<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	
	xmlns:georss="http://www.georss.org/georss"
	xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#"
	>

<channel>
	<title>security Archives - Third Rock</title>
	<atom:link href="https://thirdrock.com/blog/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>https://thirdrock.com/blog/tag/security/</link>
	<description>Building a Cyber Confident World</description>
	<lastBuildDate>Tue, 21 Jul 2020 11:49:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.5.10</generator>

<image>
	<url>https://i0.wp.com/thirdrock.com/wp-content/uploads/cropped-favicon-check.png?fit=32%2C32&#038;ssl=1</url>
	<title>security Archives - Third Rock</title>
	<link>https://thirdrock.com/blog/tag/security/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">65153150</site>	<item>
		<title>Is WannaCry still a threat?</title>
		<link>https://thirdrock.com/blog/2019/10/04/is-wannacry-still-a-threat/</link>
		
		<dc:creator><![CDATA[Clint Eschberger]]></dc:creator>
		<pubDate>Fri, 04 Oct 2019 16:45:54 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Protect Yourself]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[WannaCry]]></category>
		<guid isPermaLink="false">https://thirdrock.com/?p=8437</guid>

					<description><![CDATA[<p>WannaCry ransomware took the world by surprise in 2017, crippling systems worldwide. Do you think it's been eradicated? Think again.</p>
<p>The post <a href="https://thirdrock.com/blog/2019/10/04/is-wannacry-still-a-threat/">Is WannaCry still a threat?</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></description>
										<content:encoded><![CDATA[

<div class="et_pb_section et_pb_section_0 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_0  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2><em>If it’s not broke, don’t fix it</em></h2>
<p>Many people think that as long as their computer is running at a good speed and everything is working, there is no need to upgrade. Why spend money when you don’t have to, right? Wrong! The technology world cannot run on the mantra “if it’s not broke, don’t fix it” because in reality, it is broken and you just don’t know it. The proof can be seen when WannaCry ransomware was unleashed on the world in May 2017.</p>
<p>It crippled over 300,000 machines in 150 countries by targeting vulnerabilities in Windows operating systems, hitting Windows 7 the most. While Windows patched many of these vulnerabilities, their focus was, and still is, on their active operating systems, primarily Windows 10. According to Windows “every Windows product has a lifecycle. The lifecycle begins when a product is released and ends when it&#8217;s no longer supported.”<a href="#_ftn1" name="_ftnref1"><span>[1]</span></a> What does this mean for your security?</p>
<table>
<tbody>
<tr>
<td width="126">Operating System</td>
<td width="138">Availability Date</td>
<td width="156">End of Life Date</td>
<td width="150">End of Mainstream Support Date</td>
<td width="150">End of Extended Support Date</td>
</tr>
<tr>
<td width="126">Windows XP</td>
<td width="138">October 25, 2001</td>
<td width="156">January 9, 2007</td>
<td width="150">April 14, 2009</td>
<td width="150">April 8, 2014</td>
</tr>
<tr>
<td width="126">Windows Vista</td>
<td width="138">January 30, 2007</td>
<td width="156">October 22, 2010</td>
<td width="150">April 10, 2012</td>
<td width="150">April 11, 2017</td>
</tr>
<tr>
<td width="126">Windows 7</td>
<td width="138">October 22, 2009</td>
<td width="156">October 31, 2013</td>
<td width="150">January 13, 2015</td>
<td width="150">January 14, 2020</td>
</tr>
<tr>
<td width="126">Windows 8</td>
<td width="138">October 26, 2012</td>
<td width="156">October 31, 2014</td>
<td width="150">January 8, 2018</td>
<td width="150">January 10, 2023</td>
</tr>
<tr>
<td width="126">Windows 8.1</td>
<td width="138">October 18, 2013</td>
<td width="156">September 1, 2015</td>
<td width="150">January 8, 2018</td>
<td width="150">January 10, 2023</td>
</tr>
</tbody>
</table>
<h2><em>Windows Lifecycle</em></h2>
<p>According to Windows’ lifecycle policy<a href="#_ftn2" name="_ftnref2"><span>[2]</span></a>, a product is designed to have a 5 year mainstream support lifecycle followed by a 5 year extended support cycle. During the mainstream support, consumers have access to free incident support, security update support and the ability to request non-security updates. When a product moves to the extended support stage, security updates are still provided but no new features or design changes are available, and not all products are covered.</p>
<p>After the end of extended support, security updates greatly decrease. According to Microsoft, “the Extended Security Update (ESU) program is a last resort option for customers who need to run certain legacy Microsoft products past the end of support. It includes Critical and/or Important security updates for a maximum of three years after the product’s End of Extended Support date.” Who determines what is critical and important? Microsoft of course. It would have to be a huge security breach, such as WannaCry, to justify the amount of money it would take to push out an update.</p>
