(866) 251-4459 support@compnetsys.com
Kansas Addiction Treatment Organization’s Email Hack Leads To Data Breach

Kansas Addiction Treatment Organization’s Email Hack Leads To Data Breach

When people go to their doctors, they assume their information is protected. They freely and willingly provide personal information, like social security numbers. Their primary concern is their health and so they literally trust their lives in the hands of medical professionals and providers. This assumption that patient data is protected may be derived from the assumption that medical facilities are all aligned and in compliance with Health Insurance Portability and Accountability (HIPAA). Everyone signs the HIPAA forms and so everyone assumes — even without thinking it — that they are protected and that the medical facility and/or medical providers are in compliance. Indeed, medical providers may believe they are in compliance and their patient data is protected until it happens: the data breach. Instantly, hundreds and thousands and even millions of patients’ information is compromised. Not to mention: the medical entity where the breach occurred may be held liable for it.
Breach of Patient Data Already Making Waves in 2019: The Example of Valley Hope Association
Just recently, a data breach was investigated and confirmed at Valley Hope Association. It’s a Kansas-based nonprofit organization that treats patients with drug and alcohol addictions. They have 16 facilities located in seven states:

Arizona
Colorado
Kansas
Missouri
Nebraska
Oklahoma
Texas.

Patients number in the thousands across these seven states. As of the last week of January 2019, the organization has been notifying these patients — former and current — that there was a data breach and their information may have been accessed.
It all started in October 2018. An employee’s email account had suspicious activity. The investigation commenced with this employee’s email account. On November 23, 2018, it was confirmed: a cybercriminal hacked into the employee’s email account, and from there, was able to access patient information. The information compromised includes:

Social security numbers
Dates of birth
Financial account information
Patient claim or billing information
Driver’s license or state identification card numbers
Health insurance
Medical records
Medications, and
More.

These kinds of breaches are the beginning of identity theft. When it happens in medical facilities, it is all the more stressful because these are patients dealing with health issues. Identity theft is not a matter they want to deal with on top of their health issues. Following the breach, Valley Hope has taken two steps:

It has provided its patients with free credit monitoring and identity protection services; and
It has added additional security measures designed to secure patient data.

Unfortunately, the Valley Hope Association’s breach of patient data is not an isolated event. Many other medical facilities across the country have experienced data breaches. Examples of patient data breaches that occurred in 2018 include:

Catawba Valley patient records were breached by three phishing hacks.
Centers for Medicare & Medicaid Services (CMS) confirmed 75,000 people were affected by a data breach in the ACA portal.
Minnesota Department of Human Services was the victim of two phishing attacks affecting 21,000 patient records.
Fetal Diagnostic Institute in Hawaii was the victim of ransomware attacks resulting in data breaches of 40,800 patient records.
Legacy Health, an Oregon-based health system, experienced phishing attacks that led to 38,000 patient record breaches.
Augusta University Health confirmed in 2018 that 417,000 patient records had been breached.
UnityPoint Health experienced two large data breaches in 2018, exposing 1.4 million patient accounts to hackers.
LabCorp confirmed millions of records have been compromised and are at risk due to the hacking that forced a network shutdown.
A Missouri-based Blue Spring Family Care facility was the victim of ransomware malware, which put 45,000 patient records at risk.
Banner Health breach in Arizona compromised around 3.7 million patient records.

These are just a few of the many security breaches of patient data that occurred in 2018. As can be understood from these examples, healthcare is a lucrative target for hackers, and as technology advances, so do the hackers’ capabilities. That’s why it is imperative that medical facilities, providers, and professionals take steps to ensure their outsourced IT services providers offer all the latest technology to secure patient information.
What does HIPAA say about patient data protection, responsibility, and consequences?
The HIPAA Privacy Rule sets out to protect “individually identifiable health information” in the possession of a covered entity or its business association regardless if this health information is in electronic or paper form or transmitted orally. Covered entities include:

Health plans
Health care clearinghouses
Health care providers “who electronically transmit any health information in connection with transactions for which the [U.S. Department of Health and Human Services (HHS)] has adopted standards.”

