• Home
  • Practice Focus
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
    • How I Do It
    • TRIO Best Practices
  • Business of Medicine
    • Health Policy
    • Legal Matters
    • Practice Management
    • Tech Talk
    • AI
  • Literature Reviews
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
  • Career
    • Medical Education
    • Professional Development
    • Resident Focus
  • ENT Perspectives
    • ENT Expressions
    • Everyday Ethics
    • From TRIO
    • The Great Debate
    • Letter From the Editor
    • Rx: Wellness
    • The Voice
    • Viewpoint
  • TRIO Resources
    • Triological Society
    • The Laryngoscope
    • Laryngoscope Investigative Otolaryngology
    • TRIO Combined Sections Meetings
    • COSM
    • Related Otolaryngology Events
  • Search

Why HIPAA, Protected Health Information Cybersecurity Best Practices Are Critical in COVID-19 Era

by Steven M. Harris, Esq. • October 19, 2021

  • Tweet
  • Click to email a link to a friend (Opens in new window) Email
Print-Friendly Version
  • What if a healthcare professional providing telehealth services has their device stolen or compromised?
  • How will a healthcare organization respond to a data breach when its cybersecurity employees are working remotely?
  • Is there an emergency plan in place that contemplated both a remote and in-person workforce, and has a functional security incident response team and security incident response plan been implemented?
  • If a healthcare professional is providing telehealth services from a location outside the office, is the wireless internet connection that’s being used secure, and is the healthcare professional in a non-public location?
  • If a healthcare professional needs to step away from their device during a telehealth visit or while working remotely, will the device log off automatically within a reasonable period of time?
  • Are healthcare professionals and support staff properly trained to identify correspondence threats, such as email phishing and ransomware?

These scenarios are meant to identify potential breach vulnerabilities, but they shouldn’t necessarily be cause for concern. In the COVID-19 era, healthcare providers should take time to reevaluate their policies, protocols, and procedures to ensure they address the types of scenarios described above.

You Might Also Like

  • Avoid Data Breaches, HIPAA Violations When Posting Patients’ Health Information Online
  • Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties
  • Senate Bill Targets Medical Device Cybersecurity
  • Internal Due Diligence Review Critical for Physician Practices
Explore This Issue
October 2021

It stands to reason that cybersecurity risks are here to stay, but organizations that have contemplated and formally established policies related to threat management will be best prepared to address and resolve breaches. The best practice is to make sure the scenarios above, as well as other scenarios that an organization’s executive team can reasonably expect to face, are addressed prior to their occurrence.

Healthcare organizations may also choose to reevaluate their third-party vendors and internally audit their cybersecurity capabilities. In the COVID-19 era, the following outside vendors should be scrutinized for effectiveness:

  • Internet, data, and cellular services;
  • Firewall and malware protection;
  • Cloud storage;
  • Password protection services;
  • Email and communications services; and
  • Document management software.

The above services may already be adequate, but the best practice is to have a refreshed and informed view of the scope of cybersecurity services being performed and how those services, both independently and as a part of an overarching security plan, fit into a provider’s operations.

Further, internal audits of policies and procedures related to the procurement and ongoing maintenance of third-party services can assist in ensuring an organization is taking adequate measures to effectively leverage third-party expertise alongside internal expertise in its cybersecurity efforts.

In January 2021, the Health Information Technology for Economic and Clinical Health (HITECH) Act was amended to require the Department of Health and Human Services (HHS) to incentivize the use of cybersecurity best practices. Specifically, the legislation requires HHS to take into consideration a covered entity’s or business associate’s use of industry-standard security practices (i.e., recognized security practices) within the past year, when investigating allegations of noncompliance with the HIPAA rules and undertaking enforcement actions.

Pages: 1 2 3 4 | Single Page

Filed Under: Departments, Legal Matters Tagged With: COVID19, cybersecurityIssue: October 2021

You Might Also Like:

  • Avoid Data Breaches, HIPAA Violations When Posting Patients’ Health Information Online
  • Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties
  • Senate Bill Targets Medical Device Cybersecurity
  • Internal Due Diligence Review Critical for Physician Practices

The Triological SocietyENTtoday is a publication of The Triological Society.

Polls

Would you choose a concierge physician as your PCP?

View Results

Loading ... Loading ...
  • Polls Archive

Top Articles for Residents

  • Applications Open for Resident Members of ENTtoday Edit Board
  • How To Provide Helpful Feedback To Residents
  • Call for Resident Bowl Questions
  • New Standardized Otolaryngology Curriculum Launching July 1 Should Be Valuable Resource For Physicians Around The World
  • Do Training Programs Give Otolaryngology Residents the Necessary Tools to Do Productive Research?
  • Popular this Week
  • Most Popular
  • Most Recent
    • A Journey Through Pay Inequity: A Physician’s Firsthand Account

    • The Dramatic Rise in Tongue Tie and Lip Tie Treatment

    • Rating Laryngopharyngeal Reflux Severity: How Do Two Common Instruments Compare?

    • Otolaryngologists Are Still Debating the Effectiveness of Tongue Tie Treatment

    • Is Middle Ear Pressure Affected by Continuous Positive Airway Pressure Use?

    • The Dramatic Rise in Tongue Tie and Lip Tie Treatment

    • Rating Laryngopharyngeal Reflux Severity: How Do Two Common Instruments Compare?

    • Is Middle Ear Pressure Affected by Continuous Positive Airway Pressure Use?

    • Otolaryngologists Are Still Debating the Effectiveness of Tongue Tie Treatment

    • Complications for When Physicians Change a Maiden Name

    • Excitement Around Gene Therapy for Hearing Restoration
    • “Small” Acts of Kindness
    • How To: Endoscopic Total Maxillectomy Without Facial Skin Incision
    • Science Communities Must Speak Out When Policies Threaten Health and Safety
    • Observation Most Cost-Effective in Addressing AECRS in Absence of Bacterial Infection

Follow Us

  • Contact Us
  • About Us
  • Advertise
  • The Triological Society
  • The Laryngoscope
  • Laryngoscope Investigative Otolaryngology
  • Privacy Policy
  • Terms of Use
  • Cookies

Wiley

Copyright © 2025 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1559-4939