Software Patches and Updates – Why they are so important.

Whether you work in a medical office or are a business associate, they all rely heavily on the software they use for patient care. The reason software developers send out periodic updates is because more than likely a vulnerability has been discovered and the “patch” or “update” will mitigate the issue. Vulnerabilities come in a variety of types including electronic health records (EHRs), operating systems, custom software, databases, email, and even Java and Adobe Flash. Each program will have its own type of vulnerabilities. Unpatched software poses to a threat to ePHI and updating is required under HIPAA. Routers, phones, servers, and even some refrigerators have firmware that must be updated as well.

When discussing routers, it is important to mention that all routers come with default settings, including a username and password. These must be changed, otherwise they can be hacked. Routers also need to be rebooted or reset sometimes, depending on the type of vulnerability that has surfaced. Malware can infect not only your phone and computers, but also your router. It is imperative that you have an experienced IT professional that is current on these issues. Long gone are the days of plug and play. Although it is not difficult to set up a computer or a network, securing it is a whole new game.

Even if you utilize a cloud based system, the devices you use to access your system can be compromised. If you haven’t done so already, you should invest in a qualified IT vendor that will secure and monitor your computers and network. The data that your patients have entrusted you with is sought after in many areas. It is required under HIPAA to have reasonable and appropriate safeguards in place, but besides that… it’s the right thing to do!

For more information on how Aris Medical Solutions can help your organization with HIPAA Compliance and Protecting your Data call 877.659.2467.

“Simplifying HIPAA through Partnership, Education, and Support”

About Suze Shaffer

Suze Shaffer is the owner and president of Aris Medical Solutions. She specializes in HIPAA compliance, risk management, and cyber security. She believes that by educating her clients in understanding why and what needs to be done to protect their practice they have a better outcome.

Suze has been instrumental in helping clients nationwide with risk management, implementing privacy and security rule policies and procedures, and ultimately protecting patient data. She includes state and federal regulatory requirements to ensure clients are protected in all areas.

She has spoken at numerous conferences and functions. She continues to educate organizations how to minimize the risks of data breaches. HIPAA compliance is not an option, it is mandatory for every organization that comes in contact with protected health information to have reasonable and appropriate security measures in place. Unfortunately, most organizations don’t realize they are not compliant until they suffer a data breach or they are faced with an audit or investigation.

Did you know that the Office for Civil Rights (OCR) is the agency that investigates data breaches? Have you seen the heavy fines that have been imposed for non-compliance?

All 50 states now have their own set of privacy laws and the State's Attorney General may also investigate privacy violations!

Share This HIPAA Blog

Workstation Security

June 19, 2018

Cost of cyber attacks on healthcare are steadily rising

August 1, 2018
©2024 Aris Medical Solutions – HIPAA Risk Management | HIPAA Compliance Consultants | All Rights Reserved | Terms and Conditions | Privacy Policy
The content and images on this website is owned by Aris Medical Solutions and their owners. Do not copy any content or images without our consent.
Powered by Bandwise LLC