<p><img data-recalc-dims="1" fetchpriority="high" decoding="async" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/Issues-with-XP.png?resize=595%2C248&#038;ssl=1" width="595" height="248" alt="" class="wp-image-8442 aligncenter size-full" scale="0" srcset="https://thirdrock.com/wp-content/uploads/Issues-with-XP.png 595w, https://thirdrock.com/wp-content/uploads/Issues-with-XP-480x200.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 595px, 100vw" /></p>
<p style="text-align: center;">Image from Windows end of XP Support<a href="#_ftn3" name="_ftnref3"><span>[3]</span></a></p>
<h2><em>What’s the risk?</em></h2>
<p>If you are running an antiquated system on your home computer, that is a risk to your security and your personal information. Not smart, but not a worldwide catastrophe. However, having one device on your work network running an old system could be devastating.</p>
<p>Though Windows created security updates to counter WannaCry, it is still active on over 145,000 devices worldwide according to a survey by Armis<a href="#_ftn4" name="_ftnref4"><span>[4]</span></a>. If even one device on your network is infected, it creates a gateway for hackers to breach your security.</p>
<p>Armis discovered that within the past 6 months, 60% of organization in the manufacturing industry and 40% in the healthcare industry experienced at least one WannaCry attack. Why? Because they tend to have older technology which makes them an easy target.</p>
<p style="text-align: center;"><em><img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/tech-old-Windows-systems.png?resize=562%2C294&#038;ssl=1" width="562" height="294" alt="" class="wp-image-8440 aligncenter size-large" scale="0" /></em><em style="background-color: #ffffff; font-size: 12px; text-align: right;">Percentage of old Windows OS versions by industry type (Retail, Technology, Healthcare, Manufacturing)</em><span style="background-color: #ffffff; font-size: 12px; text-align: right;"><em style="font-size: 12px;">4</em></span></p>
<h2><em>What’s the cost?</em></h2>
<p>It is estimated that the global effort to counter the original WannaCry attack in 2017 cost around $4 billion, including $325 million paid out in ransoms. The combined efforts to stop the attacks created the false sense of security that WannaCry is no longer a threat. This is just not true.</p>
<p>In the same way that tech companies develop better, faster and more efficient software, the criminals do too. Hackers do not stay docile. If one means to infiltrate your system fails, they look for a different back door. Having the most up to date software means that Windows is fighting those battles for you. Keeping an unsupported operating system is the same as lowering the drawbridge to the attacking army.</p>
<p>According to IBM’s Cost of a Breach Report 2019, the average cost of a breach in the United States is $8.2 million. With the average size of a breach being 25,575 records, that equates to $242 per record. Lost business was the biggest contributor to this total cost, with the average business losing $1.42 million<a href="#_ftn5" name="_ftnref5"><span>[5]</span></a>. It is hard to recover from the lack of trust a customer feels when their information was stolen on your watch.</p>
<h2><em>Next steps</em></h2>
<p>Where do you go from here? Even with these numbers, you may be asking yourself, can we really afford to find and update every device that is out of date? The bigger question is, can your business survive the cost of a breach if you don’t?</p>
<p>Start with our Cyber Quick Check to see what your cybersecurity score is. Our Security Risk Assessment includes multiple scans that pinpoint weak areas that are most vulnerable, including a full inventory of what is on your network. Don’t let your records be held ransom. Fight back with the right security.  If you’re still running Windows XP, Windows 7 or Windows Vista start an upgrade program today.  Replace your computers that have the oldest versions of Windows with new computers with the latest version of Windows as you can afford it.</p>
<p>Check your cyber score at <a href="https://cyberquickcheck.com/thirdrock">here</a></p>
<p>&nbsp;</p>
<p><a href="#_ftnref1" name="_ftn1"><span>[1]</span></a> <a href="https://support.microsoft.com/en-us/help/13853/windows-lifecycle-fact-sheet">https://support.microsoft.com/en-us/help/13853/windows-lifecycle-fact-sheet</a></p>
<p><a href="#_ftnref2" name="_ftn2"><span>[2]</span></a> <a href="https://support.microsoft.com/en-us/help/14085">https://support.microsoft.com/en-us/help/14085</a></p>
<p><a href="#_ftnref3" name="_ftn3"><span>[3]</span></a> <a href="https://www.microsoft.com/en-us/microsoft-365/windows/end-of-windows-xp-support">https://www.microsoft.com/en-us/microsoft-365/windows/end-of-windows-xp-support</a></p>
<p><a href="#_ftnref4" name="_ftn4"><span>[4]</span></a> <a href="https://armis.com/wannacry/">https://armis.com/wannacry/</a></p>
<p><a href="#_ftnref5" name="_ftn5"><span>[5]</span></a> IBM Security and Ponemon Institute. Cost of a Data Breach Report 2019. <a href="https://www.ibm.com/downloads/cas/ZBZLY7KL">https://www.ibm.com/downloads/cas/ZBZLY7KL</a></p></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>

