Free HHS 405(d) resources to get you started!
Read the No Excuses article
Download the presentation slides
Kick-off your 1 hour/week plan
Links to MORE FREE HHS 405(d) resources for small practices
Links discussed during the live presentation:
HHS 405(d) Aligning Health Care Industry Security Approaches
Technical Volume 1: Cybersecurity Practices for Small Health Care Organizations (2023 Edition)
Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients (HICP)
Health Industry Cybersecurity Practices (HICP) Quick Start Guide - Small Healthcare Organization (2023 edition coming soon)
10 Practices to Protect Your Organization from Cyber Threats
See more links in the 1 hour/week plan below!
Kick-off your 1 hour/week plan:
Week 1
Formally identify one internal practice member as the primary IT/Security contact for your practice (ITSPOC)
Assign Main Document and Tech Vol 1 to your ITSPOC
Week 2
Review Email Phishing slides (slides 15-20)
Discuss then hang the Email Phishing poster in a conspicuous staff space like maybe the break room. We know it says HOSPITAL on it but the messaging is consistent for Solo Provider and Small Group Physician Practices.
Week 3
Review Ransomware slides (slides 15-21)
Discuss then hang the Ransomware poster in a conspicuous staff space like maybe the break room.
PAHCOM members are also invited to visit the videos page for Endpoint Protection Systems
Week 4
Discuss then hang the Loss or Theft of Equipment or Data poster in a conspicuous staff space like maybe the break room.
Do you like the weekly tips for how to eat this elephant? Please send us your feedback!
Links to MORE FREE HHS 405(d) resources for small practices:
HICP's 10 Mitigating Practices
Awareness Posters - You may not be the person implementing these practices, but you do need to know how to communicate your needs to vendors AND understand whether they have delivered on point!
The 405(d) Post
For healthcare practitioners: Healthcare practitioners are essential in the defense and fight against cybersecurity threats. Tools and resources are available for smaller sized practitioners that may not have the manpower of a large organization.
For small healthcare organizations: If you are considered a small organization, typically you have a smaller budget for cybersecurity mitigation as well as a smaller staff overall dedicated to cybersecurity. The 405(d) Program offers resources made just for you like the quick start guides and recommends sharing information with your security officer or provider. Check out the many resources that fit your organization!
231230