HHS Signals Continued Focus on Health Plan Privacy and Cybersecurity
Privacy and security are enforcement priorities for government regulators following HHS's restructuring of its Office for Civil Rights.
Questions about your benefits? Contact your HR administrator.
Guidance on security administration and compliance — practical resources for employers, brokers, and benefits teams navigating real operational questions.
Privacy and security are enforcement priorities for government regulators following HHS's restructuring of its Office for Civil Rights.
Federal regulators continue to emphasize that an effective security program requires more than documenting vulnerabilities.
Identifying security vulnerabilities is only the first step — organizations must implement remediation plans and maintain documentation that safeguards are actively in place.
HHS confirms that HIPAA compliance is not a one-time exercise, but an ongoing process that requires organizations to continuously assess, manage, and reduce security risks.
Email is one of the most common ways sensitive employee information is unintentionally exposed.
Cybercriminals continue to target employees and former employees using fake benefits communications designed to steal personal information.
In HR and benefits administration, employees and administrators handle sensitive information every day.
Protecting employee and benefits data requires more than a strong password — MyEnroll360 incorporates Multi-Factor Authentication as a core layer of platform security.
Cybercriminal phishing attempts are getting more sophisticated, now reaching HR teams via text messages, voicemails, QR codes, and fake benefit notices.
Tax season increases phishing attempts targeting W-2 and payroll data making awareness and verification especially important for HR teams.
Sharing files internally is routine, but small missteps can expose sensitive information.
HR plays an important role in setting expectations, reinforcing reporting procedures, and creating a culture where employees feel comfortable raising concerns quickly.
As HR professionals continue to rely on digital tools for payroll, benefits, onboarding and employee communication, cybercriminals are adapting their tactics just as quickly.
Timely access termination is one of the strongest safeguards against unauthorized activity and data breaches.
MyEnroll360 introduces enhanced password-security tools and a refreshed, modernized user-settings interface, supporting stronger account protection and a seamless user experience.
Phishing scams have become increasingly sophisticated, and benefits-related fraud is on the rise.
As remote and hybrid work models continue to shape the modern workplace, HR professionals face unique challenges in protecting sensitive employee data outside of traditional...
HR and benefits professionals are increasingly becoming prime targets of phishing scams.
The IRS and its Security Summit partners recently concluded their annual five-week campaign, Protect Your Clients; Protect Yourself .
If not handled properly, benefits information can expose both employees and the company to data breaches and compliance issues.
There is an updated version of the HHS Security Risk Assessment Tool which helps organizations evaluate and manage risks to PHI.
Employers must collect Social Security Numbers for everyone with health coverage.
There is a growing threat of phishing scams designed to steal sensitive information.
HR departments handle sensitive information that makes them a natural target for cybercriminals.
HR departments across the country are finding themselves in cybercriminals' crosshairs, and the reason is simple: you hold the keys to your organization's most valuable...
One of the simplest and most effective ways employees can help safeguard company systems and personal information is by enabling multi-factor authentication.
Whether you are a tax firm or an employer collecting personal data through benefits enrollment or payroll, a WISP should be part of your compliance and risk management toolkit.
Protecting employee benefit data requires a combination of strong systems, clear policies, and ongoing training.
As the workplace continues to evolve, so do the security risks facing organizations of all sizes.
Employees accessing company systems from personal devices raises data security, privacy and compliance risks.
Employers must collect Social Security Numbers for both employees and covered dependents.
Internal threats, whether intentional or accidental, pose a significant risk to the security of sensitive HR information.
HR can encourage employees to make good choices about website cookie selections because not every cookie is a treat.
In today’s digital workplace, strong password practices are more than an IT issue; they're a shared responsibility that protects employee data, business operations, and...
Employees should have clear, accessible guidance for recognizing and responding to cyber attacks.
Creating an environment in which employees feel empowered to report potential security issues can prevent minor concerns from escalating into major events.
Some of the most significant security vulnerabilities come from within the organization.
While many businesses focus on external cyber threats, insider threats—risks that come from employees, contractors, or other trusted individuals—can be just as damaging.
Employer awareness and caution are the best defenses against social engineering scams.
Consider educating your workforce about phishing and how to avoid falling victim to scams.
As cyber threats continue to evolve, ensuring your business’s digital security is more important than ever.
The U.S. Department of Health and Human Services released a Strategic Plan for the use of AI in health, human services, and public health.
The IRS and its Security Summit partners recently concluded the ninth annual National Tax Security Awareness Week, an initiative designed to help individuals, businesses, and...
The start of a new calendar year presents an opportunity for HR departments to reset, refocus, and ensure compliance with key deadlines.
Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced proposed changes to the HIPAA Security Rule, marking the first update since 2013.
Understanding social engineering threats is important for keeping company data safe.
During the ninth annual National Tax Security Awareness Week, the IRS and its Security Summit partners identified important steps to reduce the risk of tax scams and identity...
First introduced in 2014 and recently updated in 2023, the SRA Tool is a free, downloadable desktop application designed to assist organizations in conducting comprehensive...
An online holiday-themed security game provides free, hands-on cybersecurity practice.
Organizations are increasingly facing cybersecurity threats where attackers use social engineering tactics to bypass security controls.
The State of New York has issued new guidance addressing the impact of artificial intelligence (AI) on cybersecurity, aimed at entities regulated by the Department of...
Maintaining company cybersecurity practices is just as important outside the office as it is in the office.
Health plans and employers should review their HIPAA compliance procedures regularly.