<p>The post <a href="https://thirdrock.com/blog/2019/10/04/is-wannacry-still-a-threat/">Is WannaCry still a threat?</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">8437</post-id>	</item>
		<item>
		<title>Security starts with knowing your weaknesses</title>
		<link>https://thirdrock.com/blog/2019/03/26/security-starts-with-knowing-your-weaknesses/</link>
		
		<dc:creator><![CDATA[Ed Jones, PMP, CHSP]]></dc:creator>
		<pubDate>Tue, 26 Mar 2019 14:00:58 +0000</pubDate>
				<category><![CDATA[Protect Yourself]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[phishing scam]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://thirdrock.com/?p=5914</guid>

					<description><![CDATA[<p>The post <a href="https://thirdrock.com/blog/2019/03/26/security-starts-with-knowing-your-weaknesses/">Security starts with knowing your weaknesses</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<div class="et_pb_section et_pb_section_1 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_1  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>One of the biggest challenges in data and information security is knowing your threat level. IBM security recently released their 2018 X-Force Threat Intelligence Index. They monitor daily security events in 130 countries throughout the year for a comprehensive understanding of trends in cyber threats.</p>
<p>One of the most prominent ways organizations were found to be inadvertently open to attacks was due to improper configuration of cloud services. Misconfigured cloud servers accounted for 43% of more than 2.7 billion compromised records. This is an increase of 20% over recorded incidents in 2017.  According to the survey, “misconfiguration is now the single-biggest risk to cloud security, with 62% of surveyed IT and security professionals noting it as a problem”. While most of these breaches appear to be the result of inadvertent actions, it is possible for an insider to maliciously expose data and hide it as an accident.</p>
<p>No matter the style of attack, financial gain is almost always the motivation. Over the past few years, ransomware became a popular choice for cyber criminals. In 2018, however, we actually see a decrease in the use of ransomware by 45%. Why? Because cryptojacking is proving far more lucrative for criminals, thus increased in use by 450%! Without the need of any hardware of their own, a cyber criminal can install a cryptocurrency miner virtually undetected. Once installed, not only is the criminal gaining valuable coin at the owner’s expense, but they are also opening the door for other kinds of breaches.</p>
<p><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-medium wp-image-5909" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/chart-e1553564411692-300x115.png?resize=410%2C157&#038;ssl=1" alt="" width="410" height="157" scale="0" srcset="https://i0.wp.com/thirdrock.com/wp-content/uploads/chart-e1553564411692.png?resize=300%2C115&amp;ssl=1 300w, https://i0.wp.com/thirdrock.com/wp-content/uploads/chart-e1553564411692.png?resize=768%2C294&amp;ssl=1 768w, https://i0.wp.com/thirdrock.com/wp-content/uploads/chart-e1553564411692.png?w=777&amp;ssl=1 777w" sizes="(max-width: 410px) 100vw, 410px" /></p>
<p>The number of recorded vulnerabilities has exponentially increased in the last 3 years. This is due to the “ever-expanding attack surface as new players such as IoT devices, and other smart technologies enter the fray.” The attack surface references the span by which an organization has entry points for a cyber criminal to infiltrate. Finance and Insurance registered as the highest targeted industry, due to their access to Personal Identifiable Information (PII) links directly to bank account and credit card data that can be monetized quickly. Professional services, such as legal, CPAs and consulting, is the third most targeted industry with the second highest likelihood of a breach. Valuable customer data combined with limited security budgets and staff makes it “as vulnerable as it is lucrative”.</p>
<p><img data-recalc-dims="1" loading="lazy" decoding="async" class="aligncenter size-medium wp-image-5910" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/chart2-e1553564465916-300x205.png?resize=404%2C276&#038;ssl=1" alt="" width="404" height="276" scale="0" srcset="https://i0.wp.com/thirdrock.com/wp-content/uploads/chart2-e1553564465916.png?resize=300%2C205&amp;ssl=1 300w, https://i0.wp.com/thirdrock.com/wp-content/uploads/chart2-e1553564465916.png?resize=768%2C524&amp;ssl=1 768w, https://i0.wp.com/thirdrock.com/wp-content/uploads/chart2-e1553564465916.png?w=844&amp;ssl=1 844w" sizes="(max-width: 404px) 100vw, 404px" /></p>
<p>With all of this seemingly troubling news, you may be asking: what can we do to protect ourselves? As IBM states, we must “make security an integral part of culture and overall structure”. This is done by changing your threat landscape to reduce your risk of exposure. And that starts with knowing your risks. Our Cyber Quick Check is the first step to understanding your risk, and takes less than 5 minutes. Based on your Cyber score, discover the recommended next steps. With dedicated action and your part and the use of our automated cyber risk management system, CyberCompass™, we can increase your protection to 80% in only 90 days. The threats are real, but protection is available. Don’t wait in the dark any longer. Protect yourself and your business from threats today.</p></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>
<p>The post <a href="https://thirdrock.com/blog/2019/03/26/security-starts-with-knowing-your-weaknesses/">Security starts with knowing your weaknesses</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">5914</post-id>	</item>
		<item>
		<title>Upcoming Events of Interest</title>
		<link>https://thirdrock.com/blog/2017/11/29/upcoming-events-of-interest/</link>
		
		<dc:creator><![CDATA[Julie Rennecker, PhD, BSN]]></dc:creator>
		<pubDate>Wed, 29 Nov 2017 21:30:14 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Patient Information Privacy]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Third Rock presentations]]></category>
		<guid isPermaLink="false">https://thirdrock.com/?p=4838</guid>

					<description><![CDATA[<p>The post <a href="https://thirdrock.com/blog/2017/11/29/upcoming-events-of-interest/">Upcoming Events of Interest</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_2 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_2">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_2  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">The <a href="https://www.hcca-info.org/Events/EventInfo.aspx?sessionaltcd=003_AREA1917" target="_blank" rel="noopener noreferrer">Health Care Compliance Association Regional Conference</a> will be held in Houston on Dec. 8, 2017.<br />
Third Rock&#8217;s COO, Ed Jones, PMP, CHSP, will be participating on a panel discussing the importance of Patient Information Privacy along with representatives from <a href="http://www.thsa.org/" target="_blank" rel="noopener noreferrer">THSA</a> and <a href="https://www.winstead.com/" target="_blank" rel="noopener noreferrer">Winstead</a><a href="https://www.winstead.com/" target="_blank" rel="noopener noreferrer">, PC.</a></p>
<p>Members of our Third Rock Team will also be in Dallas on Dec.14 &amp; 15 for the <em>Cybersecurity Forum </em>at the Dallas Health IT Summit. The <em>Cybersecurity Forum</em> brings together experts in healthcare IT security and privacy issues to discuss key trends in the IT security/privacy sphere, and the top challenges facing the leaders of patient care organizations in this critical area.</p>
<p>For more information on these events and others, please visit our events page.  We welcome you to attend!  Contact us at <a href="mailto:info@thirdrock.com" target="_blank" rel="noopener noreferrer">info@thirdrock.com</a> if you would be interested in having a member of our team present at one of your events.</div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div></p>
<p>The post <a href="https://thirdrock.com/blog/2017/11/29/upcoming-events-of-interest/">Upcoming Events of Interest</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4838</post-id>	</item>
		<item>
		<title>It is Time for Us to Take Control of Our Data!</title>
		<link>https://thirdrock.com/blog/2017/09/28/it-is-time-for-us-to-take-control-of-our-data/</link>
		
		<dc:creator><![CDATA[Ed Jones, PMP, CHSP]]></dc:creator>
		<pubDate>Thu, 28 Sep 2017 16:38:47 +0000</pubDate>
				<category><![CDATA[Compliance & Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Focus on Security]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[cyber breach]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security risk analysis]]></category>
		<guid isPermaLink="false">https://thirdrock.com/?p=4591</guid>

