Training your medical staff to securely handle and protect sensitive patient data isn't as hard as you think.
Many practices lament that they don't have the money or resources to manage the security of complex data systems and protected health information (PHI). According to security expert, Aaron Ross, owner of IT Is Prepared, a New York-based IT security firm, it is unnecessary for small practices to spend thousands of dollars on IT security. He says security involves simple things like installing virus protection and tracking software, limiting staff access to the Internet, and training them to think and act proactively about data security.Ross' company has developed an easy mnemonic for medical practices to distribute to their staff members called "CHILLED." "The goal of the sheet ⦠is to teach them how to keep [information] safe," he says.To download a PDF of the slides, click here.
HIPAA highlights: 2 disturbing class actions, OCR risk analysis enforcement
April 24th 2025Two class-action lawsuits targeting the University of Maryland Medical Center and the University of Kansas Health System for years-long cyberstalking and unauthorized access to protected health information spotlight massive HIPAA risk-analysis failures and underscore the urgent need for stronger health care cybersecurity safeguards.