info@medriskinstitute.com
Medical Risk Institute
  • Home
  • About
    • Company
    • Founder and CEO
  • Services
    • The Compliance Plan Package
    • The HIPAA Package
    • MRI On Demand
  • Speaking
  • Training
    • When Your Aesthetician Declares Free Agency: Preventing Former Employees from Stealing Your Patients
    • Marketing to Patients: How to Keep It Legal
    • Everything You Need to Know About Opting Out of Medicare
    • AmSpa On-Demand HIPAA Education and Certification
  • Resources
    • Tweets, Likes, and Liabilities
    • Articles
    • Videos
  • Blog
  • Contact
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

Cybersecurity Pink Panther Style!

March 15, 2019/in Medical Risk/by Mike Sacopulos

Remember the Pink Panther movies?  Peter Sellers’ character, Inspector Clouseau, hired “Cato” to randomly attack him.  He thought unexpected ninja attacks would keep him every vigilant.  While the over the top comedy is ridiculous, it does remind me of how to approach cybersecurity.  You do not need to hire someone with a kendo stick to beat your staff into compliance, but frequent “reminders” do promote vigilance.

Most practices provide cybersecurity training when an employee is first hired, and annually after that. While certainly this method will check the box for “security training” it is highly ineffective for maintaining good cybersecurity habits.

Cybersecurity training is not a “once you learn it, you know how to do it” type of training.  It is not like riding a bicycle.  In fact, it’s just the opposite. For staff to maintain the awareness required to spot phishing emails and other cyber security scams, they must be continually reminded that there’s a threat.

Annual HIPAA training is not enough. Effective cyber security training is delivered in shorter sessions, more frequently, with ongoing reminders.

Here are six ways your practice can do this on the cheap:

  1. Send periodic emails with cyber security reminders and tips. Mark your calendar every six weeks with a reminder to send these out. In the morning is most effective. Pull tips directly from your security policies and procedures.
  2. Email a 3-question quiz just prior to a staff meeting. Present and discuss the answers in the staff meeting. Have everyone who got all three questions correct put their names in a hat and draw one for a gift certificate.
  3. Print posters and flyers. One practice I worked with created colorful “Watch Out for Phishing” posters, and hung them on bathroom staff doors, break rooms, and bulletin boards.
  4. Put reminders in Company Communications. If your practice sends a monthly newsletter to employees, include a story about security in several issues a year.
  5. Monitor employee password strength twice a year. Knowbe4 has a free tool for this: Weak Password Test (WPT). WPT checks your Active Directory for several different types of weak password related threats, providing insight to the effectiveness of your password policies and any fails, so that you can take action.
  6. Administer a verbal “cyber awareness quiz” at several staff meetings each year. This can be informal. Simply ask a few questions during the meeting (don’t put this on the agenda), and ask the team for verbal answers. For example:
    1. “Name two common human error reasons that cyber-attacks or breaches occur in healthcare?”
    2. “What are two clues that an email may be a phishing email?”
    3. “What is ransomware and how does it work.”

Choosing even two or three of the ideas presented here can improve staff retention of important security concepts. The key is keeping employees on alert for potential security threats all year long. Doing so can keep cyber security at the top of every physician and staff person’s mind – so they think twice about clicking.

If this fails, you can always bring in Cato for more “aggressive” cybersecurity compliance.

https://www.medriskinstitute.com/wp-content/uploads/2012/04/MRI-blinky-owl-800-wide.gif 0 0 Mike Sacopulos https://www.medriskinstitute.com/wp-content/uploads/2012/04/MRI-blinky-owl-800-wide.gif Mike Sacopulos2019-03-15 11:30:402019-03-15 15:17:35Cybersecurity Pink Panther Style!

Pages

  • 7 Social Media Policy Must-Haves
  • AmSpa
  • AmSpa On-Demand HIPAA Education and Certification
  • Blog
  • Compliance Calendar
  • Compliance Calendar 2018
  • Compliance Calendar 2019
  • Dashboard
  • Everything You Need to Know About Opting Out of Medicare
  • form
  • Founder and CEO
  • HIPAA Enforcement
  • HIPAA Training
  • Home
  • Marketing to Patients: How to Keep It Legal
  • Membership Cancelled
  • MRI On Demand
  • MRI On Demand
  • On Demand
  • On Site
  • Oops! This Content is Members Only
  • Oops! Wrong Membership Level
  • Parkview Health System Settlement
  • Privacy Policy | Terms and Conditions
  • Resources
  • Speaking
  • Special Fraud Alert: Laboratory Payments to Referring Physicians
  • Test Page
  • Thanks for Joining!
  • The Compliance Plan Package
  • The Compliance Plan Package
  • The HIPAA Package
  • Training
  • Tweets, Likes, and Liabilities
  • Videos
  • Webinars
  • Welcome
  • When Your Aesthetician Declares Free Agency: Preventing Former Employees from Stealing Your Patients
  • Company
  • Leadership
  • Electronic Medical Records Program
  • Why MRI?
  • Articles & Resources
  • Contact Medical Risk Institute

Categories

  • Blog
  • Medical Risk
  • Privacy

Archive

  • March 2019
  • February 2019
  • January 2019
  • December 2018

Looking for something?

Search Search

MAIN MENU

  • Home
  • About MRI
  • Services
  • Training
  • Articles & Resources
  • Contact

Categories

  • Blog
  • Medical Risk
  • Privacy
Scroll to top Scroll to top Scroll to top