Defending Against Identity Attacks – When MFA Isn’t Enough
Join Besler Holdings’ VP of Information Technology, Eric Englebretson, for an expert-led session examining why identity has become one of the most targeted areas in cybersecurity.
Join Besler Holdings’ VP of Information Technology, Eric Englebretson, for an expert-led session examining why identity has become one of the most targeted areas in cybersecurity.
In this episode, Eric Englebretson, Besler Holdings’ Vice President of Information Technology, provides us with a glimpse into Webinar, the first in its Modern Identity Defense for Healthcare Series: Defending Against Identity Attacks – When MFA Isn’t Enough live on Wednesday, August 12, at 1 PM ET.
Kelly Wisness: Hi, this is Kelly Wisness.We’re pleased to welcome back Eric Englebretson, Besler Holdings’ Vice President of Information Technology. In this episode, Eric will provide us with a glimpse into Besler Holdings’ next Webinar, the first in its Modern Identity Defense for Healthcare Series–Defending Against Identity Attacks – When MFA Isn’t Enough live on Wednesday, August 12, at 1 PM Eastern Time. Welcome back and thank you for joining us, Eric.
Eric Englebretson: Thank you so much. I’m happy to be here.
Kelly: Well, great. Well, let’s go ahead and jump in. So can you provide a quick overview of what you’re going to be reviewing during this webinar?
Eric: Absolutely. So, the thing that I think is very important for us to cover is that identity has become one of the most targeted areas in all of cybersecurity right now. It used to be that attackers focused on servers or the corporation’s network, and once they’d gotten in from there, they would pivot to get at the thing they’re really after, which is often a company’s data. In the age of cloud computing and remote work, defenses have generally gotten better because traditional defensive methods of defending the network give way to security practices like something called Zero Trust, whereby any interaction with an organization’s resources must be authenticated no matter where a location request might come from. And so, the next logical step is identity attacks. And why is that? Like I said, since attackers focus used to be on breaking into networks and servers, the payoff might be limited. A compromised web server hosting a hospital website might not have any access to any data at all, really, but in today’s integrated environments, one compromised user account. Now that can give an attacker access to email, collaboration tools, patient systems, financial applications, and cloud services, depending on your role. In most organizations, your identity becomes the new perimeter, and that’s why attackers increasingly target people and accounts instead of infrastructure. This is going to be a two-part series covering modern identity security, why attackers have moved to trying to capture identities as a first attack rather than compromised servers, what we can do about it. And in part two, one of the biggest new advancements you’re probably already using in a few places, passkeys.
Kelly: Awesome. Sounds like you’re going to cover a lot during this webinar. I’m really looking forward to it. So, we hear a lot about MFA and how attackers try to bypass it. So is MFA still effective?
Eric: Absolutely. So, MFA really remains one of the most important security controls that has come to us in the past 10 or so years, and it really does stop the vast majority of common attacks, including password reuse, credential stuffing, and other attacks similar to those. The key message here is that MFA is definitely not broken. The message is that attackers have evolved and they’re now looking for ways to get around it. It is just that effective. They’ve got to work around it now rather than just simply trying to use a username and password. And that means organizations need additional layers of protection alongside of MFA.
Kelly: Yeah, so we know that MFA is still effective. So how are attacks evolving to work around it?
Eric: Modern attackers often focus on stealing authenticated sessions rather than stealing passwords. In some phishing attacks, victims enter their credentials and complete MFA successfully, but the attacker captures the resulting session that’s created. Think about it this way. Is it easier for a thief to steal your hotel room key or to try to convince the front desk to issue a new one? In most cases, it’s easier for the thief to steal your room key. After that, they can just come and go as they please, usually without so much as a second glance. We’ve put so many guardrails around the authentication process that attackers are now moving on and looking at what’s behind that, something called sessions and tokens.
Kelly: So, what are session tokens and why should people care about them?
Eric: So, session tokens and they are kind of background… so this is kind of we enter that realm of nerdy a little bit, but stick with me. Session tokens are what keep you log in after you’ve authenticated. They’re the reason that you don’t have to enter your password and MFA code every single time you open an email or click a new page. They’re incredibly useful, but that makes them also incredibly valuable to attackers. If an attacker does steal a valid session token, they may be able to act as though they’re already authenticated without having to have your password again. And that is what makes them so important, and that is why people should care.
Kelly: Yeah, no, that makes a lot of sense. Why is healthcare such a frequent target for identity attacks? I mean, we’ve been hearing so much about this lately.
