Two factor vs Two Step Authentications

By Aris Medical Solutions

HIPAA Username and Password

Sometimes these terms are interchanged which is is not exactly correct. Let us explain the difference!

Two factor authentication is typically a username AND a password. This can also be explained as who you are and something you know.

Two step is using two different types of authentication like a username and password PLUS a one time code that is text to your phone. Some providers permit the use of a fingerprint to authorize the second step.

The use of a security word is also used as a second step type of authentication so you need to be very careful about posting any type of personal information on social media. Aris suggests when the security question asks for your mother’s maiden name, make up a name! Just don’t forget what name you used!

No matter what type of the second step authentication that is offered, it is best to select whatever is offered because although a username and password is the most common type of authentication, it is also easily compromised.

People who work within the Health Care sector are heavily targeted since the type of data they access is very valuable on the dark web. Anyone who works with patient information or for a company that provides services to a medical facility can be targeted. Again, special care must be taken to ensure that patient information is not compromised.

First step in protecting patient data is conducting a HIPAA Security Risk Analysis. Know where your data is and understand how to protect it. Secondly, make sure you have a full set of Privacy and Security Policies and Procedures. Members of your staff need to know how important protecting patient data is and understand what they need to do to accomplish this.

For more information on how Aris Medical Solutions can help your organization with HIPAA Compliance and Protecting your Data call 877.659.2467 or click here to contact us.

“Protecting Organizations through Partnership, Education, and Support”

Why should I try to secure my data?

 

By Aris Medical Solutions

HIPAA Data security

With all of the large data breaches making the news many smaller organizations think why bother. If the large companies can’t keep their data save, there is no way I can. Keep in mind, large organizations are a huge target and their data is sought after on a grander scale. Smaller companies are targets too, because their data is easier to capture. Smaller organizations typically do not have a qualified IT person or company that oversees their network. Unsuspecting employees are usually how the data is compromised because they have not been properly trained.

Here are some helpful hints how you can protect your data:

  1. Conduct a thorough risk analysis. Know where your data is and how it is accessed.
  2. Create a risk management plan to demonstrate your efforts in compliance.
  3. Conduct a network security audit to ensure your computers/network do not have any open vulnerabilities. This is more than just a scan of your network.
  4. Create a full set of privacy and security policies and procedures so employees understand patient’s rights and how to protect their data.
  5. Employee education. This is more than just once a year HIPAA training. This should be included in your monthly/quarterly meetings. Monthly emails can be sent to the staff as reminders of how important their vigilance is needed.

Patient data is valuable on the dark web and it is up to us to protect the data. One breach can destroy your organization unless you have a lot of money for reputation management. So when you are thinking about how much all of this “prevention” is going to cost, it will cost so much more if you ignore this need.

For the current breaches under investigation click below:
https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf

You can also view archived investigations that have been resolved or that are older than 24 months on the same website.
For more information on how Aris Medical Solutions can help your organization with HIPAA Compliance and Protecting your Data call 877.659.2467 or click here to contact us.

“Protecting Organizations through Partnership, Education, and Support”

©2022 Aris Medical Solutions – HIPAA Risk Management | HIPAA Compliance Consultants | All Rights Reserved | Terms and Conditions | Privacy Policy
The content and images on this website is owned by Aris Medical Solutions and their owners. Do not copy any content or images without our consent.
Powered by Bandwise LLC