The Compliance Divas Podcast
Our podcast covers current topics such as infection prevention and control, OSHA and HIPAA compliance for dentistry. We discuss the latest regulatory information, answer frequently asked questions and give suggestions for dental practices to make compliance easy and sustainable. The Compliance Divas are a trusted source for consistent, accurate information based upon current guidelines, standards, science, and recommendations.
The Compliance Divas Podcast
Episode #31 Cyber Security: It's More than HIPAA
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode, the Divas welcome cyber security experts Debi Carr and Amy Wood who specialize in dentistry. In a time where ransomware is as rampant as COVID-19, you can't afford to miss this podcast!
Welcome.
SPEAKER_02I'm Leslie Cannon.
SPEAKER_03I'm Mary Gavoni. I'm Linda Harvey. I'm Olivia Juan. And together we are the Compliance Divas.
SPEAKER_02Hello everyone. This is Leslie Cannum and I'm your moderator for this very exciting podcast today where we're going to be talking about cybersecurity. This is a special podcast of the compliance divas. We bring clarity and simplicity to compliance by navigating regulatory compliance to keep you on course. We encourage you to subscribe to the Compliance Divas podcast for your favorite podcast channel or on our website, thecompliancedivas.com. And I want to remind everyone that the resources that we mentioned today during our podcast can be found on the compliancedivas.com. We also encourage our listeners to submit questions to support at thecompliancedivas.com. Again, I'm super excited to introduce two guests who are not only very experienced when it comes to cybersecurity, but they are extremely knowledgeable in our world in dentistry. They are actually both good friends of mine and also members of the Academy of Dental Management Consultants. I'd like to introduce you to Debbie Carr and Amy Wood. And before I bring them on to say hello, let me just give you a little background. Debbie Carr is the CEO of DK Carr and Associates, LLC, a technology systems and security consulting firm. She has over 22 years of experience in private practice management experience and over 30 years of experience in technology and security. She assists dentists in obtaining and maintaining HIPAA high-tech compliance, including performing risk analysis and team security training. Welcome, Debbie. We're so thrilled to have you with us today.
SPEAKER_05Thank you for having me.
SPEAKER_02And I'd also like to introduce Amy Wood, who is CEO of Copper Penny Consulting and the president of ACS Technologies. She's been working in healthcare since she was 16 years old. And Amy has worked in direct patient care and also now works behind the scenes in risk management and technology security. Her passion for risk management actually began after her own identity was compromised. And we're going to hear a little bit more about that story. Her passion has turned into a commitment to provide an easy to understand approach to complex regulations. Welcome.
SPEAKER_00Very excited to be here today. Thank you for having me.
SPEAKER_02We're thrilled to have you, Amy. And so really what we want to do is we have a series of questions we think that our listeners would be very interested in hearing about. So I'm going to ask my fellow Diva Olivia what her questions are for Debbie.
SPEAKER_03Hi, Debbie and Amy. Thanks again for joining us. I would really like you all to elaborate for our listeners just what is ransomware and why is it happening in so many dental practices?
SPEAKER_05Well, ransomware is a type of malicious code that is deployed in an information system. It's where an unauthorized user gains access to the information system through either email that remains the number one vector through opening an email that contains the malicious code. We also with COVID, we saw a lot of uh what we call remote desktop type infections as well. And we're seeing hackers send in a system anywhere from 15 minutes to 207 days, uh depending on the type of code. The misnomer is that it's one type of infection. There are over 52,000 types, strains of viruses, so to speak, that can affect uh affect a system. So what it does is it changes the code and it used to lock the or re-encrypt so that they they have the key and you have to pay them to get the key, but they're not doing any of that anymore. They've basically changed their modus operatai and have gone to just grabbing your data and going. They're not delivering the malicious code to lock it up and with the key anymore. They're grabbing it because it's all about making money.
SPEAKER_03Thank you for explaining that, Debbie. Amy, what can you share with us about ransomware and how it's affecting dental practices?
SPEAKER_00Um it's not just about the cost of getting your data back, it's really about uh being able to see your patients. And if those files are encrypted and locked, you obviously can't take x-rays or make appointments or even accept payments. So the patient experience is definitely impacted. Uh, as Debbie was saying, the ransomware has changed, especially in the last year. And with the extraction of that data, uh, we're finding that the hackers are now going directly to the patients and demanding money as well. So not only are they making money by selling it on the dark web, they're going directly to the patients and extorting money. So it's it's uh a lot different than it used to be, and it's uh it's not as fun as it used to be to try to counteract it.
