It didn’t take long. The scammers have adapted their phishing and spear-phishing tactics to exploit the global corona virus pandemic. According to the Wall Street Journal, here’s what to watch for: Email doctored to look like a company’s purchase order for face masks or other supplies could trick an employee into wiring payments to a …
Read More “Phishing for CoVID-19”
I recently visited a doctor that I hadn’t seen in a while. And so, of course, was asked to fill out a whole new set of patient paperwork. The office understood that HIPAA requires a patient’s annual consents as far as who (besides the patient) can have access to the patient’s medical records. What the …
Read More “Open Up and Say “Ahhh yi yi””
The January 20, 2020, issue of the New Yorker magazine has a cartoon that hits the nail on the head: Information security doesn’t have to be difficult or complicated. In fact, if there’s too much difficulty and too much complexity, it actually increases the likelihood that your environment will end up being less secure. Why? …
Read More “Insecurity”
A key aspect of the alphabet soup of data protection laws is vendor risk management. You should be aghast to learn that your vendor was storing all of your customers’ data on a billboard… or in a completely unsecured database. It’s like learning the babysitter left your kids at the house and went out on …
Read More “Data, Left Alone and Unsupervised”
Seemingly every day, there’s new of another data breach. Small to mid-sized businesses are being actively targeted by bad actors. Thinking that you and your company are too small for a coordinated attack is exactly the kind of complacency that hackers rely upon. To force us to help ourselves, federal and state governments have been …
Read More “HIPAA, GDPR, CCPA, and the Alphabet Soup of Data”