The Compliance Divas Podcast
Our podcast covers current topics such as infection prevention and control, OSHA and HIPAA compliance for dentistry. We discuss the latest regulatory information, answer frequently asked questions and give suggestions for dental practices to make compliance easy and sustainable. The Compliance Divas are a trusted source for consistent, accurate information based upon current guidelines, standards, science, and recommendations.
The Compliance Divas Podcast
#188 Have You Been the Victim of Phishing?
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Ever wonder what phishing is and how it relates to HIPAA compliance? In this episode, the Divas review what phishing emails are and how artificial intelligence (AI) is super-charging ransomware. Don't miss this short, yet insightful episode.
Welcome. I'm Leslie Cannon. I'm Mary Gavoni.
SPEAKER_01I'm Linda Harvey. I'm Olivia Wan, and together we are the Compliance Divas.
SPEAKER_00Welcome to the Compliance Divas Podcast. This is Linda Harvey, and I will be your moderator for this episode. Have you ever been the victim of a fishing expedition? Well, let's talk about what that means in just a moment. As the Compliance Divas, we bring clarity and simplicity to compliance by navigating the regulatory world to keep you on course. We invite you to subscribe to our podcast through your favorite podcast channel or on our website, thecompliancedeevas.com. Any resources that we mentioned during this podcast can be found in the show notes. And we always invite your questions to be submitted to support at thecompliancedivas.com. And we also invite you to scroll down and leave us a review at the end of this podcast. Well, a fishing expedition is not one where you're going out to fish in a lake or maybe deep sea fishing, but a fishing expedition refers to the fact that you've had some kind of phishing email, meaning that you're getting direct emails or messages or something from other websites that contain grammar errors, spelling errors, formatting errors, because somebody is trying to gather data from you. So phishing simply means that just like you think with reeling, sending out that rod and trying to reel in a fish, they're trying to reel us in as the victim to divulge any information about ourselves that may be related to financial, credit card information, PHI, anything that the hacker is trying to reach for us. Earlier this fall, many of the divas attended the OCR's Office of Civil Rights Security Conference in Washington, D.C. And one of the speakers there talked about artificial intelligence. And it was interesting about what they said on that topic. And I want to quote to you from a website known as Tech Target, who is a vendor in the IT space because they provide marketing services to IT companies. So Tech Target says that as AI's popularity grows and its usability expands, thanks to generative AI's continuous improvement model, it is also becoming more embedded in the threat actor's arsenal. The threat actor is the bad guy. They are the cyber hacker, the cyber thief, the person who's trying to get into your network at work or your personal information. So that being said, Mary, can you talk just a little bit about how AI is supercharging phishing and what does that mean? And tell us about the ransomware. Absolutely.
SPEAKER_02What we're seeing are phishing, smishing, which are texting phishing messages, and now fishing, which is a video or actually a voice phishing type of message that uses a phone call. And AI is play such a big part in this. You used to be able to, and it was simpler when we just had phishing through email, but you used to be able to pick up on what was a phishing email versus something that was legit. In many cases, as you mentioned earlier, Linda, there were grammatical errors, there would have been syntax or spelling errors, and you could tell that the person who was perpetrating these was not, um didn't have a high level of um uh experience or or expertise in English as a of their first language. So that kind of gave you a hint that something was happening. Well, then along comes AI, and these people then can make themselves sound legitimate. They use fear tactics, they use all kinds of things to force you to want to take some kind of action. And as you said, Linda, it's to force you or entice you to divulge information. And so everybody needs to be aware that no matter whether you get a video that sounds like it's your um office manager or your doctor calling if it's if it's at the office or if it's a family member saying, um, hey, I've been arrested and I need you to bail me out, you need to send me some money, or any of those kinds of things, that those are not legitimate. And your financial institutions in particular will never email you, text you, or call you to ask you to verify any of your account information. So the key way that AI has infiltrated and affected these phishing or smishing attempts is in their level of sophistication that the perpetrators now can use AI to make them sound like English is their first language and they can be grammatically correct, and the words can be spelled correctly that make you think it's really a legitimate message, a legitimate request for information when it's not. So keep in mind that your financial institutions will never contact you via texting or directly by phone and ask you to verify your account information. If somebody is asking you to do that, contacting you directly, then that is a phishing or smishing attempt. So delete those, send them to the spam folder, make sure that you're not responding to that because as Linda said before, what they're trying to do is gather the information. They want to gain access to either patient files, if it's in a in a dental practice, they want to gain access to your financial portfolio, your checking account, your credit card accounts, and all those types of things. So AI is making it harder for us to discern what's not legitimate, but easier for the perpetrators to do it. And this is the perfect time of year right now at the holiday season. One of the really frequent attempts that's happening both by email and by texting is people that are pretending to be the US Postal Service in particular, but UPS or FedEx, and saying that you need to validate your address and other information to have a package delivered. So you need to be very, very careful. And there was a big ransomware attack on the MGM resorts in Las Vegas, where phishing attempt was made by somebody calling the service desk, the IT service desk at the resort. And they were able to convince the IT team into resetting that particular employee's password, which then gave them access to everything. So through that IT system, then they could theoretically get credit card information from all the guests at the resorts and all kinds of information of that type. So we need to be extremely, extremely careful when we're even opening these messages. If they're trying to use fear tactics or intimidation, you should know that that is not a normal marketing strategy that people use. Um, those are the perpetrators of the bad things that are using those fear tactics trying to make you afraid. So don't let them intimidate you. Do not let them um force you into disclosing information, but make sure that you let your IT support team know if you're getting those kinds of messages. And the other thing I just want to talk about that we mentioned before was not using a free sort of open source email account for your practice, that you should be using a domain-based email that has all kinds of levels of security on it for your practice, so that you're less likely to be hacked than you are if you're using something like um Gmail or Yahoo or Hotmail or any of those. The subscription-based, domain-based costs you money, um, usually about $25 a month, uh, more or less, but it's good risk management, it's good insurance to protect you from that kind of issue from happening.