The individually identifiable health information is known as protected health information or PHI. According to HHS, PHI includes demographic information relating to:

“an individual’s past, present, or future physical or mental health or condition
the provision of health care to the individual, or
the past, present, or future payment for the provision of health care to the individual, and that identifies the individual or for which there is a reasonable basis to believe can be used to identify the individual. Protected health information includes many common identifiers (e.g., name, address, birth date, Social Security Number) when they can be associated with the health information listed above.”

Covered entities must take measures to protect PHI. Traditionally, a covered entity breached HIPAA regulations when PHI was accessed by an unauthorized person due to unsecured PHI. When this happens, the covered entity is responsible for a breach in HIPAA regulations. But this responsibility is not as straightforward when the breach is made by ransomware or other malware activity. If the covered entity is found to be in violation of HIPAA due to these data breaches, then heavy financial fines may be imposed along with other required corrective action. Depending on the size of the entity and the amount of the fine and other imposed penalties, a data breach could be detrimental not only to the patients whose information was compromised but to the survival and existence of the facility, provider, or professional.
What can medical facilities do to safeguard their patient data?
Medical facilities or any covered entity and their business associates have options when safeguarding their patient data. These options should be interpreted into a plan of action.

First and foremost, these facilities must comply with HIPAA regulations.
Second, they must comply with HIPAA regulations by ensuring they are using the most advanced technologies to safeguard patient data. New technologies develop on a regular basis. You should hire an IT team or outsource your IT needs to an IT services provider who regularly keeps up to date with advancements in technology and consistently implements the technology into their services. If you hire such a team, you can rest assured that data is being protected to the best of technologies’ capabilities.
Third, covered entities and their business associates must thoroughly vet their IT Team and/or third-party IT services provider. There have been cases in 2018 where breaches were made by tech vendors and other third-party IT services providers, e.g., the case of MedCall Advisors in North Carolina.
Fourth, policies and procedures should be in place to ensure that on an ongoing basis, best practices are honored to safeguard PHI. These policies and procedures should apply to all staff, employees, medical professionals, and the IT team — even if IT services are outsourced.

Ultimately the responsibility comes down to the party in possession of the patient data and covered by HIPAA regulations. Don’t let what happened to Valley Hope Association happen to you. Start the new year off right: make sure your PHI is secure and safe.

How To Create A Photo Calendar In Microsoft PowerPoint

How To Create A Photo Calendar In Microsoft PowerPoint


What Can You Use Personalized PowerPoint Photo Calendars for?
A personalized photo calendar is a great way to provide loved ones with updated family pictures during holidays and birthdays. You can print them out on regular paper or cardstock, or send your projects to family and friends digitally. It’s simple to complete in Microsoft PowerPoint, even if you don’t consider yourself the artsy type. It’s also a fun project to show off pictures of employees or coworkers?
What Are the Steps to Create a Microsoft PowerPoint Photo Calendar?

Find a template. To do this, you can open PowerPoint, search for “photo calendar,” and click on the magnifying glass icon to start the search.
Choose any template and select Create.
To replace the default pictures with your photos, right-click on one of the images. Then, select Change Picture > From a file, browse for a picture you want to include, and click on Insert.

You can replace the other stock photos by repeating this step.
You can change photos you’ve added in the same way.

To save your file, select File > Save As > OneDrive – Personal, name it and save.

This example saves it to the cloud.

How Can You Share Your Calendar?
To share your calendar, print it or send the PowerPoint file (.ppt) via email or message to your family and friends. When you do this in PowerPoint Online, you can do it with the file still open and the file is automatically saved for you prior to sending.

What’s the Process to Print the Personalized PowerPoint?
To print your personalized calendar, simply press Ctrl+P. When the Print dialog opens, click the link to open the PDF version of your personalized photo calendar. Then, you use the PDF program’s Print command for optimal results.

How Can I Enter and Analyze Data via a Data Entry Form in Microsoft Excel?

How Can I Enter and Analyze Data via a Data Entry Form in Microsoft Excel?