SPEAKER_03It's really scary, and I hope that listeners are following along because you both bring so much experience and skill to the table that we can take advantage of.
SPEAKER_02That certainly is uh information that we need to pay attention to. In dentistry, we have always had to be very cautious of viruses and bacteria, and now we have to worry about these cyberviruses and other forms of attack. So, Mary, you had a few questions for Amy and Debbie.
SPEAKER_04I do. Thank you so much, uh, both Amy and Debbie for being here with us on this episode. My first question is how would you know if you were under attack? What would be some signs that a dental practice would would see?
SPEAKER_00Uh so the first indication is that the computers slow down drastically. And the confusing part of that is it could just be that someone has old computers. So uh that is not the only indication. Uh, typically you would know that you would have ransomware because all the computers lock. You have a pop-up on your screen that says you have X number of days to pay, X number of dollars in Bitcoin, or you don't get your files back. Uh, those warnings are becoming more and more ominous, uh, and the time frames are becoming shorter, and the dollar amount to get your files back is significantly larger than it used to be. Um, the other thing you can expect is uh negotiating back and forth with the cybercriminals to try to get those keys to unencrypt. Uh, they're not really negotiating anymore because they do have the upper hand. So it's uh it's definitely changed and uh we we have to adapt. You know, we use the phrase standard of care and healthcare all the time, especially you guys talking about infection control as much as you do. Uh it works in technology and security as well. It just moves at a significantly faster pace in the technology world. Great.
SPEAKER_04Thank you. Um, I always tell my clients if they suspect there's a problem, don't turn their computer off, but pull out the internet cable. Is that the right thing to tell them, Debbie?
SPEAKER_05Absolutely. And the one thing we have to remember is when you have a cyber attack, it is a crime scene. And what we're seeing again is that these um hackers are just taking the data and going. They're not, they're there's they're leaving their little note, but they're not encrypting. I just had a client where if it wasn't for the fact that they were in the process of converting practice management, they may not have even found the note. It was sitting in a folder. And so they don't necessarily pop it up on a on the screen and they're not locking up your data anymore. So it is a crime scene, and you're absolutely right. You should never um shut down power down because when you power down, you're changing the registries. And so what you should do is is unplug the cord to the internet on all devices and contain, and then it's it work with a expert to know because there's a lot of facets that come into play. You're having to deal with, you know, reporting to insurance, reporting to both Amy and I are members of uh FBI Inviguard, which is a collaboration between private sector and the FBI. So we have agents that are are assigned to us so that when we have an incident, we can go directly to them. And you're having to the doctor wants to get back up and running as quickly as possible, and that's understandable, but you also have a crime scene. So there's it's preserve the crime scene. You are required under law to do a forensic investigation. There is not an IT company that should be doing the forensic investigation. They should tell you, yes, you have ransomware, unplug and hands off. Now they may be, we may use them for data collection for the forensic team, but it it needs to be preserved and isolated and contained.
SPEAKER_04Great. Thank you for sharing that, Debbie.
SPEAKER_02Both Debbie and Amy are cybersecurity experts, and they have some certifications and letters behind their name. Amy, could you just give us an idea of what those letters mean and why you and Debbie are qualified to talk about cybersecurity?
SPEAKER_00Uh yeah, so Debbie and I are actually quite unique in the dental space. There uh there aren't a lot of people that have the experience and certifications that we have. Uh, and certifications are really just a piece of paper that say that we know what we're talking about and we know this really in depth, and someone is willing to give us that uh accolade. Um, the one that we both have is HCISPP, and that is done through ISC Squared. It's a very, very hard test. And basically, it is the healthcare information security privacy practitioner. Uh, should we choose, we could go work for Department of Defense or any hospital in the country. Uh, but we like dental and it's a very underserved market, and it is just as important to protect.
SPEAKER_02Debbie, you wanted to add to that.
SPEAKER_05Uh, that certification, yes, we can go work in the hospitals, but it's an international certification. So we can actually go anywhere in the world and work or handle cybersecurity. Because we have to study all over the country all over the world, their laws.
