My EMR/EHR Makes Me HIPAA Compliant, Right?

My EMR/EHR Makes Me HIPAA Compliant, Right?

Far too many privacy officers lean on their electronic medical record (EMR) or electronic health record (EHR) system as a HIPAA compliance crutch. They believe (mistakenly) that an EMR/EHR system keeps their organization HIPAA compliant. Maybe that’s you. However,...
Is Your Backup Data Secured?

Is Your Backup Data Secured?

In January 2017, a HIPAA-covered Texas clinic learned that someone had stolen an unencrypted external hard drive. The thief took it from a locked closet inside the clinic. The clinic used that hard drive to back up patients’ protected health information (PHI)....
What is a HIPAA Security Risk Analysis?

What is a HIPAA Security Risk Analysis?

A security risk analysis is a vital part of the risk management process. According to the HIPAA Security Rule, all HIPAA-covered organizations must conduct them. This analysis helps your organization prevent, detect, contain, and correct security violations. However,...
Update on Texting Patient Orders

Update on Texting Patient Orders

The Joint Commission (TJC) has concluded that it is not acceptable to use secure text messaging for patient care orders. Industry experts weighed in on the pros and cons of implementing secure text orders, and the impact on patient safety remained unclear. Therefore,...
Social Engineering: A Hacking Story

Social Engineering: A Hacking Story

We’re all familiar with what a technical hacker is. They sit behind a computer somewhere planning their strike on an unsuspecting healthcare company. Healthcare is a prime target for technical hackers. However, a more subtle threat exists: social engineering....