Practice Matters: Executive Insights for Independent Healthcare Groups

Practice Matters: Cybersecurity & Risk for Private Practices

DMJPS CPAs + Advisors Season 1 Episode 2

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 52:13

Cybersecurity is no longer just an IT concern. For healthcare organizations, it's a critical business risk that can impact operations, finances, patient trust, and regulatory compliance.

In this episode of Practice Matters: Executive Insights for Independent Healthcare Groups, Jonathan Peddrick, Partner at DMJPS, sits down with Debi Carr, cybersecurity specialist, for a timely discussion on the threats healthcare leaders need to be paying attention to right now.

From ransomware attacks and phishing schemes to data security, employee training, incident response planning, and risk management, Jonathan and Debi break down how healthcare organizations can better protect themselves in an increasingly complex digital environment.

Whether you're a physician owner, practice administrator, healthcare executive, or finance leader, this conversation offers practical guidance to help you identify vulnerabilities, strengthen your defenses, and reduce organizational risk.

Be sure to stick around for the Q&A session, where Jonathan addresses audience questions and explores real-world cybersecurity concerns facing healthcare organizations today.

DMJPS CPAs + Advisors provides specialized tax, accounting, advisory, and healthcare consulting services to independent healthcare organizations across North Carolina. Through Practice Matters, we bring together industry experts and healthcare leaders to share practical insights on the issues shaping the future of healthcare.

Give it a listen.

Presenter: Debi Carr - DK Carr & Associates
Facilitator:
Jonathan Peddrick, CHBC - DMJPS Partner

SPEAKER_01

Hello, and welcome to Practice Matters, Executive Insights for Independent Healthcare Groups. I'm Karen Rodriguez, Chief Marketing Officer at DMJPS CPAs and Advisors. And thank you for joining us for another important conversation focused on helping healthcare organizations navigate today's evolving risk landscape. At DMJPS, we work with physician groups, dental practices, and healthcare organizations across North Carolina, providing accounting, tax, advisory, and healthcare consulting services designed to help practices operate more effectively and protect what they've built. Today's discussion is facilitated by Jonathan Pedrick, who partner at DMJPS with our healthcare consulting practice, and features Debbie Carr, a cybersecurity specialist who works with organizations to strengthen security, reduce risk, and prepare for emerging cyber threats. It's a business issue, a patient issue, and increasingly a leadership issue. From ransomware and phishing attacks to data privacy concerns, regulatory compliance, and business planning, healthcare organizations face a growing number of risks that can help have significant operational and financial consequences. In this conversation, Debbie and Jonathan discuss the current cybersecurity landscape, common vulnerabilities within healthcare organizations, practical risk mitigation strategies, and the steps leaders should be taking today to pred or protect their practices, their teams, and their patients. And be sure to stay through the end of the QA where Jonathan dives deeper into some of the questions healthcare leaders are asking most often. Thanks for listening and let's get started.

SPEAKER_00

My name is Jonathan Pedrick. I am a partner here at DMJPS CPA and Advisors and our lead healthcare uh and our lead for our healthcare practice consulting team. This session really couldn't be more timely, especially given how quickly the landscape is evolving. The enforcement signals we're seeing right now in the industry really underscore why this conversation couldn't be more timely for an independent practice. Now, without further ado, it is my pleasure to introduce our speaker. Debbie Carr is the CEO of DK Carr and Associates, a technology systems and cybersecurity consulting firm focused on healthcare and dental practices. With over 30 years of experience in technology and security and more than two decades in private practice management, she specializes in helping practices achieve and maintain HIPAA and high-tech compliance through risk analysis, training, and security programs. Debbie is a recognized speaker, consultant, and educator dedicated to protecting patient data and strengthening cybersecurity in the healthcare settings. At DMJPS, we strongly believe surrounding our clients with the right expertise and relationships, like Debbie, allows us to deliver even greater value to the practices we serve. Without further ado, I'll turn things over to our presenter to get us started. Debbie, it's all yours.

