Ask a group of long-term care administrators whether cybersecurity is important and nearly everyone will say yes. Ask whether they feel confident about their own organization, and the answers get more nuanced. Some of the reassuring beliefs that circulate in the industry are simply not accurate, and acting on them can leave real gaps.
Here are five myths we encounter regularly, along with the reality behind each.
Reality: Attackers rarely choose victims one by one. Much criminal activity is automated, scanning the internet for exposed systems, reused passwords and unpatched software, and sending phishing messages by the thousand. A facility with modest revenue still holds valuable data, including names, birth dates, Social Security numbers, insurance details and medical information. It also depends heavily on being operational, which is exactly why ransomware pressure works. Size is not protection. Preparedness is.
Reality: Antivirus is one layer, and a useful one, but it does not address stolen passwords, phishing, misconfigured systems, unpatched servers, unsafe remote access or insider mistakes. Modern endpoint protection with behavior monitoring does better than traditional signature-based antivirus, and it still needs to be paired with other controls, including:
Multi-factor authentication
Regular patching
Email filtering
Tested backups
Staff training
Network protections such as firewalls and segmentation
Security works as layers, so that when one fails another can catch the problem.
Reality: Your vendor secures its platform, but you remain responsible for how your organization uses it. Under HIPAA, a covered entity stays accountable for protecting resident information even when a vendor hosts it. Your responsibilities often include:
Managing user accounts and removing former staff promptly
Assigning appropriate roles and permissions
Securing the computers and networks staff use to reach the system
Training staff to avoid phishing
Having a business associate agreement in place and reviewing the vendor's security practices
It is wise to ask your vendor for documentation of their safeguards, and to understand where their responsibilities end and yours begin.
Reality: Compliance and security overlap, but they are not identical. Compliance is meeting a set of requirements, often with documentation to show it. Security is whether your defenses actually hold up against real attackers. An organization can have policies on paper and still be vulnerable if they are not implemented, or it can implement strong controls that are not documented well enough to show an auditor. Aim for both. The HIPAA Security Rule is a baseline, and frameworks such as NIST CSF 2.0 and the HHS 405(d) Health Industry Cybersecurity Practices can help you go beyond it.
Reality: Technology matters, but most incidents start with people and processes. A stolen password, a rushed click, an unchecked wire request or a vendor with too much access are all organizational issues. Effective security needs involvement from administrators, clinical leaders, human resources and the business office. Leadership sets priorities, funds improvements, approves policies and models good behavior. Questions worth asking at the leadership level include:
Who owns security decisions in our organization?
Do we know where our resident data lives?
Have we tested our backups and our incident plan?
Do staff know how to report something suspicious?
Which vendors have access to our systems?
We have never had a breach. You may not have detected one. Monitoring helps you find out.
Cyber insurance will cover everything. Policies have conditions and exclusions, and insurers increasingly require specific controls.
Paying a ransom solves the problem. It may not restore all data and does not guarantee the data will not be leaked.
The good news is that meaningful progress does not require a massive budget. Start with the basics, document what you do and improve in steps. UnityCare IT can assess your current posture against common frameworks and help you prioritize the improvements that matter most for your facility.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172