Episode 256
256: Cyber Security and How to be Protected - Debi Carr
Cyber Security and How to be Protected
Episode #256 with Debi Carr
In this episode of The Best Practices Show, Kirk sits down with Debi Carr to explore the many ways in which dental practices might be vulnerable to data breaches, hacking or other cyber threats. Their conversation covers a whole checklist of areas for concern and ways to take proactive measures to protect both patient privacy and valuable assets and applications.
Debi urges dental practices to take control by treating HIPAA not as a regulation but as a tool to guide sound policy and planning with regard to securing computer and data systems. She recommends partnering with an IT specialist who understands not only the programs that are unique to dental practices but is also equipped to monitor for telltale signs of intrusion.
The wide-ranging discussion covers a gamut of cybersecurity hot-button issues confronted by every dental practice, regardless of whether business is being conducted inside the office or remotely from home. These include password security, firewalls, wireless router updates, ransomware, antivirus protection, breach insurance and coming up with a robust plan that addresses all of the above.
Today’s interview took place as part of the Covid-19 Dental Relief Conference.
Main Takeaways
- Brief background on the dental relief conference. (00:14)
- How Carr’s came to cybersecurity and health care management systems. (01:49)
- Proactive do’s and don’t’s for dealing with cyber-hacking and breaches. (05:42)
- Things you can learn and do today – a checklist for strengthening home and office cybersecurity protocols. (08:37)
- Why and how to install a firewall. (10:57)
- The importance of keeping your wireless router up to date. (11:56)
- Things to know about passwords and safety protocols. (13:11)
- Explanation of two-factor authentication. (15:40)
- More about wifi router vulnerability and strategies for protecting data. (18:04)
- Defining ransomware: How hackers infiltrate and infect systems. (20:12)
- Firmware updates and how to assess whether your router needs to be replaced. (23:55)
- Thoughts on WhatsApp as a tool. (26:56)
- The importance of maintaining IT partnerships even while working remotely or when practices are shut down by pandemic. (28:22)
- Overview of anti-virus best practices. (31:30)
- Access to QuickBooks and what it entails in terms of risk and vulnerability. (32:20)
- Protecting your system following remote access interactions.(33:35)
- Risk analysis and implementing security controls, written manuals, policies and procedures. (34:29)
- Specialty insurance against data breaches and related investigations. (41:15)
- Fundamentals of forensic investigation following computer system breaches. (46:00)
- What to do if you experience a ransom attack. (48:43)
- Cybersecurity doesn’t have to be overwhelming, scary or expensive. (51:34)
Key Quotes
- “Stop looking at HIPAA as regulation. Look at it as a guide, a tool, it’s incremental because you can use it to implement best practices.”
- “Every home in America – whether we’re in a pandemic or not – should have some basic security controls in place in their homes “
- “Any time you can enable two-factor authentication, you should take advantage of it.”
- “Any hacker that gets into an application may have a door to other applications on your computer. So strong passwords are an added line of defense.”
- “You've got your firewall, you've got your router, you've got your strong passwords, but you still want to back up and have multiple backups in multiple locations.”
- “If you’re projecting out to the Internet at all – if you’re on the worldwide web – then you need to have a firewall.”
- “The steps that every practice needs to take as part of HIPAA should include a breach notification or breach incident response plan.”
- “It’s really important that in the event of an attack you call in someone that can be an incident response mitigator and walk you through all those stacks.”
- “I don’t want it to be scary because we have the best tools at hand. We need to just take advantage of them. HIPAA does not have to be expensive or ridiculously complicated. It’s common-sense cyber-security protocols that are used in every industry.”
Snippets
- Why HIPPAA is much more than a regulation. It’s a tool and centerpiece for cybersecurity best practices, including risk analysis and inventory. (6:13- 07:20)
- Use different Password for all applications and each device to create layers of security. (9:05-9:36)
- Wifi routers and automatically generated passwords. (14:45-15:26)
- How firewalls work and why they’re so important. (17:19-17:51)
- Ransomware and what valuable information hackers can leverage once they breach systems. (20:15-21:22)
- The importance of backup, redundancy and emergency options both in the cloud and onsite. (25:39-26:45)
- Hackers are still active even if practices are shut down by pandemic, so maintaining IT partnerships is critical to monitor data traffic and abnormalities. (28:22-29:57)
- Anti-virus best practices and strategy. (31:20-32:03)
- Basic security protocol for managing QuickBooks remote access. (32:20-33:14_
- The importance of establishing sanction policy, security manuals and procedures. (34:29-35:20)
- The value in maintaining a robust IT partnership and paid anti-virus subscription. (37:27-38:20)
- Breach insurance and HIPAA compliance to avoid policy nullification. (41:15-41:50)
- What to do if you’re the victim of a ransomware attack. (48:45-50:43)
- Developing a cybersecurity program for your dental practice doesn’t have to be complicated or expensive. (51:34-52:20)
Guest Bio
Deborah Carr has 28 years of experience executing safety and security measures in the information systems and technology realms of the healthcare field. The ever-changing and expanding arena of HIPAA Privacy and Security policies has been an integral part of Mrs. Carr’s success, which has included identifying, implementing, and managing all policies and procedures, including business continuity and disaster planning. Mrs. Carr holds memberships with AADOM, ADMC, HIMSS, and ISC2.
Contact
LinkedIn: linkedin.com/in/debicarr
Website: dkcarr.com