Tag: Ransomware
HEIGHTENED RANSOMWARE THREAT: ACTION STEPS
Author: Seymore Bones Published Date: November 4, 2020 Leave a Comment on HEIGHTENED RANSOMWARE THREAT: ACTION STEPS
MGMA members-the federal government has announced a heightened risk of malware/ransomware attacks on the healthcare industry-including physician practices and inpatient facilities. We wanted to identify some actions you can take to reduce your risk and resources to assist you.
Actions to reduce your risk:
- Discuss the issue of cybersecurity with your IT/website vendor and have them block known sites that provide known functionality to the malware (reference the IOC list below)
- Have your IT/website vendor monitor endpoint detection on servers and workstations for changes in applications and running services
- Have your IT/website vendor monitor all new account creations. Especially critical are those with administrator access
- Have your IT/website vendor confirm that your data backup systems are in place and working effectively. Remember that offsite data storage is preferable
- Ensure your practice’s business continuity and disaster recovery plans are up-to-date and readily available
- Discuss the heightened threat with your administrative and clinical staff and the increased need to stay highly diligent during this time
- Consider instituting a practice-wide policy prohibiting staff use of personal email accounts as a method to decrease your risk
- Remind staff not to open emails and/or attachments from unknown senders (and even be cautious with attachments from recognized senders)
- Encourage staff to inform you regarding any suspicious email or cyber incident
Resources:
HHS Bulletin: us-cert.cisa.gov/sites/default/files/publications/…
IOC List: gist.github.com/aaronst/…
MGMA member-benefit Cybersecurity Action Steps
Robert Tennant MA
Director of Health Information Technology Policy MGMA Government Affairs
Washington DC
Recent Comments