SPEAKER_02And yet we're so lucky to have both of you in dentistry to serve our clients and community because you both brought up a really good point. And first of all, it's the reputation of the practice when these uh cyber criminals go directly to the patients. I can't even imagine what would go through my head if I was approached by someone that said that they got my information from my dental practice. And I also think that another point that Amy brought up was the standard of care, that the standard of care is so important when it comes to uh protecting your patients' data. And so I want I'm very excited to hear a little bit more. You know, Linda, you had some questions to ask Amy and Debbie as well that'll help our listeners get a little better idea of what happens in a dental office when cyber attacks occur.
SPEAKER_01Thank you, Leslie. I'm so thrilled to have both Amy and Debbie with us. This is a fantastic program, it's so timely because it's happening so frequently. All of our listeners need to learn more and be able to protect their practice more. So, my question is actually twofold. Um, I want to um address who are these people exactly, who are these cyber criminals, and then also address how do these cyber incidents happen in dental practices? So, Amy, maybe you could speak to who are these people? Who are these criminals? Where are they from? What do they do? And how how are they how they keep growing and multiplying?
SPEAKER_00Uh well, most of them are not in the US. Uh, most of these attacks are overseas. And the the reason really is for identity theft, medical identity theft, and ultimately money. There's a lot of money in identity theft, and I personally have experienced that. Um, I had my dental x-rays involved in a data breach, and my name, birth date, social security number, and insurance, uh, medical record number uh have been for sale on the dark web for approximately 10 years. Not that anybody can really do anything with it at this point. I have it locked down, but it's still out there. And I've I've been violated and victimized because someone just didn't understand the value of what they had in their possession. And I feel like a lot of dental offices these days still don't see the value of that information and are somewhat careless when it comes to the protection of that. And they end up falling victim to these things.
SPEAKER_01What a tragic story. Oh my god, I'm sure it must have been a nightmare. It probably still is to some degree. So thank you for sharing that. That's an impact for our listeners to take away. So um, would you also say that some of these um folks that are abroad or wherever they are in other countries, is it my sense is that it's they're growing in more like an underworld. Do you see that kind of happening? Just a quick follow-up question, Amy.
SPEAKER_00Absolutely. Um, so I mean, if you understand how the internet works, we're all floating on the surface web, which is only about 4% of the internet. We're all doing our Instagram and our podcasts and our online shopping and uh and you know, Netflix and Hulu and things like that. Uh, the vast majority of the internet is think of it like an underground stock market. Things are bought and sold and traded over and over again. It could be a bunch of Instagram passwords, it could be social security numbers, it could be bank account information, uh, or it could even be human trafficking. You really, there's everything is for sale, and that is the vast majority of the internet, uh, unfortunately.
SPEAKER_01Yeah, well, I think that gives our listeners more like the depth of what this you know situation is really like. And so, Debbie, I'd like you to add to that, and then maybe could you address um maybe some specific ways that these cyber incidents are happening in dental practices?
SPEAKER_05Yes, and and to add on to what Amy was saying, we are seeing a lot of state-sponsored attacks. And these are countries that do not like the United States, and so they are blatantly attacking us through a we are actually in a cyber war. And so, and then you have countries that are hiring organized crime because they don't want it to look like it's coming from their country. So we're getting that attack happening all the time. The way the most common vector is still through email. We see about 94, 95 percent coming in through email. However, with COVID, because so many people were trying to go into their practices free, they were using what we call RDP, a remote desktop port 38389 is open. And they're getting in that way because there's there's lots, there's computers that do nothing but scan the the cables that are in the internet, and they're looking for what we call open ports that you can see, or open vulnerabilities that you can see from the outside. And they when they find that open door, I always uh the analogy I I use is there used to be the police officer that at night would go lock the doors, go to would go walk the street and check the doors as he was walking the street. Well, now we don't have that. They're they're just they're finding the computer and they're going in that way and they're taking the data that way.
SPEAKER_01Thank you, Debbie. That's a really good um additional information that you shared. Thank you. And so are there any ways that you would say, Debbie, that the essence you besides email, is there anything else that's that you can think of that's coming on, or is it primarily emailed altogether?
SPEAKER_05It's primarily emails and and the uh through the bots. But the other one that we're starting to see now, and we're I I feel like we're gonna see a lot more of this, is that threat actors, that's what we call hackers, threat actors, are using social media to engage disgruntled employees. And what they're doing is they're saying, hey, if you'll just we'll send you the code, download it to a flash drive, plug it in at work, and we'll split you 40%. And if an employee is disgruntled or don't think that they're valued, or they think that they're underpaid, or as we're seeing prices going up and people trying to meet make ends meet, they may be inclined to take advantage of that. And so it's more important than ever now that we make sure that practices are secure and that they're taking the right precautions.
