Artificial Intelligence in Healthcare
Artificial Intelligence

Importance of Addressing Shadow AI for HIPAA Compliance

Criminal Use of Artificial Intelligence (AI) Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS 

The process of identifying and containing a breach can be lengthy and expensive, particularly in healthcare, in addition to eroding patient trust.  Breaches can disrupt critical healthcare operations, leading to delays in patient care and financial losses due to closing emergency departments and cancellation of appointments. Healthcare providers are legally obligated to notify affected individuals and provide credit monitoring services, which incurs substantial costs. This article addresses AI use by cyber criminals and summarizes 2024-2025 breach findings as reported by IBM’s 2025 Report.

Introduction

In 2025, the average cost of a healthcare data breach is $7.42 million, according to a recent report by IBM. Even with a reduction of $2.35 million in breach cost to the healthcare sector, healthcare breaches remain the most expensive of all studied industries for 14 consecutive years! This figure represents a decrease compared to the previous year but still signifies the highest average cost across all industries. The 2025 IBM report, conducted by Ponemon Institute, sponsored and analyzed by IBM, is based on data breaches experienced by 600 organizations globally from March 2024 through February 2025.

Shadow AI security incidents cost more - Security incidents involving Shadow AI carried an added cost. They contributed USD 200,000 to the global average breach cost. This higher cost was likely driven by longer detection and containment times for these security incidents, approximately a week longer than the global average.

According to Suja Viswesan, Vice President, Security and Runtime Products, IBM "The data shows that a gap between AI adoption and oversight already exists, and threat actors are starting to exploit it."

She also states that "The report revealed a lack of basic access controls for AI systems, leaving highly sensitive data exposed, and models vulnerable to manipulation. As AI becomes more deeply embedded across business operations, AI security must be treated as foundational. The cost of inaction isn't just financial, it's the loss of trust, transparency and control."

Employees may turn to Artificial Intelligence (AI) tools to speed up tasks, solve problems, or improve productivity. However, there are risks associated with employees using AI tools, like ChatGPT, Midjourney, or AI-powered assistants, without IT's knowledge or permission, such as Shadow AI being used by criminals. Using AI tools that don't comply with regulations (like GDPR or HIPAA) can result in fines and legal issues. 

Shadow AI

Shadow AI refers to the unauthorized use of artificial intelligence (AI) tools and models within an organization, often bypassing IT oversight and security protocols.

AI tools are being used by cyber criminals to launch smarter attacks.  Shadow AI tools can introduce unsecured APIs, unmanaged integrations, or other vulnerabilities that attackers can exploit.  To reduce the risk of an AI generated attack, it is important to address Shadow AI. 

As AI becomes integral to operations, AI security incidents have the potential to disrupt a range of business activities, including compromising sensitive data and disrupting patient care (i.e. ransomware attacks locking access to important patient treatment records).  IBM’s report identifies the following:

  • Security for AI is lacking  
    • The Cost of a Data Breach Report 2025 – the AI Oversight Gap quantifies the extent to which attackers are taking advantage of this deficiency and successfully targeting AI models and applications. While the share of breaches involving AI security incidents are small, IBM researchers expect them to grow as AI vendors gain greater market share and penetration into enterprise systems. Shadow AI is of particular concern.
  • Impacts of security incidents involving Shadow AI  
    • Among organizations that experienced a security incident involving Shadow AI, 44% suffered data compromise. Another 41% reported increased security costs as a result of those incidents. Operational disruption was more widespread than incidents involving authorized AI. These results suggest Shadow AI incidents have an outsized impact on downstream breach issues that extend beyond data security.
  • Researchers found 16% of breaches involved attackers using AI
    • Most of these breaches focused on human manipulation through phishing (37%) or deepfake attacks (35%).
  • Supply chain compromise was the most common cause of AI security incidents
    • Security incidents involving AI models and applications were varied, but one type clearly claimed the top ranking: supply chain compromise (30%), which includes compromised apps, APIs and plug-ins. Following supply chain compromise were model inversions (24%) and model evasions (21%). Incidents involving prompt injections and data poisoning made up 17% and 15% of cases respectively.
  • Unsanctioned AI security incidents were more common than sanctioned AI
    • Shadow AI may go undetected by an organization, and attackers can exploit its vulnerabilities when employees use it. Security incidents involving Shadow AI accounted for 20% of breaches, which is 7 percentage points higher than those security incidents involving sanctioned AI. A further 11% of breached organizations were unsure if they experienced a Shadow AI incident.

Foster a Culture of Responsible AI to Reduce Risk

Healthcare organizations can cultivate a culture of responsible AI by prioritizing ethical considerations and extensive workforce training regarding Shadow AI tools and how to avoid an attack.  A few tips to reduce risk are listed below.

Build communication with your workforce - Instead of penalizing your workers for using AI tools without permission, find out what they’re using and why. Their feedback could be useful in highlighting the gaps in your technology stack and governance policies. This allows you to either optimize your workflows or find a way of integrating the tool into them, thereby moving them from unsanctioned “Shadow AI” to legitimate AI tools.

  • A modern data stack is a collection of tools and technologies that are used to manage and analyze data in a particular organization or business. It includes various software, programming languages, frameworks, and platforms that can be used to extract, store, process, and visualize data.

Develop Clear Policies - Establish guidelines for AI tool usage, including approved tools and security protocols. This requires inter-departmental teamwork.  When integrating AI tools into your business, make sure that IT, operations, and governance departments are aligned.

  • For example, operations might want to use the tool in a way that compromises HIPAA security. Another example is when IT evaluates the tool for security but doesn’t understand the need for privacy in this assessment, which is the main concern for governance.
  • By bringing all these departments together, you will create better policies for responsible AI use and oversight that work for everyone.

