Dental Law - What You Need To Know
Dental Law - What You Need To Know
A summary of what every dental practice owner should know and implement in the day to day operations of their practice.
dentalattorney

Cybersecurity Program Development

Cybersecurity Program Development

6/20/2019 8:00:00 AM   |   Comments: 0   |   Views: 45
                                        
Cybersecurity Program Basics
                                        
An effective cybersecurity program will:             
                    
  • assign responsibility
  •                 
  • identify information assets
  •                 
  • conduct periodic risk assessments
  •                 
  • implement security controls
  •                 
  • monitor effectiveness over time
  •                 
  • conduct regular effectiveness reviews
  •                 
  • address third party risks 
  •             
            
                                        
HIPAA Security 
                                        
The HIPAA security rule outlines a series of security standards and implementation specifications, such as the requirement for healthcare providers to conduct risk analysis and protect against all reasonably anticipated threats. Healthcare providers must evaluate their systems from both a technical and nontechnical standpoint to ensure that policies and procedures meet HIPAA security requirements. HIPAA risk evaluations should occur routinely, after environment changes, and after operational changes.
                                        
Cybersecurity HIPAA Risk Management Guideline
                                        
            
                    
  • Determine the scope of the analysis
  •                 
  • Collect data
  •                 
  • Identify and document potential threats and vulnerability in the system (including policies and procedures involved in the system)
  •                 
  • Assess current cybersecurity standards and procedures
  •                 
  • Determine the probability of threat occurrence
  •                 
  • Determine the potential impact of threat occurrence
  •                 
  • Determine current risk level
  •                 
  • Finalize documentation of the risk analysis
  •                 
  • Periodically review and update the risk analysis
  •             
            
                                        
Routine Cybersecurity Tests Include:
                                        
            
                    
  • drills & table top exercises - active participation discussion on roles, policies, responsibilities, and response efforts should an incident occur
  •                 
  • external vulnerability scanning - using a external software-based tool to analyze vulnerabilities 
  •                 
  • penetration testing - identify the routes and methods attackers could use enter your system and compromise data
  •                 
  • phishing & spearfishing - create a mock phishing scam using social media, the phone, or email to trick employees into accessing the network or providing information
  •             
            


OBERMAN LAW FIRM 

Stuart J. Oberman, Esq handles a wide range of legal issues for the dental profession including cyber security breaches, employment law, practice sales, OSHA, and HIPAA compliance, real estate transactions, lease agreements, noncompete agreements, dental board complaints, and professional corporations.
 
For questions or comments 
regarding this article 
please call (770) 554-1400
or visit 
www.obermanlaw.com
 
 Email Emily Scarborough at emily@obermanlaw.com to hear Stuart J. Oberman, Esq speak at your next event.

You must be logged in to view comments.
Total Blog Activity
997
Total Bloggers
13,451
Total Blog Posts
4,671
Total Podcasts
1,788
Total Videos
Sponsors
Townie Perks
Townie® Poll
Who or what do you turn to for most financial advice regarding your practice?
  
Sally Gross, Member Services Specialist
Phone: +1-480-445-9710
Email: sally@farranmedia.com
©2025 Dentaltown, a division of Farran Media • All Rights Reserved
9633 S. 48th Street Suite 200 • Phoenix, AZ 85044 • Phone:+1-480-598-0001 • Fax:+1-480-598-3450