You can create a data entry form in Microsoft Excel without using VBA or even recording a macro. If those terms don’t mean anything to you, don’t worry. You won’t need to learn them. Excel has a hidden tool you can use to make dreaded data entry fast and easy. Using a data entry form lets you view one record at a time while entering the data, but also makes it easy to analyze multiple records in a tabular format.
1. Open an Excel file.
2. Place the Form tool in your Quick Access Toolbar.
3. Click the Form command to bring up the data entry form view (no other step is needed for this).
4. Use the Find Prev and Find Next buttons to analyze your data one row at a time.
How do I Format the Data for the Data Entry Form?
To use the data entry form, simply put the data in the following format:

One record of data goes in each row in Excel.
Include column headings above the data.
You need at least one record prior to activating a data entry form.

How Do I Add the Forms Toolbar to Excel’s Quick Access Menu?
You can add the Forms… command to Excel’s Quick Access Menu for convenient usage. Here’s how to do that:

Press the options icon that lies to the right of your quick access toolbar.
Choose More Commands when the drop-down list appears.
Add the Form command to the quick access toolbar.
Go to the Choose commands drop-down list. Select Commands Not in the Ribbon from the list.
Scroll down until you come to Form… and click on it to highlight it.
Press Add.
This brings the Form… command in the rightmost box.
Press OK.

How Can You Analyze the Data?
Here are some quick tips for navigating the data block created by your entries.

Place the cursor anywhere inside your data block.
Each row has a single record.
Each column has a column heading.
Press the Form button in the quick access toolbar.
The data entry form activates, allowing you to view data or add records one at a time.
Use the Find Prev or Find Next button to surf through the records.
Add a record using the New button or delete existing records with the Delete button.

Ransomware Explained

Ransomware Explained

Ransomware. Ransomware. You have heard the word and know it involves a cyberattack. You assume from news reports that it only happens to large companies like Target, Equifax, and Marriott Hotels for example, and that cybercriminals will not want to bother with your small or medium-sized business (SMB). Unfortunately, that assumption is wrong.
The Federal Trade Commission (FTC) notes that ransomware is a major concern of small business owners across the country. Another report notes that since nearly 50 percent of SMBs have no employee security and awareness training, they are particularly vulnerable to cyberattacks, including ransomware.
The U.S. Department of Justice (DOJ) reports that since January 1, 2016, more than 4,000 ransomware attacks have occurred every single day. Business owners suffer the temporary or permanent loss of their proprietary information, disruption of their daily business operations, and the extreme expense of restoring files, if that is even possible. Their reputation in their community may also be damaged.
What is Ransomware?
Ransomware is a type of malware, a software program intended to damage computer files. It quietly invades your computer, encrypting as many files as it can locate on your local and network drives. The encryption is done by using a complex mathematical algorithm. When the encryption is complete, your files become unreadable unless you have the key to unlock them.
The only one with the key is the cybercriminal who demands you pay a ransom in order to regain access to your files. Your data has been kidnapped. A simple virus scan cannot undo the encryption. Your data is being held hostage by the cybercriminal.
In many cases, there is a time limit for payment. A count-down clock may even appear on your screen telling you that you must pay the ransom within a certain period of time or forever lose access to the files.
How Ransomware Gets into Your System
Ransomware enters your computer most often by a “phishing” approach. This happens when an innocent user receives an email that appears to be from a friend, co-worker, or reputable company. It includes an attachment. When the user clicks on the attachment, it is downloaded and, voila, ransomware invades that device and all other devices connected to the network.
Some websites have malware lurking in the background. It only takes one keystroke and the malicious software will now infect all the files it can access. The intent is to cause as much damage as possible to your network so that it shuts down and you can no longer access any of your files.
Should you Pay the Ransom?
The DOJ does not advise SMBs to pay the ransom. But, it does note that victims of ransomware have tough decisions to make when considering whether or not to pay. It recommends ransomware victims consider the following factors before paying the ransom:

How to best protect employees, customers, and shareholders.
Paying the ransom does not guarantee that the cybercriminal will provide the key to decryption.
Some victims who paid the ransom and did get the decryption key were again targeted by other cybercrminals.