Effectively Communicate Policies - Provide workforce training and support. Educate employees about the risks of Shadow AI and offer resources for using AI responsibly. By investing in training and education, you inform your workforce of potential pitfalls and consequences. At the same time, you train those unfamiliar with such tools so they can utilize them effectively as well. Whether it’s GenAI or AI-powered automation, using it responsibly helps reduce your security vulnerabilities and helps your employees perform better.

Implement Authentical methods - Today, many attackers are logging in rather than hacking in, according to IBM’s report. To combat this issue, it’s critical to prevent attackers from obtaining those credentials in the first place. One of the most effective ways to do so is by ensuring all human users adopt modern, phishing-resistant authentication methods, such as passkeys. These technologies are designed to eliminate the vulnerabilities of traditional passwords and one-time codes, making it significantly harder for attackers to intercept or misuse login credentials.

Monitor and Manage AI Usage - AI models and applications can pose significant risks if left unchecked. Consider including tools powered by AI and automation which can augment already overburdened security teams. They can significantly reduce the volume of alerts; identify at-risk data; spot security gaps and threats earlier; detect in-progress breaches; and enable faster, more precise attack responses.

Conclusion

The rapid evolution of AI technology presents a challenge to existing regulatory frameworks. Relying solely on HIPAA, not originally designed specifically for AI, leaves gaps in addressing AI-specific risks.

When employees use Shadow AI, healthcare organizations lose visibility and control over how PHI is being accessed, processed, and stored. This makes it difficult to ensure that HIPAA's Privacy and Security Rules are being followed. Shadow AI tools may not have the same robust security measures in place as approved, HIPAA-compliant systems, making them vulnerable to cyberattacks and data breaches. If sensitive patient information (Protected Health Information or PHI) is exposed through these unauthorized channels, it constitutes a HIPAA violation, triggering potential fines legal repercussions and reputational damage. Another consideration is the lack of required Business Associate Agreements. Many AI tools are developed by third-party vendors. If these vendors handle PHI without a Business Associate Agreement (BAA) in place, another HIPAA enforcement action could be looming as Shadow AI usage bypasses the essential BAA requirement, exposing healthcare organizations to significant risk.

About the author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS. Joanne is the Chief Executive Officer of the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor and investigator in the healthcare field.

References

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

Artificial Intelligence, Extinction-Level Threat or Solution?

Written by the AIHC Education Department    


This article provides an overview of how the media and government are reacting to the potential of artificial intelligence (AI) and potential threats associated with this advanced technology.  Please read other AI articles published by the American Institute of Healthcare Compliance regarding how AI can advance quality of care, how AI is regulated, use of AI and HIPAA privacy/security, to name a few topics.

A Government-Commissioned Report Released February 2024

The U.S. State Department commissioned the first-ever assessment of proliferation and security risk from weaponized and misaligned AI. In February 2024, Gladstone AI, a four-person company which runs technical briefings on AI for government employees, completed that assessment. It includes an analysis of catastrophic AI risks, and a first-of-its-kind, government-wide Action Plan for what we can do about them entitled “An Action Plan to Increase the Safety and Security of Advanced AI.”

According to Time in a March 11, 2024 exclusive, U.S. Must Move ‘Decisively’ to Avert ‘Extinction-Level’ Threat From AI, the Gladstone AI report recommends a threshold should be set by a new federal AI agency which would require AI companies to obtain government permission to train and deploy new models above a certain lower threshold.

We can argue that there needs to be some type of controls to guide artificial intelligence, but hopefully the government will dive deeper, and quickly seek additional recommendations.  The government commission for this report from Gladstone AI was made in 2022.  According to the Time article, “The rise of advanced AI and AGI [artificial general intelligence] has the potential to destabilize global security in ways reminiscent of the introduction of nuclear weapons. AGI is a hypothetical technology that could perform most tasks at or above the level of a human. Such systems do not currently exist, but the leading AI labs are working toward them and many expect AGI to arrive within the next five years or less.”

As technology advances, so do cyber criminals 

When it comes to cyberattacks and cyber extortion (ransomware attacks), health care organization continue to suffer as prime targets and continue to struggle to recover after an attack.  

Threat actors (cyber criminals or extortionists) are leveraging AI to their advantage, which can be used as a potent weapon.  According to the National Cyber Security Centre (United Kingdom), artificial intelligence (AI) is expected to increase the global ransomware threat over the next two years. “AI enables relatively unskilled threat actors to carry out more effective access and information-gathering operations. This enhanced access, combined with the improved targeting of victims afforded by AI, will contribute to the global ransomware threat in the next two years.”

Using AI to Secure Healthcare Data

Government agencies are harnessing the power of AI for threat intelligence and defense. This involves using AI algorithms to analyze vast datasets, identify potential threats, and predict cyberattacks before they occur.  For now, health care organizations and business associates can access cybersecurity guidance through various agencies.

America’s cyber defense agency CISA (Cybersecurity & Infrastructure Security Agency).  CISA provides information on AI under Cybersecurity Best Practices on their website: https://www.cisa.gov/ai.

Artificial Intelligence, Cybersecurity and the Health Sector July 13, 2023 from the Office of Information Security and Health Sector Cybersecurity Coordination Center.  This PPT addresses:

  • What is artificial intelligence?
  • How does it work?
  • What does it mean for cybersecurity, especially for healthcare?
  • What can be done to remain secure, given AI-enhanced cyberthreats?

AIHC recommends training healthcare executives, managers and key workforce members in HIPAA privacy and security – training online available at: https://dev-main.aihc-assn.org/courses/hipaa-privacy-security-course/

AIHC is a Licensing/Certification Partner with the Centers for Medicare & Medicaid Services (CMS)

https://www.cms.gov/training-education/medicare-learning-network/partnerships#Licensing


Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved 

Read More
HIPAA Compliance
HIPAA

How to Handle Passwords Like a Boss!