SPEAKER_02

Thank you so much, Jonathan. Thank you so much for having me. And yes, um, any if there's any questions, please feel free to let me know. So I am Debbie Carr. I'm with DK Carr and Associates, and I belong to a bunch of uh dental, medical, optometry, uh, and cybersecurity organizations. So, where to start? A couple of months ago, I was conducting a risk analysis in uh practice, and they told me that they had a consultant. So I asked, where is the consultant's documentation? And the consultant that was consulting with this practice had no idea that she was required to have a document uh in place, and so I thought that that's where I would start is that it's important that all businesses and and when you are a private owner or when you own a practice, you are in business, and so it's important that all businesses identify what regulatory requirements you have. A lot of times we think, oh, well, we know we've got HIPAA because we're healthcare, but what other requirements do you have? If you have patient records, you may also come under the 21st Century Cures Act, which is in force and it talks about how you have to release records right away. Or you, and of course, we're all operating in states, all 50 states, including Puerto Rico, have some laws on their books that are to design to protect the residents, and it always encompasses information that we are gathering in our healthcare records. So it's important that we document what our regulatory requirements are and that we identify what they are, and then we make sure that our staff and our team members are aware of what those regulatory requirements are. There's been a lot of conversations happening about the upcoming changes to the security rule. They HIPAA has always had the requirements in place. It's just that they've not been very prescriptive. They've been very, well, you should do these things. As our technology has changed, our security requirements has changed. And that's actually the beauty of HIPAA, is that it's always been there and it was written in such a way that as the technology changed, the we had the flexibility of being able to change and to add those security protocols. Well, encryption's been required. Back when the law was written, encryption was very expensive, and it was very uh it required a lot of uh processes. You had to buy a very expensive uh piece of software, and then you had to back up all your data, and then you had to load the software on, and it had to do its thing for probably 24 hours, then you could load, so it was very time-consuming, it was a very expensive process, so it was addressable, and addressable meant you had to do it unless you could document why it was too expensive to do it. Well, now it's a click of a button, and so it's no longer addressable, it is required, and we know it's required because of enforcement, but more importantly, it should be required on all endpoints because it is a good best practice cybersecurity protocol to protect the information, the data that we have in our businesses. This is an actual ransom note from one of my clients. Unfortunately, we have seen an uptick of ransomware attacks in the last um few months, even, where um the uh the attacks are happening um quicker. Sorry, my the things flipped through. The attacks are we're seeing 237 percent uptick in cyber attacks happening across the healthcare space. Healthcare continues to be a prime target, and this is because the hackers know that we're not taking the precautions that we should be taking. We're not we haven't implemented best practices. I had a conversation just the other day with an IT that kept telling me that I was asking too much of him to give unique user. Well, that's been in HIPAA since since 1996, so why is this difficult? So it's just that we are not wanting to change, and I get that change is hard, but it when it's for the best, it is it it makes it a lot easier. So we want to trust but verify. We want to make sure that we are uh trusting the vendors that we're doing business with, we want to trust the people that we have hired in our business, but we want to verify, we want to make sure that we are uh that they're doing what they said they're doing. I was at a conference last week and I loved what one of the speakers said. Trust is not a security protocol, it's not a cert security control. There has to be mechanisms in place to make sure that we are truly protecting our patient information and our business information. We forget all the data that we have, and there's a lot a lot of a lot more data in our practices than just patient information. You have financial information, you have employee information, so we have to protect that information so that we're protecting the investment of our business. Documentation, documentation, documentation. I see that end got messed up there, but if it's not in writing, it did not happen. And when there is any kind of investigation, whether it be through OCR, the Office of Civil Rights, which is the enforcement for HIPAA, or a state regulator, a lot of times we forget that there are state regulators that may come in and do investigations. They don't ask you, well, what do you think, or what were you thinking, or what's your policy? They ask you, they send you a letter with a list of the documents that they're going to ask and that they want out of you. And it's all in your documentation. I had an auditor tell me one time, the more the boring, more boring you can make my the audit for me, the more likely you are to escape fines and penalties. And I'm happy to report so far that my clients have been able to escape those fines and penalties. But if it's not documented, you haven't done it. So if you're training your team, document that you trained your team. If you're looking at a security protocol uh in your practice management, document that you did that. It's all going to be in the documentation. So you need to identify what PHI you have and where what systems is it located on and what devices and what applications. A lot of times we don't think about all the applications that we have in our practices. There we put all of our stock in the practice management, which is important. No, yeah, not minimizing it, but there's other technology that we use in our practices that also have patient information. A lot of times when I go into practices, I'm looking for all of those other applications, all of those other technologies. And a lot of times I can go to that at that application