Question:
Jennifer,
My practice suffered a Cyber breach. An extortionist emailed me he has my patient records and will post them on the dark web if I do not give him money.
What do we do first?
Please help.
Answer:
I receive this call or email frequently. Too frequently. Which is why I am using this question, received this week, again, to write about insurance, your broker, and your IT Tech. Because, while I am here to be your first call / inquiry if the above scenario happens, I will immediately ask whether you have also contacted your insurance broker and IT Tech prior or simultaneously as me, your attorney.
When your system is breached, our first order of business is to understand how it was breached and the extent. Now, today's newsletter is NOT on breach notification obligations. We will cover that, again, soon.
Today's newsletter is on ensuring you have a qualified IT vendor and also a competent insurance broker - both key partners to your practice. Your IT Vendor should -
Be familiar with HIPAA - spelling the acronym wrong is a key sign your Vendor is not familiar with HIPAA. That is 1 P and 2 As.
Be aware of the obligation and be performing your annual Security Risk Assessment - Required -See - https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html
Actively monitor your HIPAA/HiTech obligations - technical and physical safeguards - two factor authentication, proper firewalls, proper back up systems, emergency protocols, etc. You should not have to take a weekend MIT computer science seminar (for the hat and qualifications) to ensure your IT security - hire a vendor who knows what they are doing
Offer you a Business Associate Agreement along with their service contract!!!!
Represent and contractually promise the vendor has Insurance for their work and have them indemnify you for exposure they create! Yes, I want to look at your IT vendor agreement.
Your Insurance Broker should -
be challenged or potentially fired every 2 years - check premiums, push for competitive quotes - do not accept auto renew on your policies.
(Check premiums, annuity payments, retention limits, etc)
Make sure you IT broker speaks healthcare - litmus test necessary insurance
be transparent about fee structure!!!! How is broker being paid? Is it at your expense? Yes, carrier pays broker, but are you really backstopping the fee?
Types of insurance -
You have patients and a computer - you need Cyber insurance, with preferably a retention lower than $50k ($15k-25k is better so you can actually access it
You have employees - you need Employment Practices Liability Insurance, again, with a retention (deductible) lower than $50k so you have reason to access it before it is too late an claims spiral
You have a physical office, even if subleases or licensed, you need General Liability insurance
You practice medicine - you need professional liability insurance, and, yes, the carrier and coverage matters - check premium, annuities, retention, liquidity, etc. If you have a broker, how is that person being paid?
Of course, always reach out if you are not sure if you are being covered properly or need assistance finalizing a relationship with an IT Vendor or broker. Both relationships should governed by contract, and your protection matters, in the relationship and in the Vendor's results. Surround yourself with proper professionals and you get to focus on your strengths, which, hopefully, if you are a licensed physician, is patient care and not IT Security!!