					<description><![CDATA[<p>The post <a href="https://thirdrock.com/blog/2017/09/28/it-is-time-for-us-to-take-control-of-our-data/">It is Time for Us to Take Control of Our Data!</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_3 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_3  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignright wp-image-1415 size-full" style="margin-top: 5px; margin-left: 10px;" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/ARRRGH-Background-Design.-The-Word-Cloud-Concept.c655643_s.jpg?resize=267%2C200&#038;ssl=1" alt="" width="267" height="200">The EquiFax breach really has me angry.&nbsp; Mostly because I have no control over any aspect of this mess.&nbsp; EquiFax scoops up data on all of us without our consent.&nbsp; They seem unaccountable and untouchable.&nbsp;&nbsp; With a last name like mine, I’ve had many opportunities to dispute incorrect data on my credit reports, which is always time consuming and irritating.&nbsp; They make it known how unimportant you are and assume you are “guilty” unless you prove otherwise.&nbsp; They collect data on all the people in the U.S. old enough to make purchases using credit, and they don’t even bother to encrypt it!&nbsp; Worse yet they didn&#8217;t even bother to patch their systems after they had several breaches earlier this year!&nbsp; Talk about arrogant!</p>
<p>Is EquiFax just one bad apple?&nbsp; Sadly, they are not. &nbsp;Historically, industries with self-certification of compliance to data protection regulations have woefully low compliance. &nbsp;Government surveys say the healthcare industry is about 15 percent compliant!&nbsp; With respect to the credit card industry, they are better than the healthcare industry by a whopping 5 percent!&nbsp; Eighty percent of businesses fall short.&nbsp; The insurance and financial industries currently have NO regulations to protect your data!&nbsp; The “good news” is regulations are being drafted and are being implemented starting with New York state.</p>
<p><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft wp-image-3133 size-medium" style="margin-top: 5px; margin-right: 10px;" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/Information-Security-on-Red-Key-on-white-keyboard.jpg?resize=300%2C200&#038;ssl=1" alt="" width="300" height="200"></p>
<p>I hope EquiFax is a tipping point for the consumers in our country!&nbsp; It’s time we take control of our data and demand it is properly protected.&nbsp; Nothing seems safe when each morning news declares there is another data breach and the North Koreans launched another missile! It is alarming and discouraging.&nbsp; But I shouldn’t have to give away my hard-earned credit score to buy that shiny new toy for my man cave (I wish!) for a low price on the Internet. I shouldn’t have to worry that my most confidential data is in jeopardy because I had my annual physical! Should I buy that insurance policy to protect my family, or will the data I provide on the application fall into the hands of cybercriminals and cause significant damage to my family?</p>
<p>Going forward, I will do my homework when purchasing online by selecting reputable companies and not chasing the lowest price.&nbsp; I will ask my doctor when was the last time his practice did a security risk assessment and all staff had cyber security training?&nbsp; Does their medical system encrypt the data at all points (most don&#8217;t)?&nbsp; I will look at my financial and insurance companies with a skeptical eye and make informed decisions.&nbsp; I will also add my voice to the Equifax failure to better protect my children and their future.</p>
<p>I encourage you to take our confidential&nbsp;<a href="https://cyberquickcheck.com/">free mini-Risk Assessment</a>&nbsp;to see how compliant your organization is. Should you discover you aren&#8217;t as compliant as you had hoped, contact us at&nbsp;<a href="mailto:compliance@thirdrock.com">compliance@thirdrock.com</a>. &nbsp;We&#8217;d be happy to help you improve your score and protect your patients, your practice, and yourself!</div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div></p>
<p>The post <a href="https://thirdrock.com/blog/2017/09/28/it-is-time-for-us-to-take-control-of-our-data/">It is Time for Us to Take Control of Our Data!</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4591</post-id>	</item>
		<item>
		<title>Could this breach have been prevented? – A new series</title>
		<link>https://thirdrock.com/blog/2017/09/26/could-this-breach-have-been-prevented-a-new-series/</link>
		
		<dc:creator><![CDATA[Julie Rennecker, PhD, BSN]]></dc:creator>
		<pubDate>Tue, 26 Sep 2017 14:00:37 +0000</pubDate>
				<category><![CDATA[Compliance & Security]]></category>
		<category><![CDATA[HIPAA Training]]></category>
		<category><![CDATA[Policies & Procedures]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[continuous improvement]]></category>
		<category><![CDATA[culture of compliance]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA Security]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[leadership]]></category>
		<category><![CDATA[policies and procedures]]></category>
		<category><![CDATA[prevention]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[privacy training]]></category>
		<category><![CDATA[process improvement]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security training]]></category>
		<guid isPermaLink="false">https://thirdrock.com/?p=4572</guid>