Eric: Absolutely. So, the main reason for that is that healthcare combines highly valuable data with extremely time-sensitive workflows. Clinicians and staff are constantly dealing with alerts, messages, urgent requests, and attackers understand that environment, and they design their hacking and phishing campaigns specifically to exploit human pressure and urgency. Healthcare isn’t targeted because it’s careless. That’s actually quite the opposite. It’s targeted because its mission creates very unique opportunities attackers can try to exploit.
Kelly: Yeah. I guess having that– always having that sense of urgency probably doesn’t help us in that way, right?
Eric: Absolutely.
Kelly: Yeah. So, what are some warning signs that an account may be compromised?
Eric: So, a few of the things that you should look out for some of those red flags include unexpected MFA prompts, alerts about sign-ins from unfamiliar locations. If you are looking at your inbox forwarding rules, which I recommend that everybody does every once in a while, if a forwarding rule you didn’t set up has appeared and it’s forwarding to some account you don’t know about, that is definitely a big red flag, or just anything that seems off to you that might signify unusual account activity. And one of the most important things you can do here is just to simply report those to your IT staff, help desk, or security staff, whatever your normal workflow is, immediately. Early reporting can often stop a small incident from becoming a major breach.
Kelly: Yeah, no, that makes a ton of sense. Just be more vigilant. So, what’s the next evolution beyond traditional MFA?
Eric: And that is an excellent question. This is something I’m going to cover in part two. The future is phishing resistant authentication. So, there are technologies, and I’m going to use another nerd word here like FIDO2 security keys, Windows Hello for Business, and Passkeys are designed to prevent attackers from stealing or reusing credentials and session information. In part two of the webinar series, we’re going to explore how passkeys work, why companies should adopt them, and how they can dramatically improve both security and user experience.
Kelly: Wow, sounds like things are always changing in this space for sure. Well, thank you so–
Eric: Absolutely.
Kelly: Yeah. Well, thank you so much for joining us, Eric, and for giving us this glimpse into our next free Webinar — Defending Against Identity Attacks – When MFA Isn’t Enough. Join us live on Wednesday, August 12th at 1 PM Eastern Time. And as a bonus, you can also earn CPE. Thanks again, Eric.
Eric: Absolutely.
Kelly: And thank you all for joining us for this episode of The Hospital Finance Podcast. Until next time…
[music] This concludes today’s episode of The Hospital Finance Podcast. For show notes and additional resources to help you protect and enhance revenue at your hospital, visit besler.holdings/podcasts. The Hospital Finance Podcast is a production of Besler Holdings.
If you have a topic that you’d like us to discuss on The Hospital Finance Podcast or if you’d like to be a guest, drop us a line at update@besler.com.
In this episode, Kristin DeGroat, Besler Holdings’ Chief Legal Officer, provides us with a glimpse into Webinar, Medicare Cost Report Appeals and Reopenings: Best Practices, presented live on Wednesday, July 22, at 1 PM ET.
Kelly Wisness: Hi, this is Kelly Wisness. We’re pleased to welcome back Kristin DeGroat, Besler Holdings’ Chief Legal Officer. In this episode, Kristin will provide us with a glimpse into Besler Holdings’ next and final webinar in its Medicare Cost Report Appeals and Reopening series. This one focused on Best Practices. This will be live on Wednesday, July 22nd at 1 PM Eastern Time. Welcome back and thank you for joining us, Kristin.
Kristin DeGroat: Thank you for having me again.
Kelly: All right, well, let’s go ahead and jump in. So, this webinar will focus on best practices. Can you give us a quick review of what we can expect in the way of best practices?
Kristin: Yes. Navigating a Provider Reimbursement Review Board appeal requires rigorous adherence to strict rules and regulations. And because of that, there are some extremely valuable best practices that you need to think about when you’re filing these appeals. The portal and the deadlines are not just suggestions, they are requirements. So, navigating those in terms of best practices and setting forth how you remember when things are due and that kind of stuff in terms of an appeal is really important. But also important is the reopening process, ensuring that you adhere to the max deadlines, and that’s the Medicare Administrative Contractors deadlines and requirements. They are different. You do things a little bit differently. So, you need to think of how you handle that and getting those filed as well. And then just in general, CMS in general, there’s so many different parts and pieces that lead into appeals and reopenings. So just trying to set yourself up for success in terms of getting these filed and following the protocols, and basically trying not to irritate the board and the MAC are very important in this process.
Kelly: Yeah, that sounds like solid advice, Kristin. And we always love best practices, so this is going to be a really great webinar. So, what do you think is going to be some key takeaways from the webinar?
