Zanda Health

Think Like a Hacker, Act Like a Pro: Real-World Security Tips for Health Clinics

Webinar details

What's covered:

  • Think like a hacker: Where clinics are vulnerable
  • Practical defences you can put in place today
  • Building a security-first culture

Speakers

Damien Adler

Damien AdlerCo-Founder & Head of Customer Success, Zanda

Damien Adler is a registered psychologist, best-selling author, entrepreneur, and Co-Founder of Zanda. He has a background in health administration, having held senior positions in the public health sector. He later founded a successful group private practice, and it was there that Damien discovered his passion for using technology to make life easier for health practitioners. These days, Damien dedicates his time to improving healthcare practices through technology. His unique insights stem from working closely with thousands of practitioners worldwide, from hospital settings to private practices, allowing him to identify universal challenges and opportunities within allied health. Damien's unique blend of practical experience and technological insight makes him respected in advancing healthcare practice efficiency and effectiveness.

Paul Adler

Paul AdlerCo-Founder & Chief Technology Officer, Zanda

Paul is a co-founder of Zanda and a seasoned technology entrepreneur with a track record of building and scaling high-growth businesses. He founded one of Australia's largest tech support companies from a $200 startup, earning recognition on the BRW Fast 100 three times along with multiple industry awards. At Zanda, Paul leads the development of a platform that balances robust, scalable systems with the simplicity practitioners need. He placing a strong emphasis on security and reliability while solving complex challenges and creating software that genuinely makes people's lives easier.

Click Transcript above to read the full webinar transcript.

DAMIEN:

Welcome to today's webinar, Think Like a Hacker, Act Like a Pro: Real-World Security Tips for Health Clinics. My name is Damien Adler and I'm one of the co-founders here at Zanda, and head of customer success. I am still a registered psychologist, but previously I developed and ran a group psychology private practice. I'll hand over to my co-host today, Paul, to introduce yourself.

PAUL:

Thanks, Damien. I'm Paul Adler. We're actually brothers, and I'm the other half of the co-founding of Zanda. I'm an engineer by background and profession, and prior to founding Zanda 15 years ago I had a technology advisory company where we helped businesses implement and run technology well.

DAMIEN:

Very good, thank you, Paul. Today we're going to look at a range of things, basically covering security and practical measures you can take in your practice to help keep your data secure and your practice safe. We'll touch on it from a psychology point of view and look at some of the ways people try to manipulate from a psychological perspective, as well as a technology perspective. We'll touch a little on Zanda's security features too, but for the bulk of this we're really going to be talking about practical things that help keep your practice secure and help your staff stay aware of what to think about when it comes to security.

So why does it matter? It's an obvious question, but we wanted to touch on it anyway. This webinar is for practice owners, managers and team members. It's not designed for specialist IT people. It's very much designed for the real world, for people running small practices all the way up to large clinics.

The threat landscape is changing and rising every day, so it's a very dynamic space and we thought it was a good time to give an update on the current ways people attempt to get around security, what can go wrong, and how to protect yourself.

Why is this worthwhile? In the health space we're dealing with very sensitive private information, and our patients trust us to look after it. That's critical in every element of health. The relationship with our clients and patients relies on us being able to protect that information and on people having confidence in our ability to do so. That goes at every layer of an organisation, not just for practitioners but for admin team members and anyone else who handles and is responsible for managing practice and treatment information.

Looking at the landscape we operate in, I won't go through the ins and outs of each regulation, but I do want to say that Zanda operates across multiple jurisdictions, so we need to comply with different privacy and security frameworks from around the world. What's really fantastic about that for our customers, no matter where you are, is that we have to comply with the strictest standard of any jurisdiction we operate in. In some areas Australia has stricter regulations, in other ways Europe has higher standards and requirements, and Canada and the USA may have areas they're particularly strong on. One of the things that's great about working across all those jurisdictions is that we have to raise our security and privacy approach to meet the highest standards wherever they are in the world.

We actually comply with a lot more than we have on screen here, but we wanted to give you a broad-brush idea. Really, though, we're looking at the practical side: what does this mean in practice for practitioners?

So let's dive in. Paul, we're going to talk about this idea of keeping your practice safe, and we've got an analogy about locking your doors and windows. I'll hand over to you to take us through that and explain why it's a helpful way to think about it.

PAUL:

What we're going to share today isn't about implementing fancy, expensive firewalls or throwing out all your computers. We're not talking about complicated security, because most of the issues, incidents and security breaches that happen are actually quite simple. It's not really high-tech governments hacking in.

The reason I particularly like this house analogy is that when you leave your house, you always shut and lock the front door. But if you lock the front door and leave your garage door open, or leave all your windows open, then the front door isn't very useful and it isn't going to keep your house secure.

You're only as strong as the weakest link. It's really important when you think about security in your practice to think about all the different areas. Think about it like a house: when you leave, you lock all the doors including the back door, and you shut and lock the windows. It's a very simple thing, but it's the same concept for keeping your practice or business secure.

DAMIEN:

I think that's good. The other dimension to the analogy I like is that you could have the highest-grade locks and the best alarm system, but if you put the key under the front mat, it doesn't matter. That high-grade lock doesn't help. And if you've got your alarm code on a sticky note next to your alarm pad, it doesn't matter how good that security is, someone comes in and it's right there. It's very much like that with the technology we use, and that a lot of technology providers use, to make sure there's absolutely the highest-grade security. But it's often the common, easy things that really bring you undone.

PAUL:

You wouldn't have the same key as all of your neighbours. You wouldn't lock two windows but leave ten open. It's the same thing with keeping your practice and your information secure: you're only as strong as the weakest link. What we're going to show you are simple practical tips, literally like locking your front door, having a key and not leaving it under the doormat, not leaving the alarm code on a sticky note next to the pad. Simple little tips that help make your business more secure.

DAMIEN:

That brings us to the common risks in practice settings. Do you want to take us through these, Paul? These are the equivalent of leaving the window open.

PAUL:

The most common risk, and the way information gets accessed, is human error. I won't dwell on that now, but we're going to show you a few things about it. Then there's phishing and social engineering, which we'll talk about with some examples, including an email we received not very long ago. Then things like having a weak password, or sharing a login. Third-party risk, so other software you might have installed on your system or signed up to on the web. And the last point is not having knowledge about what users are doing in your business or with your software.

DAMIEN:

On that note, let's jump into what a phishing email is and what the goal is when people send these. What are people aiming at? What are they trying to do when they send you an email?

PAUL:

They're usually trying to trick you, to impersonate somebody else and make you believe they're a legitimate sender, perhaps your bank. Or they could try to trick you into thinking they're some other software and get you to click a link and log in with your credentials into their system. That's usually the most common objective. They could also be making payment-type requests, trying to trick you into thinking there's an invoice that needs to be paid so you send the money to them. They're pretty sophisticated in the way they go about it, and it's very easy to be misled.

DAMIEN:

The other thing is that when people collect this information, sometimes they exploit it directly. They'll grab credit card information and use it to make purchases. Other schemes aim to collect all that information and then sell it on the dark web to people who will exploit it. There are going rates for recent stolen credit card details, and each viable card has a certain dollar value. So depending on the goal, sometimes they're directly going to exploit it, sometimes they're going to package that information up and sell it. So what are the signs to look out for, Paul? What are the giveaways?

PAUL:

The first thing is a created sense of urgency. They want you not to think about it too much and to act fast, so you feel there isn't enough time to check it out. I need to pay this right now. Or you've been hacked and you need to do an emergency fix right away.

Other things: asking you to log in, or asking you to click an attachment or a link in the email. You can also notice little variations in the way words are spelled. In that example there, and I had to look very carefully, you'll notice PayPal has a one instead of an L.

And sometimes they might not know any personal information about you. So instead of "Hi Damien," they'll say something generic.

DAMIEN:

Then you know something's a bit off, because you think that provider should know your details. Your bank will definitely know who you are, so it's unlikely they'd send something like that.

PAUL:

It's also about looking carefully at who the sender is. They might say it's this bank, but if you expand it out and look at the email address, you'll see it isn't the bank's email address, or it's a generic-looking one. It's a combination of those things that should raise your suspicion.

DAMIEN:

Let's look at a real example. Take us through this, Paul, because this is a real thing that happened.

PAUL:

This came through very recently. If you look carefully, it's a request coming to our accounts department. It's an internal request to please pay an attached invoice, now. Notice it says "please set up the vendor and make payments," so they know we wouldn't have them on file already. And look at what they've done: they've even made it look like it's been forwarded, as though Fiona has forwarded the email to our accounts department.

It meets all of those criteria, and it did set off alarm bells. It's really important, this invoice has not been paid, it's still unpaid, here's the number. Please give the settling of this invoice top priority. There's that sense of urgency, but there's also something familiar about it, and it is being sent to one of our addresses. But the supplier isn't someone we know. This is a genuine phishing email that came into our email system.

DAMIEN:

We won't give away how we internally set up vendors to ensure they're legitimate, but we see these sorts of things happen. It's important to make sure your internal processes are sound. If you're used to forwarding your bills to a practice manager or someone to sort out payment, or if you're the recipient of those, just be aware these things can be exploited and that you've got another channel for verifying. You should never set up a vendor and take action based on an email alone, because that can be easily exploited. Let's go to another example. If we look at this credential phishing example, do you want to take us through what they're trying to do here?

PAUL:

They're sending a message purporting to protect you, because of unusual sign-on activity they've detected. But this is a phishing attempt.

There are a few things to look at. It's purporting to come from Microsoft, and it says "Microsoft Team," which could be what they use. But if you look at the email address on the right-hand side, there's no way Microsoft would send a message from that type of email address. Also, have a look at any links included in the email and see whether the domain names look legitimate.

We've got a comment in here about not clicking links in the email, and the suggestion to hover instead. That's really good advice, because often there's a little code at the end of the link, and when you click it they know that code links back to the email they sent you. They know you definitely received it and clicked, so they know you're a real person, and then they can keep trying you again. So don't click the links, because then they know there's a person here they can send more to.

DAMIEN:

They might then send a follow-up saying, hey, we noticed you haven't completed the reset process, please complete this in the next three hours or your account will be deleted. And then it feels like, well, they know I haven't completed it, and I did click on it. That adds to the sense of legitimacy and urgency and plays right into the risk that you act on it.

Maybe you've got a shared support email box where one person looks at it and another person looks at it, and the second person does go in, click through and enter their details. It's very common for clinics to have one incoming email address, like reception at my health practice, with different people on at different times. That's exactly that type of risk.

The other point I was going to make is that if you're listening to this and thinking, I already know that, the question to ask yourself is: does your team know that? Does the latest person you hired know that? Does your new admin person know that? It's really important you have a way of educating them. We'll send a link out to this webinar, but just have people be aware that these are the sorts of things to look out for.

Let's move on to social engineering. This is a different modality, often trying to achieve the same goals, but using the psychology of interaction and knowing the vulnerabilities in processes. It's often more about the process and the people element than the technology. Social engineering means manipulating people into giving up confidential information, often without realising it. You see things like fake IT support, impersonating patients or staff, and the same use of urgency, fear, sympathy or authority.

We'll run through a couple of examples to show what that can look like, because this stuff happens in the real world. We see it because we have thousands and thousands of practices using Zanda all over the world, so we get to see what's happening in different areas.

In the first example, someone calls the practice claiming to be from a health industry directory or registration board. They say, we're just updating your information, or we're updating information for the practitioners in your clinic. They might start by giving some publicly available information they already know, which adds to a sense of legitimacy. They might say, we've got this name, they're this profession, this is the address, is that right? Is this the phone number? Yes, okay, look, we're missing their registration number, their date of birth, something else.

So they gain confidence by showing they already have some information, which makes it sound a lot more legitimate. And the admin person receiving that call is likely busy, wants to help, and wants to provide the information. The interesting thing about these social engineering attempts is that the sense of authority, or the confidence the caller projects, often sets the frame for how the person receiving the call feels.

In the second example, a receptionist receives a call from someone claiming to be a general practitioner or physician. The caller says a shared patient has just arrived in a distressed state and they need urgent information about the latest treatment records or sessions. They might even say the patient arrived in a suicidal state, to create the sense of a medical or psychological emergency, and use that pressure and the authority of "I'm a doctor from this clinic" to get the information. It's very easy for a receptionist to get flustered and to feel that if they withhold that information they'll be doing something harmful to the patient. So it plays on authority and on the desire to help.

On that theme of authority, here's an interesting example from when I first started working in the hospital system. I used to work in public psychiatry, and very often we'd have patients come in where we needed to get information from the general practitioner. It was often urgent and we did have a legitimate right to request it.

When I first started I was a new practitioner, wasn't confident in my role, and wasn't sure the receptionist would give me the information. So I'd go into it half stuttering, asking, could I please have this information. And almost universally I'd get turned down: no, this is the process, we can't hand that out over the phone. But then I noticed colleagues who'd been there a lot longer were getting on the phone and getting the information straight away, and I wondered what they were doing differently.

I realised it was using an authoritative, confident voice. So I changed my approach. I'd ring up and say, this is who I am, I know this patient sees this doctor, I need this, this and this, and it's urgent. Short, direct, a very clear and confident request. And I'd get the information nine times out of ten. There was no difference: they had no better reason to trust I was who I said I was than when I first started. But that approach made the difference.

So just be mindful that the people answering your phone, if it isn't you, are going to want to help and to foster good relationships with GPs and everyone we work with. There's a risk that can be exploited by leveraging exactly that. The way to address it is to call back instead of providing information over the phone. Call back on the legitimate number registered publicly for that GP, verify the request, verify the consents. But do it on a different channel from the incoming call you received.

Okay, let's move on to system-level protections. I'm going to hand over to you, Paul. What are we talking about here?

PAUL:

System-level protections are some pretty simple but really important and often overlooked measures that will significantly improve the level of security inside your practice.