outside of the practice management, even though it's bridged to the practice management. I can still open it as a standalone uh technology or application on the computer, and here is all this patient information: patient name, patient date of birth, medical record number. That is what PHI is. So it's important that we identify what information we have, where do we have it stored, on what devices, and what uh or or what applications. A lot of times I'm seeing practices now that are using iPads and they're using personal phones. Uh, there's a lot of the uh phone systems now will allow employees to have a little application on their personal phone that they can see who's calling or they can maybe uh see what the schedule is going to be for the upcoming week. That's wonderful. We don't want to impede our patient flow, but we want to know about that so that when that employee leaves, we can terminate that access right away. But you can't terminate it if you don't know who has access to it or what where it is and what where it's created, transmitted, or stored. So one of the things that another thing that we want to look at is what services do we have, who outside of our organization is touching our information. We do that by by creating a mapping of how the data flows through our practice. Everybody should be using multi-factor authentication by now, it's 2026 because that is an extra layer. That multi-factor authentication. It used to be we used passwords, now we're going to pass keys because that is an encrypted key that only I'm going to have access to. But that multi-factor authentication is just that, it's creating an extra hurdle for hackers to jump through. And the idea is that if they want to get in, they're going to get in, but we want to give them so many layers. We call it security in depth or layers of security. We want to give them so many layers that they say, you know what, I'm going to go to the office down the street that doesn't have anything in place. So the more layers that you can give, the more hurdles, the more less likely you are to be compromised and have any issues. All right. One more thing about the uh multi-factor authentication. I I prefer to use a authenticator app on my phone because that way it's something I have, but at minimum, enable multi-factor authentication on everything, your personal items as well as your business items. Security is not nine to five. The we live in a culture where we need to think about security 24-7. The only people that are going to protect our information is us. And so having that multi-factor authenticator on my phone is something I have, and that way when it comes up, I have to put in a code that comes up on my phone, and then I can put it in. So we want to make sure that we're we're doing multi-factor authentication. All right, I talked about data encryption again. It used to be very expensive, but it's not expensive anymore. And with Windows 11, it 11 Pro, all it is is a toggle. All you have to do is toggle. And we should be encrypting our personal computers as well as our business computers. On your personal computer, you go into systems and it's very easy to get it. Just make sure that you grab a copy of that key that you're going to get and that you store it safely because if you ever lose that key, that could be devastating. But make sure that you save that key. But if a hacker gets in, they're not going to see anything because everything's encrypted and you have the key. Emails. A lot of times I'm still seeing emails with sensitive, highly sensitive information, and that's patient information, financial information being sent through regular emails. If you ever read the agreement when you signed up for your Gmail account or your Yahoo account or your Hotmail account, then you would have known that you're giving them permission to scan your computer so that they know how to market to you. So we don't want them to be able to scan our emails so that they know how to market to us when we have information in it that can that has patient information. Would you want your patient information being sent through regular channels? No, we want to make sure that we're protecting patient information at the same level that we expect our pay our information. We're all patients somewhere. So, and it's building a trust. I talked about trust but verify. When patients come into us, we ask for a lot of information right off the bat. Before they even get to see the doctor, we have asked for a lot of information, and that is the start of that trust relationship. So when a doctor says you need to have this treatment, the patient is most likely to follow through with that because that trust relationship has been built and is established. But as Warren Buffett said, it takes 20 years to build that trust relationship, it takes three minutes to destroy it. So we we don't want that destruction to happen. So we want to take the steps and protocols. And like I said, now it doesn't cost anything, it's just a toggle, so there's no reason. We also want to make sure that we're conducting a risk analysis. This is something that they are requiring. Back in 2024, the Office of Civil Rights they started a risk analysis initiative because they were seeing so many practices that were not complying with HIPAA. When you look at the HIPAA security rule, the very first requirement is that practices and hospitals will conduct a periodic risk analysis, and it and it must be thorough to determine all of the vulnerabilities that, if exploited, could adversely impact the practice. This was not being done. So they basically said we are going to start enforcing that. And if you have not done that, there will be fines and penalties. Well, back in April, they expanded that because they're finding that practices are not following the second rule of HIPAA security rule, which is having a security management plan in place. And that is so now what they're saying is that if you don't have the documentation to support that you've had a risk analysis and that you have a security management plan in place, it's considered willful neglect. And willful neglect holds the highest penalties under the HIPAA security rule. It starts at $75,000 and it can go up to $2.5 million per record. So it's important. Now they did cap it, $2.5 million, so there is a little bit of grace there. But an OCR does not want to put you out of business, but they want to make it hurt. My philosophy is let's not even get there. Let's put the things in place so that we don't have that issue. Conducting a risk analysis right now, like I said, it's it's uh not prescriptive, it's um there's a lot of leeway. We do expect to go where it will be required every 12 months. But if you have not done a risk analysis, today's the day to start that process because that is something, it's not a matter of if you will have an incident, you will have an incident. Handing the wrong walkout statement to someone can cause an investigation. I know because I've had it happen on several several occasions. 