Written by: J. David Sims, CHITSP, CHMSP, Managing Partner at Security First IT, LLC; Board Member with the American Institute of Healthcare Compliance; Podcaster, Speaker, & HIPAA Instructor; Help Me with HIPAA Podcast Contributor and Federal HICP 405(d) Task Group & HIC-TCR Task Group




Cybersecurity starts with the basics, such as appropriately managing passwords within your organization. The Health Insurance Portability & Accountability Act (HIPAA) requires access controls and password management, which requires a top-down approach within your organization. Whether you are a Covered Entity or Business Associate, handle it like a boss!

In a recent article by Joanne Byron, she discussed one of the biggest challenges with proper password management… password sharing! In this article, I’m going to introduce you to some ways that you can overcome this challenge in your organization.

First, let’s start by setting three ground rules that I use for cybersecurity:

Rule #1 – Security is not convenient

Rule #2 – Security is not optional

Rule #3 – Security should not unnecessarily hinder the user

Understand that by design, security is there to hinder or stop an action. Think of your house for a minute. I have a sign in my yard advertising that I have monitored security in my home. I also have an alarm system, a deadbolt, a dog, and a shotgun. All these things represent different levels of security and incident response. They all cost me money and they are all inconvenient in some way. To protect my family, my most precious assets, is not optional. However, I can’t make this level of security so inconvenient that it doesn’t work. Therefore, I’ve ensured that these levels of security do not hinder my family’s ability to quickly enter and exit the home.

Security is there to deter the bad guys and to keep out those who should not be in my home (like the in-laws).

Passwords are just one layer of security for your electronic Protected Health Information and other digital assets. It is also a layer of security that is heavily dependent on the user… the human. The human must follow your password policy so that proper passwords are created and used in the correct manner. However, like a flowing river, humans will often find the path of least resistance (or create one) to get their job done.

Therefore, it is so important to train employees on your password policy, why passwords matter, what can happen when passwords are shared, and so on. Equally important is that the organization should take reasonable measures to make using passwords not a huge hinderance. Let’s take a look at some solutions to help your team be password ninjas!

Password Managers

Password managers are a fantastic tool for… you guessed it… managing passwords! I could not do without a password manager. At last check, I had over 1700 unique passwords stored in my password manager.

Password managers offer an array of other benefits and services but at its core, a password manager allows you to store all your passwords in a single, secure place. Instead of having to remember dozens or hundreds of passwords, the user only has to remember the one password that opens their password manager. Think of it as a vault for your passwords.

Another feature of most password managers that I love is the ability for me to share a password with someone without giving them the password. There are a few ways this can be used. I can set up a user account for someone and program their password into the password manager so that they can login to the application using their own credentials, and they never see the password. This ensures that a user can’t use their credentials outside of the office to access anything business related.

This is also very helpful for those websites that do not allow for multiple user accounts, but you still need multiple users to access it and use it. I see this often in practices where a business website only gives the practice a single account to use. The practice uses the same username and password for every employee that needs access to that website. Even worse, when employees leave the practice the credentials are not changed, which allows the separated employee to assess the site from anywhere.

There are several additional benefits of a good password manager application, so investigate one for your organization. They are well worth the small investment.

Creating Passwords

Whether you use a password manager or not, you still must deal with creating secure, unique passwords. Remember, you do not want to have the same password used more than once. Using the same password for everything is like having one key for your house, your car, your office, as well as all your past houses, cars, and offices. Oh, and the key has your name and address on it. Can you see how important it is to use different passwords everywhere?

Before we continue, it is important for you to understand that the bad guys aren’t trying to login to your online accounts typing in one password at a time hoping to get lucky. The bad guys use software automation and databases of passwords to throw at your accounts. This is called a brute force attack.

They know that most people are lazy and use terrible passwords. The most common password is 123456. You may laugh, but this password has been exposed in breaches more than 23 million times. It seems that no matter how terrible of a password it is, people still use it. For these people convenience is a higher priority than security. I wonder if these same people leave their car and homes unlocked… because, yeah… fumbling for a key is not convenient either.

Just a few months ago, the cybersecurity world learned of a leaked list of passwords called RockYou2021. This massive list of breached passwords and passwords from other sources comprises an impressive list of 8.4 billion unique passwords. 8.4 billion!!! Is there a chance that a password you use will show up on a list that size? Yeah, most likely. Unless you are one of the smart ones that use good password creation practices.

Since I’ve already mentioned password managers, it is worth noting that most password managers come with a password generator built-in that allows you to select a few criteria for your password and presto, it creates a password for you to use. Whether you’re using a password manager or not, here are some criteria to consider for your secure password:

Size Matters

Length is more important than complexity. Forever and a day we’ve heard that password complexity is necessary. Well, after years of research, we’re finding that all that complexity lends itself to creating other problems.

Many users fulfill this complexity requirement the same way by simply capitalizing the first letter of the password and adding a 1 or ! to the end. If I just guessed 25% of your password, you should be relegated to using a manual typewriter for the next month. Your password should be at least 8 characters (I prefer 12 to 16) minimum. The longer the password, the harder it is for software to crack it.

Change Is Good, or Is It?

Consider eliminating or reducing periodic password resets. We are also finding out that having people change their passwords too often means that they can’t remember them. I can often tell how many times someone has changed their password by how many exclamations they have at the end. Every time there was a password change, they simply added an exclamation.

If you are using secure passwords, there is no need to change them unless they become compromised in any way. However, knowing if they are compromised becomes super important and your organization should subscribe to services that monitor your accounts for compromised credentials. This brings us to the next point.

You Made the List! That Sucks.

