Southwest Networks - Managed IT Services & Cybersecurity

Breach Reporting Is The Law

Published June 25, 2026

About This Video

In this Episode I talk about the fact that you need to report any breach, but it's not that cut and dry on when plus some things you can do now to protect your medical practice. #SouthwestNetworksIncPalmDesert ➡ Download our Free IT Buyers Guide: https://www.southwest-networks.com/it-buyers-guide ➡ Interested in working with us, book a quick and easy call: https://www.southwest-networks.com/discoverycall Connect with us! https://www.southwest-networks.com https://www.facebook.com/southwestnetworks https://www.linkedin.com/company/southwest-networks-inc ⏰ Timecodes ⏰ 00:00 Introduction 00:18 Local Hospital was Breached 00:39 2 Months without being Reported 01:07 Would you know if an attacker was in your business? 01:37 What can you do to protect your practice

Full Transcript

Auto-generated from the video's captions. Minor transcription errors may exist.

Welcome back to another episode. This time we're talking about the breach reporting law as it relates to compliance. So, welcome back. This time we're talking about reporting a breach if it happens and that it is the law. So, a healthcare provider in San Bernardino and Riverside counties was hit by a cyber attack back in February of this year, but nobody found out about it until the end of April. So, that's that's 2 months. That's how long an attacker was inside the hospital systems having access to all that patient data and things like that. But, here's what most people don't realize. That's not unusual. The attackers nowadays, they move slow on purpose. They're trying to gather as much information as they can. They're trying not to set off alarms. They're trying to map the system and find out what's all there. By the time the breach announcement hits the news, the damage is been done. So, if you're running a healthcare practice, whether it's a medical office, dental practice, behavioral health, any kind of provider, the question that this raises is a simple one. Would you know if somebody was in your system right now and what to do? But, without active monitoring tools that your your IT provider can provide, um, MDR, managed SOC, the most businesses aren't going to find out cuz attackers aren't going to put up signs on your screen and say, "Hey, we're gathering all your patient data and we're we're stealing things and we're going to reach out to everybody and act like we're you and we're going to open up credit card accounts in your patients' names and tell them that it's because of you." It That's not what happens. So, what are some things that you can do to help prevent your practice from these types of attacks? Well, first things first, have a conversation with your IT provider. Not just a vague check-in, "Hey, how are things going?" but a real walk-through of what's going on. Talk to them about these types of attacks. Now, if your provider isn't having regular conversations with you, that's kind of a sign. Now, I don't mean that they're reaching out to you, but you're not responding. That's totally different, right? So, you want to do that. So, you want to have an incident response plan. If you have one, review it. That's where if things something like this were to happen to you, would your staff would you know what to do? Right? Go through that. Do a practice run to make sure everybody knows who to call, where to find the phone numbers, those kinds of things. Look at your cybersecurity awareness training. When was the last time everybody did it? How did everybody do on the quizzes? Was there any anything going on? So, you need to make sure you check these things so that this type of attack doesn't happen to you. So, the goal here is not fear. We want to make you aware of what's going on so that you can be better prepared to prevent it. I don't want to say that it's always going to happen no matter what you do, those types of things, but the odds are this is going to happen to you or someone you know, someone you do business with, and maybe even your doctor's office itself. So, be aware of these types of situations. It's not easy out there. We get it. We understand. That's why we here at Southwest Networks, we work with our clients so that they can understand some of these different security issues that may be present. Doing what any reasonable person would, protecting your business, is going to make you a harder target in the first place. Most attackers don't want to spend a lot of time. Right? Especially the small medical dental practices. They're not there to They're not going to wake up in the morning open the phone book and choose you over a big hospital. But, a lot of medical doctors have affiliations with the local hospitals. So, you do rotations, you're on staff, you're part of their boards. So, you're going to get caught up in those big attacks and it's going to spread down to your practice. So, that's where these things come into play. Don't ignore it when your IT provider comes to you saying, "Hey, there's these new types of attacks. We need to talk about this new security prevention system that we've got for you. Let's sit down and talk it through so that you understand. They're not just trying to sell you something. It is for your own good and and and what it's going to do to protect you from it, right? So, make sure you're understanding that. Walk through it. And again, the big question is and the one question that I ask all the time is when people say, "Hey, it's never happened to me. You know, no one's ever going to want to attack me." But, just like this kind of emphasized that it took this big hospital 2 months to figure it out that somebody was in the system, how would you know if somebody was inside your medical practice right now? How would you know that somebody was inside your billing system? How would you know if they're inside your EMR system? You wouldn't. Again, they're not putting up red flags. So, take the security stuff seriously. Unfortunately, it's a big business for them just like your practice is your business. So, if you have any questions or concerns, want to know more about what you should be looking at inside your medical practice, please reach out to us here at Southwest Networks 760-770-5200.

Ready to Protect Your Business?

Schedule a free consultation with our team. No obligation, no pressure — just a clear picture of where you stand.

Or take the free IT security assessment first — see exactly where you stand in minutes.