99.9% of people, if they got the wrong person's walkout statement, would hand it back and say, I think you gave me the wrong piece of paper. It's that 1% that we have to guard against. And believe me, if you hand it to the wrong person, they will they will take it and run and report you as a as a violation, especially if they think that they are gonna make any money off of it. Now they're uh with the new rules, we do expect that they're going to uh demand um at least vulnerability testing, if not penetration testing. Again, this used to be expensive, it still can be expensive, but every practice should be doing at least vulnerability testing, vulnerability scans. When I do a risk analysis, we scan the entire network, both internal and external, because we want to know what potential issues that could adversely affect the practice. Um, a lot of times I see practices are using remote desktop because it's free, it comes with the uh windows and it lets us remote into our practice, but it also leaves a big door open. And there are tools that are out there that were designed for good and are used for good, but they're also used for bad. And there's a tool that goes out and just scans the entire internet specifically looking for those open doors, and that remote desktop is an open door, so we don't want to give anybody uh the open door, so we should be doing testing, and again, test trust but verify is your IT doing what you think they they should be doing. We think that IT is is gonna make us compliant, but IT takes care of the hardware. And the software. That is their role. They have a critical role in any security management plan, but they are not going to make you HIPAA compliant. And then there's the data breach role. Because when there is a violation in any way of anybody's information, it is a violation of your civil rights. So whether it be a ransomware attack or the wrong walkout statement or the wrong disclosure in any way, shape, or form, I've seen where somebody looked at a record that they weren't supposed to look at. That is an investigation that's going to happen because that's considered a data breach. So we want to have plans in place, documentation, we want to train on it on how to handle all of these occurrences. So you are required to have a approved or a security management plan in place. In 2021, there was a one-page amendment to HIPAA that says if you can demonstrate and document that you've had that approved, uh that you've had a security plan in place for 12 months with any kind of data breach, it could create a safe harbor. It has to be NIST approved. So NIST is National Institute of Standards and Technology. And it has to be within 12 months that you've done all these things. I like to use the cybersecurity framework with my clients because it's NIST approved. Check that box. And it is scalable. I have practices where it's the doctor and their assistant and a wife that comes in when the kids are in school up to practices that have 19 doctors and I don't know how many team members. So it's scalable, and you can do it across all business structures. So that's what we're going to touch on now. Governance is just that. Those are the documents that govern how the practice wants to run. This is, I always tell the doc tell doctors, this is your domain, your world. You get to have things your way as long as it's in writing. So it's establishing those policies and procedures of how you want things to run in your practice, defining the roles and responsibilities. Every position in your practice should have a written job description. And in those job descriptions, you should say exactly what information the that role requires access to in order to do their job. And then you want to have risk management strategies. You want to have go through your security controls in all of your applications, and you have to have those policies and procedures, and you have to train on them. And again, go back and identify what your regulatory requirements are. You want to have an overall or overarching security policy. And again, if it's not in writing, did not happen. And then you want to identify all the information that you have by creating that data map. You want to identify to identify what information you have, I recommend that practices conduct what we call a business impact analysis. And I recommend that you have several people in your pot in your practice help you do this because there may be processes that you aren't aware of. For instance, I had a um pediatric practice that they do a lot of referrals, and the person they had with her sole job was doing referrals, tracking and handing out referrals. And she was tracking and handing out the referrals and keeping copies of every referral that she did in her personal Dropbox account, which was not uh she just didn't know what to do because the doctor had never never told her where he wanted them stored. So we want to identify all the data we have, where it's created, where it's transmitted, where it's stored, who's touching it inside our practice, who's touching it outside of our practice, and have a data mapping. So you can't protect what you don't know about. So you want to make sure that we're protecting that information, but we've got to identify what it is first. Vendor management. There's two main ways that a cyber attack happens in a practice. One is through emails, through phishing emails, or through someone clicking on something that they shouldn't have clicked on. And the third that we've seen a huge uptick in is through vendors. Vendors that are providing services to us, they get hacked, and then we get hacked, or they get hacked, and it causes a ripple effect, and because they were compromised, it opens an investigation for us. I can't tell you how many IT companies have been hacked and it trickled down to their clients. Change Health. Many of us went through the change health. That was a lot of my clients had no idea that Change