Every password should be checked against known “blacklists” that include dictionary words, repetitive or sequential strings, passwords taken in prior security breaches, variations on the site name, commonly used passphrases, or other words and patterns that cybercriminals are likely to guess. Using a password that is on a Blacklist makes the password almost useless. Imagine if your home had one of those digital keypads for keyless entry. Now, imagine that there was a list floating around your town that had your home’s key code. How would it make you feel that thousands of strangers can easily walk right into your home if they desire? Using a compromised password is much the same.

Lie… Seriously!

You know those password hints you had to create to set up your bank account? Chances are, those answers are fairly easy to get by just paying attention to your social media accounts and what you share online. Heck, the answers may even be able to be socially engineered out of you.

When presented with these password hints and security questions… lie like crazy! What’s my mother’s maiden name? NunYoBitNess!

Get creative and have fun with it but remember you may need to use these answers at some point to recover or reset your real password, so you need to keep this information. I hate to keep coming back to password managers, but most of them also allow you to keep secure notes in your vault (it’s not just for passwords).

What Do You Have? What Do You Know?

Multi-factor (MFA) or Two-factor (2FA) authentication requires users to authenticate themselves using something they know and something they have.

2FA has been around for a very long time. If you’ve ever used an ATM machine to get cash, you’ve used 2FA. You used your card (something you have) and your PIN (something you know).

Using 2FA will likely require that you use an “Authenticator” app. There are many available but stick with the known companies like Google, Microsoft, Authy, etc.

I highly recommend using 2FA everywhere it is available. Even if someone has your username and password, it will be difficult for them to get past your additional authentication methods.

Wrapping It Up

Now that you know how to create secure passwords, how to store them safely, and how to manage them properly, you are ready to go out into the world and show everyone in your organization how they too can handle passwords like a boss!

Want More Information on HIPAA Compliance?

Help Me With HIPAA is the most popular, longest running podcast of its kind. Patient care starts from the moment a person entrusts you with their personal information. Join Donna and David each week as they deliver HIPAA and humor in a way you've never experienced. Who says learning can't be fun? Not us!


Train Online in HIPAA Privacy & Security Compliance – Click Here for more information.


Only need short refresher courses or targeted training? Check out the AIHC HIPAA short courses.

Read More
HIPAA Compliance
HIPAA

Is Sharing EHR Passwords a Problem?

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




This article addresses the importance of Electronic Health Record (EHR) security to help health care organizations, health plans, clearinghouses (Covered Entities) and their business associates avoid HIPAA violations under the Security Rule Standard § 164.312(a)(1). To obtain more information about mitigating the risk of a HIPAA violation, please consult with legal counsel or a HIPAA Security Consultant. 

 

What If . . .

 

What would happen if you shared your login and password to your online bank account? How about sharing the password to access your credit cards? How would you feel if you knew your doctor shared his/her password to your personal medical records with an unauthorized user? What if someone in medical billing shared his/her password to your account (containing your medical and financial identity) with someone not authorized to access your information?


What If EHR Passwords Are Shared . . .


Electronic health records (EHRs) incorporate a vast amount of patient information and diagnostic data, most of which is considered protected health information. With the advancement of technology, the emergence of advanced cyber threats has escalated, which hinders the privacy and security of health information systems such as EHRs.


As defined by the Center of Medicare and Medicaid Services (CMS), “An electronic health record (EHR) is an electronic version of a patient’s medical history, that is maintained by the provider over time, and may include all of the key administrative clinical data relevant to that person’s care under a particular provider, including demographics, progress notes, problems, medications, vital signs, past medical history, immunizations, laboratory data and radiology reports.”


Because this protected information and data can easily get into the wrong hands, individuals should not share passwords with anyone.  


Is This Really a Problem? Doesn’t Everyone Share Passwords?


Due to the sensitive nature of the information stored within EHRs, several security safeguards have been introduced through the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.


Prevalence of Sharing Access Credentials in Electronic Medical Records

To summarize an abstract published by PMC (Public Med Central) of the U.S. National Institutes of Health’s National Library of Medicine, it was found that to prevent data leakage, many countries have created regulations regarding medical data accessibility. These regulations require a unique user ID for each medical staff member, and this must be protected by a password, which should be kept undisclosed by all means. A survey was conducted with the following results:

  • A total of 299 surveys were gathered.
  • The responses showed that 220 (73.6%) participants reported that they had obtained the password of another medical staff member.
  • Only 171 (57.2%) estimated how many times it happened, with an average estimation of 4.75 episodes. All the residents that took part in the study (45, 15%) had obtained the password of another medical staff member, while 57.5% (38/66) of nurses reported this.

Their conclusion from this study: the use of passwords is doomed because medical staff members share their passwords with one another. Strict regulations requiring each staff member to have a unique user ID might lead to password sharing and to a decrease in data safety. Click Here to access the full study.


Remember to Comply With the 3 Pillars of Securing ePHI


The three pillars to securing protected health information outlined by HIPAA are administrative safeguards, physical safeguards, and technical safeguards. These three pillars are also known as the three security safeguard themes for healthcare. These themes range from techniques regarding the location of computers to the usage of firewall software to protect health information. A brief list of the HIPAA Security Safeguards:

  • Access control (technical safeguard) is a technique that prevents or limits access to an electronic resource. The intent behind access control techniques is to limit access to only authorized parties. The healthcare facility collects, stores, and secures patients’ data, which is very sensitive. This safeguard can take the form of role-based access control, attribute-based access control, and identity-based access control. Role-based refers to a person’s role in the healthcare facility. For instance, when a provider begins working at a healthcare facility, he/she has access to patient data, but only the patient data for his/her patients. If this provider also serves on a certain committee in the hospital, then another set of privileges is created to enable access to committee resources. When other data is accessed, a log is created that is periodically audited. When a front-desk clerk begins working in a facility, he/she has no reason to access clinical data, but may need access to the administrative data such as address and phone number, depending on the role that the person plays in the organization. Other names for this are media controls, entity authentication, encryption, firewall, audit trails, virus checking, and packet filtering.
  • Physical access control (physical safeguard) is a technique that prevents or limits physical access to resources. The intent of this control is similar to the technical safeguard: It limits access to only authorized parties. A patient in a facility will not have access to any clinic or ward except the one he/she is seen in. A front-desk clerk in the optometry clinic will not typically need access to the emergency room, so his/her access card will not open those doors. A provider in a facility will not typically need access to the server room, so his/her access card will not unlock those doors. Other names for this are physical security, (some) workstation security, assigned security responsibility, media controls (access cards), and physical access control.
  • Administrative safeguards are techniques that are not entirely technical or physical, but may contain a piece of each. These safeguards typically take the form of policies, practices, and procedures in the facility to regularly check for vulnerabilities and continually improve the security posture of the organization. Other names for this control are risk analysis and management, system security evaluation, personnel chosen for certain roles, contingency, business continuity, and disaster recovery planning.

When Someone Shares a Password – It Is a HIPAA Violation Under the HIPAA Security Rule – Technical Safeguard Related to Access Controls. 

 

The Security Rule defines access in § 164.304 as “the ability or the means necessary to read, write, modify, or communicate data/information or otherwise use any system resource. (This definition applies to “access” as used in this subpart, not as used in subpart E of this part [the HIPAA Privacy Rule]).” Access controls provide users with rights and/or privileges to access and perform functions using information systems, applications, programs, or files. Access controls should enable authorized users to access the minimum necessary information needed to perform job functions. Rights and/or privileges should be granted to authorized users based on a set of access rules that the covered entity is required to implement as part of § 164.308(a)(4), the Information Access Management standard under the Administrative Safeguards section of the Rule.


Unique User Identification Requirement - § 164.312(a)(2)(i)

 

The Unique User Identification implementation specification states that a covered entity must: “Assign a unique name and/or number for identifying and tracking user identity.”


User identification is a way to identify a specific user of an information system, typically by name and/or number. A unique user identifier allows an entity to track specific user activity when that user is logged into an information system. It enables an entity to hold users accountable for functions performed on information systems with ePHI when logged into those systems using audit trails (addressed toward the end of this article).


Regardless of the technology or information system used, access controls should be appropriate for the role and/or function of the workforce member. For example, even workforce members responsible for monitoring and administering information systems with electronic protected health information or ePHI, such as administrators or super users, must only have access to ePHI as appropriate for their role and/or job function.


Sample questions for covered entities to consider:

  • Does each workforce member have a unique user identifier?
  • What is the current format used for unique user identification?
  • Can the unique user identifier be used to track user activity within information systems that contain ePHI?

So, What Can Happen If We Have Insufficient ePHI Access Controls?

Violating HIPAA law 104-191 can be costly. The HIPAA Security Rule requires covered entities and their business associates to limit access to ePHI to authorized individuals. The failure to implement appropriate ePHI access controls is also one of the most common HIPAA violations and one that has caused financial penalties. 


Financial penalties issued to covered entities for ePHI access control failures include:


Anthem Inc. – $16,000,000 penalty for access control failures and other serious HIPAA violations

OCR Imposes a $2.15 Million Civil Money Penalty against Jackson Health System for HIPAA Violations

OCR Imposes a $1.6 Million Civil Money Penalty against Texas Health and Human Services Commission for HIPAA Violations

University of California Los Angeles Health System – $865,500 penalty for the failure to restrict access to medical records

Colorado Medical Center – $111,400 penalty for the failure to terminate access to ePHI after an employee termination and a lack of a business associate agreement

Controlling Access to ePHI: For Whose Eyes Only?


The government HIPAA privacy/security enforcement agency is the Office for Civil Rights (OCR). OCR published the Summer 2021 Cybersecurity Newsletter on July 14, 2021, which states:


The rise in data breaches due to hacking as well as threats to ePHI by malicious insiders highlight the importance of establishing and implementing appropriate policies and procedures regarding these Security Rule requirements. Ensuring that workforce members are only authorized to access the ePHI necessary and that technical controls are in place to restrict access to ePHI can help limit potential unauthorized access to ePHI for both threats.


A recent report of security incidents and data breaches found that 61% of analyzed data breaches in the healthcare sector were perpetrated by external threat actors and 39% by insiders.


Without appropriate authorization policies and procedures and access controls, hackers, workforce members, or anyone with an Internet connection may have impermissible access to the health data, including protected health information (PHI), that HIPAA regulated entities hold. News stories and OCR investigations abound of hackers infiltrating information systems, workforce members impermissibly accessing patients’ health information, and electronic PHI (ePHI) being left on unsecured servers.


Information Access Management and Access Control are two HIPAA Security Rule standards that govern access to ePHI.


Download this newsletter:

Monitor Audit Trails


Audit trails automatically register and record where, when and who accessed the system. They also record what users do when they access the system. This tracks every change in patients’ information and documents it.


Since all the data is logged in the EHR system, it enables users to review the data at regular intervals and flag activities that seem suspicious. Regular reviews can also help correct mistakes caused by human error that could be flagged as a HIPAA violation. An audit trail answers the following:

  • Which patients’ data was accessed?
  • What time was it accessed?
  • Who retrieved the data?
  • Where was the data accessed from?

EHR software can also be set to send notifications to patients when their information is accessed. This way patients can report breaches as soon as they happen.


Conclusion


Create strong policies and procedures, then communicate these rules to your workforce. Enforce compliance through auditing and monitoring. Explain that when an individual allows another to use his/her password to access ePHI, that individual can alter and perform unauthorized functions and not be held accountable. The audit trail points back to the person who is assigned that password. 


