Most New Year resolutions fade by February, and technology goals are no different. Ambitious plans such as a complete security overhaul tend to stall when the first busy week arrives. Smaller, specific commitments tend to last, and they add up.
Here are six resolutions that a long-term care operator, assisted living community or clinic can realistically keep in the coming year, along with the first step for each.
Passwords alone are the weakest link in most healthcare breaches, because they can be guessed, reused or stolen through phishing. Multi-factor authentication adds a second check, such as a prompt on a phone.
First step: list your email, remote access, EHR and cloud accounts, then mark which ones require MFA today. Start with email and administrator accounts, since those unlock the most.
A backup that has never been restored is an assumption, not a safeguard. Ransomware has made this more important, because attackers often try to delete or encrypt backups first.
First step: schedule a restore test every quarter. Confirm that you keep at least one copy that cannot be changed or deleted from your main network, and note how long a full recovery would actually take.
One long annual session is easy to forget. Short lessons delivered monthly, using real examples from your own inbox, work better. New hires should get training before they receive access to resident information.
First step: put a five-minute topic on the agenda of an existing staff meeting each month. Rotate topics such as phishing, lost devices, tailgating and password habits.
Your EHR provider, pharmacy, therapy contractor, eFax service and billing company may all handle protected health information. Under HIPAA, business associates must sign agreements and protect the data they hold.
First step: build a simple vendor list with the service provided, the data they touch, whether a business associate agreement is on file, and who owns the relationship internally. Add a column for how you would reach them during an outage.
Old servers, unsupported operating systems and forgotten user accounts are favorite targets. If a device cannot receive security updates, it should be replaced, isolated or both.
First step: run a report of devices and accounts that have not been updated or used in a long time. Make a short replacement plan and put the costs into the annual budget now, rather than after an incident.
Having an incident response plan is good. Having practiced it is better. A tabletop exercise is a one-hour discussion where leadership walks through a scenario, such as ransomware locking the EHR on a weekend.
First step: pick a date in the first quarter, invite the administrator, DON, business office, IT contact and a representative from maintenance, and walk through who would do what in the first hour. Write down what surprised you.
Tell your staff and leadership what has been completed. A short update at a monthly meeting, such as MFA is now on for everyone in the business office, reinforces that the effort is real and encourages people to keep going.
Resist the urge to add all six resolutions to the same month. Consider spreading them across the year:
January and February: MFA and vendor list
March and April: backup testing and training rhythm
May and June: retire unsupported systems
Later in the year: run your tabletop and update your risk analysis
Track progress on one page that leadership can see. Celebrate finished items. Security improves through steady progress, not perfection.
UnityCare IT supports healthcare and senior-living organizations across Oklahoma, Texas and Arkansas with cybersecurity, managed IT and compliance-minded planning. If you would like help turning these resolutions into a schedule and budget that fit your building, we are happy to talk it through.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172