search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
White text reading 'Auditor Tips' on a dark geometric background with a small blue underline.
Auditor Tips: Healthcare Security And Best Practices
HIPAA Audit

Healthcare security gaps often stem from communication issues. It’s common to see executives and practice leads who aren’t listening to their staff about their current state of compliance and security.

White text reading Auditor Tips on a dark geometric patterned background with a small blue line below.
Auditor Tips: Penetration Testing Best Practices
Penetration Testing

A penetration test will give you a holistic view of what your security system truly looks like. Organizations with poor security practices across their environment leave themselves vulnerable.

White bold text reading 'Auditor Tips' on a dark geometric background with a blue underline.
Auditor Tips: Minimum Necessary Best Practices
HIPAA Audit

The minimum necessary requirement is a key part of the HIPAA Privacy Rule. The goal of this requirement isn’t to encourage organizations to perform the minimum necessary, but rather for organizations to only use and disclose the minimum amount of PHI necessary

White text reading 'Auditor Tips' on a dark geometric patterned background.
Auditor Tips: Regularly Conduct Vulnerability Scans
HIPAA Audit

Regular vulnerability scans are a critical preventative security control as they detect and assess known weaknesses that may be opening up your systems, applications and networks to undue risk of intrusion. Vulnerability scanning is not penetration testing.

White text reading 'Auditor Tips' on a dark textured background with a small blue line underneath.
Auditor Tips: Set Up Your Intrusion Detection/Prevention System
HIPAA Audit

You need a team to choose and manage an IDS/IPS. Whether it’s the responsibility of your IT Security Team,Data Loss Prevention Team, a managed service provider, or a designated co-managed team consisting of security-related department heads.

White text reading Auditor Tips on a dark textured background with a small blue line below the text.
Auditor Tips: Unique ID, Passwords, and Passphrases
HIPAA Audit

More recently, password length, in the form of longer, memorable word strings have proven to be a more important security practice than the use of shorter complex passwords.

White text reading Auditor Tips on a dark textured background with a blue underline.
Auditor Tips: Audit Logs and Log Monitoring
HIPAA Audit

Monitoring audit logs for all critical systems and devices in your environment is key to understanding what types of events and actions occur on a daily basis, allowing you to establish a baseline of what is considered normal system activity.

White text 'Auditor Tips' on a dark geometric background with a small blue underline.
Auditor Tips: Secure Remote Access
HIPAA Audit

Remote access to tools and data is essential to employees who work from home or are unable to go into the office for health or other logistical reasons.

Text reading Auditor Tips in white on a dark textured background.
Auditor Tips: Firewall Best Practices
HIPAA

Healthcare organizations of all sizes use firewalls to protect the perimeter of their sensitive networks. Here are some firewall best practices to get you started.

White text reading 'Auditor Tips' on a dark geometric background with a small blue underline.
Auditor Tips: System Configuration
HIPAA Audit

Whenever a system is configured make sure you know exactly what is running and also what is necessary to allow the system to perform its intended function.

White text 'Auditor Tips' on dark geometric background with a small blue underline.
Auditor Tips: Permanently Delete Files
HIPAA Audit

Most people know how to destroy physical sensitive data, but when it comes to securely destroying electronic data, most healthcare professionals don’t know where to begin.

White text 'Auditor Tips' on dark background with a small blue underline below the text.
Auditor Tips: Implement Encryption
HIPAA Audit

You should implement encryption to protect PHI any time it is stored.

White bold text reading 'Auditor Tips' on a dark patterned background with a blue underline.
Auditor Tips: Practicing Good Cyber Hygiene
HIPAA Audit

While every organization is different, the end goal of practicing good cyber hygiene is to identify vulnerabilities, minimize risk exposure, and reduce the potential for a breach.

White text reading 'Auditor Tips' on a dark geometric background with a small blue underline.
Auditor Tips: Know Your PHI’s Lifecycle
HIPAA Audit

Fully understanding all the PHI you have, where it is stored, what processes touch it, and how it is used in your organization is critical to enabling a business to properly handle and secure PHI.

White text 'Auditor Tips' on a dark geometric patterned background with a small blue underline.
Auditor Tips: Conduct an Accurate and Thorough Risk Analysis
HIPAA Audit

Yet a complete and thorough risk analysis is one of the best ways for you and your organization to make intelligent and informed business decisions

3D blue outlined text saying PCI 4.0 with layered line design on a light gray background.
What’s New with the SAQ A-EP
HIPAA Audit

The SAQ A-EP PCI assessment is for merchants who have an e-commerce card data flow that is not entirely outsourced to a PCI validated third-party service provider.

SecurityMetrics guide titled HIPAA Compliance for healthcare entities and business associates.
The SecurityMetrics HIPAA Guide Simplifies HIPAA Guidelines
HIPAA Audit

HIPAA laws and cybersecurity are not simple. The 2023 HIPAA Guide breaks down HIPAA guidelines into actionable steps and easy-to-understand information so that your healthcare staff can be fully educated on data privacy and protection.

Man in business attire relaxing on a deck chair holding a drink, with briefcase and towel nearby.
How to Start a Career in Cybersecurity
Data Security

If you have a knack for solving problems, good organizational skills, and attention to detail, cybersecurity might be a good fit for you.

'Make security training fun!' on a blue background.
Five Ways to Make Security Training Memorable
Training

One of the easiest ways to make cybersecurity training more interesting is by making it fun. Here are five tips for making workforce security training fun and memorable.

Blue outlines of six smartphones on gray background with a lock icon centered on the middle phone.
How Can You Tell if an App is Secure?
Data Security

This blog explains how to do a quick risk assessment on an app in the app store or one that you’ve downloaded on your phone to determine if an app is secure.

3D blue number 40 casting a shadow on a light background.
Performing an SAQ P2PE version 4.0 Self-Assessment
PCI Trends

This blog will discuss changes made to the SAQ P2PE version 4.0 and will review the process of performing a self-assessment using the SAQ P2PE.

Side-by-side illustrations of a blue-striped zebra on white and a white horse on a blue background.
SecurityMetrics vs. Other PCI Program Providers
PCI Partner

What should you look for in a PCI program and how will you know which PCI program is right for you?

White geometric outline forming abstract shapes over a dark cityscape with tall buildings.
Firewalls 101 - What is a Firewall?
Data Security

Firewalls 101 - What is a Firewall? Tune in this week as Noah Pack and Kaden Payne give you the basics on all things firewalls .

White geometric abstract logo overlay on a black-and-white cityscape of tall buildings.
Best Sites to Learn Cybersecurity
Data Security

The vast field of Cybersecurity can be very intimidating for a newcomer. Tune in this week as Noah Pack gives the best sites to learn cybersecurity and tools to get you building your skills in infosec.