Conduct on-going training of your workforce, which needs to include your C-Suite executives (who are not exempt from the rules). To gain the BEST results, conduct additional quarterly training with your front-line managers and supervisors.  Give them tools to incorporate HIPAA training at EVERY department meeting. If you think annual HIPAA training is sufficient, then you simply are not doing enough to protect your patient’s ePHI.


Additional Resources


Weekly HIPAA Podcasts (free) at:

OCR “The Security Rule” on the HHS website:

Train Online in HIPAA Privacy & Security:

Read More
HIPAA Compliance
HIPAA

Cybersecurity Is Not an IT Issue

Why it takes more than technology to defend your organization


Written by J. David Sims, HHS 405(d) Task Group Member and AIHC Board Member




Introduction

This article is reproduced with permission from the HHS 405(d) Task Group Newsletter.  In 2021, the 405(d) Program has grown its reach and continues to pursue its mission of Aligning Healthcare Industry Security Approaches. The 405(d) Program is now able to assist in many of your cybersecurity needs. Whether it is instituting cybersecurity practices using the Health Industry Cybersecurity Practices, better known as “HICP,” or educating your staff on cybersecurity, we are here for you! AIHC is so excited that our talented Board Member, David Sims, is serving on this important task force.


“Dr. Cooper, the computers aren’t working right. They all have a message on the screen about paying to have our data and systems unlocked!”


This was the welcome that Dr. Cooper received on Monday morning from his panicked practice manager, Sherry, as he walked into his practice. No, this would not be a good morning, not at all.


“Sherry, get IT on the phone!” shouted Dr. Cooper as he made his way to every computer and was met with the same ransomware message on each screen. Dr. Cooper had invested a modest amount of money each month to outsource his IT support and security to a local IT firm.


“The IT guys said they can’t log in remotely, so they’ll have to send someone out. It will be an hour or so before anyone can get here,” Sherry explained. In the meantime, patients were starting to fill the lobby for their morning appointments. With no plan of how to respond to such an incident, Sherry instructed her staff to start rescheduling patients and prepared to close the office for the rest of the day. A little while later, Scott from their IT firm arrived. He instantly realized he was walking into a mess. As he walked through the parking lot, he could hear agitated patients complaining about having to reschedule.


Upon entry he noticed another patient expressing concern about their medical records as the front desk person explained that they are experiencing a ransomware attack. Scott quickly assessed the situation and realized that there was nothing he can do to resolve this. Scott turned to Dr. Cooper with a look of dread and began rapidly firing questions:


“Do you have a ransomware response plan?”  “Do you have cyber insurance?”  “Who is handling public relations?”  “Have you called your attorney?”


Dr. Cooper threw up his hands and said, “Wait. So, you’re telling me that you can’t fix this?”


Scott replied, “You have an active ransomware attack happening. Likely, this is going to be a data breach. If so, you are going to have to notify all your patients that have been affected. You may also have to notify the State and HHS and follow State and Federal breach laws. You’ll also need to determine if the media will need to be notified.”


“How could this happen?! We pay you for security!” exclaimed Dr. Cooper, who was sitting down with his head in his hands as he pondered what this will mean for his practice and his patients.


We will leave this true story now and look closer at the question Dr. Cooper asked, “How could this happen?” Afterall, they are indeed paying for cybersecurity and the IT firm is providing good security. So, how then, can this happen?


Like many businesses, this practice did not understand that cybersecurity is not just a function of IT. In fact, there are three areas that must be present for an effective privacy and security program to work. Let’s take a closer look at these three areas.

People

Social engineering, or hacking humans as it is sometimes called, is today’s most successful way to attack an organization. The attacker can bypass all the security that keeps them out if they are able to have someone on the inside let them in. Technology has no way of keeping out the bad guys if the good guys are letting them in through the “employee entrance.”


Your people will either be a security asset or a security liability.


Mostly, people want to do what is right. They want to protect the patients and their employers, but they are often not given the proper tools or training to make them effective security assets.


Organizations should dedicate time and resources to effectively train and test their employees on proper cyber hygiene, privacy and security topics, and incident response. Remember, it’s the people, people.

Processes

A process is the guide that explains to employees how your business does certain things. All too often, a business will either not have processes in place, or they do have them, but nobody knows what they are because they are not trained on them.


It is a guarantee that if your organization has never practiced an incident response, even a table-top exercise, your team will do nearly everything wrong when an actual incident occurs.

Not having an effective, planned response will cost you much more when (not if) disaster strikes. “Failing to plan is planning to fail,” as Ben Franklin said.

Technology

This is the final piece of the cybersecurity trifecta, and yet most people think it is the only piece. This is also the most confusing piece due to its complexity and many other factors. Following a framework or guide, like HICP (Health Industry Cybersecurity Practices), will help organizations understand where their focus should be to properly address the most common threats. Ensure you are devoting enough resources to this area, but understand that technology alone will not properly protect you.

Conclusion

People, processes, and technology. Those are the three areas that must thrive for any organization to have an effective privacy and security program. A cyber incident can happen at a moment’s notice. How well you can recover from it will depend on how prepared you are in advance. In a crisis, people do not rise to the occasion; they fall to their level of preparation.


A resource that can definitely get you started and begin to protect your patients from cyber threats are publications located on the 405(d) Task Force Website.

This publication lays out the top five threats facing the healthcare industry and provides the top 10 practices needed to mitigate them. If you do not have your IT department in house but use a third party, this is a document you can provide to your IT contractor and ask- “Are you doing these things? And if not, why?”


Protecting patients is our number one priority and we all now have to realize that this includes cyber, and using the most up to date practices is paramount to achieving this goal.

