The Compliance Divas Podcast
Our podcast covers current topics such as infection prevention and control, OSHA and HIPAA compliance for dentistry. We discuss the latest regulatory information, answer frequently asked questions and give suggestions for dental practices to make compliance easy and sustainable. The Compliance Divas are a trusted source for consistent, accurate information based upon current guidelines, standards, science, and recommendations.
The Compliance Divas Podcast
#133 Chatting with a Cybersecurity Expert
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
This timely episode will familiarize you with cyber security in healthcare and how you can minimize your risk against online threats. It's hard to recover financially from a cyber attack. The Divas interview cyber expert, Alex Berta. Tune in to learn how you can help protect your practice!
- Cybersecurity & Infrastructure Security Agency (CISA)- Cybersecurity Best Practices https://bit.ly/3QMLQls
- CISA Cyber Threats and Advisories https://bit.ly/3swhImb
- U.S. Dept. of Health and Human Services - Cybersecurity Guidance https://bit.ly/3QXcoBF
Welcome. I'm Leslie Kennedy. I'm Mary Gavoni.
SPEAKER_02I'm Linda Harvey. I'm Olivia Juan, and together we are the Compliance Divas. Welcome to the Compliance Divas podcast. I'm really excited in this episode to speak with Alex Berda. My name is Olivia Juan, and I'll be your moderator today. Alex Berta is recognized as a talented and skilled cyber threat analyst, and he's also a major contributor and thought leader in the cybersecurity industry. As the Compliance Divas, we bring clarity and simplicity to compliance by navigating regulatory compliance to keep you on course. Please subscribe to the Compliance Divas podcast through your favorite podcast channel or on our website, thecompliancedivas.com. We would also appreciate your time in leaving us a review. Any resources that we mentioned during the episode can be found on our website. Please submit your questions to support at thecompliancedivas.com. So, Alex, I'm so excited to have you on this podcast with the Divas, and we are excited to pick your brain and talk with our audience of dental office people and helping them to be aware. Not only, you know, we talk a lot about HIPAA compliance during these episodes, but we want to focus on cybersecurity and cyber hygiene. And you provide that threat intelligence and support for cybersecurity and incidence response. So tell us a little bit about you, Alex.
SPEAKER_04Um, so I have about 20 years of cybersecurity experience. I actually grew up in this industry. Uh a lot of people, you know, will go to school and everything for it, which is great. But I had the opportunity from a very young age to meet, you know, like people like Kevin Mitnick and Steve Wozniak and uh Steve Jobs and all these icons that you hear about. I actually grew up around. So it was really interesting, you know, my upbringing in it. I saw it from you know the the early 2000s, late 90s of how cybersecurity was and kind of just became part of that community and have been in it ever since.
SPEAKER_02Wow, that's so interesting, Alex. I know the divas are excited to ask some questions, so I'm going to pass the mic and let Mary give you some uh queries that we're interested in.
SPEAKER_03Alex, I am truly thrilled that you are here to share your expertise, and I'm very impressed that you knew Steve Jobs and Steve Wozniak. That's wow, that's way cool. Um my question is what's the biggest concern for cybersecurity, or the biggest cybersecurity threat, if you will, for healthcare facilities and their employees, especially um dental health care facilities?
SPEAKER_04So for any type of medical facility and the employees that work there, the number one thing that needs to be on the back of everybody's mind is data breaches. A data breach can expose sensitive information like social security numbers, medical records. Uh, this can lead to identity theft and financial fraud. I did some research around this several years ago in 2021. We were looking at roughly 34.4 million healthcare records being published online. That's almost 2.8 million records per month that were being posted through data breaches. Phishing attacks are another thing. Phishing attacks are becoming more and more popular in the healthcare industry. This includes fraudulent emails or websites trying to trick individuals into revealing sensitive information such as credit card details or logging credentials. And then we have ransomware. We hear about this in the news all the time. This is where unknown threat actors, those are threat actors, we don't know who they are just yet, um, are able to encrypt and extort data that belongs to that organization where they have to pay to get their data back. In 2023, this year, there have been roughly 1,500 ransomware attacks resulting in organizations paying an unknown uh amount to the threat actors, but it's in the hundreds of millions of dollars. And then we have insider threats. This is one of the largest threats uh that healthcare organizations face because when we think of an insider threat, we often think of people that work in an organization. So this is like a disgruntled employee or you know, somebody new that accidentally like does click on like a phishing link or is sending stuff to their personal email from their work email. But we also have to remember the most important insider threat. These are people that come in and out of clinics every single day. So we know what our staff and our teams are doing, and you know, we may know that one or two disgruntled employees that works there, but we don't know any of the patients that are coming in, especially new patients. So this can pose a risk to medical facilities all across the board, from dental to healthcare uh hospitals, you name it, because we don't know if that person has a different agenda when they're visiting. And then out-of-date systems. We see organizations not refreshing their hardware like they should. So organizations will keep legacy equipment installed and running. The issue is that those devices are not receiving the proper updates and they're not maintained properly. So somebody may have a, you know, we'll throw an example out, and I've seen this a Windows XP box, you know, is still running in their environment. But Windows XP is not compliant and it's end of life. Like it can't be in that stack, but they want to keep it because it's cost effective. It still works, but it's not receiving security updates anymore. So, does it really work?
