ABYDE FOR PATIENT READY DENTAL IT USERS

It's time for stress-free compliance.

  • EASIEST SOFTWARE YOU’LL EVER USE

    And if we’re being honest, easy is an understatement. All companies say it, but we are so confident in the simplicity of our software that we will prove it.

  • ‘HANDS OFF’ APPROACH

    We automate it all – from notifications about training to policy generation. Can you imagine not having to set your own reminders?! Go ahead, focus on your patients – we will ping you with the important stuff.

  • CUSTOMER SUCCESS TEAM LIKE NO OTHER

    We will meet you where you are – whether that’s by phone, chat, or email. It’s tough stuff in the tech space, but our customers love us as much as we love them.

  • STATE BY STATE, LAW BY LAW

    No matter what state your practice is in, our solution is for you — from sea to shining sea. We know our stuff and dedicate ourselves to staying on top of the latest state and federal changes so you don’t have to.

  • MORE THAN JUST SOFTWARE

    With us, you get more than policies and software. We offer Master Classes, newsletters, and more to keep you up to date. At the end of the day, we are proud to lead with education.

LATEST COMPLIANCE NEWS

Ransomware Data Breach in Healthcare

Ransomware Strikes Again: What the Latest HIPAA Fine Teaches Us

July 28, 2025   Healthcare’s cybercrime nightmare just got more expensive. With over half a million dollars in fines and the second HIPAA ransomware fine issued this month alone, it’s time to acknowledge the serious threat cybercrimes pose to healthcare.  The Office for Civil Rights (OCR)  just announced its latest HIPAA fine, following a ransomware attack affecting a surgery center in New York, totalling $250,000 and placing the practice under a two-year Corrective Action Plan (CAP). The two-year period includes constant government monitoring, ensuring the healthcare provider has taken action to mitigate risks and secure Protected Health Information (PHI).  Here’s where things get interesting. Upon further inspection, the exact ransomware variant, PYSA, explicitly targets the healthcare industry. Think about it: cybercriminals know the absolute treasure trove of sensitive patient data a healthcare organization holds.  As malicious actors know the importance of patient health records, your practice must be extra vigilant when handling PHI.    What Happened? In March 2021, an unauthorized actor gained access to the networks of Specialty Surgery Center of Central New York (also known as Syracuse ASC, LLC). The hacker deployed ransomware in the organization’s networks for over two weeks. This ransomware exposed nearly 25,000 patient records, with access to Social Security numbers, addresses, health histories, and more.  Syracuse ASC, LLC, notified the OCR of this breach in October 2021, over six months after the initial intrusion. This wait violated the HIPAA Breach Notification Rule. Given the massive breach, the healthcare provider had to notify the OCR, patients, media, and potentially the State Attorney General within 60 days of discovery. Notifying these parties allows patients to take control and explore options for protecting and monitoring their data post-breach. Additionally, it could have expedited the OCR and State officials’ investigations into the extent of the ransomware attack. During the investigation process, the OCR made another startling discovery: no Security Risk Analysis (SRA) was in place.  A thorough SRA is required to maintain your practice’s security. By examining existing safeguards, you can identify and address vulnerabilities proactively before they cause problems. This practice learned the hard way about a common HIPAA pitfall: missing an SRA. Due to this, a hacker infiltrated and exploited the vulnerability of an insecure network, leading to a quarter-million-dollar fine.    Protecting Your Practice Against Ransomware Hackers have discovered a gold mine with medical records costing upwards of $1000 on the dark web, compared to the average credit card number fetching 25¢. When hackers directly target healthcare practices, your compliance program and safeguards must be in order.  Proactive compliance is key to the security of PHI. Your practice can mitigate and minimize ransomware threats by using the right compliance solutions and robust IT assistance. With the right software, it’s easy to streamline pillars of HIPAA compliance, like the SRA, identifying issues early to avoid risking your patients.  Meet with our team of experts to learn more about how you can simplify HIPAA compliance for your practice. 

Read More »
HIPAA Compliant Password Management

Strong Passwords, Secure Patients: Protecting PHI in Healthcare

July 23, 2025   While Password123 might be easy to remember, it might not be the best password.  In our current healthcare landscape, intertwined with technology, from EHR systems to patient communication, it’s time to upgrade password security. A strong password and other layers of protection are key to keeping your practice’s logins secure and, ultimately, patient Protected Health Information (PHI).  Thorough password management might be the deciding factor in stopping a major breach.  Just look at the Change Healthcare debacle. Billions of dollars lost, systems crashed, insurance claims in limbo, and over 100 million patients exposed. At the root of this? Missing multi-factor authentication (MFA).  After major breaches caused by poor password management, it’s time to prioritize your passwords and adhere to best practices.   Ditch the Default Password Let’s face it. It’s tempting to use passwords everywhere. However, it’s a password security red flag.  When it comes to passwords, we recommend at least eight characters with several unique characters, including a number, an uppercase letter, a lowercase letter, and a symbol.  This enhanced security makes unauthorized account access more challenging. Also, if one account is compromised, the breach can be more easily contained than if all logins shared the same password. On that note, ensure all staff have their own logins. This isn’t just about stopping password sharing; it’s about giving your practice the power to keep a close eye on who’s accessing Protected Health Information (PHI) and quickly spotting anything out of the ordinary.    When in Doubt, Change it Out  We also recommend changing passwords at least three times a year, keeping account access current, and making unauthorized users’ access more difficult.  Regular password changes help mitigate risk if an older password is exposed in a data breach, and make it harder for hackers to brute-force guess your password. They also ensure that anyone who has lost access to your accounts, such as offboarded staff, cannot continue to access systems.  By consistently making password changes a part of your security routine, you create a dynamic defense that significantly reduces the risk of unauthorized access.   Your Password’s Best Friend: Multi-factor Authentication On top of having a secure and current password, having MFA enabled on all your accounts is key to keeping PHI safe.  Just like peanut butter and jelly, passwords and MFA are a perfect pair. MFA is that crucial next step, providing an extra layer of security that makes a major difference in keeping your information safe. Common MFA examples include a text, a random code generated, or even through an automated call. That extra protection ensures that the person logging in is authorized and authenticated.  This extra level of protection ensures that when someone tries to log into your accounts, it’s truly you. It’s all about verifying and authenticating that the person accessing the account is authorized. With MFA enabled, a hacker won’t be able to log in without that unique code sent to your phone, an app, or even your email. This significantly increases the difficulty for unauthorized access, giving you peace of mind that your PHI remains secure.   Securing your Compliance Program  The sheer volume of tasks can make managing compliance feel like a full-time job, from multi-factor authentication to complex password policies and regular access reviews. While it’s easy to feel overwhelmed, your practice can streamline this with the right solution.  Smart software simplifies compliance for your practice by sending out compliance reminders, such as when it’s time to change your password, providing best tips and practices, and automating policies and procedures for your practice.  Meet with an expert today to see how you can streamline compliance for your practice. 

Read More »

READY TO BE STRESS-FREE?