July 1, 2022

Watch Your Cybersecurity Blind Spots!

Healthcare organizations can protect patient data and reduce the risk of a cyberattack by being mindful of common blindspots.


Reliance on HIPAA Data Standards

Standards for data security are the backbone of healthcare cybersecurity, with HIPAA being the most ubiquitous framework. Although HIPAA borrows from the robust set of NIST standards, it does not match up favorably with more intensive data frameworks, so healthcare systems that rely exclusively on HIPAA are still at risk of attack. These standards remain a solid starting point, but organizations should look further if data security is their goal.

Nation-State Threat Actors

Recent world conflicts escalated the risk of attacks, with the Russia-linked REvil ransomware being a notable example. While individuals equipped with ransomware attacks may pose a moderate threat to hospital systems, nation-state hackers with unlimited resources pose a formidable threat to even the most secure health organizations. In addition, these nation-state actors have proven to be highly interested in data about the U.S. population collected in hospitals.

Attacks on Trusted Software

With this escalated risk following current world conflicts, many seemingly secure companies have suffered attacks, putting partners at risk. For example, SolarWinds and Microsoft Exchange attacks sent shockwaves through multiple industries, including healthcare. As a result, healthcare organizations and providers looking to protect themselves need to regularly evaluate the security of their systems and their vendor's systems.

Work from Home

COVID-19 created a cybersecurity blind spot for many providers in the form of "work-from-home." Even if IT locks down all data in hospital computers, employees working with sensitive PHI from home without the same safeguards as company equipment expose the information to risk. Additionally, home users may not be as savvy to potential malware and may click on suspicious links sent to their private accounts. If a bad actor gets access to their home PC, they potentially gain access to work information.

Covering IT Blind Spots

Fortunately, many trusted institutions like NIST and AICPA (American Institute of CPAs) maintain stringent guidelines and standards for companies to lock down their data. By being aware of these blind spots and taking steps to mitigate them, providers can protect their patients and livelihoods.

For steps to secure your medical organization's data, click here. For a guide on cybersecurity frameworks for medical organizations, click here.

 

Peer Review Cost Calculator: MDs & Midlevels

Internal Review Cost Assumptions

External Review Cost Assumptions

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

I'm Interested in External Peer Review

Complete the form to schedule a demo or request an expert.

protected by reCAPTCHA
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Medplace

How External Reviews Support Risk Management and Malpractice Prevention

Unbiased external peer reviews reduce legal risk, detect care issues early, and create defensible documentation for your organization.

Read More
September 16, 2025

What We Learned from Reviewing 10,000 Charts

After 10,000 chart reviews, we’ve learned what works: unbiased reviewers, structured reports, random sampling, and fast, digital workflows.

Read More
September 11, 2025

What Makes an External Peer Review High Quality?

What makes a great external peer review? Clear structure, unbiased review, specialty questions, positive feedback, and actionable insights.

Read More
September 9, 2025

Get started in minutes.

Jul 01, 2022