SPEAKER_00Mary, I couldn't agree with you more about the good risk management piece because it is all about being proactive to protect our patients and our practices and ourselves as individuals, because we have multiple identities in this world. It's not just our credit card information, but we have our driver's license information, we have our medical insurance information, we have all kinds of PHI about ourselves, ourselves individually, as providers of healthcare, and as well as of our patients. So again, phishing is when these bad actors use some kind of social engineering ploy to trick the recipient into sharing information about themselves, whether it's medical history information, credit card information, whatever it might be. Um, and just like you said, Mary, just that even that one email, tricking them to give an email account into MGM gives them almost the keys to the whole kingdom of zona speak there, with everybody being able to get through all of those. So let's talk now about what happens if you are the victim of a phishing expedition and it causes a credible breach. Um, Olivia, what what do we do next? Or how do we know that it's a credible breach? What kind of steps should our listeners follow follow if they have something along these lines?
SPEAKER_01Well, Linda, I want to point out that it's not as easy as just calling your IT provider and turning this matter over to them. There's actually a whole process, and I've actually represented a client with a breach, and I became more aware of how complicated and the numerous steps that we have to go through. So, first, of course, it's detection and initial response. And no doubt, either the dental worker or IT noticed that there's a breach. And so we identify it as soon as possible, and that's using detection systems, or if someone you know came in and the computer was locked up asking for an encryption key. But it's important to assemble a response team. So that's where we go way beyond just having an IT service. And the people on your response team is going to include yes, your IT provider, but also forensics. The forensics team are actually the one that goes into the system to figure out what was exfiltrated or not. You know, was it an incident or was it a data breach? You will also have an attorney that you need to work with because the attorney will speak to the OCR attorney and then communication professionals. So when you get to the point of notifying individuals, that's a special service. There's no way that a dental office could handle sending out first-class letters to thousands of people. Uh, so that's handled by a company or a group. Of course, containment is an issue, making sure we isolate affected systems to stop the breach from spreading. This is all going on simultaneously. So we have to change access codes and credentials if necessary. Now, when the forensics get involved, these people are the experts that determine what happened and the scope of the breach. Now, I know for the case that I handled, it mirrored what Mary was talking about. The breach was the result of a phishing email. And once the link was clicked on, it deployed ransomware on the system. So when forensics gets involved, they do a very detailed report, they capture forensic images of affected systems and analyze the evidence. So we need that as part as the of the report that we will be providing to the OCR. Then, as I mentioned, the affected individuals are notified. We have to do notification on the OCR website, whether it's 500 or more or 500 or less that were affected, let the stakeholders know. Um also painful, very, very painful is having to let um media outlets know. I mean, that was a painful thing for me to have to reach out to the Tennessee Associated Press and do a press release. And you just hope that they don't publish it. Remediation, implement measures to address vulnerabilities and prevent future breaches, and update policy. So in the case that I handled, obviously we had to go through and just uh breathe life into these previous policies by just basically starting over and taking a fresh, clean approach, including uh training as well. The whole process is documented, uh, the investigation, findings, actions, and then a per a very comprehensive report for the practices records as well as what the OCR may ask for. And then there's a post-incident review to conduct a review to identify lessons learned and improve future incident response plans. And it may even involve finding a different IT provider, you know, because if we find out that the uh the weakness or the vulnerability was that we were dealing with an incompetent IT provider, need to look for someone that's familiar with working with healthcare systems. Also, and also taking in consideration that the IT provider is a business associate. And basically those are the steps that we go through, Linda. And it I guess emphasizing that there's no way around not having an attorney and these different people that serve on your breach response team. So there'll be multiple people that a dental office works with to work through this response.
