The 10 Most Common Security Incident Response Mistakes (Part II)

June 24, 2011
Picking up where I left off in my last posting, here are five more common mistakes that health care organizations make in responding to data security

Picking up where I left off in my last posting, here are five more common mistakes that health care organizations make in responding to data security breaches:

6. Failing to train your personnel to spot a security breach. When a laptop is stolen that contains Social Security numbers or other personal information, it is a significant event that must be promptly reported to an organization's compliance and legal departments. If rank and file employees don't recognize a security breach when they see one, then the best security incident response plan will be ineffective.

7. Failing to follow proper computer forensic procedures. Before starting an investigation and reviewing systems directly, consider whether you're applying appropriate forensic procedures that might preserve evidence. By first making a forensic image, you preserve everything (including the metadata), so that you can return to that snapshot at any time. Such measures may permit an organization to identify a hacker's IP address.

8. Inadequate management of vendor relationships. A company that entrusts its personal information to a vendor should bind that vendor to reasonable privacy and security representations. For example, if a vendor is responsible for a breach, it should be required to notify its customer of the event within a relatively short time frame.

9. Failing to notify appropriate regulatory agencies. Even though it may not be required, health care organizations should consider whether relevant regulatory agencies, such as a state Department of Insurance regulating an HMO or insurer, would be offended if they read about a security breach in the paper. An increasingly wide range of health care regulatory agencies have asserted their jurisdiction to conduct investigations related to health care security breaches.

10. Failing to coordinate effectively with law enforcement authorities. Most state security breach notification laws permit you to delay notification if it would impede a criminal investigation. Carefully consider the appropriateness of notifying law enforcement, as well as which agency might most aggressively pursue the case, whether it's the local police department, the FBI or a local high tech crimes task force. But don't delay notification based upon a half-hearted investigation by the local PD into a routine laptop theft!

Sponsored Recommendations

Admit it, your EHR can’t do everything: Strategies for efficiency and better consumer experiences

Discover strategies to overcome EHR limitations and boost efficiency in your practice. Join industry leaders as they explore how a unified care enablement model can streamline...

Driving top quality performance through data-driven actionable insights.

Join us to explore how data-driven insights are transforming healthcare. Learn how leveraging big data and analytics can enhance patient care, optimize workflows, and drive top...

CMS Interoperability and Prior Authorization Final Rule: What no one is thinking about but should be

Join our panel as we explore the overlooked challenges of the CMS Interoperability and Prior Authorization Final Rule. Discover key implications for payers and providers, and ...

The Race to Replace POTS Lines: Keeping Your People and Facilities Safe

Don't wait until it's too late—join our webinar to learn how healthcare organizations are racing to replace obsolete POTS lines, ensuring compliance, reducing liability, and maintaining...