Too Many Passwords to Remember? Use a Password Manager


Computer Security Tip of the Week

Scott Aurnou – Security experts will always tell you to use different, hard to break passwords for every website you log into, but it can be pretty hard to remember all of them. Password management software solves that problem for you. Here’s how…

Websites referenced in this video include:
Roboform Everywhere
Kaspersky Password Manager
DataVault
KeePass
LastPass

If you enjoyed this video, you can see more on TheSecurityAdvocate YouTube channel (and subscribe if you like).

Tagged with: , , , , , , , , , ,
Posted in Cloud Security, Laptops & Desktops, Network Security, Security Tip of the Week, Smartphones & Tablets

What is Endpoint Security?

Endpoint SecurityBy Scott Aurnou

Literally speaking, ‘endpoint security’ refers to protecting the various electronic devices that can connect to a computer network. Each device that can access a network creates a separate endpoint that has to be secured. This can include anything from cameras to printers or anything else connected to the network though, for most people, endpoint security means protecting laptops, smartphones and tablet computers against various electronic threats, as well as physical ones (like being stolen). In practice, this means trying to put in place an equal minimum level of protection for every device capable of accessing the network. To enforce this, a network may be configured to only allow access to devices that have certain specific security measures in place before connecting to the network and potentially accessing proprietary information and/or sensitive data. If an infected laptop, smartphone, tablet or portable storage – like a USB thumb drive – does connect to the network, it could upload malicious software (aka malware) or expose sensitive data from the network once it’s downloaded to the improperly secured phone, etc.

While this may sound like a relatively straightforward process, it’s often one of the weakest spots in any computer network. This is because of an increasingly common workplace concept referred to as Bring Your Own Device (aka BYOD). Employees, guests, consultants, students, doctors, co-counsel, family members, etc. frequently use their own laptops, phones and tablets and generally expect to be given access without the ‘hassle’ of having them checked first or downloading security software before exposing the network to whatever unfriendly software is lurking on their devices. An infected device can easily spread malware like a computer worm that, by design, will self-replicate, spread throughout a system and create openings additional malware like rootkits and Trojans (all things you would definitely rather not have on your network).
Read more ›

Tagged with: , , , , , , , , , , , , , , , , , , , , ,
Posted in Laptops & Desktops, Network Security, Smartphones & Tablets

How Can You Email Clients (or Patients) Securely?


Computer Security Tip of the Week

Scott Aurnou – Given the current climate of (understandable) suspicion over who can access email in transit and the client and patient privacy provisions of rules and laws like the American Bar Association’s Model Rules or HIPAA, what steps can you take to safeguard the emails you send? Here are a few suggestions…

Websites referenced in this video include:
Cubby

If you enjoyed this video, you can see more on TheSecurityAdvocate YouTube channel (and subscribe if you like).

Tagged with: , , , , , , , , ,
Posted in Privacy Issues, Security Tip of the Week

Changes to HIPAA Breach Notification Rule: What Providers Need to Know Now

By Catherine G. Patsos, Esq.

Changes to the Health Insurance Portability and Accountability Act (HIPAA) Rules are here,[i] and covered entities and business associates have until September 23, 2013 to comply with them. Many changes have been made to the Breach Notification Rule, as well as the Enforcement Rule, Notice of Privacy Practices and marketing requirements. One of the most significant changes for providers is that a business associate’s discovery of a breach is imputed to the covered entity, so that the covered entity is presumed to have knowledge of the breach at the time the business associate discovers it, regardless of when the business associate notifies the covered entity of the breach. These changes to the HIPAA rules require covered entities to take a closer look at their business associate agreements, and revise them to implement as many safeguards against liability as possible.
Stethoscope & ComputerModifications to the Breach Notification Rule

The definition of a breach has been modified to clarify that an unauthorized use or disclosure of protected health information (PHI) is presumed to be a breach unless the covered entity or business associate demonstrates through a risk assessment that there is a low probability that the protected health information has been compromised. This definition eliminates the previous harm standard (i.e. that the breach caused no significant risk of harm to the individual), and substitutes it with a low probability test. Breach notification is now required in all situations where there has been an unauthorized use or disclosure of PHI, except where the covered entity or business associate demonstrates through a risk assessment that there is a low probability that the PHI has been compromised, or another exception applies.
Read more ›

Tagged with: , , , , , , , , ,
Posted in Guest Posts

Is Your Router Secure? Be Sure Your Network Is Encrypted Properly


Computer Security Tip of the Week

Scott Aurnou – Your router is the piece of equipment that connects your computer to the Internet. If it’s not set up (aka ‘configured’) properly, it can leave you vulnerable to a number of different electronic attacks. These can include stealing your business, financial and personal data, as well as a few other nasty surprises…

Websites referenced in this video include:
Secure Your Wi-Fi Router (it’s What Connects You to the Internet)

If you enjoyed this video, you can see more on TheSecurityAdvocate YouTube channel (and subscribe if you like).

Tagged with: , , , , , , , , , , , ,
Posted in Network Security, Security Tip of the Week
Twitter: saurnou
TheSecurityAdvocate Youtube Channel