Back
Latest
Healthcare Providers: 15 Million Reasons to Migrate off Windows 7

March 10, 2020

Healthcare Providers: 15 Million Reasons to Migrate off Windows 7

The average cost of a healthcare data breach in the United States is $15 million dollars. The United States experienced more than 40,000 security incidents and 2,000 documented data breaches in 2019 alone, more than 15% of which were in healthcare organizations. This amounted to more than 40,000,000 individuals being affected by healthcare breaches in 2019. These numbers are staggering and pale in comparison to the cost of maintaining your IT infrastructure in an effort to mitigate known risks.

While it is always important for the healthcare industry to be in compliance with the Health Insurance Portability and Accountability Act (“HIPAA”), now more than ever it is imperative that systems no longer run Windows 7.  HIPAA’s security provisions and data protections are among the most stringent technology regulations in the US, and the fines for HIPAA violations can be debilitating. Even in times of worldwide uncertainty, criminals do not stop seeking protected information from unsuspecting data handlers. Projects geared toward replacing Windows 7 should continue at all due haste.

As of January 14, 2020, Microsoft no longer offers support for the Windows 7 operating system, which means those systems no longer receive software updates, technical support, and—most importantly—security updates for known vulnerabilities. In order for healthcare organizations to protect sensitive patient data on their systems, they must upgrade legacy Windows 7 systems.

It is an extreme risk for healthcare organizations to continue running Windows 7 on their systems. The lack of security updates on these systems exposes the organization to vulnerabilities that could lead to security breaches. This is a risk that healthcare providers should not ignore, as fines for HIPAA violations can be as much as $1.5 million annually for HIPAA violations.

 A data breach is a security incident in which protected information (including protected health information) is accessed without authorization. Protected health information is anything that relates to the past, present, or future physical or mental health or condition of an individual. This includes name, date of birth, credit card numbers, social security numbers, address, any diagnosis information, health plan numbers, and even extends to identifiers such as IP addresses.

The world is currently undergoing a global pandemic that has healthcare providers scrambling to provide necessary care to affected individuals. These extreme circumstances do not mean criminals will offer a reprieve from seeking to steal data. Adding a data breach and corresponding incident response to an already strained organization could be detrimental to the lives of its patients it is so desperately seeking to protect.

Ask yourself this: can your organization afford to ignore the risk?

Follow Us

Related insights

Technology Entrepreneurs’ Conundrum: Build or Buy Legal Services?

August 9, 2019

There’s an old saying that business owners refuse to work a 40-hour-per-week job for someone else, so instead they work […]
View

GDPR Compliance: Far More than IT Security Controls

April 16, 2018

The European Union (EU) General Data Protection Regulation (GDPR) goes into effect May 25, and many organizations remain woefully unprepared […]
View

What Businesses Need to Know about the FCC’s TCPA Ruling, Part 2

August 18, 2015

In the previous post, we began to lay out the highlights of the Federal Communications Commission’s recent Declaratory Ruling about […]
View
Let’s protect your business. Schedule a consultation to get started.

Let’s protect your business. Schedule a consultation to get started.

"*" indicates required fields

Name*
This field is for validation purposes and should be left unchanged.

What to expect:

  1. Use the form to schedule a consultation.
  2. You’ll talk with a real attorney about your business and needs and how we can help. Then, you’ll get an initial estimate.
  3. If you like what you hear, you’ll get an engagement letter and pay the deposit.
  4. We’ll get started protecting your business.
Let’s protect your business. Schedule a consultation to get started.

Let’s protect your business. Schedule a consultation to get started.

"*" indicates required fields

Name*
This field is for validation purposes and should be left unchanged.

What to expect:

  1. Use the form to schedule a consultation.
  2. You’ll talk with a real attorney about your business and needs and how we can help. Then, you’ll get an initial estimate.
  3. If you like what you hear, you’ll get an engagement letter and pay the deposit.
  4. We’ll get started protecting your business.