- Failure to conduct Risk Assessment
- Incomplete or improper documentation
- Phished, hacked, breached email due to human error
- Human errors due to missing updated training or phishing attacks
- Assumptions that compliance is covered by IT company along with Business Disaster Business Continuity planning
Results to Avoid
- Civil lawsuits
- Federal fines
- HIPAA
- OSHA
- US Attorney General
- State Attorney General fines
- Individual states have unique rules
- Closing of office due to expenses associated with a breach
- Small Business Association – 60% close within 6 months of a breach
- Loss of Patients due to lack of confidence
- Over 30% of patients leave after a breach
- Investigation disruptions to the office and equipment
- Local police
- State police
- FBI
- HHS/OCR
- Secret Service
- Insurance