We’ve curated our weekly tips shared on LinkedIn every Tuesday into this monthly blog for your convenience.

Cybersecurity Awareness Month
Let’s make a pact: we won’t only think of cybersecurity awareness in the month of October, or the day (or day after) we read an article about another organization (not just healthcare) falling into a breach due to a cyber attack.
Don’t be afraid (or remiss) to share with staff and management scary stories on email phishing attacks or network compromises that led to data breaches. Keeping your team well-informed on security and cybersecurity awareness is one of the best concepts for proactively securing your organization.
Here are some fun activities (yes, I said fun!) to use to engage your team during Cybersecurity Awareness Month:
- Board of Red Flags: Create a wall or board where staff can post anonymized examples of suspicious emails, odd phone calls, strange texts or even weird device behaviors.
- Security & Snacks Mini Meeting: Host 10-15 minute meetings either with the whole team or by department, focusing on one or two cybersecurity topics or the latest healthcare breach in the news.
- Short Security Quizzes: These can be for the whole staff or create teams to see who can answer the most questions correctly on patient privacy, data security, lack of physical securities that can create vulnerabilities for the organization.
Reward the team for their participation – free lunch, losers have to buy winners their favorite coffee or beverage the following morning (NOT from the break room). And remind everyone how their cybersecurity awareness just moved up a notch and with their commitment your organization will be that much safer!

Health-ISAC
Health Information Sharing and Analysis Center or Health-ISAC is a source of timely, actionable and relevant information for the global health sector offering access to resources, expertise and connections.
Health-ISAC plays an essential role providing situational awareness around cyber and physical security threats to the Health Sector so that companies can detect, mitigate, and respond to ensure operational resilience.
The non-profit, private sector organization connects thousands of health security professionals globally to share peer insights, real-time alerts, and best practices in a trusted, collaborative environment.
As the go-to source for timely, actionable, and relevant information, Health-ISAC is a force-multiplier that enables health organizations of all sizes to enhance situation awareness, develop effective mitigation strategies, and proactively defend against threats every single day.
As a member of Health-ISAC your organization can better protect patients against cyber and physical security threats and vulnerabilities. You are also actively contributing to safeguarding healthcare’s critical global infrastructure.
For more information on Health-ISAC and how to become a member visit: https://health-isac.org/h-isac-membership/

What is Quishing?
We’ve all heard of email phishing: a fake message designed to look like a real email from a trusted source, tricking the recipient into giving away private information such as passwords, company information, or clicking on a link or attachment that contains malware that will infiltrate the device and network.
And then there’s smishing: a form of cybercrime that uses fraudulent text messages to trick someone into sharing personal information or clicking on a malicious link; generally the messages create fake panic (account that will be locked out immediately unless actions are taken, or a package that is delayed), or excitement on winning something (cash refunds, prizes).
What about quishing? This is a type of cyberattack where scammers use fake QR codes to trick people into visiting harmful websites or downloading malware. Unlike text links in emails, no one can see the real destination website on their screen before the QR code is scanned. Email and message filters struggle to read QR codes, bypassing security measures. And now because QR codes are commonly used for everyday tasks people trust them.
Always verify the source of the QR code; check the URL if your phone shows a preview of the web address after scanning; look closely to see if the domain name looks strange or even misspelled. Install mobile security software that can scan and warn about malicious links.

Take Responsibility and Own It!
Enough with the complaints about having to secure your organization against cyber attacks and breaches! Working in a healthcare environment comes with requirements like any other regulated industry. And if you deal with regulated industries in your daily life, you expect guidelines to be followed.
Secure PHI and ePHI on every level from limiting access to medical records rooms, server rooms, cabinets (that lock after hours), to having auto-lock/time-outs on computers for all systems and applications containing ePHI or sensitive data. Two-factor or multi-factor authentication (2FA/MFA) is enabled for all remote connections into the EMR, Practice Management, Windows, billing and email systems.
Include in required training cybersecurity and security awareness for all staff on the biggest threats to businesses through hacking or ransomware, email phishing, weak passwords, mobile and remote device security. Do NOT train annually – there needs to be continuous reminders. HHS 405(d) Program (https://405d.hhs.gov/kod/five-threats) and CISA Healthcare Guidance (https://www.cisa.gov/topics/cybersecurity-best-practices/healthcare/mature-your-cybersecurity-efforts) can assist for free!
Policies and procedures must be current and shared with all staff so they are aware and knowledgeable of the organization’s privacy and security posture when handling patient data. Consider making all workforce members sign off on the HIPAA Confidentiality Agreement, Acceptable Use of Information and Assets, and Sanction Policy during their annual evaluations.

Cybersecurity & Infrastructure Security Agency
America’s Cyber Defense Agency known as the Cybersecurity & Infrastructure Security Agency, or CISA, offers services and tools for private and public sector organizations across the cyber community.
Start with these top 3 services:
- Connect with your Regional Cybersecurity Advisor. CISA's program of work is carried out across the nation by personnel assigned to its 10 regional offices. Regions are based on your state. https://www.cisa.gov/about/regions
- Sign up for Cyber Hygiene Services. CISA's Cyber Hygiene services help secure internet-facing systems from weak configurations and known vulnerabilities. https://www.cisa.gov/cyber-hygiene-services
- Cybersecurity Performance Goal (CPG) Assessment. CISA's CPGs are a common set of practices all organizations should implement to kickstart their cybersecurity efforts. Small- and medium-sized organizations can use the CPGs to prioritize investment in a limited number of essential actions with high-impact security outcomes. CISA has mapped the free services in its Free Cybersecurity Tool & Services database to the CPGs to aid prioritization of risk-reduction efforts. https://www.cisa.gov/resources-tools/resources/cisa-cpg-checklist
CISA’s services and tools help organizations further advance their security capabilities.
Compliance Is Ongoing
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.
Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.