SPEAKER_01Wow, that's amazing to think to begin to think about that, isn't it? But uh, that's a good point. Thank you, Sammy. Uh Amy, I think you had something else you'd like to add, right?
SPEAKER_00Yeah, I'd just like to comment that uh most of the dental offices we see being hacked at this point, uh, they're not adhering to what we consider the standard of care for technology security. Uh, just little common sense things like the big four that we look for are uh business grade antivirus, patches and updates, a firewall, and uh backups. And, you know, backups have changed, you know, standard of care for that has changed. Uh, I remember when I met my husband, he was doing IT for a dentist who I happened to be nannying for. And uh he brought a copy of her practice works database on an unencrypted thumb drive to back up on her home computer. That's actually how we met. Uh and I'm horrified to say that now, but back in 2004, that was cutting-edge technology. Uh, now things are a little bit different. Having even a cloud backup is no longer considered reasonable and appropriate. And so I think it's really important that dentists understand that that standard of care has changed and they need to adapt to the current threats and vulnerabilities that they have. And cyber is definitely part of risk management at this point. I know you guys talk about HIPAA, you talk about OSHA, you talk about all of these different things with risk management. Uh, cyber needs to be added in there. Uh, and and keeping up with that, those current standards is uh the best way to uh protect yourself and to protect these offices because that the hackers are really looking for low-hanging fruit. They're not going to spend a ton of time trying to hack into a dental office. They really are looking for casting a broad net to get as many practices that are not uh having basic protections in place.
SPEAKER_05Debbie, did you want to add to that? I did. A lot of times I've had dentists tell me I'm just a dentist who wants my information. But here's the thing hackers are threat actors are excited when they find out they're in a dental office because they know that they've got the whole picture. We have their demographic information, we have their oral health information, we have their dental insurance. But we also have their medical um insurance, and we also have their medical history. We are the only, dentistry is the only healthcare entity that asks about their medical. Your medical doctor may say, when was the last time you went to the dentist? But they're not going to ask you what did you have done at the dentist? The dentist office is the complete picture. And so when they get into a dental office, they are thrilled because they can recreate. And as Amy was saying, it's identity theft is prevalent. And I can recreate an entire person with the information inside of a dental practice.
SPEAKER_02You know, that's a pretty broad range of information. And I'm actually getting a little nervous because I'm hearing bad actors, crime scene, violated, and identity theft. And uh, if you've ever met anybody, I know I have a I had a coworker who was a victim of identity theft. And she literally, it was like a part-time job to have to keep explaining herself and explaining to uh you know potential creditors every time she wanted to buy a car or had refinanced her house or applied for a credit card, there was somebody else that had ruined her credit, and and it was like a part-time job for her to undo the damage. So, what I'd like to do is just help our listeners understand a little bit about not only what could happen in a dental practice, but I'd like Amy to share with us what everyone should know about what we give away on social media without even knowing it.
SPEAKER_00Oh, social media. Um, it's a necessary evil for businesses, right? Uh I I am myself considered an elder millennial. So of course I am myself on social media on various platforms. But I do notice a lot of people giving away too many pieces of information, especially in things like Facebook quizzes or sharing of children's birth dates or anniversary dates, and then not closing down their profiles, not locking them down. Just remember that nothing is secure out of the box. Everything you have, whether it's an online login or social media or, you know, even your Netflix account, everything is not secure out of the box. But almost every single one of these online platforms has the ability to lock them down. But I think the Facebook quizzes are probably my favorite because people will share it's National Sons Week, give all this information about my kid. And, you know, what's my favorite color? And all of those are your password prompts when you forget your password. So, you know, I really encourage people to stop taking the quizzes. I know you're bored and you're just trying to pass the time and check out because life is stressful, especially these days. Uh, but do not take those because those are scraped and absolutely sold and uh on the dark web and files are being created on you. This is not a conspiracy theory. I know it sounds that way. Um, and and I love a good conspiracy theory, but um no, this is the reality. This is what the FBI is seeing. And because Debbie and I are both involved in in uh FBI groups and government groups, we're seeing this a lot more, especially with children.
SPEAKER_02Debbie, you wanted to add to that.
SPEAKER_05I did. There is a whole science called OSINT, which is open source intelligence. And it's what threat actors do, and we're starting to see more and more of this happening with dentists and with advertising, because we put the staff, we put the our our dentist and me and our staff on our website. Well, then a threat actor can go out and he can use all of the open source information. If you really want to get scared, Google yourself and see the amount of information. Google your name, it's amazing. And it's a full-time job to scrub yourself and it can be very costly. So it's out there, it's what it is, but they're using that information again. Our major vector is through email. So I get the information and then I can send you an email. I know from your Facebook, from your Instagram, from your Snapchat, whatever, that you like fishing. I'm going to send you an email about check out this rotten reel. We're giving it away. And the doctor opens it. The rest is history.
SPEAKER_02There's certainly a lot to be uh concerned about and to be aware about. And so I'm going to take us back into the dental practice. And uh, Debbie, uh, you've had some experience with some very expensive ransomware attacks uh for clients that you, without giving any names, can you tell us just a little bit about the cost that what these clients were at first asked to pay and what they ended up paying?
SPEAKER_05Well, let's see here. Um, if it's just a there's been several large where multiple offices were attacked and those ransomware payments were in the millions. We have to remember that Bitcoin right now is right around like $60,000. So even one Bitcoin can be expensive. But the usual is when they when the threat actor figures out that they're in a small entity, they will ask for anywhere from one to three Bitcoin. And that can be very expensive, but then you have the forensic team. Your forensic team is right around $50,000. And then you have your lawyers that you need to have. And then because data is being exfrated, you have to notify all of your patients. And then you have to, in some states, you're required to provide credit monitoring. The uh people don't realize that it's not just the federal government that you have to report to. All 50 states have some laws to protect their citizens. So now you have to report to the state. And it in some of the cases, it's the state where the person lived at the time. I had one breach where it was uh the we wound up reporting to five states. And so it can become very, very costly.
SPEAKER_02Oh my goodness. You know, we could continue talking about this all night long. It's it's scary, but it's intriguing. Um, I think the bottom line is that uh HIPAA isn't just a form that you give to your patient that says you're going to protect their privacy. There are a lot of steps behind that. And then there's technical steps that most dental team members and dentists, quite frankly, don't quite understand. So it's great to bring in the experts and to have experienced dental IT personnel and understand what the risks are and how to manage a cyber attack to know exactly what to do so that you can um have a forensic investigation and keep those bad actors from violating not only your patients, but the reputation of your practice. And uh, Debbie, before we close, uh I'd just like to one final question for you is uh if our listeners were interested in reaching you, could you please give us your contact information and then any resources that we could put on our website, just tell them what they can look for as far as checklists, and we'll be sure and post that on our website.
SPEAKER_05Yes, I'll be happy to. The thing is, don't be scared, be prepared. There it is avoidable, and so that's what you need to do is be proactive. You can reach me at infoddcar.com, and my telephone number is 844 DKCAR1.
SPEAKER_02And I think you provided us with a checklist that we can uh post on our compliance divas, but compliance diva's website so that our listeners could download some action steps that they might follow and give them a little bit better idea of a checklist against what they're doing and and whether they're measuring up to what would be considered security. I'd like to also ask Amy if you could tell us a little bit about how our our listeners could get a hold of you. And I think you said you had a white paper that our listeners could get. So could you please uh give us that information?
SPEAKER_00Sure. Uh I can be reached at uh HIPAA. You can spell it wrong if you want to. It still goes to me, but please try to spell it with two A's um hippA at copperpennyconsulting.com. And uh my white papers are available for download on things such as Internet of Things devices uh and cybersecurity checklist at copperpennyconsulting.com forward slash white papers.
SPEAKER_02Ladies, thank you very much, and thank you, divas, for all the wonderful questions. Uh we would like to close this program by reminding everyone that we at the compliance divas bring clarity and simplicity to compliance by navigating the regulatory environment to keep you on course. Please submit your questions to support at thecompliancedivas.com. If they are questions for either Amy or Debbie, we will forward them to the two experts and ask them to provide the answers so that everyone can see what those answers are on our website. And again, check for the resources so that you can stay on top of HIPAA compliance, protect yourself, protect your practice, uh, pick protect your patients. It's a win-win-win all the way around. Thanks everyone for a wonderful podcast.