SPEAKER_00Olivia, that's a great analysis. So thank you for sharing all that. And also reminds me of the fact that when you talk about your IT company, it's not just a matter to turn over to them, it's a matter of understanding what their role is because day in and day out, they are the team that steps in when you're having any kind of computer problems and they save the day. And that's what they do best. And so they may want to jump in and save the day for their client, but they may be spoiling evidence that needs to be in place for a third-party company to do the analysis or the forensics, if you will. So, and the media notification is a bit of a scary thing because when it has to go public, um, it has to go public, and that's just no way around that. The main thing um I think is to be sure you do a credible breach analysis during that 60-day window of time so that you can act promptly and efficiently and having the right people on your team and having a good breach response policy that you can activate when this happens and don't just call IT to fix it because they may fix it temporarily, but you don't know perhaps if your data was what's called exfiltrated, meaning taken out of your system, and now it's for sale on the dark web. And lo and behold, the Office of Civil Rights could find it, the Federal Federal Bureau of Investigation, FBI, or the Federal Trade Commission, anybody else can find it, and then you will be even in a less favorable light with the Office of Civil Rights for not reporting that. I also wanted to mention, Olivia, that and we think we're thinking about PHI here, protected health information, and this breach from a HIPAA perspective, but there are state privacy laws, and then the Federal Trade Commission has a privacy law for consumer information. So in our dental practices, we house a lot of information about the patient. Um, and if they're and if they're minors, so we've got their legal guardian and whoever the insured person is, we have a lot of information about families in general. So when that information can be breached, some of that is considered consumer information, personally identifiable information. So it could be reportable to other groups as well. So that being said, so there's so much to be in mind here. So please be sure that you have a good breach response policy and that you are following it when something happens and not just inviting IT to fix it so you can get back on track in the snap of a finger because that's not what you want to do. You want to do so carefully. And having a cyber risk carrier that you can call for legal advice and a good breach expert are extremely important as well. So I wanted to share with us, our listeners, as we begin to wrap up this podcast that there's a company called No B4, K N O W B E, and the number four. They're an international company that helps, they're a security company, they're international, and they help organize organizations to reinforce what's called their human firewall. Every dental practice, every every company in general, not just medical and dental, has the human firewall, and then you have your computer firewalls. So the human firewall is where this organization helps them to reinforce your team to build a stronger security culture. And recently they published the 10 most common phishing email subject lines. And so I want to share this with you real quick. So here's their top 10. I'll just read them quickly. Um, but this is taken from their global analysis from cybersecurity uh information from the third quarter of 2024. So this is pretty much still hot off the press, if you will. So the first subject line might be possible typo, and another one is IT assigned cybersecurity training. Another one, uh please update W4. Number four, paycheck issues, number five, reimbursement notice. Number six, performance review, number seven, test emergency notification system, number eight, timesheet, number nine, logistics proposal comments due, and number ten, emergency evacuation plan. Many of these could be quite applicable to a dental setting that you may be the first receiving this, especially and Mary and Olivia, I don't know about you, but I have one of our clients or several of our clients have received emails from their contractor, dentist, for example, and they were phony emails asking for their direct deposit information to be changed to another bank. And thankfully they caught it in time and their payroll was safe. It didn't get sent to the wrong person. So there's so much to bear in mind with all this. And please be sure that you're protecting yourself by providing periodic security awareness training to your team, not just annual training and new higher training. Make sure that your IT company is providing top-notch services, including managed services. You can't afford not to have those services these days. Be sure that you have a good cyber risk carrier supporting you and that you know the limits and exclusions and deductions of your policy. So, Mary, what additional thoughts do you have?
SPEAKER_02One last thought is also for our listeners to remember that their practice every year needs to do their HIPAA required security risk analysis. And the Office for Civil Rights has a tool that you can use that's online. It's a little complex. I mean, you may have to do it in conjunction with your IT support team. But that's one of the first things, if there's a HIPAA audit or there is a breach, is one of the first things that they ask for is where's your risk analysis so that you could have known perhaps before something happened.
SPEAKER_00Good point, Mary. And I think we'll have to do a podcast on that entire subject because just earlier this year, the Office of Civil Rights launched their security risk analysis initiative, and they are dedicated looking and asking for that. And it's not simply a checklist that we get from IT or an online vendor. So we'll circle back to that topic because that's a very important topic as well. Well, Divas, thank you for sharing all that great information on phishing, and we hope that our listeners take away some good information for themselves personally as well as for their practice and their patience. As a compliance divas, we bring clarity and simplicity to compliance by navigating the regulatory role to keep you on course. Please subscribe to the podcast through your favorite podcast channel or on our website, thecompliancedevas.com. Any resources that we mentioned today can be found in the show notes. And we invite you to submit questions to support at thecompliancedevas.com. We also invite you to scroll down to the end of this podcast and leave us a review. We'd love to hear from you. We look forward to seeing you at the next episode.