Read More
General Compliance

A Reemerging Threat in the Age of COVID-19 & Remote Healthcare

Hacking With Worldwide Implications   

Written by Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)   

As HIPAA Privacy & Security Officers struggle to secure data due to the increase in our remote workforce, an important potential hack could be looming for unaware organizations.  Healthcare IT departments secure our computers and train us in the rules governing what can be accessed in effort to enforce HIPAA security. Nevertheless, are you unintentionally posing risk to the security of your company’s data? 

This article is for all Covered Entities and Business Associates with a remote workforce or with providers accessing patient data remote on a mobile device and smaller organizations new to remote workers due to COVID-19.

As Healthcare Technology advances, so do the skills of hackers!  People are trying to find ways to stay healthy during the pandemic.  What is one hack likely to occur that may escape our HIPAA Security Officer’s attention?  The wearing of activity trackers (also known as FitBits, smartwatches, and other wireless-enables wearable technology devices). According to USA Today, Smartwatch sales soared during the start of the Coronavirus crisis with Apple selling more than 3 times as many devices as its competitors (https://www.usatoday.com/story/tech/2020/05/07/smartwatch-shipments-rise-20-despite-pandemic-sales-led-apple/3086904001/).  

Think I watch too many crime dramas?

Unfortunately hackers are evolving at pace with technology and even the most innocuous and personal technology can be, and has been, hacked. This includes the immensely popular Fitbit. Like the personal cell phone most employees believe these devices are innocuous and will not be harmful if they get plugged in to the work computer. In this article I will cover a threat that faces the immensely popular personal health monitoring device. But be aware, this applies to any wearable technology device.

The Fitbit continues to show how personal devices can be hacked, and proprietary medical information can be extracted and malicious software remotely downloaded. Even information that does not seem to show you the truth is far more concerning than crime dramas.

In a November 14, 2018 article, Jennifer Falsetti wrote how the FitBit can be used, in this case by law enforcement!  At that time, in 2018 in Oklahoma there was a case of the missing jogger, Mollie Tibbetts. Tibbets went out for a jog, and never returned. Law enforcement desperately searched for her and Mollie was found not far from the road she frequently ran. The way investigators searched for Mollie was to the Fitbit tracker she was wearing at the time. Although cell phones had been used as location devices for years, the Fitbit added an element that gained rapid national attention. When  interviewed by Falsetti, Midwest City Police Chief Brandon Clabes had this to say. "These things have grown in the past few years where it's something we use quite often in our investigations. Both criminally and missing persons, these Fitbits have tracking devices inside which really is a safety factor for the individual that wears them because it tells us exactly where you are, and what time, and what place and it gives us the information to determine, especially on a missing persons case trying to locate you like the Mollie Tibbets case. It also helps us investigate crimes because people will tell us one thing but we can verify through GPS, through their Fitbit," said Clabes. 

So how does this apply to HIPAA security?  Let me explain. The tracking capacity of the Fitbit answers many important, and valuable questions for healthcare hackers using the same technology that helped find Mollie Tibbetts: "When do they see their doctor? Where do they see their doctor? When are they home? When are they not home? What pharmacy do they use? What are they doing? Who else are they with while they're not at home?

So, hackers can track information through your personal health device, but hackers can also feed malicious software into the device, and when plugged into any computer the malware will be downloaded. 

The wearable device directly communicates with your phone. It's unsecure, and if you're within range of the device or multiple devices like it and you know what you're doing, you can start surveying and see who is out there. Although the range for this info-grab is only 10-30 feet or so, think of how many times you are in an area with multiple people within these parameters. Even during these initial reopening phases of COVID-19 in a given day there can be many. How many do you know? And are those people with their faces buried in their phones as innocent as they seem?

A real life example of the ability to transfer malicious data was clearly displayed a few years back. Darlene Storm, regular writer for COMPUTERWORLD magazine in her column SECURITY IS SEXY October 26, 2015 wrote about an astounding act of research that caused concern in the security community and an aggressive counterattack by Fitbit. The event took place in 2015:

  • At the Hack.Lu 2015 security conference in Luxembourg, Fortinet researcher Axelle Apvrille presented a proof-of-concept vulnerability in Fitbit Flex fitness trackers; an attacker in close range needed only 10 seconds to wirelessly inject malicious code into a Fitbit Flex wristband via a Bluetooth connection. 
  • The foreign code could persist and then infect a PC or other devices to which the Fitbit Flex connects. 10 seconds. The portion which really arrested the attention of security-conscious audiences was when Apvrille demonstrated how Flex could be infected via Bluetooth. Granted, while the maximum bytes of foreign code to infect Fitbit are only 17, she pointed out that the Trojan capable of crashing Pentium in 1997 (the “FOOF bug”) was a mere four bytes and the Mini DOS virus was only 13 bytes.

So what if the Bluetooth is the part infected? The Fitbit is remote and although hooked to the phone via Bluetooth, isn’t the threat contained? No. One of the scariest extensions of Apvrille’s results was that by infecting through Bluetooth, when the Fitbit gets plugged in to a computer, the computer gets the infection as well. At this point no one is likely to believe their information would be worth hacking. In a rare instance that may be true but consider: what if you have a medical condition and you are reporting data to your doctor based on Fitbit? And to keep it current you will have to plug it into your computer regularly. And maybe your information may not be worth stealing or selling; but what about the President of the United States? As of this article’s publication President Barack Obama wore a Fitbit Surge for 8 months (and he was noted to use his personal phone often). Fortinet, Aprville’s sponsor, explained three steps which would take the problem from research to active attack; two of which were conclusively proven:

“There are three steps to seeing this go from ‘proof of concept’ to a problem in the wild:

  1.  Upload malicious code to any Fitbit wristband in close range.
  2. Automatically transmit the code from the Fitbit wristband to any computer that connects to it (via the Fitbit dongle).
  3. Have the code be executed by the connected computer.

