image_pdfimage_print

You have just found out that your medical office has had a data breach. Your patient health information has been compromised. Was your computer the entry point for the hackers? Do you want to be known as the weakest link? Of course not. However, in today’s highly connected medical practices and hospitals, the weakest links often remain the people. Practicing basic cyber hygiene is one of the first steps to protect yourself and your office against cyber attacks. Employees’ cyber hygiene is mandatory and done in conjunction with several other actions performed by your IT personnel to keep your patient data secure and private.

The Center for Internet Security has developed a Cyber Hygiene toolkit that clearly outlines what can be done to promote good cyber habits.
 
Count:
– Always know what devices you have and where they are. This applies to personal and corporate devices that access your patient’s data – they may be computers, mobile phones, tablets, etc.
– Be careful of how many people can access each of your devices. Keep them password protected and limit the number of users who have rights to login to each device.
 
Configure:
– Install anti-virus or anti-malware software on all computer systems.
– Be sure to download all updates from anti-virus software – if not, they will not properly detect and clean viruses and malware.
– Enable security features on your devices and accounts, e.g. tracking features, two-factor authentication, encrypt your phone if it has the feature, lock your screen, set up logon passwords. Most of these features are very easy to set up.
 
Control:
– Having a password is good only if it is a strong password and if it is truly private. Do not share your passwords or keep them written in plain text.
– Be careful of how much information you share online. If you announce on social media that you are embarking on a 2-week vacation to Europe with your family, it is almost like handing out an invitation to steal.
– Watch out for phishing emails. They have become so sophisticated these days that it is often very difficult to distinguish between a real email and a phishing message. Check the source – hover over the link to identify where the email is coming from, do not click on any links in emails unless you are sure that they are directed to the right place.
Patch:
– Update, update, update!
– When a company brings out a software update for their product, especially one that is meant to address security vulnerabilities, do update your apps at the earliest.
 
Repeat:

– Repeat all steps mentioned above, to continuously improve your cyber hygiene and get cyber healthy! 

To watch a brief video on Cyber hygiene and to take the Cyber pledge, visit https://youtu.be/-bTVO6aOkoc or use your smartphone QR reader app to scan this QR code: 

 
 
 
 
To learn more about strong passwords and how to remember them, visit https://www.youtube.com/watch?v=drTJq9CmyHw or scan this QR code: