cybersecurity 101 for ophthalmology & physician practices

28
Cybersecurity 2016 Ravi D Goel, MD Regional Eye Associates, Cherry Hill NJ Clinical Instructor, Wills Eye Hospital

Upload: ravi-d-goel-md

Post on 14-Apr-2017

147 views

Category:

Healthcare


0 download

TRANSCRIPT

Page 1: Cybersecurity 101 for Ophthalmology & Physician Practices

Cybersecurity 2016Ravi D Goel, MDRegional Eye Associates, Cherry Hill NJClinical Instructor, Wills Eye Hospital

Page 2: Cybersecurity 101 for Ophthalmology & Physician Practices

2

The good old days

Page 3: Cybersecurity 101 for Ophthalmology & Physician Practices

3

The good old days

CCHPIROS

VAIOP

AnteriorSegment

Testing

PosteriorSegment

A/P

Page 4: Cybersecurity 101 for Ophthalmology & Physician Practices

EMR 2016

Page 5: Cybersecurity 101 for Ophthalmology & Physician Practices

ICD9 ICD10

Page 6: Cybersecurity 101 for Ophthalmology & Physician Practices

6

PQRS Measures 2016

Page 7: Cybersecurity 101 for Ophthalmology & Physician Practices

7

IRIS Registry

Page 8: Cybersecurity 101 for Ophthalmology & Physician Practices

8

Meaningful Use & Security Risk Assessment

Page 9: Cybersecurity 101 for Ophthalmology & Physician Practices

9

Meaningful Use & Security Risk Assessment

Page 10: Cybersecurity 101 for Ophthalmology & Physician Practices

10

Security Risk Analysis• Pearl #1 – Define Scope of Security Risk Analysis

• Pearl #2 – Gather data

• Pearl #3 – Identify potential threats

• Pearl #4 – Assess Existing Security Measures

• Pearl #5 – Determine Likelihood of Threat Occurrence

• Pearl #6 – Determine the Level of Risk

• Pearl #7 – Identify and Document Improved Security Measures

CMS HIPAA Security Series (2007)

Page 11: Cybersecurity 101 for Ophthalmology & Physician Practices

11

“Reveton” cryptolocker ransomware (2012)

wikipedia (Sophos screenshot - for identification andcritical commentary relating to the website in question)

Page 12: Cybersecurity 101 for Ophthalmology & Physician Practices

12

“Locky” cryptolocker ransomware

(Sophos.com screenshot - for identification andcritical commentary relating to the website in question)

Page 13: Cybersecurity 101 for Ophthalmology & Physician Practices

13

? Spear Phishing

Page 14: Cybersecurity 101 for Ophthalmology & Physician Practices

14

Craigslist

Page 15: Cybersecurity 101 for Ophthalmology & Physician Practices

15

Hollywood Presbyterian Medical Center

wikipedia (Junkyardsparkle)

Page 16: Cybersecurity 101 for Ophthalmology & Physician Practices

16

Hollywood Presbyterian Medical Center - $17k

wikipedia (Kangasbros)

Page 17: Cybersecurity 101 for Ophthalmology & Physician Practices

17

T. Boone Pickens cybersecurity?

Page 18: Cybersecurity 101 for Ophthalmology & Physician Practices

18

T. Boone Pickens cybersecurity = Yellow NotePad

Page 19: Cybersecurity 101 for Ophthalmology & Physician Practices

19

Cybersecurity – Top 10 Tips in Health Care

Page 20: Cybersecurity 101 for Ophthalmology & Physician Practices

20

Cybersecurity – Top 10 Tips in Health Care

Page 21: Cybersecurity 101 for Ophthalmology & Physician Practices

21

Cybersecure – Your Medicare Practice

Page 22: Cybersecurity 101 for Ophthalmology & Physician Practices

22

Cybersecure – Your Medical Practice

Page 23: Cybersecurity 101 for Ophthalmology & Physician Practices

23

Cybersecure – Your Medical Practice

Page 24: Cybersecurity 101 for Ophthalmology & Physician Practices

24

Cybersecure – Your Medical Practice

Page 25: Cybersecurity 101 for Ophthalmology & Physician Practices

25

“Locky” cryptolocker ransomware (Paul Ducklin)

(Sophos.com screenshot - for identification andcritical commentary relating to the website in question)

Page 26: Cybersecurity 101 for Ophthalmology & Physician Practices

26

Ravi’s Practical Pearls 2016

• Pearl #1 – Who is your IT guy? Could you text him right now?

• Pearl #2 – Who backs up the data? How often? On-site or off site?

• Pearl #3 – Does your team use internet from desktops or server?

• Pearl #4 – Are all mobile devices encrypted? Wifi secure?

• Pearl #5 – How often is your security software backed up?

Page 27: Cybersecurity 101 for Ophthalmology & Physician Practices

“If there is no downside,there is an inherent upside.”

Malik Magdon-Ismail, PhD (Caltech)Professor of Computer Science, RPI

Page 28: Cybersecurity 101 for Ophthalmology & Physician Practices

Thank you!