The last week of the year is often the calmest stretch on an administrator's calendar. Census is steady, vendors are slow to respond, and many staff members are out. It is also a good time to step back and ask a simple question: if something went wrong in January, would we be ready?
A year-end security review does not need to be a big project. For a skilled nursing facility, assisted living community or clinic, a focused pass through ten areas will surface most of the problems that lead to incidents. Work through the list below with whoever handles IT for you, whether that is an internal person or a managed services partner.
Pull a list of everyone with a login to your email, EMR, scheduling and payroll tools. Compare it against current staff, agency workers and contractors. Disable accounts for anyone who has left, and do not forget shared logins that a former employee knew about.
Confirm that MFA is turned on for email, remote access, and any system that holds resident or patient information. Pay special attention to administrator accounts. If a system cannot support MFA, write down why and what compensates for it.
Few people should be local administrators on workstations or global administrators in your cloud tools. Trim the list to those who truly need it, and give everyone else standard accounts.
Look at operating system and application updates on workstations, servers, laptops and the tablets used on the floor. Anything that has missed several months of updates deserves attention. Also list devices that are too old to receive security patches at all.
Verify that antivirus or endpoint detection software is installed, current and reporting on every device. Machines that quietly stopped reporting are a common blind spot.
You cannot protect what you do not know about. Update your list of computers, medical devices connected to the network, printers, cameras and wireless access points. Unknown devices on the network should be investigated.
Most organizations can tell you that backups ran. Far fewer have tried to restore from them. Pick a file, a folder and, if possible, a server, and restore it to a test location. Confirm that at least one copy of your backups is stored offline or in a location that ransomware on your network cannot reach.
Look for resident information in places it should not be, such as shared drives with open permissions, personal email, or old laptops in a closet. Clean up what you no longer need under your record retention policy.
HIPAA requires security awareness training for your workforce. Schedule the next round now, add new hires, and plan a few simulated phishing messages for the first quarter. Keep the tone supportive. Staff who feel safe reporting a suspicious email are your best early warning system.
Check that the plan lists current names, phone numbers and decision makers. Make sure printed copies of key contacts exist, since email and phones may be unavailable during an incident. Decide in advance who talks to your insurer, your IT partner, and your legal counsel.
Do not try to fix everything in a single week. Score each item as green, yellow or red, then pick the three reddest items to tackle in January. Assign an owner and a due date to each one. Keep the results in a short document you can show to your leadership team, your board or an auditor. Documented, repeated reviews also support the risk management expectations in the HIPAA Security Rule.
If you would rather not do this alone, UnityCare IT can walk through these ten areas with you and give you a plain-English summary of what we find. We work with long-term care and healthcare organizations across Oklahoma, Texas and Arkansas, and we are happy to start with a conversation.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172