One of my 3rd party partners has been hacked, now what?

More and more, we are vulnerable not through our own network but through other software companies. Whether you are aware of this or not, when you sign up for an AI service, more often than not you have shared your entire patient database with them, and they are now as responsible in the care of your patient data as you are. As AI companies proliferate, think carefully about the risk versus reward.

The biggest question you need to ask yourself before signing up for any new software or service is, “How is this helping my company and is it worth the risk and fees associated?”. You need a clear plan on how this software will help your practice and how you will be implementing this plan. Having a plan is the first step in a successful implementation, including gaining buy-in from your staff. They will ultimately be responsible for learning and using the software or service so working with them to gain buy-in early in the process will help everyone out.

While you are putting this plan together, ask the company a few questions before getting started:

  • What onboarding training will we be getting at the start of the implementation?

  • What training is available to us as we continue to use the product and you introduce more features?

  • What support is in place for us for issues we have with both the product and use of the product?

  • What is your security plan and documentation you have in place for your own company and for the data that we will be sharing with you?

  • Will you sign a BAA?

Starting with these questions will help to identify if this is a mature company and what they have in place once they have your signature and money. More than that, it will clarify how they see you and handle your data. 

As a full service company I handle this part of the process for any new software that my customers are looking to implement. More often than not, I can tell how smoothly the onboarding process will go by the answers to these questions and can help my customer find alternative solutions if it seems like a company has not thought through the cyber security issues.

So what happens if your partner does end up getting hacked? If you had followed the process above, then you know what processes they have implemented and how they are handling their end of the data. You have done your due diligence and if there is a problem, you know they (or your insurance company) will handle the financial fall out, and you will get help if your clients are directly affected. If this is all catching you by surprise, then now is the time to get these things in place. There are few immediate steps to reduce your own vulnerability.

  • Change all passwords associated with the breach and any places you had reused that password.

  • Evaluate what access they had to your data to be knowledgeable about what might be at risk.

  • Reach out to the company to confirm the breach and get any available information

  • Verify you have a BAA with the company.


One of the other items is to speak with your insurance company but that is dependent on what you are sharing with the company and what type of insurance you have. There are a lot of insurance companies that want to know immediately and can help you through the whole process. There are others that just need to know if data was compromised.

Above all, having a partner there to help you through the process and navigate these trying times is imperative! Make sure you have a trusted Cybersecurity company helping you keep your business on track. Give us a call and see how we can help clarify the risk vs reward before it turns into something that can change your life…for good or not!

Next
Next

What is next for AI?