Get Live Chat Request a Callback Get live demo

← Back

Cybersecurity & the Rise of Medical Identity Theft

Medical Billing

Disclaimer: This blog article was written by an AdvancedMD partner. The views and opinions expressed in this article are those of the author(s) and do not necessarily reflect the official policy or position of AdvancedMD.

If you have been watching the news the last few weeks Cybersecurity has been a huge issue. Just in the last few weeks,

  • The FBI took down a Russian Bot Net Server that target the Internet of Things (IoT). The Internet of things are devices that are connected to the internet that are not computers and computer related equipment including but not limited to Doorbell Cameras, Home and Office Security Systems, IV Pumps, and any other device that you can control by an app on your cell phone.
  • The US and German took down a major server hub that sold stolen information including stolen medical information.
  • The US Government has issued warnings that Russian hackers are likely to target computers and servers that are part of the US infrastructure in response to the sanctions levied.

Medical Identity theft is big business and the health information on people in the US may be a high value target to Russian hackers. This means your data is at much greater risk than it was just a few months ago. The HIPAA regulations require us to take all reasonable precautions to protect our data and failing to do so is a HIPAA violation.

In addition, if you get ransomware and you pay the ransom you may be paying money to a country or organization that has been labeled a terrorist organization and that is a violation of Patriot Act and This law, anyone who provides so-called material support to a designated terrorist organization can be prosecuted. Using this law, the Justice Department has convicted hundreds of Americans. (USA PATRIOT Act | FinCEN.gov)

This means you need to be even more vigilant in protecting your data than ever before.

One of the ways we can prevent breaches and HIPAA events, and one way we protect ourselves against fines from the federal government is to share information when we have an event, so that others do not fall victim to the same type of hack or intrusion that attacked our systems.

To assist you in that endeavor the Cybersecurity & Infrastructure Security Agency has published a fact sheet to assist you in event reporting. (Sharing Cyber Event Information With CISA: Observe, Act, Report). This guidance document includes 10 key elements to share with the government include:

  1. Incident date and time
  2. Incident location
  3. Type of observed activity
  4. Detailed narrative of the event
  5. Number of people or systems affected
  6. Company/Organization name
  7. Point of Contact details
  8. Severity of event
  9. Critical Infrastructure Sector if known
  10. Anyone else you informed

We strongly advise you to download the document and keep it handy so that you can become part of the collective shield that protects all medical practices from a cybersecurity event. This is truly a case where we can help ourselves by helping others.

TLD Systems assists practices of all sized to implement strategies that will help to avoid a cybersecurity event with the goal of never needing to report a cybersecurity event in your practice. For more information, please contact TLD Systems.

Visit our webpage
Our Phone number (631) 403-6687
My direct email [email protected]

Let the TLD Systems team be your resource to help YOU protect YOUR DATA.

 



Avatar photo
Michael Brody, DPM
Dr. Brody has been actively involved in computers and medicine since the 1980s. He is a Residency Director at a VA hospital located in Long Island, NY. Notably, he was present as the VA moved from paper records to computerized records. During this time, he was exposed to the stringent rules and regulations that government employees must adhere to when protecting patient information. He co-founded TLD Systems with Warren Melnick. They wanted to create a platform for private practice doctors that provides a cost-effective method of implementing HIPAA compliance in their practices. He has served on the Health Information Technology Standards Panel (HITSP), the Standards and Interoperability Framework (S&I), as a member of the Ambulatory Care Committee at the Certification Commission on Health Information Technology (CCHIT), and numerous other organizations. He is currently a member of the Physicians Committee at the Healthcare Information and Management Systems Society (HIMSS) and a co-chair of the EHR workgroup at Health Level Seven International (HL7). He co-founded TLD Systems with Warren Melnick to create a platform that doctors who wish to work in private practice have a cost-effective method of implementing HIPAA compliance in their practices in a manner that does not interfere with their ability to practice medicine. He has served on the Health Information Technology Standards Panel (HITSP), the Standards and Interoperability Framework (S&I), as a member of the Ambulatory Care Committee at the Certification Commission on Health Information Technology (CCHIT), and numerous other organizations. He is currently a member of the Physicians Committee at the Healthcare Information and Management Systems Society (HIMSS) and a co-Chair of the EHR workgroup at Health Level Seven International (HL7)

Topic: Medical Billing


Other Resources Related to This Topic


Telemedicine

The Ultimate Telemedicine Billing Guide for Maximum Allowable Reimbursement

Telemedicine is medicine’s biggest shakeup in history. The shortfall of primary care physicians over the...

Business

Top 10 Hacks for Improving Profitability

For many physicians, independent practice actually is everything it’s cracked up to be – on...

Medical Billing

Medical Billing for Private Practice: A Beginner’s Guide

In this eBook, AdvancedMD takes a deep dive into the most common medical billing challenges...