Get certified in HIPAA for just $29.95.
To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
Now we will review why Cybercriminals want PHI and ePHI for their own cause, the value of PHI on the black market, and what Ransomware looks like. We will showcase how to protect PHI and ePHI and your obligation in the event of a data breach. Healthcare is consistently one of the most targeted and costly sectors for data breaches, with hundreds of millions of records exposed in recent major incidents like the Change Healthcare breach. Because Healthcare faces a constant threat of data breaches, we must actively protect PHI at all times. For example, the theft of credit cards and account data has a limited lifespan. It is useful only until the victim cancels the card numbers and accounts. The information contained in medical records has a much broader utility and can be used to commit multiple types of fraud or identity theft and does not change, even if compromised. While a stolen credit card might sell for a few dollars, complete medical records can sell for hundreds of dollars on the dark web. PHI is extremely valuable to cybercriminals so they can create and sell a brand new identity on the dark web. You must actively protect PHI at all times. Ransomware and electronic attacks continue to pose a critical threat to healthcare organizations. The platforms used include Business Applications, USB Drives, Social Media, Website Attachments, and Emails. Be very cautious of USB drives as they are used at multiple locations and can become infected easily. Phishing emails and malicious attachments remain a leading way cybercriminals breach networks and distribute malware. If you receive a suspicious email, NEVER open it. Just delete the email and notify your HIPAA compliance officer and IT company. NURSE JOY: Hey Mary, I just got a really weird looking email. Can you come look at this? OFFICE MANAGER MARY: Of course! Did you already click it open? NURSE JOY: No, I think it might be a virus? OFFICE MANAGER MARY: Oh, yeah. This is definitely suspicious. I’m so glad you didn’t open it. Okay. The best way to handle this is to use the "Report Phishing" button in your email client. That flags it for our security team and moves it out of your inbox. Yeah. You know, I'm also going to notify our Privacy Officer just in case other employees received it. This kind of email can lead to a data breach. NURSE JOY: Oh, wow, okay. In this scene, Nurse Joy did the right thing by not opening the unfamiliar email and by immediately notifying her office manager and privacy officer. Reporting suspicious emails right away helps protect your entire organization from potential security breaches.
In this lesson, we review why cybercriminals target PHI and ePHI, the financial value of medical records on the dark web, common threat vectors like ransomware and phishing, and how to respond if you receive a suspicious email.
Question: You just received a strange-looking or unfamiliar email in your inbox. What should you do?
A) Do not open the email
B) Delete the email or mark it as junk
C) Immediately notify your manager, privacy officer, or IT team
D) All of the above
Correct Answer: D) All of the above
You should never open a suspicious email, always remove or report it, and promptly notify your manager or privacy officer to protect your entire organization.
Healthcare is consistently one of the most targeted and costly sectors for data breaches, with hundreds of millions of records exposed in major incidents such as the Change Healthcare breach.
Medical records are significantly more valuable to cybercriminals than stolen financial data due to their permanence and versatility:
Pro Tip #1: Because healthcare data retains its value indefinitely and faces constant threats, healthcare professionals and business associates must actively protect PHI and ePHI at all times.
Cybercriminals use multiple delivery methods and platforms to launch ransomware and distribute malware into healthcare networks:
If you receive a suspicious or unfamiliar email, NEVER click links or open attachments. Clicking an unverified attachment can immediately trigger a malware infection or data breach. Use the "Report Phishing" button in your email client to flag it for IT, and promptly alert your office manager and Privacy Officer.
Pro Tip #2: Prompt Reporting Protects Everyone: In the office scenario, Nurse Joy did the right thing by avoiding the unfamiliar email and notifying her team immediately. Reporting suspicious activity right away helps safeguard your entire organization from potential security incidents.