Kristin:Kind of what I just said about the being able to categorize or set up maybe calendaring or other avenues to ensure that you’re meeting the deadlines. And also cataloging, keeping your documentation together in a way that somebody else can understand. We all get caught in the, I’ve done it, I’ve looked at it so much, then we forget that people aren’t exactly like us and don’t read things exactly the same. So, cataloging that in a way that others can understand and appreciate, I think, will be the greatest takeaway.
Kelly: Yeah, that sounds like a great takeaway too. So, this is the last in our Medicare Cost Report Appeals and Reopening’s webinar series. Can you do a quick recap of the first two, and how does this one fit in?
Kristin: So, the first one was a deep dive into the PRRB and the rules and the deadlines, the timeliness, the amount of controversy. Those strict requirements and then we talked a little bit about the reopening requirements. And so, all of that together then led us to, well, what are the most common issues? That was the second webinar. And we did the deep dive into the most common issues, and we gave the status, kind of case law where they were sitting right now, and what we expect, or hope, maybe, is a better word, the outcome will be for those cases. So, the third one will definitely not hit the issues and the updates. So really, if you want to learn about the most common issues, updates, that one you’ll have to go watch if you didn’t join us for the second webinar. Hopefully, you’ll join us for the taped version, so to say. But I think this third one really will kick and tie to the first one where we kind of went through everything, but this will just be a little bit different approach. So maybe the lingo might be repeated, and I might forget to give the definition for my lingo. So, I will do my best. But I invite you to look at the whole series together, because I do think the whole thing together really makes sense.
Kelly: Yeah, creates that complete picture, right?
Kristin: That’s correct.
Kelly: Yeah. So, do you have to watch the first two or watch them in order for this webinar’s content to make sense? I mean, or are they standalones?
Kristin: I don’t know that they’re necessarily standalones completely. The first one did go through in detail what we’re going to talk about in best practices. And it gave a little overview of the issues. But really, that second webinar, the diving into those issues and really telling you what the status is, where they are right now, I think really is a standalone. But in order to get there, you had to meet all of the requirements. And you have to have the best practices to ensure that you’re really not irritating your audience. You want to make sure that you’ve complied and have done things showing not to be rude, right? When the board says you have 20 days to file this, don’t do it on the 21st day. It’s just as simple as that. Just following the rules and some best practices to help get you through. The other thing is appeals aren’t new, reopenings aren’t new. So, there is a lot. 30-plus years of going through the process has really, I think, laid out for us a nice, seamless transition from, “Here’s the rules,” to, “Here’s the issues, and here’s how you keep the goodwill going with your issues and your appeals, and even your reopenings.” So we’re going to talk a little bit more about reopenings, probably, in this third series, because I think the max concerns about how we approach issues and appeals, I think it’s something that we really need to take heed of because they are the ones that are going to help you settle your cases and help push these cases through. So, I think I want to do a little bit more focus there.
Kelly: Okay, that makes a lot of sense. Looking forward to that one. So, who do you recommend attend this webinar? Who is the target audience?
Kristin: Really, anyone in reimbursement. If you are filing a cost report or even thinking about an appeal, and you’re probably filing reopenings, so anyone doing those that has always wondered, “Well, I wonder why I did my reopening this way, and I didn’t get a really good response,” or, “Wow, I thought this would move faster. I’m not sure what I did wrong. I thought I compiled the evidence.” So, I think really focusing on that and moving through that process. And maybe that’s it. Maybe you’re someone new to reimbursement. This would be a great way to kind of experience, okay, so this is what I need to do. And it’s not all going to be about rule following. Some of it is just common courtesy.
Kelly: Yeah. That makes a lot of sense, yeah.
Kristin: Oh, I was just going to say I hope everyone can join the webinar. I’m really excited about this one. I think it kind of gives you more of a– let’s me put some personal flair on it and what I’ve experienced over the years.
Kelly: Yeah, love that. Well, thanks so much for joining us, Kristen, for giving us this glimpse into Besler Holdings’ free webinar, Medicare Cost Report Appeals and Reopenings Best Practices, that we’re going to do live on Wednesday, July 22nd, at 1 PM Eastern Time. And as a bonus, you can also earn CPE. Thanks again, Kristin.
Kristin: Thank you. Have a great day, Kelly.
Kelly: Thank you. And thank you all for joining us for this episode of The Hospital Finance Podcast. Until next time…
[music] This concludes today’s episode of The Hospital Finance Podcast. For show notes and additional resources to help you protect and enhance revenue at your hospital, visit besler.holdings/podcasts. The Hospital Finance Podcast is a production of Besler Holdings.
If you have a topic that you’d like us to discuss on The Hospital Finance Podcast or if you’d like to be a guest, drop us a line at update@besler.com.