Health was even a vendor of theirs because it was being used by their vendors. So that third-party management is very, very crucial. Ask questions when you want to it's a vendor that you want to sign up with, great. But ask them when was their last risk analysis? If they are touching patient information, they have to meet HIPAA as much as the doctor does. But the doctor is still ultimately responsible for where his data is created, transmitted, and stored. So as a lot of us are going cloud now, we still have to make sure that we are making doing the right thing and asking questions. When was the last risk analysis? When was your team last trained on HIPAA? What certifications do you have? Do you does your team have? Those kind of questions make sure that we're asking them how to uh protect that because they they're going to have access to our information. I mentioned cloud a lot of times, and for me, computers have come full circle. When I first got into technology, I'm old. The computers were really just coming out. We laughed because I I met my husband over in Atari. Um, but computers back then, really productive computers and businesses, they took up the entire room. We're going back to that. Now we are cloud and which are really just big computers somewhere. We're just renting space. The the application that we're using is renting space on this huge computer. When we run out of room, we just rent more rooms. But it's it's comical to me because now we're going back to what we identified what information we have. We want to protect that information. The way we protect it is by access control. First, we have to identify who's touching our information, and once we've established that, then we want to give them access. Our employees, we want them to have as much information as they need to be able to do their job, but no more. We want to keep in mind what we call the minimally necessary role. Give as much access as they need, but not every everybody needs full access. A lot of times I go into practices and I see everybody is an administrator in the practice management. That is not access control. And again, trust is not a not a security control either. Look at what the job duties are and what information do they really need access to, and then limit it. Does everybody need access to the internet? And if they do, is it only a couple of applications? Can we whitelist those applications? And think about physical control as well. A lot of times I go into practices and everybody has keys to the practice, but not everybody really needs keys to the practice. So think about who really needs the access. Absolutely, give them the access, keeping the minimally necessary role in place. But anybody who doesn't need the access, pull those privileges back. Awareness training. Again, phishing emails are the number one, number one way, and then of course, our vendors are a second way. So the way that we combat that is teaching employees on a regular basis what phishing emails look like because those emails are coming across, and used to be we would tell people, oh, you could tell them the Nigerian prints because the grammar wasn't good. We have Chat GPT, their grammar is better than ours now, and so we want to make sure that we are training on how to uh to how to see those those um phishing emails. I was recently in a practice and the front desk uh came to the doctor because that's the protocol. She had received an email that she was unsure about. The doctor reviewed it, the doctor was unsure about it. It came from a doctor in Kansas. This practice happened to be in New Jersey, and they were unsure why this doctor in Kansas would be sending the record. So there's their policy states that they bring it to the doctor, and if the doctor doesn't uh okay it, then they need to follow up with the sender. So Nicole was the front desk and she called the sender who was this practice in Kansas. Come to find out the doctor's email had been compromised, and the hacker was sending out this information. It looked like patient information, it looked like they were exchanging information about a patient and made it look like this patient was moving to New Jersey. But they actually sent this letter, this email out to practices all throughout the United States. So these hackers are very, very sophisticated. They're not more sophisticated than us, it's just that we're not as uh comprehensive in our security controls as we need to be. And then those policies, make sure that you have policies. Every practice should have a written security manual that is trained on, not your employee menu manual, a security manual that you train on regularly. If it's not in writing, it didn't happen. A lot of times I see practices. Oh, it's our policy. Where's the policy? Well, it's in my head. In my head does not count, it's got to be documented. You have to have a security manual that your employees can access on a regular basis, whether it's a hand printed or a digital one, but that your employees can go and look to see how that they would handle whatever the situation is. And then again, goes back to encryption, encrypting that information. How do you it directing your employees how to transmit that information through encryption through encrypted email? Uh, we've protected and then the multi-factor authentication. We've protect identified, protected, now we want to detect, and this is where your IT is going to come in huge because it is a full-time job to detect all those logs that you need to look at. Uh, endpoint detection response. We used to have McGaffey antivirus, now we need to have endpoint detection response, and these these tools that the IT are using are very expensive tools, they can spread the cost up across all of their platforms, across all of their clients, so it's not as expensive. But if you had to buy that endpoint detection and response for all of your clients and then uh you had to monitor it, this becomes a very expensive proposition. This is why we have to outsource our IT. But we want to make sure that we're getting an IT partner, not a vendor, a partner, somebody who has a seat at the table, somebody that is going to um check in with you regularly and is going to, when you want to add technology, that you go through a process with them, that you say, okay, here's what my what I'm looking at, here are the technical requirements, and have them give you documentation. Yes, this is gonna work. I had a doctor that during COVID, she put in a very, very