Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

2025-09-05

All User Bulletin - Internet Security Certificate Update (Action May Be Needed)

All-user-bulletins highlight stumbling blocks that all prescribers need to be aware of when using the Connect Care clinical information system.

Internet Security Certificate Update - Personal devices may require user action

On September 4 and 5, 2025, AHS IT Identity-Directory Services will renew its Public Key Infrastructure (PKI) certificate servers. This PKI service manages electronic security certificates and unique electronic keys that verify end users, devices, systems and servers throughout AHS and its affiliates. AHS devices and personal devices enrolled in the AHS Bring Your Own Device (BYOD) program should not be impacted, but personal devices not enrolled in BYOD may be impacted and require user action. Prescribers who haven't yet done so may want to consider enrolling their device in BYOD prior to this change.

  • AHS devices and personal devices enrolled in BYOD: No action is required by users if their computer or mobility device is enrolled in BYOD. PKI certificates will be automatically updated.
  • Personal devices not enrolled in BYOD: Both Android and Apple devices may be impacted by this change. Users may see warnings to the effect that a security certificate cannot be verified, and will then need to follow a few simple steps on or after September 5 to restore AHSRestrict wireless connectivity following the PKI update (see memo for more details).

For instructions for affected users on what actions may be required, see the memo.

2025-05-28

Multi Factor Authentication for Microsoft 365 Apps Accessed from Personal Workstations

As of Wednesday, May 28, 2025, Multi Factor Authentication (MFA) will be required when users access Microsoft 365 (M365) applications - i.e., the web versions of Microsoft Office software, including Outlook, SharePoint, and OneDrive - from personal workstations such as laptops. This change may prompt MFA when accessing CMIO and other AHS resource links, as most of our materials are hosted on SharePoint; however, links clicked from within Connect Care will not prompt MFA.

What is changing and why?

AHS IT is restoring Multi Factor Authentication (MFA) for Microsoft 365 (M365) applications accessed from personal workstations such as laptops. MFA was previously required for M365 apps, but was temporarily removed in December 2024 while AHS' SharePoint was migrated to the cloud. The migration process is now largely complete, and so M365 MFA is being reactivated to align with AHS' security policies. 

This change does not impact shared workstations, or any other applications including Connect Care.

What action do you need to take?

The M365 MFA will be triggered only on personal workstations when accessing the web versions of Microsoft software; this includes opening a Microsoft web app (e.g., Outlook) as well as opening a document created by/saved on Microsoft software (e.g., a Word file, or a document saved on SharePoint) on your browser. Users will be prompted for personal login as usual, and then prompted for MFA confirmation (such as a code texted to a mobile phone). Once the MFA step is complete, the user will not need to re-authenticate for at least 6 hours. 

  • Tip: When accessing SharePoint, please select "Keep me signed in" when prompted, to allow for even longer timeout.
Problems?

If you have any issues with M365 MFA, please contact the IT Service Desk (1-877-311-4300).

2023-10-20

All User Bulletin - Internet Security Certificate Update

All-user-bulletins highlight stumbling blocks that all prescribers need to be aware of when using the Connect Care clinical information system.

Internet Security Certificate Update - Personal devices may require user action

On October 19 and 20, 2023, AHS IT Identity and Directory Services will renew its Public Key Infrastructure (PKI) certificate servers. This PKI service manages electronic security certificates and unique electronic keys that verify end users, devices, systems and servers throughout AHS and its affiliates. AHS devices and personal devices enrolled in the AHS Bring Your Own Device (BYOD) program will not be impacted, but personal devices not enrolled in BYOD may be impacted and require user action.

  • AHS devices and personal devices enrolled in BYOD: No action is required by users if their computer or mobility device is enrolled in BYOD. PKI certificates will be automatically updated.
  • Personal devices not enrolled in BYOD:
    • Android devices: Will not be impacted, with the possible exception of Google Pixel devices. Google Pixel users experiencing issues following the PKI update should call the IT Service Desk (see memo for more details).
    • Windows and Apple devices: May be impacted with this change. Users may see warnings to the effect that a security certificate cannot be verified, and will then need to follow a few simple steps to restore AHS Restrict wireless connectivity following the PKI update (see memo for more details).

For instructions for affected Google Pixel, Window, and Apple device users on what actions may be required on or after the PKI update is completed, see the memo.

2023-08-26

AHS Expands Use of Multi-factor Authentication for Information Access

We've previously posted about the introduction of a multi-factor authentication (MFA) requirement when accessing AHS email from outside AHS facilities and networks. 

AHS is expanding MFA requirements to increase protection from growing cyber security threats. MFA is a security measure that requires the user to verify their identity during login by using a mobile device app or phone call to a cellphone or landline.

Starting September 13, 2023, users logging in to AHS Insite or SharePoint on a personal device or an AHS device externally without a virtual private network (Netmotion or Forticlient app required) or Citrix Workspace connection will be prompted to authenticate using one of the MFA methods they have already set up. Users are advised to set up at least two MFA access routes, as explained in the following resources:

2023-08-25

Using Third-party AI at AHS

Artificial intelligence (AI) can refer to any attempt to simulate human thinking with software. This can include generative AI, large language models (such as OpenAI’s ChatGPT), speech-to-text dictation, and analyzing trends from data sets.

As Alberta Health Services (AHS) considers how to approach the use of third-party AI tools, our workforce is asked to follow these preliminary guidelines for the use of AI at AHS:
  • Do not load any confidential AHS health, personal, or business information into unapproved AI programs or tools.
  • Use caution when accessing AI websites with AHS devices.
For more information:

2022-01-24

Updates to AHS Email Access - Multi-Factor Authentication

On January 27, 2022, Alberta Health Services (AHS) expands use of Multi-Factor Authentication (MFA) for medical staff, further protecting clinicians from growing cyber security threats.

When logging in to Microsoft Outlook Web Access to gain access to AHS email on a personal device, users will need to verify their identity with a code number obtained by either:

  • using an authenticator app on a smartphone or tablet;
  • receiving a text message to a mobile number of their choice; or
  • receiving a phone call to either a cellphone or landline of their choice.

User name and passwords alone will no longer be sufficient to gain access to AHS email from non-AHS computers not connected to the AHS network.

Instructions about setting up MFA will be mailed prior to January 27, and can be followed at any time using an AHS MRA user guide:

These MFA requirements for prescribers currently apply to Outlook Web Access on  non-AHS laptops or desktop computers.  This MFA solution will not be required for Outlook Application on mobile devices managed by Workspace ONE.

2020-11-21

Practical Paranoia - Pandemic Phishing on the Rise

Hospitals are prime targets for cyberattacks and this is especially true during COVID-19. The consequences not only disrupt patient care but can be lethal. 


Hackers use phishing emails to trick healthcare workers into downloading ransomware, a type of malicious software that attacks computer systems when an infected link or attachment is opened. The ransomware logs out users and shuts off access to critical information until a "ransom" is paid by the organization.
 
Some recent examples:
  • Outpatient appointments were postponed in Quebec due to a recent cyberattack targeting health board members.
  • A recent ransomware attack in Germany meant that a patient had to be rerouted to a hospital 20 km farther away, delaying care and likely contributing to her death. 
  • An early morning cyberattack at Universal Health Services’ US facilities disabled multiple antivirus programs, logged off users and shut down system access. Affected hospitals had to redirect ambulances and relocate patients in need of surgery to other nearby hospitals. Universal Health Services operates in both the US and UK and is similar in size to AHS with more than 400 facilities and more than 90,000 employees providing healthcare services to about 3.5 million patients annually. 
You can help stop these attacks. 
  • Take note of AHS’ external email warning message. 
  • Don’t open unsolicited email attachments or click on links. 
  • Always report suspicious emails using the "Report Phishing" button on Outlook or forward to stop.spam@ahs.ca, then delete.
Learn more about some of the common tricks cybercriminals use to access your information by viewing Don’t be fooled by Scammers and visit InfoCare on AHS Insite for information on all privacy and information security matters.

2020-05-24

Practical Paranoia - COVID-19 Cyber Attacks Continue

Exercise caution in handling any email with a COVID-19-related subject line, attachment, or hyperlink, and be wary of any COVID-19 related social media plea, text, or phone call.

Cyber criminals and hackers are taking advantage of the heightened anxiety around COVID-19 by sending emails with malicious attachments or links to fraudulent websites to trick victims into revealing sensitive business or personal information or donating to fraudulent charities or fake causes. Please take the following precautions:
  • Watch for AHS’ external email warning – it signals greater risk.
  • Beware of unsolicited emails and avoid clicking on links or opening attachments.
  • Do not respond to email solicitations asking you to reveal business, personal or financial information.
  • Use only trusted sources for up-to-date fact-based COVID-19 information.
  • Always verify a charity’s authenticity before donating by checking out their official website and always look for the secure browser ‘lock’ icon before making donations.  
Learn more about some of the common tricks cybercriminals use to access your information by viewing Don’t be fooled by Scammers and visit InfoCare on AHS Insite for information on all privacy and information security matters.

2020-05-22

Alberta Health introduces Secure Messaging Service during Pandemic

Alberta Health is sponsoring a new voluntary service that can help physicians securely message with patients during the COVID-19 pandemic.  BrightSquid is the selected provider for "MHR Secure Mail" and Alberta Health is making it available at no cost to participating physicians until July 31, 2020.

While any Canadian physician can sign up, the target audience for the Alberta Health promotion is physicians who do not already have a patient portal or other secure communication service available to their patients. There is no requirement to use MHR Secure Mail, or to use it in preference to other secure communication tools.

Physicians sign up for the BrightSquid service and invite their patients to participate. A link to BrightSquid is available via MyHealthRecords, which is also where patients can launch MyChart for secure communications with physicians who use Connect Care as their record of care.

Physicians using AHS information systems should continue to use the secure clinical messaging services provided by AHS, with priority given to communication tools integrated with clinical information systems. Future postings (or in our FAQ Channel) will address questions about how Connect Care physicians can support patients seeking clarity about secure clinical communications in Alberta.

2020-05-18

Secure Clinical Messaging for users of AHS Clinical Information Systems

As tempting as it is to send clinical queries via email, this can risk a privacy breach. Alberta Health services (AHS) provides clinicians with tools for secure transmission of clinical information via email, including encrypted email to external (non-AHS) addresses. These should be used in all health service contexts where AHS has responsibility for the legal record of care. Such records can be paper-based,  AHS supported Electronic Medical Records or any of the AHS clinical information systems (CIS).

Transitory communications (e.g. request to meet) do not require secure transmission if they do not contain information that might identify a patient. Non-transitory communications about patients and the care they receive (e.g., patient instructions) must be protected and recorded or referenced in the record of care. 

Clinicians interacting with patients via email or messaging systems should use the most secure and integrated system available:
  • Connect Care Messaging
    • Use messaging solutions within Connect Care when both sender and recipient have access. This includes clinicians who do not use Connect Care as the record of care but have access to the Provider Portal. 
  • AHS Secure E-Mail
    • If both sender and receiver have AHS email addresses (@albertahealthservices.ca or @ahs.ca or @covenanthealth.ca or @albertapprecisionlabs.ca), then clinical communications can be securely sent and received using AHS email.
    • If the sender has an AHS email address but the receiver does not, then add “!Private” to the subject line so the email message is encrypted. 
  • External Approved Solution
    • If none of the above are appropriate for clinical communication, consider use of an external clinical secure messaging solution that meets Health Information Act requirements. Some have been approved for use with AHS records, to be replaced when Connect Care and its patient portal are fully implemented province-wide. 
    • An instance of the BrightSquid secure messaging system, "MHR Secure Mail", is available to Alberta physicians during the COVID-19 pandemic at no cost and can be used when no other AHS-provisioned system is available or appropriate.
We will update the Connect Care physician manual as secure communication options evolve in Alberta.

2020-05-16

Practical Paranoia - Protecting Personal Devices

Personal computing devices (laptop, notebook, tablet, desktop) may support clinical work when physicians take call from remote sites, or otherwise participate in the provision of healthcare services outside AHS facilities. 

Because identifiable personal health information could appear on data storage devices which, if stolen, could risk a privacy breach, it is essential that personal devices be configured in compliance with AHS policy and legislative requirement, including:
  • Password protection with a strong and well maintained code
  • Inactivity timeouts that re-challenge for a device password after automatic system suspend or sleep states
  • Hard drive encryption
  • Firewall protection
  • File sharing off or appropriately protected
Encryption is a method of protecting information by converting it to a format that's unreadable by anyone except those with a special key (usually a very long password). All Windows operating system devices must have native hard drive encryption enabled (BitLocker). All Macintosh operating system devices must also have native hard drive encryption enabled (FileVault).

2020-04-16

Practical Paranoia - Important message from our CEO

We've previously posted about additive privacy and security challenges emerging in the context of a pandemic.

Dr. Verna Yiu reminds us about the vigilance needed to avoid situations where our pandemic activities increase the risk of privacy breaches:

Dear AHS staff, physicians and volunteers,

Protecting privacy and ensuring that patient information remains confidential is as important now as it has ever been.

During this state of emergency, our obligations to our patients have not changed. The Health Information Act (HIA), the Freedom of Information and Protection of Privacy Act (FOIP), AHS’ privacy policy and best practices still apply.

We each have a duty to protect the information entrusted to us. We can only collect, use, access, and disclose the information needed to perform our AHS job, duties, and responsibilities. As healthcare professionals, our patients trust us to appropriately access and safeguard their health and personal information. We must always remain fully committed to ensuring this trust is never broken through inappropriate collection, access, use, or disclosure.

Under no circumstances should staff or physicians access or disclose health records of individuals they are not providing a health care service to. For example accessing information outside of your role – even if your reason is concern for colleagues, friends, neighbours or loved ones – is a privacy breach.

A privacy breach occurs when there is an unauthorized collection, use, disclosure, access to, or disposal of personal or health information. It’s a serious matter that will be investigated by our Privacy team and could result in potential workplace disciplinary action, college sanctions, fines, and/or criminal charges. It is your individual responsibility to report any breach you discover, even if it did not originate from you. Report privacy breaches here.

I encourage each of you to be vigilant and advocate for patient privacy and the confidentiality of our information. If you need support or are unsure what information you can and cannot access in your AHS role, speak with your manager or contact infocare@ahs.ca. More information is available on the InfoCare Insite pages.

Sincerely,
Dr. Verna Yiu
AHS President and CEO


2020-03-18

Practical Paranoia - Even in a Pandemic?

It is heartening to witness how a shared challenge brings out the best in us. It is disheartening to note how the same crisis brings out the worst in some.

While we struggle with COVID-19, it is deeply disappointing to witness an increased frequency of phishing and other cyber-attacks. These try to take advantage of forced work from less secure home networks.

In particular, phishing attacks are on the rise. These appear to come from a trusted source while inviting opening of a document or link. The unwary recipient can expose sensitive information or, worse,  fall prey to information extortion.

Please re-skim our many warnings about 'phishing', brush up on phishing-prevention, and be paranoid about any click-bait.

2020-02-06

Practical Paranoia - Celebrating our Cybersecurity Team

We've oft posted about alert fatigue and physician burnout. Despite our best efforts to design the Connect Care clinical information system for efficient interaction, we continually seek ways to reduce clinicians' total informational burdens.

A recent CHIME newsletter article describes how alert fatigue is not just for clinicians! Fascinating to read about the struggles of our cybersecurity teams, who are constantly bombarded by alerts to possible new security threats. Their work is high-stakes-high-stress. Health care organizations crippled by hackers suffer great financial, reputational and health care losses.

2020-01-12

Practical Paranoia - PLEASE don't trust links in e-mails!

Cyber-threats just keep getting worse!

Last week Saskatchewan health was hit by disruptive malware that proved very expensive to recover from. Alberta Health Services, like all big organizations, fends off thousands of attacks daily.

The hackers' windfall remains the unwary insider with access to protected networks and temptation to click on links in emails. We've managed to contain a few more of these lately, but affected users face extended downtimes and work is lost when damaged files are replaced by older copies.

Please re-skim our many warnings about 'phishing', brush up on phishing-prevention, and be paranoid about anything inviting your click.

2019-11-16

Practical Paranoia - Don't Click on Links in Emails!

We've frequently emphasized the place of practical paranoia as an essential privacy protection and clinical skill.

The Connect Care initiative benefits from robust technical privacy protections. As important are the behavioural privacy protections promoted through InfoCare, which all Connect Care users must participate in.

Neurons, not networks, remain our biggest risk. AHS continues to be targeted by phishing attacks, as previously explained. The size of our target may be bigger because of the publicity Connect Care has attracted.

Be especially vigilant about email messages. Seemingly familiar communications can contain links that install hacker software. Safest to practice universal precautions and never click on hyperlinks in emails (even those from internal AHS email addresses).

The CMIO portfolio is changing its approach to email communications. We will spell out internet links so the user can copy and paste to a browser, rather than clicking the link. By knowing the exact location of the link, take care to only use links where the "domain" or root is recognized and trusted ("ahs.ca", "albertahealthservices.ca", "connect-care.ca", "ahs-cis.ca", "ahs-cmio.ca", "bytesblog.ca").

2019-07-24

Mandatory Privacy Awareness Training

All physicians must complete privacy awareness training prior to gaining Connect Care access. This can be done independently and online by completing “InfoCare: On Our Best Behaviours” through MyLearningLink.ahs.ca (MLL). A search in “Courses & Registration” for “Infocare” will bring up the module. Note that it must be completed in full to expose a final attestation which must be completed before full Connect Care access is granted.

MLL has a “Required Courses” menu item and section. Note that the many courses listed are not required of physicians, with the exception of InfoCare. Physicians will receive explicit instructions in their training packages about which modules fit their needs.


2019-07-16

Practical Paranoia - Why Use AHS Secure Email?

We've previously posted about warranted worry when using email for clinical purposes.

Alberta health Services (AHS) offers a secure email solution that can support sending identifiable patient health information between AHS email and, with "!Private" in the subject line, to non-AHS email addresses.

Clinicians have raised a number of questions. Hopefully, this FAQ helps:

2019-07-06

Practical Paranoia - Sending Clinical Email

Clinicians should take great care when using electronic mail to communicate about clinical work, especially messages that may contain identifiable patient information.

We look forward to Connect Care launch, as the clinical information system (CIS) has advanced clinical communications tools.  These include email, text/chat, image capture and telehealth. Everything that happens within Connect Care stays within Connect Care. The physician and patient portals securely extend these clinical communication channels to those without full CIS access.

But what are we to do before Connect Care deployment is wide enough for all recipients to to receive? Before launch, and during transition periods when some but not all areas have launched, Alberta Health Services (AHS) secure email should be used for clinical communications.

Any email sent from one AHS address (ending with @ahs.ca or @albertahealthservices.ca or @covenanthealth.ca or @albertapubliclabs.ca) to another is automatically encrypted and acceptable for clinical communications.

An additional step is needed to protect email sent from an AHS address to a non-AHS address. It is easy. Just add "!Private" (remember the exclamation mark comes before, with no space, "private") anywhere within the email subject line. The recipient will receive instructions about how to decrypt the protected message. This will work even if there are attachments. And simply adding "!private" to the subject works with any email management software (e.g., Outlook, Apple Mail, Web mail, etc.).

For more information:

2019-07-05

Privacy Awareness - an Essential Clinical Skill

Privacy awareness is essential to good clinicianship. It does not come naturally and so we all need training. Our digital world presents ever-changing threats to information security, making it hard to know when we may unintentionally weaken the vigilance our patients expect. Breaches harm patients, and can be devastating for clinicians.

On the eve of Connect Care implementation, Alberta Health Services has overhauled its universal privacy awareness training. A new online elearning module, called "InfoCare - On Our Best Behaviors" is now available on MyLearningLink.ahs.ca (MLL). This privacy awareness training is required of all physicians prior to gaining access to Connect Care. The module is engaging, case-based, and easy to complete. It highlights a series of behaviors that physicians can promote for patient care, professionalism and Connect Care readiness.

InfoCare is delivered through MLL, which is most commonly used on AHS computers in AHS facilities. As physicians are more likely to complete the course on personal devices outside AHS facilities, we have prepared a summary of tips that can help those using personal devices. To complete privacy awareness training:
  • Go to MyLearningLink.ahs.ca (we recommend the Chrome Internet browser for those who do not have access to Internet Explorer 11 on Windows 7 or 10).
  • Sign on with your usual AHS credentials (same as those for email)
  • Search the Course Catalogue for courses containing the word "InfoCare"
  • Register for and complete the course online
  • Verify that your confidentiality and user agreement is accepted and the course is marked as complete.
  • Tips: Using MyLearningLink