SPEAKER_02Great information, Alex. I appreciate how you mentioned about the data breaches. You know, we talk about that a lot as the compliance divas, but you know, you said something I had never thought about, and I'm sure Mary can chime in. I never thought about a new patient being the source of a threat, entering into that building, having close-by access to a workstation. You know, we've talked about patients looking at the screen if they're unauthorized to look at the monitor, but I never thought about what you mentioned. So that's an interesting concern that I had not shared, and also about the out-of-date hardware. What's your thoughts, Alex?
SPEAKER_04So with the patients coming in, one of the things I used to do a long time ago was go into organizations that I was hired by the organization, but I would go in as a person, you know, off the street. So we would go in, we would conduct, you know, our penetration tests. That's where we would like break into the organization. And a lot of the times we'd do it right there from the lobby. We would get on the free Wi-Fi or sit in a parking lot, we would connect to our printer that had wireless access, and we would just do our business that we had to do and then leap. And you know, people that sit in a clinic, you know, in the waiting room, it's quite common for somebody to sit there for an hour or two hours, and we would be in and out in an hour and a half. We'd have all the information that we needed.
SPEAKER_02Wow, that's crazy, Alex. And I don't know, emergency rooms, you could wait up to nine hours has been our experience. And it's funny you say that because years ago I did a privacy HIPAA training, and I that this was during paper charts. I took three or four paper charts that were out and around and concealed them and then asked the staff to find those records that they didn't even realize I had taken them. So it's interesting how you did that as a cyber expert in what'd you say, an hour and a half?
SPEAKER_04Yeah, hour and a half, two hours. We were always we were very efficient, like because we had done it for such a long time, but it was never any questions being asked of like, hi sir, you know, what are you doing on that tablet or that laptop or whatever in the waiting room? We would just be sitting there scanning their network and and doing what we needed to do.
SPEAKER_03Mary, your thoughts? Uh a couple of questions. Well, first of all, I I've done on a very small scale the same thing, sat in the parking lot of a especially a new client office, and um tried to get into their network um some years ago were not password protected, and I could get right into their network from my smartphone or my tablet. But um, if I'm using as a patient or as a guest in a facility, if I'm using their Wi-Fi network, are you saying that even that is not secure? I just want to clarify that.
SPEAKER_04Um, so a lot of organizations that I've seen in the past where you know the Wi-Fi network, if it's not segmented properly, you can touch everything on that network. You have to completely isolate it. So the Wi-Fi is a separate network from you know the medical equipment, the computers at the front desk. A lot of the times, you know, we see organizations go in and they just like throw in a home router and you know, they have a guest Wi-Fi and a home Wi-Fi, you know, type of name on there, but they're not isolated, it's all the same network.
SPEAKER_03Okay. So as long as they're on a separate network that's not on their office intronet, then they should be okay.
SPEAKER_04In theory, yes.
SPEAKER_03Separate URL.
SPEAKER_04Yes, there's separate IPA, I should say. Yes, but there's always, you know, the threat actors are always one step ahead. So you know, it it's good that they're you want them completely isolated from each other.
SPEAKER_03Okay, and so that's a function of their hardware and working with their technology um support people.
SPEAKER_04Correct.
SPEAKER_03Got it. All right, thank you for that clarification.
SPEAKER_02Alex, this is just so helpful. I I want to introduce you now to Linda Harvey. Linda.