expensive technology, but her computers were not set up to run them. Uh, she was running eight gigs of RAM, and the minimum requirement on these particular in this particular technology was 16 gigs, and she had to uh buy all new devices for her uh practice. And in order to do that, she actually took out a mortgage on her house, and then her practice was shut down for about nine months because of the state that she lived in, so she almost lost her house over it. So that could have been avoided because she would have known not to buy that technology until her infrastructure was set. But anytime you make any changes inside of the practice, you add technology, and worse, you take away technology. I can't tell you how many data breaches I've been called in on because the technology was breached, but it hadn't been used for six months. It was just there and it was still on the systems, and a hacker found the door in. So we want to make sure that uh we don't have that. Perimeter firewall. A lot of times I see where we're still using the firewall that the I the internet provider gives us. No, that's not acceptable. We want to have a perimeter firewall that stands alone, that we can say this is what we allow in and what we allow out, and segmented networks. Again, we're starting to use voiceover IP, that should be on its own network, subnet, which you can do through the firewall. And then we have smart TVs in our practices. Well, we want those to be on their own network, so we want to be able to segment that net network out so that we have things that are likely to be compromised. If you get in, all you're gonna see is the other smart TVs, you're not gonna see the rest of our networks. A lot of times I see uh we've started using iPads because doctors are using Care Credit or they're using uh it for patient uh kiosk. Wonderful, great. The problem is that they're not letting the IT know about that iPad, and the front desk knows how to put the iPad on the guest Wi-Fi, so now we have patient information on a guest Wi-Fi. And I've actually had IT companies that because they go to the doctor too, hack into the system so that they can show how bad the current IT is doing. So these are all things that we have to kind of think about because eventually we are going to have to respond. We're gonna have to either respond to a cyber attack or natural disasters. Natural disasters happen. I've had practices that have caught on fire. That is not the time to find out that your backups were not working. I've had practices that were hit by hurricanes, tornadoes, natural disasters happen. I had one practice that actually flooded because their sprinkler system went off in the middle of the night. So natural disasters can happen. We want to have a plan in place. We want to have a plan in place that if the fire happens after hours, but we more importantly, remember those fire drills from when we were kids? We want to have plans in place to respond to those things when we do have patients in the in that practice. How would we safely evacuate? And then we also want to be able to have a plan in place on how we respond to a cyber attack because in that first 24 hours of a cyber attack, there's a lot of decisions that have to be made, and unfortunately, I see a lot of bad decisions being made. So having that plan in place and making sure that we know what to do, there's a lot of regulatory systems that we have to meet, both federal and state. And so it's important that we know that we have a standalone cyber insurance policy because they're going to help offset the cost. But one misnomer or one myth buster here, your insurance company does not absolve you of the responsibility. OCR and state regulatories will hold the owner of the practice accountable for all the data that is compromised. So you want to have those plans in place so that you respond to those that attack in a timely manner because as soon as you realize that clock that attack has happened, the clock starts ticking. And some states you've got to notify within 10 days. So uh it's important that you know that regulatory and that you have that plan in place so that you respond correctly, because there is a lot that goes into it. You're gonna need to have uh attorneys to because they're gonna have to represent you, and then you've got your compliance regulators, you want to make sure that you tell your team that we've had a security incident because you've got to hold an investigation, which means you're gonna need a forensic team. Your IT is not your forensic team, you need to use a certified forensic investigator because I can tell you within hours of reporting, you will have lawyers creating class action lawsuits uh against the practice. So it's important that you have all your ducks in a row because time goes by very quickly, and it is a very emotional and traumatic time, but it is a hiccup if you have the plan in place, and if you use the right um and know what those plans are, you will not have it, it'll become a hiccup and you will get through it, I promise. Um, cyber insurance again, it offsets, but it does not replace. You want to have a minimum of the average practice that I see, I a minimum of a million dollars because you've got to think not only reporting, but you also want to think about recovering. You want to you want to have in depending on the type of virus that you're infected with, you may have to replace everything, you may we may just have to go in and wipe, you may just have to replace server hard drives, you may have to replace your server. It just depends on a lot of variations, but whatever you want to have insurance there that is going to help with the recovery of replacing or restoring all of your hardware because it's time consuming for your IT company, and they're gonna charge by the hour. This is not gonna be in your regular thing, and I've even seen IT companies where they were the reason why the compromise happened, and he still charged my client by the hour. So we want to have cyber insurance to combat that and be prepared for that, and then you have the attorneys that um fees that are involved with that. So good cyber standalone cyber insurance policy will cover that. A lot of times, what I see is that they use the endorsement that comes on their med mile practice um policy that's $50,000, and I guarantee you the forensic team is going to take that. So there's a lot of things. So I recommend uh at least a million dollar practice um policy through uh cyber insurance.

