Note: Your progress in watching these videos WILL NOT be tracked. These training videos are the same videos you will experience when you take the full ProHIPAA for Leaders program. You may begin the training for free at any time to start officially tracking your progress toward your certificate of completion.
In this lesson, we review why cybercriminals target PHI and ePHI, the financial value of medical records on the dark web, common threat vectors like ransomware and phishing, and how to respond if you receive a suspicious email.
Question: You just received a strange-looking or unfamiliar email in your inbox. What should you do?
A) Do not open the email
B) Delete the email or mark it as junk
C) Immediately notify your manager, privacy officer, or IT team
D) All of the above
Correct Answer: D) All of the above
You should never open a suspicious email, always remove or report it, and promptly notify your manager or privacy officer to protect your entire organization.
Healthcare is consistently one of the most targeted and costly sectors for data breaches, with hundreds of millions of records exposed in major incidents such as the Change Healthcare breach.
Medical records are significantly more valuable to cybercriminals than stolen financial data due to their permanence and versatility:
Pro Tip #1: Because healthcare data retains its value indefinitely and faces constant threats, healthcare professionals and business associates must actively protect PHI and ePHI at all times.
Cybercriminals use multiple delivery methods and platforms to launch ransomware and distribute malware into healthcare networks:
If you receive a suspicious or unfamiliar email, NEVER click links or open attachments. Clicking an unverified attachment can immediately trigger a malware infection or data breach. Use the "Report Phishing" button in your email client to flag it for IT, and promptly alert your office manager and Privacy Officer.
Pro Tip #2: Prompt Reporting Protects Everyone: In the office scenario, Nurse Joy did the right thing by avoiding the unfamiliar email and notifying her team immediately. Reporting suspicious activity right away helps safeguard your entire organization from potential security incidents.