SPEAKER_01Hi, Alex. Um, like Mary and Olivia and Leslie, I'm thrilled to have you here. And I think the divas are going to want your autographs where you have all those wonderful, famous people that you knew. But you know, we we all know people that have done something in the cybersecurity industry, but I've never met someone with the depth of background that you have. So my question is basically around some ways that's sort of two part is how can healthcare professionals, particularly in dental practice, minimize the risk? And you addressed one with the free Wi-Fi and you know, having those set work networks set up separately. But I'd like to just talk about with you as you list off some ideas, those new patients or any patient, because we typically teach our teams, Alex, to lock their screen if they have to leave the room for a minute or two. So I'd like I'm curious about some more tips there, as well as any other tips you might have for healthcare professionals to minimize their risk in these areas.
SPEAKER_04So with screen locking, there's a way that you can go within like Windows to set it to like 30 seconds, a minute, like I think 30 seconds is the shortest amount of time you can do. But it comes back to like cybersecurity hygiene, right? Like you kind of have to remind people if they're not doing it, hey, like you need to do this, you're putting us at risk by leaving the screen unlocked. You know, it'll and it comes down to user awareness training. Organizations that have user awareness training, you know, at least once a year, they're gonna be a lot more protected than these organizations that don't have any cybersecurity awareness training at all, because the people that aren't receiving the training, they don't know what to look for. You know, they think this email that came in, you know, from one organization, you know, offering like free trials of their hardware or software for whatever, that it might seem like a great idea, but you know, it's being sent from some Gmail address from overseas disguised as something else, you know, for phishing email. So by training users, the people that work there, the see and notice this type of stuff, to either raise it up to their IT teams or even just delete it, you know, will help a whole lot. Um, another thing that can help is you know creating a cybersecurity policy and having everybody sign it, you know, make everybody read it, make everybody sign it, saying you understand the risks of you know being on your Facebook account all day or going to work computer or watching TikTok or something like that. So if you already have a policy, go through and revise it because a policy from 2020 is not gonna work for today. Technology changes every single day, and every single year we see more and more requirements coming out for like HIPAA compliance and you know PCI for taking payments. Um just go back through and and refresh it, kind of look at it, see what needs to be revised, and then fix it.
SPEAKER_01Thank you, Alice. That's yeah, those are some great points. Olivia, back to you.
SPEAKER_02So this is really uh scary information, Alex, but much, much needed because sometimes people are misinformed that they just put a policy together, put it on the shelf, and they're in compliance. And that's not the case at all, especially in the cyber world. Now I'd like to introduce you to our diva, Leslie Cannon.
SPEAKER_00Hi, Alex. Um, I am terrified of the cyber world, and to me, it seems like I'm looking over the edge of an abyss with all that could go wrong. How can we stay ahead, one step ahead of the cyber criminals, if they're always at one step ahead of us with the new trends? And what are the new trends that you're seeing with cyber attacks?
SPEAKER_04So the stay one step ahead is people need to get into a like a routine of patching their computers, right? Like I see this all the time where people are like, Oh, I'm not gonna install these Windows updates because it breaks something, or I'm not gonna install the latest release of this software because you know it changed something. Well, those updates are being pushed out by vendors, which they're normally security updates that are being pushed because that means there was a problem with the previous version and they wanted to go ahead and fix it. And with the holidays, you know, they're coming up. Well, we have like six, seven weeks until Christmas, you know, with the holidays coming up that close, we're seeing an increase in phish, we're seeing an increase in credential theft from fishing where people are trying to get people to sign into stuff. Uh online scams, we're gonna see an increase in that. Uh, scam deals is something we see. So if you're ever browsing like social media and there's an ad for something on sale and it seems too good to be true, that's normally a scam deal. Those people really are just after your credit card information. And then we're seeing a lot of social media account takeovers taking place right now. But as the holiday season gets closer, we're gonna see more and more of that as we get towards Christmas. And then if you think about like your social media accounts, all the things that are connected to it, if somebody runs like a business page or multiple pages, once that account is compromised, those unknown threat actors, the bad guys, they have access to that. So now all your followers they could go out onto your business site, create a malicious, you know, link or post and push it out. And then everybody that follows your organization now is gonna click that link, potentially get their account compromised or information compromised. And it's just a vicious circle, you know. We go through this every year, but you know, this year it's gonna be a lot worse than it was last year and the year before that.