SPEAKER_00

You were talking about doing for compliance. One of the questions in our poll was this practice has to run vulnerability scans for PCI credit card compliance, right? Does that count what with talking about?

SPEAKER_02

I mean, it would it it would, but what they're doing is they're just scanning the outer network, they're not scanning internal, so it would not be um it. I mean, it's it at least it says I'm doing something, but that's a very good point. Uh everything that I'm telling you is required under PCI compliance. So a lot of times we think this is just HIPAA, but they didn't say, you know what, let's make doctors' lives miserable, let's give them this rule. No, what they did was they said, let's let's take best practices and have healthcare follow best practices. CPAs have to do the same thing, it's just that you're protecting financial client financial information, but everything I've gone through, I guarantee you're doing in your in your business, in your practices across all 10 offices, because you're required by DLB to do that. It's it all we're doing is we're talking about a healthcare law versus it's still a business, it's just which law, and because we take credit cards, we now have to follow PCI. But PCI is contractual, where HIPAA, Gram Leahy, those are regulated. I think I'm almost done. So in case there's other questions, and of course, we do want to recover as quickly as possible, and backups are a key function of being able to recover. We usually Recommend the it's called the 321 or grandfather father son, depending on who you're talking to. But the reality is, is it looks like this you once a month you do a full system backup of everything on your systems, and then weekly you do what we call a um incremental. Um no, I'm sorry, I just totally went brain dead on what that the the in uh it's the full system, all of the updates that you've made in the last week, and then nightly is your incremental, and you want to keep those off the network. So often when I'm doing a risk analysis, I find that they're using an external drive or they're using a um a cloud backup. I've had the cloud backups compromised, I've had cloud backup accounts completely deleted. So anything that's protected would be completely off the network. That's really the only way. So, what I recommend to my clients is that they work with their IT, um get a five or um terabyte drive, or else run a shadow server that's air gapped, that is completely off away, that they're not gonna see it because the more backups you have, I had a practice that they got hit in May, the last good backup was January. So we lost everything from January to May, and that had to be reconstructed. Fortunately, they were using a vendor that had some of the information, and we were at least able to recapture some of the information. But you want to have a backup uh system that is not just one and done, it's to the cloud. The cloud is because my building has burned out, because it takes hours for that information to get back up and running. A lot of IT will use what they call a data system or an on-prem, and that is great because if there's a hardware failure, you can just unplug, plug, and within five minutes you are back up and running, slower than molasses, but you're at least able to run. So each backup has its own purpose. Multiple backups, multiple locations, and off the off the network completely, at least one of them, ideally once a month, but um at least have one of them in a locked drawer somewhere. If even if it's just the data, because if it's just even if it's just all your data, we can reconstruct, we can work with your practice manager, we can work with your other vendors to recreate and upload the data to it. So um, depending on your your storage space and all those things, get with your IT and and get a good plan for your backups because that's what's going to help you recover.

