Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
23
24
25
26
27
28
1
2
4
5
6
7
8
9
11
12
13
14
15
16
17
18
19
20
21
23
26
27
28
29
30
31
1
2
3
4
5
Health IT Summit in San Francisco
2015-03-03 - 2015-03-04    
All Day
iHT2 [eye-h-tee-squared]: 1. an awe-inspiring summit featuring some of the world.s best and brightest. 2. great food for thought that will leave you begging for more. 3. [...]
How to Get Paid for the New Chronic Care Management Code
2015-03-10    
1:00 am - 10:00 am
Under a new chronic care management program authorized by CMS and taking effect in 2015, you can bill for care that you are probably already [...]
The 12th Annual World Health Care  Congress & Exhibition
2015-03-22 - 2015-03-25    
All Day
The 12th Annual World Health Care Congress convenes decision makers from all sectors of health care to catalyze change. In 2015, faculty focus on critical challenges and [...]
ICD-10 Success: How to Get There From Here
2015-03-24    
1:00 pm
Tuesday, March 24, 2015 1:00 PM Eastern / 10:00 AM Pacific Make sure your practice is ready for ICD-10 coding with this complimentary overview of [...]
Customer Analytics & Engagement in Health Insurance
2015-03-25 - 2015-03-26    
All Day
Takeaway business ROI: Drive business value with customer analytics: learn what every business person needs to know about analytics to improve your customer base Debate key customer [...]
How to survive a HIPPA Audit
2015-03-25    
2:00 pm - 3:30 pm
Wednesday, March 25th from 2:00 – 3:30 EST If you were audited for HIPAA compliance tomorrow, would you be prepared? The question is not so hypothetical, [...]
Events on 2015-03-03
Health IT Summit in San Francisco
3 Mar 15
San Francisco
Events on 2015-03-10
Events on 2015-03-22
Events on 2015-03-24
Events on 2015-03-25
Articles

Protect Yourself and Your Patients Protected Health Information

data security technologies

Protect Yourself and Your Patients Protected Health Information

Social engineering sounds so pleasant, like someone making introductions at a party. Unfortunately, it’s actually the practice of manipulating someone to disclose confidential information. If you work for a large company you may have been warned about social engineering in the form of people trying to find out more about your business or break into areas of your company to which they should not have access, like thieves dressed as computer repair man walking out with a company’s servers. What you might not consider is that social engineering can be aimed directly at you, as an individual, or to your medical provider to fraudulently acquire your personal information including protected health information. Here are some scams to be aware of as both a medical employee and a private individual, and ways to protect your personal information.

The Call

One method frauds use to try to get your data is through neighbor spoofing. Once again, this fun term isn’t what it sounds. Instead, the thieves will copy part of a phone number you recognize in the hopes you will think it is the number of a company with which you do business. This call can be to an individual patient, or to a medical provider. The caller will pretend to be whoever you expected and use this expectation to get you to reveal personal information they can use to steal your identity.

If you are a medical provider and want to prevent your number from being used in this way, it is important to make sure your numbers will always show up on a caller ID as your business name. You may also want to consider third-party help to see if this has already happened to your numbers and how you can manage it. If you are the person answering the phone, verify who is calling. If the caller ID didn’t clearly identify the caller, ask to call them back through their mainline, not a number the caller provides. If it will be difficult to reach the person, let them know you will call them back directly on the line they’ve given after you’ve verified their details with the business.

Never reveal your social security number over the phone. One company used numbers similar to a hospital’s but then switched the script when their calls were answered, offering a bogus credit card application that required applicants to give all their personal information. Other times the caller may indicate that there is some sort of time-sensitive emergency to throw you off balance and throw out common sense. There is always time to verify before you give out information.

The Email

Phishing is another form of social engineering that affects email. Scammers can again act like someone they are not. Protect yourself by double-checking the email address itself, not just the name that pops up with the email. Often these email addresses will look “off” in some way or have an excess of jumbled numbers and letters. While responding to scam emails isn’t a good idea, the worst option is clicking on any links they send. Right now ransomware attacks on protected health information are exploding. Ransomware holds your patients’ information hostage, threatening to reveal it and make it available for any fraudster to use. Of course, the best way to avoid this type of attack is to have effective network security and email filters, but the fact is that there is no way to avoid all scam emails. Make certain you and your staff are trained on what to look for in these phishing attempts.

No matter what, if a provider is contacting you, they shouldn’t need excessive personal information to verify who you are. Work with them ahead of time to know what data they need to verify who you are before they give you personal information by phone. If you are a provider your employees need to use these same common sense tactics to protect your patient’s data.