SPEAKER_02Thanks for scaring us, Alex. No problem. Um, it's just really, you know, and the thing it is with social media, we're all on it. We we all have businesses, dental practices, vendors. It's important to have a presence, and yet it seems uh quite intimidating. But Alex, I I was wondering from the aspect of criminal organizations out there that target specifically healthcare facilities, hospitals, uh, dental offices, uh, you know, who are these criminals and what do you suggest if there is an attack?
SPEAKER_04Sure. So you have to remember when you talk about these criminals, like we we see in like movies and TVs that these criminals, you know, are in these like high-tech server rooms, right? And you know, a bunch of blinking lights and blue light and them in hoodies, uh, portrayed most of the time. But cyber criminals are really people of opportunity, they often attack organizations at their weakest length. They're people. So this is where like the phishing and and stuff like that comes in. But when we really start talking about known threat actor groups, these are people that we have identified to attack the healthcare sector, we see things like Lockbit 3.0, Klopp, Royal Ransomware. These are all ransomware groups that target the healthcare sector. Not they don't specifically attack certain organizations, they want to attack you know anybody that has that open opportunity within that sector. So they specialize and and they know the type of hardware and software that these organizations run. So these threat actors, you know, they'll often target vulnerabilities or even people within the organization, but they also look at things that are publicly facing on the internet for an organization. So things like organizations not having proper security controls, like firewalls and things like that, that would normally stop these attacks. You're opening yourself wide open for not having them. Um, and the threat actors are able to see these. We often also see organizations uh that are nation states. So this is gonna be like Eastern Europe, Russia, China, Middle East, and even the United States that are targeting healthcare organizations. Because at the end of the day, a healthcare organization, a lot of the times they'll have ransomware insurance or some type of cybersecurity insurance where there is an attack, they have that money in an insurance pool where they can pay it. And threat actors know that that you know, a healthcare organization might have a million-dollar policy. They may not take the full million dollars if they can get in, but they're gonna at least gonna take about a half a million if it's a small company, if it's a larger company, it's gonna be into the millions.
SPEAKER_02Wow, and that doesn't count all of the fines and everything else that goes with it if they weren't following those recognized security practices that we've been learning about over the last year. Uh, Alex, this has been very informative. And did you have some other thoughts you wanted to share?
SPEAKER_04Yeah, so uh back in a previous life, uh what I was talking about earlier, going into healthcare organizations, we would have to at all quite a bit after a data breach go in and review security controls for insurance pools. So a lot of people think, you know, when there's a cybersecurity incident, insurance is just gonna, you know, fork over 500k, you know, for an example. Well, a lot of the times there's people like myself that would show up to these organizations and we would spend weeks there reviewing everything policies, uh, systems, their critical infrastructure, making sure stuff was properly password protected, um, users' devices, you know, if they would let us a lot of places would be like, yeah, hand over that laptop or whatever, depending on what it was. And we would go through everything and see, hey, like this server is missing patches or it's misconfigured, or you have an admin account with the username admin and password. I used to see that all the time. Uh, no password complexity, um wireless networks being on the same wireless network, and then we would have to go back to the insurance pool and be like, hey, like, you know, this is bad, you know, because they failed all this and they checked off at the beginning of the year that they had all this to have this, you know, insurance, and they they don't meet any of the requirements. And the insurance pool would be like, all right, well, we're not gonna give them the half a million dollars then, since you know they failed. Good luck getting their data back. You know, we would see that time and time again, and not just in small organizations, we would see this in you know large medical facilities as well.
SPEAKER_02And and there was a case, Alex, with travelers that they they didn't pay, and it all went to court, and it, you know, it was affirmed that the the customer didn't fill out the application correctly. I mean, basically they lied on it, they call it omitted facts. But these are really good points that you're making to our our dental groups and our audiences that follow the compliance divas because this is such a technical aspect that we have to surround ourselves with the right IT professionals and security experts like yourself that are staying current. Not the fact that you're current two years ago, five years ago, but what is current right now? And you have hit on all of these excellent points that we appreciate that we can share with our group. So, once again, Alex, I want to, in closing, thank you very much for your time. I know that you're a very busy professional and you made time for the compliance divas, and we uh will send you a small token of our appreciation. As the compliance divas, we bring clarity and simplicity to compliance by navigating regulatory compliance to keep you on course. Please submit any questions to support at the compliance divas.com. Any resources that we mentioned will be in the show notes. Once again, I'm Olivia Wan, and we appreciate you tuning in.