					<description><![CDATA[<p>The post <a href="https://thirdrock.com/blog/2017/09/26/could-this-breach-have-been-prevented-a-new-series/">Could this breach have been prevented? – A new series</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_4 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_4">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_4  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft wp-image-4087 size-medium" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/continuous-improvment-yellow-keyboard-key.jpg?resize=300%2C200&#038;ssl=1" alt="" width="300" height="200" scale="0" style="font-size: 12px; margin-top: 5px; margin-right: 10px;" /></p>
<p>One of the first lessons of process improvement is that <em>preventing errors is much less expensive and time-consuming than remedying the damage after the fact</em>. The same is true for an information breach. The time and cost for installing new software, training staff members, and reinforcing policies and procedures pales in comparison to cleaning up the damage of an information privacy or security breach.</p>
<p>Recent headlines of multi-million-dollar OCR fines and the hundreds, thousands – even millions! – of lives affected suggest the scale of the damage to both businesses and individuals. The news reports rarely explain, however, exactly <em>how</em> the breach could have been averted. This is the first in a new series of articles using publicly reported breaches as teaching opportunities for breach prevention. These are not intended as an “I told you so” for the organizations breached – each incident could happen at almost any healthcare organization today. <em>The goal is for all of us to continuously improve our understanding of the risks to patient information and the options available to us for protecting that information without creating an oppressive atmosphere for our patients, staff, and visitors.</em></p>
<p><strong><em>Unauthorized photographs of a surgical patient</em></strong></p>
<p>This first example was reported in the <em>HIPAAJournal</em> just last week. Basically, surgical staff members photographed a patient’s genital injury using their personal phones and shared the photos with friends. Details of the incident are available in the <a href="https://www.hipaajournal.com/hospital-staff-discovered-taken-shared-photographs-patients-genital-injury-8968/">HIPAAJournal post</a>. What we want to focus on here is whether and how management could have prevented this breach.</p>
<p>This incident is particularly egregious because the information disclosed was so sensitive and because so many health care professionals and staff members – the very people charged with keeping the patient and his information safe – were complicit in the violation. I understand that in the face of such irresponsible behavior, a manager might be tempted to feel helpless &#8211; “I can’t watch every person every minute. What can I possibly do to make sure none of my staff ever do something stupid?” Here are some suggestions.</p>
<p><strong>Action 1: Policy disallowing use of personal phones in the OR (or any patient area) <em>for any reason</em></strong>.</p>
<p><img data-recalc-dims="1" loading="lazy" decoding="async" class="size-medium wp-image-4187 alignright" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/ISS_8815_00637.jpg?resize=300%2C200&#038;ssl=1" alt="" width="300" height="200" scale="0" srcset="https://i0.wp.com/thirdrock.com/wp-content/uploads/ISS_8815_00637.jpg?resize=300%2C200&amp;ssl=1 300w, https://i0.wp.com/thirdrock.com/wp-content/uploads/ISS_8815_00637.jpg?resize=768%2C512&amp;ssl=1 768w, https://i0.wp.com/thirdrock.com/wp-content/uploads/ISS_8815_00637.jpg?resize=1024%2C683&amp;ssl=1 1024w, https://i0.wp.com/thirdrock.com/wp-content/uploads/ISS_8815_00637.jpg?w=2160&amp;ssl=1 2160w, https://i0.wp.com/thirdrock.com/wp-content/uploads/ISS_8815_00637.jpg?w=3240&amp;ssl=1 3240w" sizes="(max-width: 300px) 100vw, 300px" /></p>
<p>As a former frontline nurse, I understand the tendency to scoff at policy – “What good’s a policy? People will do whatever they want to anyway!” There’s some truth to that – practice never perfectly matches policy – but <em>what a policy does do is establish clear guidelines for expected behavior.</em></p>
<p>If the hospital wants staff to have mobile communications, they need to supply them with Vocera badges or other devices and not rely on staff members’ personal telephones. Personal phones can be used at the desk and in the break room, but not in patient areas – period. <em>Responsibility for enforcing the policy must be shared</em> by charge nurses and circulating nurses, not just the department manager or director. A charge nurse found not to be enforcing the policy could be suspended just as if s/he had been using the phone him or herself.</p>
<p><strong>Action 2:  Intensive staff training, retraining, and reinforcement</strong>.</p>
<p>The speed and shamelessness with which these staff members brandished their phones suggests gross ignorance of the HIPAA Privacy and Security Requirements <em>and</em> of the potential consequences for violating them – termination, civil charges and fines, and criminal charges that could include probation or jail time.  <em>Staff should receive comprehensive HIPAA training during their orientation before being given access to patients or PHI.</em> That <em>training should then be reinforced</em> with shorter refresher courses and/or routine discussions of patient privacy and information security in staff meetings, organizational Town Hall sessions, and online forums on the organization’s intranet.</p>
<p><strong>Action 3:  Leadership in the moment</strong>.</p>
<p><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft wp-image-4149 size-medium" style="margin-top: 5px; margin-right: 10px;" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/02G68129.jpg?resize=300%2C211&#038;ssl=1" alt="" width="300" height="211" scale="0" srcset="https://i0.wp.com/thirdrock.com/wp-content/uploads/02G68129.jpg?resize=300%2C211&amp;ssl=1 300w, https://i0.wp.com/thirdrock.com/wp-content/uploads/02G68129.jpg?resize=768%2C540&amp;ssl=1 768w, https://i0.wp.com/thirdrock.com/wp-content/uploads/02G68129.jpg?resize=1024%2C720&amp;ssl=1 1024w, https://i0.wp.com/thirdrock.com/wp-content/uploads/02G68129.jpg?w=2160&amp;ssl=1 2160w, https://i0.wp.com/thirdrock.com/wp-content/uploads/02G68129.jpg?w=3240&amp;ssl=1 3240w" sizes="(max-width: 300px) 100vw, 300px" />In the OR, the anesthesiologist, the surgeon, and the circulating nurse all possess significant authority. Any one of these individuals could have called a halt, required everyone to power off their phones, sealed the room, and called hospital security to confiscate the phones until someone from IT could sit with each individual involved to clear the photos.</p>
<p>This action is still more Band-aid than prevention, but <em>it is the actions of leaders in the heat of the moment that either reinforce or undermine policy and training.</em> It did sound like the executives were taking the incident very seriously and had applied appropriate sanctions. It may also have been the case that the circulating nurse or surgeon brought the incident to the executives’ attention – that information wasn’t included in the article. The critical takeaway is that <em>protecting patient privacy, confidentiality, and information security are now as important a leadership responsibility as patient safety and infection control.</em></p>
<p>The above actions, taken together, are the pillars of creating a Culture of Compliance. Whether the focus of the compliance is HIPAA, CLABSI protocols, or hand washing – <em>all require clear expectations, appropriate training, and unrelenting leadership</em>. Culture is powerful – the trick is to create a culture that makes it easy – automatic – to <em>do the right thing</em>.</p>
<p>Our very best wishes to the patient and everyone at UPMC Bedford Memorial trying to remedy the situation.</p>
<p>If you need assistance establishing a <em>culture of compliance</em> please contact us at <a href="mailto:compliance@thirdrock.com">compliance@thirdrock.com</a></p>
<p style="text-align: center;"><strong>Protect Your Patients.  Protect Your Practice.  Protect Yourself.™</strong></p></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div></p>
<p>The post <a href="https://thirdrock.com/blog/2017/09/26/could-this-breach-have-been-prevented-a-new-series/">Could this breach have been prevented? – A new series</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4572</post-id>	</item>
		<item>
		<title>Texas Healthcare Privacy, Security Focus in Recent Partnership</title>
		<link>https://thirdrock.com/blog/2017/08/17/texas-healthcare-privacy-security-focus-in-recent-partnership/</link>
		
		<dc:creator><![CDATA[Robert Felps]]></dc:creator>
		<pubDate>Thu, 17 Aug 2017 15:18:35 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Press Release]]></category>
		<category><![CDATA[HIPAA Privacy]]></category>
		<category><![CDATA[Partnership]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Texas Health Services Authority]]></category>
		<category><![CDATA[Third Rock Inc]]></category>
		<category><![CDATA[Third Rock Incorporated]]></category>
		<category><![CDATA[THSA]]></category>
		<guid isPermaLink="false">http://thirdrock.com/?p=4261</guid>