*Fortinet researchers demonstrated and verified steps 1 and 2. Step 3 would rely on exploiting a vulnerability in the computer to which the Fitbit wristband was synced, which was out of the scope of our research. To date, we are not aware of an exploit that would enable this third step, nor did we actively look for one. However, we would caution against working under the assumption there is no such exploit possible, now or in the future.”

Despite the evidence Fitbit vehemently denied there was any vulnerability in their product, and my research to date has not located anything indicating Fitbit has changed its position. In addition, hackers attacked Fitbit itself. Cybercriminals used leaked email addresses and passwords from third-party sites to log into accounts of Fitbit wearable device users. Fitbit confirmed that once inside the accounts, the attackers changed details and attempted to defraud the company by ordering replacement items under the user's warranty. The attackers also reportedly had access to customer data, including GPS history, which shows where a person regularly runs or cycles, as well as data showing what time a person usually goes to sleep.

A January 2018 article in Hackaday reported how Strava, a well known data monitoring service, followed Fitbit users’ data; in part monitoring GPS data. Even though Strava had a sound Privacy policy, the heatmap they built based on GPS data built visualizations using over 6 trillion data points and could be assembled into a fascinating gallery, but there was a downside. The weekend this article appeared an announcement on Twitter reported Strava’s heatmap also managed to highlight exercise activity by military/intelligence personnel around the world, including some suspected but unannounced facilities. Additionally, some mapped paths imply patrol and supply routes, knowledge security officers would prefer not to be shared with the entire world. What this glaringly brought to light was Strava’s redacted data sharing did not identify any individuals: but did or could not do the same for groups of individuals like active duty military personnel whose exercise regimens are clearly defined on these heat maps. 

The biggest contributor (besides wearing a tracking device in general) to this situation is that data sharing is enabled by default and must be opted-out. This finding and report stands in a class of its own. That Fitbits can be hacked has been recognized for some time but to date the hacks have been localized. That this kind of data can be discovered globally caused enormous concern throughout every industry that demands privacy, confidentiality and seeks to safely compartmentalize proprietary data. I watched local news stations report on this event, and the article can be found at https://hackaday.com/tag/fitbit/.

So, as a loyal workforce member, think about your healthcare organization; think about the daily, weekly, monthly, etc. volume and flow of electronic data. Now think of someone like The Centers for Medicare and Medicaid Services (CMS), Blue Cross and Blue Shield and even your state’s Worker Compensation groups. When an experienced hacker trawls the Internet for healthcare data and information the “hook” is bound to find its mark somewhere, and a breach is inevitable. This is where your IT security teams truly start their work.

Security teams, as a rule, have far too many systems and too much tech landscaping to protect from hacks. They will use automated systems such as IPS (Intrusion Prevention Systems) and IDS (Intrusion Detection Systems) takeover to limit the damage. Because attacks and probes happen at very high volumes, manual reaction and protection cannot be accomplished individually. Human intervention typically comes after the threat has been identified. Determining the threat, point of entry, potential or caused damage, threat risk assessment and how to close the vulnerability so it cannot be reused and building effective firewalls are the tasks of the manpower part of the tech security equation.

The security team will spend hours poring over documents, programs, systems, protocols, laws and, especially in health care, security breach reporting algorithms. See why TV hates reality now? Both sides in reality spend hours in very labor intensive work. The fastest part is done before and after the fact, automatically.

We all know that there are instances where hackers and security do battle in real time: and they are fascinating even if you do not understand everything they do. They’re called Capture The Flag (CTF) games. People do NOT know anything-television shows try to convince them these battles occur in real time. This entire section is showing examples where these battles do happen: but they are closely monitored and security is tight.  

CTFs are conducted in one of two ways. One, there is a Red Team contest where the hackers are given systems with no active defenses. The Red Team works against a set of protections they are given before the contest. The more familiar contest pits the Red Team (hackers) against the Blue Team (security forces). As one would anticipate, the Red team scores points for successful hacks and penetrations; and the Blue Team scores points through successful deflections of the attacks and securing/closing of discovered vulnerabilities.

Why add this last story? It may be interesting but what does it have to do with hacking Fitbits? To demonstrate both the hackers and security forces are constantly evolving but the technology is there and has been successfully exploited for some time. When that hacker sits near you in the coffee shop, many person-hours have gone into trawling the Fitbit or smartwatch, its defaults, capabilities and vulnerabilities. Although the articles used here date back to 2015, be aware these problems are still considered to be real threats today and strict security precautions are the norm at most organizations. 

Conclusion

Never plug your phone or personal device into your work computer to recharge.  Notify your organization’s HIPAA Officer if wearing a FitBit, Smartwatch or other personal device which could pose a threat to the security of your organization’s system, even if you are working remote from home on your own computer which VPNs into the company’s systems.

Follow your organization’s HIPAA policies and procedures at work, at home or working anywhere remote.

Still not convinced that hacking is a problem?  I encourage you, I dare you to visit the U.S. Department of Health and Human Services Office for Civil Rights “Wall of Shame” at https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf and just look only at cases under investigation the volume just under the cause “Hacking/IT Incident” would be difficult to tally, there are so many. 

Look at the Health Plans, small and large providers as well as Business Associates listed on the Wall of Shame due to large breaches under investigation. 

The problem is current, it is relevant and with the ever increasing popularity of individual electronic devices coupled with great numbers of healthcare employees now working, basically unsupervised, from home the vulnerabilities of these devices will continue to rise and be exploited.

About the Author

Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)

Carl is an experienced professional and contracted auditor with the military. His background includes HCC auditing for CMS, coding and auditing for a large global healthcare network, and serving as a compliance educator and speaker for AIHC. He currently volunteers as a subject matter expert for AIHC, a non-profit licensing and certification partner with CMS.  

References:

  1. http://2015.hack.lu/talks/#geek-usages-for-your-fitbit-flex-tracker
Read More