As remote work continues, ensuring employee privacy remains a significant concern.
Requiring employees to use a password manager is a simple yet powerful step toward safeguarding company data and improving security.
HR professionals play a key role in maintaining workplace cybersecurity by educating employees about the risks of phishing and the importance of staying vigilant when it comes to
The government released confirmation that its cybersecurity guidance applies to health plans.
CISA has a list of free cybersecurity services and tools available from government and industry partners.
As cyber threats increase, ensuring physical security measures are in place is just as important as protecting against digital breaches.
Benefit Allocation Systems prioritizes data security through its annual privacy and security refresher training for employees.
In today's digital age, phishing emails have become a pervasive threat to organizations worldwide, putting sensitive data and company security at risk.
with Our Affordable and Accurate Solution One of the key administrative aspects of the Affordable Care Act (ACA) that HR professionals must navigate is the requirement to...
The Department of Health and Human Services (HHS) reached a settlement over potential HIPAA Security Rule violations following a ransomware attack on a healthcare provider...
Safeguarding health information is not just a best practice—it is a requirement under the Health Insurance Portability and Accountability Act (HIPAA).
In today’s digital-first environment, safeguarding sensitive company and personal information is top of mind.
In today’s digital age, Human Resources (HR) departments hold an important responsibility in safeguarding employee information.
Department of Health and Human Services’ Office for Civil Rights (OCR) recently updated its FAQs on their webpage regarding the cybersecurity incident at Change Healthcare, a...
The HIPAA Breach Notification Rule requirements have been updated and now require certain entities to notify individuals, the FTC, and sometimes the media about breaches of
With the rise of data security incidents, businesses are encouraged to maintain a Written Information Security Plan.
The Internal Revenue Service (IRS) emphasizes the importance of safeguarding tax and financial information as part of disaster preparedness.
Department of Health and Human Services (HHS) recently revised its guidance on the use of online tracking technologies by Health Insurance Portability and Accountability Act...
CISA offers cybersecurity tools along with a database of free resources to help employers bolster their security posture.
The IRS has launched its annual Dirty Dozen campaign, urging taxpayers to beware evolving phishing and smishing scams targeting sensitive taxpayer information.
The Internal Revenue Service (IRS) has launched its annual Dirty Dozen list, cautioning taxpayers about evolving phishing and smishing scams aimed at stealing sensitive...
HR departments doing business with UnitedHealth Group (UHG) are probably aware of the cyber incident experienced by the company.
Department of Health & Human Services Office for Civil Rights (OCR) recently issued two reports to Congress on Health Insurance Portability and Accountability Act of 1996...
The Department of Health and Human Services (HHS) and the National Institute of Standards and Technology (NIST) released new guidance, SP 800-66 Revision 2, aimed at...
Employers should monitor security protocol for employees with access to personal data.
Covered entities experiencing a breach of unsecured protected health information must report the breach to the OCR.
In today's digital age, prioritizing security is paramount for HR professionals to safeguard sensitive employee data and protect against cyber threats.
As tax season approaches, HR professionals take the lead in ensuring their workforce is well-informed and prepared to counter potential online scams and identity theft risks.
In the ever-evolving landscape of cybersecurity, HR professionals play an important role in fostering a culture of vigilance among employees.
Human Resources data serves as the lifeblood of organizational operations and ensuring its security is non-negotiable.
In the digital age, where technology serves as the backbone of organizational operations, the significance of robust cybersecurity practices cannot be overstated.
HR departments should alert employees to the security risks of clicking on unsolicited PDF attachments.
Department of Health and Human Services' (HHS) Office for Civil Rights (OCR) reached a resolution agreement involving a phishing cyberattack.
In the age of technological advancements, QR codes have become ubiquitous in streamlining processes and enhancing user experiences.
A virtual private network (VPN) is important to protect against cyber intruders when working remotely.
Department of Health and Human Services (HHS) entered into a settlement agreement on October 31, 2023 with a Massachusetts-based medical management company.
Information was released to help organizations quickly and securely restore critical business functions after a cyber incident.
A comprehensive guide gives employers strategies to safeguard against ransomware attacks.
The Biden Administration issued a first-of-its-kind Executive Order addressing artificial intelligence (AI).
Keep your information protected with MyEnroll 360 In a collaborative effort, the Cybersecurity Infrastructure and Security Agency (CISA), the National Security Agency (NSA),...
As guardians of employees' well-being, employers know the critical importance of safeguarding healthcare data.
October is Cybersecurity Awareness Month. Learn how to get involved in protecting your digital world.
The U.S. Department of Health and Human Services updated its risk assessment tool to help with compliance.
HR professionals play a pivotal role in safeguarding their workplace against potential phishing cyberattacks.
As HR professionals, it's crucial to equip employees with the knowledge and tools to navigate the online world safely.
Learn how MyEnroll360 employs Multi-Factor Authentication (MFA) for enhanced security
Maintaining robust authentication processes is important for thwarting cyber attacks.
Safeguarding sensitive employee information, personal data, and confidential business records is crucial to protect against cyber threats.
BAS prioritizes data security through its annual privacy and security refresher training for employees.
The SEC's latest rules require cybersecurity transparency for publicly held companies and registered investment advisors.
Defend against sophisticated spear phishing attacks. Stay vigilant with awareness training & robust defenses. Safeguard your business now!
MyEnroll360's multifactor authentication system provides enhanced security for HR professionals and employees. Learn more about its benefits today!