Saturday, January 22, 2011

What is YOUR Time Worth?

It seems like we go through phases when Clients or prospects begin asking whether they can do some of their own network support.  Of course this really starts coming up more often when the economy is in a poor condition.  We always try to get our Clients to take on some of the basic day to day support tasks.  For instance, why pay us to replace a mouse or keyboard.  In some cases, if the Client has a little more technical expertise we will help them take on higher level tasks.  However, when it comes to items they may affect the security or reliability of their network, we draw the line.

Most often these requests are based on perceived costs.  “If I do the task myself I don’t have to pay you and therefore I save money.”  In the case of lower level tasks that may be true.  However, in higher level tasks it may not only be untrue but can also be disastrous.

First, let’s think about pure cost.  Over the years I have had doctors, lawyers, business owners and other high level people attempt to do their own network support.  Let’s say that an IT Pro charges $100.00 per hour.  A problem occurs on the network.  The doctor, lawyer, business owner does his/her own troubleshooting and tries to resolve the issue his or herself.  Let’s even say they get things going.  Perhaps it took several hours, maybe a day, maybe more.  So we saved the cost of the IT person, right?  Probably not.  Consider this.  How much is the value of that doctor’s, lawyer’s, etc time?  In most cases, the value of that persons time far exceeds the $100.00 that the IT Pro would have charged.  Beyond that, how much faster would the IT Pro have solved the problem?  If we just estimate half the time, how much is that in downtime cost to the organization?  Do you know how much it costs your organization for every hour of downtime?

Another perhaps even more serious consideration is even if the network is up and running again, what might you have missed?  Perhaps the hard drive is failing and simply turning the server off and on cleared the immediate problem.  Everyone goes back to work and after a few minutes, hours, days, or weeks it goes down again.  This time this system will not come up and after more time is spent trying to fix the problem you call in an IT Pro.  What he or she finds is that not only is the hard drive now completely dead, the backup has not been running since the original issue.  What is the cost of all that lost work?

While it is true that Clients have the capability to fix simple IT related problems, in most cases the perceived cost savings by trying to handle more involved IT issues is simply not there.  And in some cases the results can be disastrous.

Monday, November 15, 2010

EPHI Information Breach Concerns

As most of our health care Clients are probably already aware, a VNA here in Connecticut was in the news recently and it wasn’t good news.  A nurse’s laptop was stolen from her car.  The laptop contained information on around 12,000 patients. 

Almost immediately, we started getting inquiries from some of our health care Clients asking about the security of their laptops.  I decided to write this blog post to respond to these inquiries in a fashion that will hopefully help all our health care Clients.

First, laptops should be encrypted.  Encryption insures that if a laptop is stolen or lost the information on the hard drive cannot be accessed by taking the drive out of the laptop and trying to access it in another device.  Having a laptop encrypted means that if a laptop is stolen or lost you would not have to report it as required by HiTech/HIPAA.

Covered entities and business associates must only provide the required notification if the breach involved unsecured protected health information.  Unsecured protected health information is protected health information that has not been rendered unusable, unreadable, or indecipherable to unauthorized individuals through the use of a technology or methodology specified by the Secretary in guidance. 

We use TrueCrypt, a free open source encryption tool to encrypt devices.  There are some things to know about encrypting laptops.  First, it is time consuming.  Encrypting a brand new laptop can take 2 or more hours depending on the size of the hard drive and the speed of the laptop.  It can take 4 or more hours on an older laptop.  It can also affect the performance of the laptop, especially older laptops that are already running slow.  Once the laptop is encrypted, the user will need to enter two passwords to start the laptop up.  (there are several variations on how data can be encrypted)  If the encryption key is lost, the data on the laptop is lost (we have processes in place to make sure the key is not lost)

Now come the hard facts.  A large portion of the laptops we work on have the password attached to the laptop somewhere.  Do you know if that is happening in your practice?  If the password is exposed you have no security, even if the laptop is encrypted.  Also, if the device is left logged on when it is being moved from location to location, you don’t have security either.  If the laptop is lost or stolen, one simply needs to open the laptop and all the data is exposed.  Again encryption doesn’t matter.

We have been getting inquiries as to whether an organizations laptops are encrypted or not.  While this is a good question to ask, I’m afraid that you should already know the answer to the question.  Also, this is not the only question to ask.  What are your security policies relative to the laptops and your EPHI in general?  Are your nurses and other staff aware of the policies and are they following them?  What are the consequences if they don’t follow them.  What happens if there is a breach?  Does everyone in your organization know what the protocol is?  If the media is asking questions, do you have a protocol in place?  When was the last time you changed passwords? Do you have an inventory of all your devices?  How often is it checked to see if anything is missing? etc., etc.

Unfortunately, security and ease of use are not synonymous. Security can be painful.  We have to remember complex passwords and follow rules that make our jobs just a little more difficult.  However, it is imperative that security be taken seriously today, in our personal and professional lives.  We do not want to be the next security related news story.

Feel free to contact us if you would like to review your security status.

Tuesday, October 26, 2010

How To Use Signatures in Outlook 2010

Microsoft provides some great resources to help users learn how to use their products.  From simple How-To documents to videos and even live training.  I will publish some of these resources on this blog. 

In this multimedia training module you will learn how to create and use professional (or not) looking signatures in Outlook 2010.  The concepts are similar for earlier versions of Outlook but may be slightly different.

One note I would add to this session.  Outlook, Outlook for Web Access and Outlook mobile do not use the same signature template.  You must create a signature in each of these Outlook modes.  The session does discuss setting up a signature in Outlook for Web Access.  You will need to use your mobile phone email application to create your “mobile” signature.

Be sure to click the next button to get through the whole session.

Use E-Mail Signatures in Outlook 2010

Friday, October 22, 2010

No More Pre-Installed Windows XP on New Laptops/Workstations/Netbooks

Today is the 1 year anniversary of the release of Windows 7.  And it is also the first day that Microsoft is no longer allowing Windows XP to be preinstalled on any workstations/laptops/netbooks. 

For the most part, our Clients have been switching to Windows 7 when buying new workstations and laptops.  We have seen very few issues.  The phase out of Windows XP has been publicized for quite some time now, so it should be a shock to no one.  It’s time to move forward!

Wednesday, October 13, 2010

Largest Windows Update Release Ever

MC900044955On Tuesday, Microsoft released its largest set of security patches ever.  Patches for 16 security related issues were released.  10 of these patches are rated critical, 5 are rated important and 1 is less critical.  We have begun our testing process and will start releasing the updates to our Monitoring Plus Clients on Monday October 18th.  More detailed information on these patches can be found here