What should we do if someone outside our organization hacked into our computer system?
HIPAA Weekly Advisor, July 18, 2005
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
The good news is that a breach of your network or computers doesn't necessarily mean that ePHI has been compromised. You still need to minimize damage as much as possible, but don't panic and start disconnecting network cables and shutting down firewalls and computers. This can eliminate potential evidence that you can use to track down the culprit.
If you suspect malicious behavior but don't have experience about what to look for or how to respond, contact an incident-response expert/computer forensics investigator. If you're experienced and know which system(s) are affected, simply unplug (instead of formally shutting down) the device. But be careful. Although this can help preserve evidence, it's also tricky if it's a database system that can become corrupt if not shut down correctly. You also may not be able to afford to have the system offline for any extended period of time either.
If you believe criminal action has taken place, contact your local law enforcement cyber-crime investigator. Someone at your local city or county law enforcement office should handle this type of investigation. If this office can't help, go to your state bureau of investigation or your nearest FBI field office directly (for cyber crimes that cross state boundaries).
Most importantly, make sure you have documented, in advance, formal procedures to follow, and establish contact with computer security experts and law enforcement investigators in your area.
Editor's note: Kevin Beaver of Principle Logic answered this question. This is not legal advice. Consult your attorney for legal matters.
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
Related Products
Most Popular
- Articles
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- Topic: CMS, OESS post new security compliance review information, checklist
- Capturing all necessary codes for IUD insertion and removal can be challenging
- What does case-mix index mean to you?
- QA:Coding multiple initial infusions
- News and briefs: Oklahoma Osteopathic Association against residency bill change
- HIPAA Q&A: Level of encryption needed for email
- OB services: Coding inside and outside of the package
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- New conflicts of interest create new challenges
- Q/A. One injection code or two?
- What does case-mix index mean to you?
- ED-to-inpatient transfers are flawed with safety gaps
- Joint Commission Center announces handoff communication solutions
- Inside best practice: Reduce patient falls with a stoplight
- Identify modifiable risk factors to prevent patient falls
- Searched