The DOJ encourages businesses who have been invaded by ransomware to report it to law enforcement. There is a chance that they can use legal tools, including working with international law enforcement, to locate the encrypted data.
How to Prevent Ransomware from Invading Your Network
The most important step of preventing ransomware from invading your network is education. Your employees need to understand how ransomware works, and they need to be constantly aware of the importance of not clicking on any attachment no matter how legitimate the sender appears to be. The attachment must first be scanned for malware.
Every file needs to be backed up so it is accessible off of the network so that if there is a ransomware attack, your business is not crippled beyond repair. If an attack is discovered on one device, immediately shut down all devices connected to the network.
Cybercriminals are getting smarter and learning how to circumvent cybersecurity that is installed to prevent the ransomware and other malware attacks. There are Managed Service Providers (MSPs) who can provide a robust cybersecurity system that can withstand the threats. They should also be able to ward off a threat before it can cause any harm.

Are You Part Of The 55% That Fails To Offer Security Training To Staff Members?

Are You Part Of The 55% That Fails To Offer Security Training To Staff Members?

Making sure the employees that rely on computer systems are trained in cybersecurity is the easiest way to avoid compromising attacks. However, only about 45 percent of business organizations actually make sure their employees are properly trained through mandatory training, and roughly 10 percent make cybersecurity an optional training. This information is alarming for a lot of reasons.
Most Attacks Happen via the Compromise of an End User
Primarily, this new study means that 55 percent of organizations do not think their end users have a big enough role to play in keeping their network safe. In actuality, the end user is usually where systems are compromised in business settings. Phishing messages and other business security threats target people opening emails, performing things on social media, and doing basic functions that end users tend to do. Even if business owners do train their higher-ups, such as management members and team leaders, there is a major risk if the typical system users are not properly trained.
Formal Security Training Is a Struggle in Most Business Settings
Even organizations that offer security training as a mandatory thing to all system users in the work environment, most do so in a limited fashion. According to Mimecast, only about six percent conduct cybersecurity training sessions or courses on a monthly basis. Four percent of business owners do training four times a year, and nine percent only require training when they bring in a new hire. Surprisingly, many places don’t really offer any kind of formal cybersecurity training; they just send out a mass email of tips on occasion.
Employees Are Often in the Dark Where Cybersecurity Is Concerned
Because business owners are not taking the time to ensure their team members are adequately trained in cybersecurity, employees are left in the dark about the threats that could be sitting in wait when they log in to the company system. Studies actually show that one out of four employees have no idea what some of the most common cybersecurity threats are, let alone what they look like or how to avoid making major mistakes.
Considering that one in ten employees are using devices at work, connected to the work network, for personal reasons for at least four hours a day, the aforementioned facts show just how relevant cybersecurity training should be to all team members. Team members may be checking personal emails, hitting up social media sites, or otherwise doing things that could leave companies wide open for an attack. Even if the risks are handled through intranet email, for instance, threats can still get through on other email platforms that an employee uses on a network device.
Implementing Cybersecurity Training Does Not Have to Be Difficult
The majority of business who do not have a good cybersecurity training plan in place avoid the process because they believe it will be too time-consuming. Some wrongly assume that formal training really is only necessary for people who have higher ranks in the company, which is obviously not true. Implementing a good training plan does not have to be a difficult or time-consuming thing. A few ways to incorporate a good training plan include:

Working with a cybersecurity company who provides employee training material with their services
Making cybersecurity a mandatory part of other training processes, such as safety training
Creating basic cybersecurity training modules employees can do in their spare time throughout the day
Handing out informative resources and worksheets on cybersecurity threats and protection

In addition, cybersecurity training should be an ongoing thing. Threats are always changing and evolving by the day as criminals get smarter with every thwarted attack or exposed risk. Therefore, it is critical that business owners get proactive about training and make it a priority over the long term. In the long run, this can be a change that saves the livelihood of the business from a serious cybersecurity attack.
Overall, cybersecurity training should be just as important to a business operation as any other form of training. In 2017 alone, cybercrime cost the world an estimated $600 billion, according to CNBC. If you believe your business is not adequately training all employees in cybersecurity, reach out to a cybersecurity training or consulting company for advice.