p>\n<p><strong><span style=\"color: #ffffff;\">1. Brute Force:<\/span>\u00a0<\/strong>A cyber-hijack that involves brute force breaks systems by repeatedly trying different passwords until finding one that finally works. Once the encryption is compromised, the hackers can take down the system. Find an overview of brute force attacks on healthcare and how to combat them by the\u00a0<strong>Department of Homeland Security\u00a0<\/strong>at\u00a0<a href=\"http:\/\/www.dhs.gov\/sites\/default\/files\/publications\/Encryption-Software-TN_0913-508.pdf\">www.dhs.gov\/sites\/default\/files\/publications\/Encryption-Software-TN_0913-508.pdf<\/a>.<\/p>\n<p><strong><span style=\"color: #ffffff;\">2. Cloud Computing:<\/span>\u00a0<\/strong>This type of health IT is \u201ca model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service-provider interaction,\u201d instructs the\u00a0<strong>National Institute of Standards and Technology\u00a0<\/strong>(NIST). Cloud computing remains a popular, cost-saving technology in healthcare with a plethora of certified vendors, but recent\u00a0<strong>HHS Office for Civil Rights\u00a0<\/strong>data attributes some common breach issues to problems with poorly configured systems with the culprit \u2014 cloud computing technologies.<\/p>\n<p><strong><span style=\"color: #ffffff;\">3. DDoS Attack:<\/span>\u00a0<\/strong>Distributed Denial of Service attacks wiggle into your systems and attack your resources, stopping your ability to do business. \u201cHackers accomplish a DDoS attack by literally sending so much web traffic at a target that it is unable to function,\u201d notes Homeland Security\u2019s fact sheet on DDoS attacks. A famous DDoS healthcare case involved the takedown of\u00a0<strong>Boston Children\u2019s Hospital\u2019s\u00a0<\/strong>servers in 2014 by hackers from the group\u00a0<strong>Anonymous<\/strong>.<\/p>\n<p><strong><span style=\"color: #ffffff;\">4. Handshake Traffic:<\/span>\u00a0<\/strong>This back-and-forth greeting centers on the agreement of two systems to do business. Technically speaking, it refers to the \u201cprotocol dialogue between two systems for identifying and authenticating themselves to each other, or for synchronizing their operations with each other,\u201d the NIST guidance says.<\/p>\n<p><strong><span style=\"color: #ffffff;\">5. Internet of Things:<\/span>\u00a0<\/strong>Also known as the IoT, the internet of things concerns the connection of devices, systems, objects, and more to the internet. This coordination supports the idea that connecting everything in your office and life will make providing healthcare services more efficient and easier \u2014 but, that\u2019s not always the case. With each new hookup, the opportunity for the loss of electronic protected health information (ePHI) rises.<\/p>\n<p><strong><span style=\"color: #ffffff;\">6. Jailbreak:<\/span>\u00a0<\/strong>This is a slang term that concerns the override of restrictions, usually on mobile devices like cellphones and tablets, in order to decrypt and install malware, illegal software, and\/or other barred applications. For this reason, it is critical to keep all your agency\u2019s devices locked with multifactor authentication and at-rest protocols as hackers may attempt to jailbreak a mobile unit when you leave these tools unattended.<\/p>\n<p><span style=\"color: #ffffff;\"><strong>7. KRACK:\u00a0<\/strong><\/span>Key Reinstallation Attacks, or KRACKs, happen when a hacker uses weaknesses in Wi-Fi systems. \u201cAn attacker within the wireless communications range of an affected [access point] AP and client may leverage these vulnerabilities to conduct attacks that are dependent on the data confidentiality protocol being used,\u201d says the\u00a0<strong>U.S.<\/strong><\/p>\n<p><span style=\"color: #ffffff;\"><strong>Computer Emergency Readiness Team (CERT<\/strong>)<\/span> in vulnerability report VU #228519. The only way to eradicate KRACK issues is to consistently install updates to impacted products. See the US-CERT report at\u00a0<a href=\"http:\/\/www.kb.cert.org\/vuls\/id\/228519\">www.kb.cert.org\/vuls\/id\/228519<\/a>.<\/p>\n<p><strong><span style=\"color: #ffffff;\">8. Mobile Device Management:<\/span>\u00a0<\/strong>Often referred to under its acronym MDM, mobile device management covers the administration of a provider\u2019s mobile devices, and also the security, updates and upgrades, implementation, and protection of these devices. MDM software helps with the organization of your agency cellphones, tablets, and laptops to ensure the protection of ePHI.<\/p>\n<p><strong><span style=\"color: #ffffff;\">9. 2FA:<\/span>\u00a0<\/strong>Formerly known as two-factor authentication, this type of encryption increases the protection of your devices by requiring both a password and another security measure. This adds another layer of user authentication for covered entities to protect ePHI.<\/p>\n<p><strong><span style=\"color: #ffffff;\">10. Virtual Private Network:<\/span>\u00a0<\/strong>Though many remote users know this term under its acronym VPN, they often don\u2019t know what it means. A VPN allows you to securely share your health data in a public network through the utilization of a private and secure network. The VPN offers you online protection virtually, and the utilization of a secure VPN remains a top tip to \u201chelp secure and protect PHI on mobile devices,\u201d according to the October 2017 edition of the OCR\u00a0<em>Cybersecurity Newsletter<\/em>.<\/p>\n<p><a href=\"https:\/\/www.supercoder.com\/coding-newsletters\/my-homecare-week-alert\/hipaa-boost-compliance-by-reviewing-top-10-cybersecurity-terms-157716-article\"><i><span style=\"font-weight: 400;\">Source- SuperCoder<\/span><\/i><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>What you don\u2019t know may hurt you. Failing to keep up to date on important cybersecurity issues can leave you wide open for a HIPAA breach. Keeping in sync with &hellip; <a class=\"readmore\" href=\"https:\/\/advantagehcconsulting.com\/blog\/2018\/05\/25\/hipaa-boost-compliance-by-reviewing-top-10-cybersecurity-terms\/\">Continue Reading &rarr;<\/a><\/p>\n","protected":false},"author":1,"featured_media":263,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[11,12,13,14],"class_list":["post-262","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","tag-home-care","tag-hospice","tag-ltc","tag-snf"],"_links":{"self":[{"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/posts\/262","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/comments?post=262"}],"version-history":[{"count":2,"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/posts\/262\/revisions"}],"predecessor-version":[{"id":265,"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/posts\/262\/revisions\/265"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/media\/263"}],"wp:attachment":[{"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/media?parent=262"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/categories?post=262"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/tags?post=262"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}