A Nashville story
The Tuesday the billing vendor called the front desk
the practice administrator of a nine-physician medical group in Cool Springs
It is a Tuesday in March, tornado sirens tested at noon as always, and the practice administrator of a nine-physician group in Cool Springs is on the phone with the bank about a line of credit. Claims have been slow since the clearinghouse changed systems, and payroll is Friday. The front desk is three deep with patients.
At 12:40 the front desk coordinator takes a call from a man who says he is with the billing vendor. He is calm and knows the vendor's name, the practice's tax ID and the name of the administrator who is on the other line. He says he can release the stuck claims today if she can approve his remote login. A code will come to her phone.
She wants the claims released as much as anyone in the building. The code arrives on her phone, six digits, and with a patient's insurance card still in her other hand she reads him the first three.
The practice administrator, walking past with the bank still on hold, asks who is on the line, and the coordinator says the billing vendor, and the administrator says the billing vendor does not call the front desk.
What changes the ending
- Training that uses the phone call and the stuck-claims pretext, not just the phishing email, and one rule that codes are never read aloud to anyone (CIS 14 Security Awareness and Skills Training)
- Phishing-resistant multi-factor authentication on the EHR, the clearinghouse and remote access, so there is no six-digit code to read out (CIS 6 Access Control Management)
- Each vendor with a named contact, a defined support channel and a written access procedure, so a stranger who knows the vendor's name still has no door (CIS 15 Service Provider Management)