Yesterday, December 6, 2023, the Department of Health and Human Services published a concept paper titled Healthcare Sector Cybersecurity, setting out how the department intends to push the health sector toward stronger security. It follows the National Cybersecurity Strategy released earlier this year and it arrives after a run of large ransomware incidents that took hospital systems offline for weeks.
The numbers HHS cites explain the tone. Large breaches reported to the Office for Civil Rights rose 93% between 2018 and 2022, from 369 to 712, and large breaches involving ransomware rose 278% over the same period. Most of the paper is aimed at hospitals, where the consequences of an outage are measured in diverted ambulances. But independent practices hold the same kind of data, are attacked with the same tools, and have far less help. This is what we think a practice should take from it.
Key takeaways
- The paper imposes nothing today. It signals voluntary performance goals soon, hospital requirements through Medicare conditions, and a HIPAA Security Rule update beginning in spring 2024 that will reach every covered entity.
- The breaches that hit small practices are phishing without multifactor authentication, exposed remote desktop, shared logins, reachable backups and unpatched servers. None needs a hospital budget to fix.
- A ransomware incident is a billing incident. Know how claims keep moving if the office is offline for two weeks.
- The risk analysis HIPAA already requires is the document OCR asks for first. Do it, date it, and fix what it finds.
What the paper says HHS will do
| Pillar | What it means | Timing in the paper |
|---|---|---|
| Voluntary cybersecurity performance goals | A set of health-sector-specific goals, split into "essential" and "enhanced" practices, that HHS will publish to give organizations a clear starting list | Coming soon; no date fixed |
| Funding and incentives for hospitals | HHS will work with Congress on an upfront investment program for under-resourced hospitals and an incentive program for advanced practices | Requires legislation |
| Enforceable standards | HHS plans to propose new cybersecurity requirements for hospitals through Medicare and Medicaid conditions, and to begin an update to the HIPAA Security Rule to add new cybersecurity requirements | Security Rule update planned to begin in spring 2024 |
| Coordination | ASPR to serve as the department's one-stop shop for health sector cybersecurity, with more resources and a mature coordination role | Ongoing |
Two of these matter to a practice directly. The performance goals, when published, will be the closest thing to an official checklist the sector has had, and we expect payers, cyber insurers and business associates to start asking about them. And the HIPAA Security Rule applies to every covered entity, including the smallest practice. A rule update that adds specific required controls would change what a practice's risk analysis and policies have to contain.
The Security Rule today is largely built on "addressable" implementation specifications, which lets a practice document why a control is not reasonable for its size instead of implementing it. Multifactor authentication and encryption are examples. The paper's language about "new cybersecurity requirements" suggests some of those addressable items may become required. That is the practical meaning of the update for a small practice: less room to document around a control, more expectation that it is simply in place.
What we see in practice breaches
The breaches that reach small practices are rarely sophisticated. In the incidents we hear about from practices and their IT vendors, the pattern is the same few things: a staff member's email account taken over through a phishing message, with no multifactor authentication to stop it; a remote desktop connection left open to the internet with a guessable password; a billing or EHR vendor account shared among staff so that nobody knows who logged in; backups that were on the same network as everything else and were encrypted with it; and an old server that had not been patched since the person who managed it left.
None of these need a hospital security budget to fix. All of them are on every published list of basic controls, and we expect them to be on the HHS "essential" list too.
What to do in a practice, in order
- Multifactor authentication on everything that supports it. Email first, then the EHR, the practice management system, the clearinghouse, payer portals, remote access and the bank. This one control stops most account takeovers we see.
- Kill shared logins. Every user has their own account in every system, and accounts are disabled the day someone leaves. Shared accounts make audit logs useless and are a HIPAA problem in their own right.
- Backups that ransomware cannot reach. Offline or immutable backups, tested by actually restoring a file, at least quarterly. A backup nobody has restored from is a hope, not a backup.
- Patch and retire. An inventory of every device and server, automatic updates where possible, and a plan for anything running an operating system that no longer receives security updates.
- Email filtering and phishing training. Short, regular, and specific to the messages practice staff actually receive: fake payer remittance notices, fake EHR login prompts, fake invoices from vendors.
- The risk analysis. HIPAA already requires an accurate and thorough risk analysis. OCR's enforcement actions repeatedly cite the lack of one. Do it, write it down, date it, and fix what it finds.
- An incident response plan on paper. Who to call (IT, counsel, cyber insurer, the practice's billing partner), in what order, and where the phone numbers are when the network is down.
What a small practice's first quarter looks like
A worked example, from the kind of plan we help practices put together. A three-physician practice with twelve staff, one server, a cloud EHR and a local practice management system had none of the controls above in place beyond antivirus. Its IT vendor priced the work and the practice spread it over a quarter.
| Month | Work | Effort and disruption |
|---|---|---|
| Month 1 | Multifactor authentication on email, the EHR and remote access; separate logins for every user; disable three accounts belonging to former staff | Two hours of IT time per system; one afternoon of staff enrollment; a week of grumbling |
| Month 2 | Offline backup of the server with a restore test; patch inventory; retire a 2012 workstation running an unsupported operating system | One IT day; one replacement workstation |
| Month 3 | Risk analysis with the IT vendor; incident response plan on one page; first 15-minute phishing session at a staff meeting | Two half-days for the administrator; one staff meeting |
The practice did not become unbreachable. It did remove the five failure modes that account for most small-practice incidents, and it produced the two documents (the risk analysis and the response plan) that OCR and a cyber insurer ask for first. The total cost was well under what a single week offline would have cost in delayed claims alone.
The revenue cycle angle
A ransomware incident is a billing incident. The practice cannot generate claims, cannot post remittances, cannot check eligibility, and timely filing clocks keep running. Practices that recovered fastest in the incidents we know of had three things: a billing partner or system that could continue submitting from the last known good data, a paper charge capture process that could be switched on in an hour, and a list of payers and clearinghouse contacts kept outside the network. Ask your billing partner what happens to your claims if your office is offline for two weeks. If the answer is a pause, ask what the plan is.
Every vendor that touches protected health information should be HIPAA compliant and should be able to say how they protect your data. A SOC 2 report is a reasonable thing to ask for from a billing company or a software vendor. Have a current business associate agreement with each one, and know what the BAA says about breach notification timelines. The practice is responsible for its patients' data whoever holds it.
Questions we hear
Does the concept paper impose any requirements on us today?
No. It describes intentions. The requirements that exist today are the current HIPAA Security Rule and, for some practices, state law. The paper tells you where the requirements are going, which is a reason to move now rather than when the rule lands.
Is cyber insurance a substitute for these controls?
No, and insurers increasingly require the controls (particularly multifactor authentication and tested backups) as a condition of coverage. A practice that cannot answer yes on the application may find itself uninsurable or excluded when it matters.
Where should a small practice get help?
A managed IT provider with healthcare clients for the technical work, and counsel for policy and incident response. This is operational guidance, not legal advice; the practice's obligations under HIPAA and state law are questions for its attorney.
What to do this month
- Turn on multifactor authentication for email and the EHR before the holidays, when staff are thin and attackers are busy.
- List every shared login in the practice and give each user their own account, starting with the systems that hold patient data.
- Ask your IT provider for the list of devices without current patches and the date of the last successful backup restore test.
- Find your last risk analysis. If it is older than a year or does not exist, schedule one for January.
- Watch for the HHS cybersecurity performance goals and, in the spring, the proposed HIPAA Security Rule changes.