					<description><![CDATA[<p>The post <a href="https://thirdrock.com/blog/2017/08/17/texas-healthcare-privacy-security-focus-in-recent-partnership/">Texas Healthcare Privacy, Security Focus in Recent Partnership</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_5 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_5">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_5  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_5  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><a href="https://healthitsecurity.com/">HealthITSecurity </a>August 16, 2017-Texas covered entities will now have assistance in working toward healthcare privacy and security compliance measures through a recent partnership between the Texas Health Services Authority (THSA) and Third Rock Incorporated.</p>
<p>THSA will utilize Third Rock’s cloud-based compliance management platform, which “streamlines and automates the privacy and security compliance process,” <a href="http://www.thsa.org/august-2017/thsa-partners-with-third-rock-for-new-hit-compliance-service/">according to a THSA statement.</a></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div></p>
<p>The post <a href="https://thirdrock.com/blog/2017/08/17/texas-healthcare-privacy-security-focus-in-recent-partnership/">Texas Healthcare Privacy, Security Focus in Recent Partnership</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4261</post-id>	</item>
		<item>
		<title>Focus on Security: In plain sight</title>
		<link>https://thirdrock.com/blog/2017/07/27/focus-on-security-in-plain-sight/</link>
		
		<dc:creator><![CDATA[Clint Eschberger]]></dc:creator>
		<pubDate>Thu, 27 Jul 2017 14:00:58 +0000</pubDate>
				<category><![CDATA[Compliance & Security]]></category>
		<category><![CDATA[Focus on Security]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[ePHI]]></category>
		<category><![CDATA[hipaa]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[policies and procedures]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://thirdrock.com/?p=4110</guid>

					<description><![CDATA[<p>The post <a href="https://thirdrock.com/blog/2017/07/27/focus-on-security-in-plain-sight/">Focus on Security: In plain sight</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_6 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_6">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_6  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_6  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><a href="https://i0.wp.com/thirdrock.com/wp-content/uploads/secure_doc1.jpg?ssl=1"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft wp-image-4111" style="margin-bottom: 5px; margin-right: 10px;" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/secure_doc1.jpg?resize=225%2C150&#038;ssl=1" alt="" width="225" height="150" srcset="https://i0.wp.com/thirdrock.com/wp-content/uploads/secure_doc1.jpg?resize=300%2C200&amp;ssl=1 300w, https://i0.wp.com/thirdrock.com/wp-content/uploads/secure_doc1.jpg?resize=768%2C512&amp;ssl=1 768w, https://i0.wp.com/thirdrock.com/wp-content/uploads/secure_doc1.jpg?w=933&amp;ssl=1 933w" sizes="(max-width: 225px) 100vw, 225px" /></a>Sometimes we tend to focus strictly on the technical side of security and compliance and fail to notice the very important issues hiding in plain sight. While a hacker breaking into your network and stealing ePHI is the threat that is being talked about the most, it is sometimes the overlooked old-fashioned threats that present the greater risk.</p>
<p>Think about how many times a patient record has been sitting somewhere and how long does it actually take for someone to pick it up and walk off? What about allowing easy access to documents or equipment that contain sensitive data? Over the years we have seen clients forget some of the simple things that they could do to protect patient information.</p>
<p><strong>Below is a simple walk-through checklist</strong> that you can use to recognize and fix security issues that may be hiding in plain sight&#8230;</p>
<ol>
<li>Have any documents been left on the counter face up when not in use?</li>
<li>Have patient documents been left on a surface that is accessible to patients, visitors, vendors, etc.?</li>
<li>Have paper charts been left unattended where someone could grab them while walking down a hall?</li>
<li>Are all discarded documents containing PHI shredded or placed in a locked container to await shredding?</li>
<li>Have security cameras been installed to track unauthorized access to anywhere patient data could be found?</li>
<li>When calling a patient from the waiting room, do staff use only the patient&#8217;s name, and preferably only a first name?</li>
<li>Have staff logged out of all unattended computers, especially those in exam rooms and publicly-accessible hallways?</li>
<li>Do you and your staff lock unattended rooms that could provide access to the network or computer equipment?</li>
<li>Is the back door (or other secondary entrance) ever left open or unlocked for any reason?</li>
<li>Do you and your staff lock offices when unattended?</li>
</ol>
<p>Sometimes, just by walking through on a weekly basis you can find simple issues that need to be addressed. We recommend doing this during business hours as you want to see what your visitors see. Not only will this help you be more vigilant in your security, but it will allow visitors to rest easier seeing that you are actively taking steps to protect them and their health information.</p>
<p style="text-align: center;"><strong>Protect Your Patients.  Protect Your Practice.  Protect Yourself.™</strong></p>
<p style="text-align: center;"><a href="mailto:info@thirdrock.com">info@thirdrock.com</a> | 512.310.0020</p></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div></p>
<p>The post <a href="https://thirdrock.com/blog/2017/07/27/focus-on-security-in-plain-sight/">Focus on Security: In plain sight</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4110</post-id>	</item>
		<item>
		<title>Third Rock Recognized at Austin Recovery&#8217;s 50th Anniversary Event</title>
		<link>https://thirdrock.com/blog/2017/07/25/third-rock-recognized-at-austin-recoverys-50th-anniversary-event/</link>
		
		<dc:creator><![CDATA[Robert Felps]]></dc:creator>
		<pubDate>Tue, 25 Jul 2017 10:00:15 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Press Release]]></category>
		<category><![CDATA[Austin Recovery]]></category>
		<category><![CDATA[CompassDB]]></category>
		<category><![CDATA[cybersecurity guide]]></category>
		<category><![CDATA[HIPAA policies & procedures]]></category>
		<category><![CDATA[Nivola Heathcare Solutions]]></category>
		<category><![CDATA[prioritized corrective action list]]></category>
		<category><![CDATA[Risk Management Plan]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Risk Assessment]]></category>
		<category><![CDATA[Third Rock’s Worry-Free Compliance™]]></category>
		<guid isPermaLink="false">http://thirdrock.com/?p=4099</guid>