SPEAKER_00

There is one question, and and let's maybe, maybe it's my simple mind, but okay, you get one of those emails you shared saying that you have a ransomware something that you know that you shared. What's the first thing a practice leader should do at that point?

SPEAKER_02

Unplug from the internet, cut the cut cut the connection and um and call your IT. IT should come in and verify that yes, you have a ransomware. And I say come in and verify because it used to be that we got those ransom notes and we knew something was wrong because we would try to go into the practice management and everything was locked, and all of our extensions had been changed to dot D H R M A or whatever the type of they don't even do that anymore. Now, what they do is they go in and they're in your system for weeks and they're they're taking your data. Ever I had one practice, they were taking the data every night at 2 14 in the evening from workstation number 13. They would turn it on and they would take the data and turn it off. So nobody knew anything because they weren't monitoring the network like they should have been. But anyway, um what they do is they go on a scavenger hunt, they just kind of say, here's the email, but wait, everything's not encrypted, so it must be a joke. This isn't real. No, they don't bother encrypting anymore, they just take your data and they they will do things with it. They hackers are in the business and they run it like a business. They're in the business of making money, just like we're in the business of making money. So, what do they do? If you're not gonna pay them, they're gonna go to somebody that will. I've had them call patients, I've had them email patients, I've had them go to the insurance company. Here are all the EOBs that we have from this provider. We hacked into their system. So the more people that know, the more likely you are to have to report. So the IT should come in, find out what, say yes, this is a ransom, and stand back. They've cut the connection. So once that connection is hit, the act the hacker has no longer has the access, and then that's when you want to activate your incident response plan. You want to contact your insurance company, and because they're gonna have a panel that you are gonna should work in, so that's gonna set up your attorneys. You want to create a circle of trust, and that's very, very important that that you work with the attorneys to create that circle of trust so that because you're gonna be working with regulators, state and federal, and you want to be well represented, they will assign a forensic team for you. They will assign a if it goes to reporting, they will work with a reporting team. Um, I like to work with um, I try to work with the with the attorneys because there's a lot of other things that are happening. Then we're having to tell the IT, don't let your IT start um restoring right away because that forensic team's got to come in. But we want to get back up and running. So depending on the circumstances, we may be able to do that. And that's where my expertise comes in because I've worked with this so long. I we can come up with some workarounds to at least try to get back up and running a little bit. But you want to have that plan, you want to tell your team, okay, we have a technical issue. Please don't say anything to anybody outside of our office until we know what we have. You need to have somebody that's appointed to speak for the office because when it involves a ransomware attack, that is over 500 people. You now may have to uh report to the news. So you may have your your local WSOC standing outside of your office. Um, so you don't want anybody speaking for your practice until we know exactly what has happened, we've notified everybody the right way, positive way, because this is a bad situation. So we want to kind of try to put a positive spin on it. We were doing everything, this still happened. So we want to make sure that we have everything in place before we speak to the media. We want to do things the right way, and we only do that by having a good, strong incident replan, incident response plan in place up front, and we test that plan, we train on that plan, and we work on that plan.

SPEAKER_00

Well, Debbie, thank you so much. You you are a wealth of knowledge with this subject matter. Um, I'm sure you could go on for hours and hours, and I am sure you also have some great stories too as well, but we really appreciate your time.

SPEAKER_01

Thank you for listening to Practice Matters, Executive Insights for Independent Healthcare Groups. We hope this conversation with Debbie and Jonathan provided practical guidance for strengthening cybersecurity awareness and reducing risk across your organization. To access supporting resources, learn more about DMJPS healthcare consulting, or explore additional episodes in the Practice Matters series, visit DMJPS.com. If you have questions about today's discussion or would like to connect with our team, email connect at dmjps.com and we're happy to help. Thanks for listening, and we'll see you next time on Practice Matters.