Pulse September 20, 2024
When will a healthcare organization suffer its first or next cyberattack? The phrasing of that question is intentional because reality has certainly moved into the “it’s a matter of when” phase and the “if” option is gone. Given that an attack needs to be expected, what is occurring to enable a ready to go response?
Having plans, such as a disaster recovery plan or breach mitigation plan, is one key component. Not only are those plans good idea, but the HIPAA Security Rule calls for them to be in place. That means skipping the step of developing recovery plans will become quite problematic down the road when the inevitable attack occurs and OCR investigates afterward.
Let’s take an operational viewpoint...