HIPAA Security Rule Compliance Improves Defenses Against Social Engineering

Malicious actors often use social engineering in their attacks on individuals to trick them into installing malware or disclosing sensitive information. In cybersecurity terms, social engineering is the use of deception to convince an individual to take an action they would not normally take, and it has proven to be highly effective in healthcare cyberattacks and has been the root cause of many large healthcare data breaches.

In its October 2024 cybersecurity newsletter, the HHS’ Office for Civil Rights explains some of the most common types of social engineering and how HIPAA Security Rule compliance helps HIPAA-regulated entities prevent and mitigate social engineering threats. Social engineering can take many forms including phishing, smishing, baiting, and deepfakes, and malicious actors target individuals via email, SMS, social media networks, and over the telephone and Internet. Phishing is the most common type of social engineering threat and involves tricking individuals into disclosing sensitive information electronically. An attacker usually impersonates a trusted individual, organization, or institution and uses social engineering to convince an individual to take an action such as clicking a link in the email or opening an email attachment. The link directs the individual to a spoofed website where they are asked to disclose sensitive information such as their credentials and attachments are often used to install malware.

Smishing is a form of phishing that uses Short Message Service (SMS) messages for initial contact. Links are often sent via SMS that direct the user to a malicious website where malware is downloaded, or they are asked to disclose sensitive information. The malicious messages may include a phone number to call, for instance, to receive important security advice; however, the line is manned by malicious actors.

Baiting is a type of social engineering where individuals are enticed into taking an action they would not normally take, often by offering something of value. This could be a notification that an individual is eligible for a prize or a too-good-to-be-true offer. Hackers have been known to leave portable storage devices in lobbies and parking lots, as they know there is a good likelihood that someone will pick up the device and plug it into their computer. Doing so will see malicious software automatically transferred to the user’s device.

Deepfakes are a growing concern. Deepfakes are videos, photos, or audio that have been manipulated using artificial intelligence to depict someone saying or doing something that they never said or did. As with other forms of social engineering, they trick people into taking certain actions but these threats can be even more convincing. For example, a recent deepfake of Elon Musk was used in a cryptocurrency scam to trick people into investing to double their cryptocurrency. Deepfakes have also been used to impersonate authority figures in video conferencing calls, tricking employees into thinking they are communicating with their CEO or another executive.

According to the 2024 Verizon Data Breach Investigations Report, 68% of breaches in the past year involved attacks on humans rather than attacks on technology. As OCR explains, while it is important to implement technical defenses to protect against unauthorized attempts to access healthcare networks, HIPAA-regulated entities need to also improve human defenses by providing security awareness training to the workforce. Informing members of the workforce about social engineering and new social engineering threats should be incorporated into the HIPAA Security Rule obligation to implement a security awareness and training program. OCR also suggests using phishing simulations as part of the HIPAA Security Rule requirement to issue security reminders, as these can reinforce training and test knowledge of how to identify phishing emails.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

“Educating workforce members on these attacks is essential when it comes to an individual’s ability to identify and potentially halt social engineering attacks before they start,” explained OCR. “Such knowledge is powerful not only to protect individuals in their personal online activities, but also by extension an individual’s employer. This is especially important in the current environment where work is taken home on laptops, smartphones, and through remote work.”

OCR also reminds HIPAA-regulated entities of their obligation to conduct a comprehensive risk analysis and to implement technical defenses against social engineering such as anti-phishing technologies. These include spam filters that verify that emails have not been sent from malicious IPs and include machine learning and behavioral analysis to detect potential threats.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/