					<description><![CDATA[<p>The post <a href="https://thirdrock.com/blog/2017/07/25/third-rock-recognized-at-austin-recoverys-50th-anniversary-event/">Third Rock Recognized at Austin Recovery&#8217;s 50th Anniversary Event</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<div class="et_pb_section et_pb_section_7 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_7">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_7  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong style="font-size: 12px;">Round Rock, TX, July 25, 2017</strong><span style="font-size: 12px;"> – On May 5</span><sup>th</sup><span style="font-size: 12px;">, Austin Recovery celebrated its 50</span><sup>th</sup><span style="font-size: 12px;"> Anniversary with a luncheon gala at the Shalom Austin Jewish Community Center in Austin, TX. At the event, they recognized Third Rock, Incorporated and its partner Nivola Healthcare Solutions for their work and donations supporting the organization’s HIPAA compliance activities and related information security practices.</span></p>
<p>Austin Recovery requested Third Rock’s and Nivola Healthcare Solutions’ support to reestablish their HIPAA compliance baseline after a major business restructuring in 2016. The business restructuring resulted from Austin Recovery’s separation from The Council on Alcohol and Drugs Houston, which had merged with Austin Recovery in 2013.  Ms. Laura Sovine, Austin Recovery’s Executive Director, recognized that the operational impacts of the restructuring necessitated a review of the organization’s information privacy and security practices.</p>
<p>Third Rock and Nivola Healthcare Solutions performed a comprehensive security risk assessment, provided updated HIPAA policies &amp; procedures, and prioritized corrective actions.  An online risk management plan, cybersecurity guide and recommendations for more efficiently managing the organization’s information stores and maintaining HIPAA compliance were also provided to Austin Recovery.  Robert Felps, CEO of Third Rock, stated, “We are proud to be supporting such a successful and important local organization as Austin Recovery and to be helping them protect their clients.”</p>
<p>Austin Recovery is a community-based, compassionate provider of substance use disorder treatment for individuals and families serving Austin and the surrounding areas since 1967. During its 50-year history, Austin Recovery has assisted an estimated 60,000 clients.</p>
<p>Third Rock’s Worry-Free Compliance™ is a comprehensive and industry leading cybersecurity and HIPAA compliance solution that maximizes information privacy and security while minimizing the administrative burden of the HIPAA/HITECH regulations.  It is powered by CompassDB™, a cloud-based compliance management software that streamlines HIPAA compliance, reducing the workload while delivering full compliance reporting.</p>
<p>More information about Third Rock and its services is available at <a href="http://thirdrock.com/">thirdrock.com</a>.</p>
<p>More information about Austin Recovery and its services is available at <a href="http://www.austinrecovery.org/">austinrecovery.org</a>.</p>
<p>More information about Nivola Healthcare Solutions and its services is available at <a href="http://nivolahealthcaresolutions.com/">nivolahealthcaresolutions.com</a>.</p>
<p style="text-align: center;"># # #</p></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>
<p>The post <a href="https://thirdrock.com/blog/2017/07/25/third-rock-recognized-at-austin-recoverys-50th-anniversary-event/">Third Rock Recognized at Austin Recovery&#8217;s 50th Anniversary Event</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4099</post-id>	</item>
		<item>
		<title>Celebrating Nurses – Cornerstones of the “Human Firewall”</title>
		<link>https://thirdrock.com/blog/2017/05/09/celebrating-nurses-cornerstones-of-the-human-firewall/</link>
		
		<dc:creator><![CDATA[Julie Rennecker, PhD, BSN]]></dc:creator>
		<pubDate>Tue, 09 May 2017 14:00:57 +0000</pubDate>
				<category><![CDATA[Compliance & Security]]></category>
		<category><![CDATA[ePHI]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[human firewall]]></category>
		<category><![CDATA[Nurses]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://thirdrock.com/?p=3688</guid>

