(2 min read) EMS agencies are very attractive targets for cybercriminals. But, there are easy steps you can take to better protect your information from a cyber-attack.
Third-party billing companies and ePCR vendors host a lot (sometimes almost all) of our patient data. Ask your vendors the following questions:
Software updates address vulnerabilities that already exist in software. It’s critical to monitor for urgent patches and implement updates before vulnerabilities are exploited. Ask your vendors about updates and how they occur (automatically and how often). If your vendor maintains an open connection to the installed software (a “back door”), ensure that there is a secure connection at the firewall.
Make sure:
Ask your IT folks, “If we got hit with a ransomware attack today, what would we do?”. You need a plan and you need to test that plan periodically. That means making sure you can restore data from backups in a timely fashion and that folks report events immediately to the appropriate individual(s).
Make sure you:
Important data should be encrypted while at rest and in motion. Recommended best practices for encrypting health information can be found at https://www.hhs.gov/hipaa/for-professionals/breach-notification/guidance/index.html.