					<description><![CDATA[<p>The post <a href="https://thirdrock.com/blog/2017/05/09/celebrating-nurses-cornerstones-of-the-human-firewall/">Celebrating Nurses – Cornerstones of the “Human Firewall”</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_8 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_8">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_8  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_8  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">In their roles as both care giver and care coordinator, nurses generate, transmit, transcribe, and interact with enormous amounts of information using a dizzying array of devices. Not surprisingly, nurses play a critical role in keeping patients’ protected health information (PHI) safe.</p>
<p><strong>Nurses, <em>you are amazing!!</em></strong><em> </em></p>
<p><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft wp-image-3691" style="margin-top: 5px; margin-right: 10px; margin-bottom: 5px;" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/Nurses-using-digital-tablet.jpg?resize=200%2C133&#038;ssl=1" alt="" width="200" height="133" /></p>
<p>In the course of a single hospital shift, a hospital nurse may interact with a single patient’s record 10-20 times – or more – depending on the intensity of the care and length of the shift, while caring for 2-10 patients! (A physician office nurse may interact with 20-50 patient records per day!)  In addition, nurses coordinate patient care activities across departments and facilities, including pharmacy, food service, PT, OT, radiology, lab, respiratory therapy, the OR, and more. Nurses also serve as the primary point of contact for an ever-shifting array of family members and friends. And to make it possible to fit all this activity into a single shift, health systems have equipped nurses with a variety of mobile technologies – workstations on wheels, laptop computers, iPads, mobile phones, and Vocera badges being the most common. And we haven’t even gotten into the details of actually <em>caring for</em> the patients!</p>
<p><strong> </strong><strong>You are also vulnerable to information breaches.</strong></p>
<p><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignright wp-image-3694" style="margin-top: 5px; margin-left: 10px;" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/male-female-nurse-at-nurses-station.jpg?resize=210%2C140&#038;ssl=1" alt="" width="210" height="140" /></p>
<p>Each time you interact with patient information – whether face-to-face, over the phone, or via one of the many gadgets that occupy your day – your actions either protect or expose patient information. With everything on your plates, it’s easy to understand how you might leave a workstation unlocked and unattended or might misplace a mobile device. Unfortunately, these actions can now have significant negative consequences – for you, your patients, and your organization. Your patient’s identity – and credit – can be impacted for years. Your organization may be heavily fined in addition to paying lawyers’ fees and the cost of notifying affected patients. And <em>you</em> may face civil &#8211; and possibly criminal &#8211; charges.</p>
<p><strong>Protect your patients. Protect your organization. Protect yourself. </strong></p>
<ol>
<li>Keep your voice low when speaking with patients and colleagues.</li>
<li>Only share the minimum necessary information to accomplish the task at hand.</li>
<li>ALWAYS lock your work station before stepping away (“Windows” logo key + L).</li>
<li>Double-check for mobile devices before leaving a patient room.</li>
<li>Store mobile devices in locked drawers or a locked room when not in use.</li>
<li>DO use secure email and texting applications.</li>
<li>If you must use an unsecure channel, don’t include identifying information in the message.</li>
<li>Always validate the identity of an information recipient before disclosing PHI.</li>
<li>Don’t use work computers to do personal business or shopping.</li>
<li>If you see something, say something!</li>
</ol>
<p><img data-recalc-dims="1" loading="lazy" decoding="async" class="wp-image-3693 alignnone" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/Medical-team-group-photo.jpg?resize=290%2C193&#038;ssl=1" alt="" width="290" height="193" /></p>
<p style="text-align: left;"><strong>Thanks for all you do. Keep up the good work!</strong></p>
<p>As a reward for all your hard work, check out these <a href="https://thenerdynurse.com/2017/05/nurses-week-2017-freebies-giveaway.html">freebie offers</a> from restaurants just for nurses, gathered onto a single page by <a href="https://thenerdynurse.com/about">Brittney Wilson, The Nerdy Nurse</a>.</p>
<p>And if you think your organization could use an easier way to conduct HIPAA Risk Assessments, HIPAA Training, and manage HIPAA documentation, contact us:  <a href="mailto:info@ThirdRock.com">info@ThirdRock.com</a>.</div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div></p>
<p>The post <a href="https://thirdrock.com/blog/2017/05/09/celebrating-nurses-cornerstones-of-the-human-firewall/">Celebrating Nurses – Cornerstones of the “Human Firewall”</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3688</post-id>	</item>
		<item>
		<title>One small step for man, one giant leap for privacy!</title>
		<link>https://thirdrock.com/blog/2017/03/23/one-small-step-for-man-one-giant-leap-for-privacy/</link>
		
		<dc:creator><![CDATA[Ed Jones, PMP, CHSP]]></dc:creator>
		<pubDate>Thu, 23 Mar 2017 14:00:08 +0000</pubDate>
				<category><![CDATA[Compliance & Security]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://thirdrock.com/?p=3091</guid>

					<description><![CDATA[<p>The post <a href="https://thirdrock.com/blog/2017/03/23/one-small-step-for-man-one-giant-leap-for-privacy/">One small step for man, one giant leap for privacy!</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><div class="et_pb_section et_pb_section_9 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_9">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_9  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_9  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">“To err is human”… a pretty obvious statement. So if we all know we are going to make mistakes, why not add an extra level of security to mitigate the effects of the mistake?</p>
<p><img data-recalc-dims="1" loading="lazy" decoding="async" class="wp-image-1479 alignright" style="margin-left: 10px;" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/Data-Encryption-Red-over-white-Text-c655360_s.jpg?resize=210%2C157&#038;ssl=1" width="210" height="157" /></p>
<p>I am sure we have all been in the predicament of sending John C. an email, but when we clicked on our contacts list we accidentally sent it to John B. I have conversations constantly with clients and friends about encrypting their email to protect themselves and often get the same set of questions…</p>
<ul>
<li>“Isn’t that expensive?”</li>
<li>“How does someone unlock the email I sent?”</li>
<li>“Won’t that take a lot longer for me to encrypt it?”</li>
<li>“Why should I take the extra time? The person who gets it will just delete it.”</li>
</ul>
<p>There seems to be a lack of understanding in the market place of how simple it is to take this <em>one extra step</em> to protect yourself and private information.</p>
<p>This has become an increasingly obvious issue in the healthcare space. The amount of ePHI sent daily between providers, insurers, patients, labs, etc. is vast and sooner or later mistakes will be made. When one patient receives another patient&#8217;s records this typically worries the individual who receives it and angers the patient whose information was released &#8211; accidentally or not. There are numerous low cost encrypted email services and even most of your standard email platforms come with settings for encryption. Encrypting your email ultimately protects you, your patients, and your practice.</p>
<p><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft wp-image-3100 size-full" style="margin-right: 10px;" src="https://i0.wp.com/thirdrock.com/wp-content/uploads/white-padlock-on-4-red-puzzle-pieces.jpg?resize=200%2C200&#038;ssl=1" width="200" height="200" srcset="https://i0.wp.com/thirdrock.com/wp-content/uploads/white-padlock-on-4-red-puzzle-pieces.jpg?w=200&amp;ssl=1 200w, https://i0.wp.com/thirdrock.com/wp-content/uploads/white-padlock-on-4-red-puzzle-pieces.jpg?resize=150%2C150&amp;ssl=1 150w, https://i0.wp.com/thirdrock.com/wp-content/uploads/white-padlock-on-4-red-puzzle-pieces.jpg?resize=160%2C160&amp;ssl=1 160w" sizes="(max-width: 200px) 100vw, 200px" /></p>
<p>I recently ran across an article that gives a very simple explanation of how encryption works and the advantages. When we do make mistakes and the wrong person can’t open the information, we have ultimately protected everyone with a single, simple step. Let’s do all of mankind a favor and take one small step…ENCRYPT.</p>
<p>I hope you enjoy the article.</p>
<p><a href="https://www.ltnow.com/how-does-email-encryption-work/">https://www.ltnow.com/how-does-email-encryption-work/</a></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div></p>
<p>The post <a href="https://thirdrock.com/blog/2017/03/23/one-small-step-for-man-one-giant-leap-for-privacy/">One small step for man, one giant leap for privacy!</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3091</post-id>	</item>
	</channel>
</rss>