The most important thing is enabling 2FA, so that's when you're asked to put in a code, maybe generated from your mobile phone, or some other separate code used in addition to your password. That can also include passkeys, which have been gradually implemented. Enabling 2FA on all of your important systems, including Zanda, helps significantly. The way it helps is that if your password is somehow breached, if someone's guessed it or you've reused it elsewhere, they still won't be able to get in because they need another piece of information: a code generated from your phone.

DAMIEN:

I know they're annoying. Ultra annoying.

PAUL:

I and a lot of other people have thought hard about how to make it less annoying, because it's such a good method, and I'm hopeful there'll be improvements broadly. But for now it's the best thing.

The next thing is having strong passwords. They've got to be longish, 10-plus characters is good and longer is better. The other thing that's super important is that each one is unique, so that password isn't used anywhere else.

Trying to remember these long, unique passwords is impossible, which is why you need a password manager. That sounds counterintuitive, keeping all your passwords written down in one place, but these are dedicated systems meant for storing passwords, and a good one can't be got into by anybody. They're encrypted in such a way that not even the IT people who work there can get in.

In our case, passwords at Zanda are encrypted in a way where there is no known way to get those passwords. Not us, nobody. Having unique passwords is really important because although companies like Zanda have good ways of encrypting, other companies may not have the same level of system and approach. They may store passwords in a way where it's possible to recover them. Once people find the password, they can reattempt it in other systems, like your email or your bank.

So keep them unique and store them in a password manager. Apple has one, and there are others like Bitwarden, 1Password and LastPass. There are a few of them and they're well worth using.

The other thing is restricting who can install software on your computers, because someone could be tricked into installing software that captures the password as you key it in and sends it on, and then they know your username and your password.

DAMIEN:

Tying that back to the first point: if they know your username and password but don't have access to your phone because you're using 2FA, they still can't get in. That's why enabling 2FA is the highest priority. I know it's a hassle, but it's a really good measure to keep everything secure.

The other dimension, and this is again about the different people in your practice, is that when I've talked to people I'd consider complacent about password management and unique passwords, their thought is, what are the odds someone's targeting me and is going to individually get my username and password and try it somewhere else?

The thing to understand is that these are large-scale attempts. This isn't necessarily someone sitting down thinking about you. The way it works is that there'll be a data breach of some other system that doesn't store passwords securely. So the weakest system gets exploited, and at some point you've registered an account with some random company and put in your email address and password. If you've reused those across all your other systems, only one of them needs to be breached for people to get hold of that username and password.

Then they attempt that combination on thousands and thousands of different websites and services, because it's automated. Every bank, every email provider, everything you can think of, bang, bang, bang. Once they get a hit, it's not someone individually looking at it. That hit just goes into a list: these are all the accounts we can access with that combination. And then they either exploit it or sell it. So it's done at very large scale.

When I talk to people about this they say, no one's worried about what I'm doing. Right, but be mindful that it's automated and done on a mass scale. By having a unique combination, even if one system is breached, you haven't used that combination anywhere else. So when they attempt it on thousands of other sites, it won't work, and the breach is limited to that one dodgy company that didn't have good security. That's fine, but at least it doesn't contaminate everywhere else.

PAUL:

If you can get everyone in your practice to do one thing, it would be having a very strong unique password for your email. And also please do it on Zanda.

DAMIEN:

Exactly, unique. Now let's move on to device and physical security.

PAUL:

There are some really simple things here. If someone can physically get hold of your computer or your phone, and you're using 2FA on that phone, that's a risk. So make sure you've got password-protected screen savers and a phone lock. It's simple and obvious, but imagine someone comes in and steals it. That's a pretty common thing to happen, it's not obscure. How are you going to be protected? A screen saver, and needing a code, Face ID or a PIN to access your phone.

There are also locking systems to secure devices to desks, which is useful especially in a reception environment where someone may be opportunistic and just grab it. Prevent that from happening.

There are simple tools as well, not expensive, that allow you to remotely lock computers and even destroy the contents, so no one can use the machine any more. We use tools like that internally, maybe 20 dollars a year or something.

It's also important to keep printers and physical filing cabinets out of public areas, which helps mitigate obvious risks. And it's an old one but really important: make sure the wifi network is password protected.

DAMIEN:

Also be mindful if you still have physically wired internet in your reception or waiting room. People often reconfigure their waiting room and leave a plug in the wall that's still wired to their central network, and someone can just put a device into that. If there's no security on it, or if it's connected through to their network, they've got access. When I go into waiting rooms I always spot that, it's an occupational hazard of scanning for these sorts of things.

PAUL:

One other simple thing is making sure the hard drive is encrypted, if you're storing any files on it. These days not that many people are, they're uploading to the cloud and to systems like Zanda. But encrypting the hard drive is usually just a checkbox, and it means that if your machine is stolen someone can't just pull the hard drive out and read it. If it's not encrypted, people can do that easily. Literally take it out, plug it into any device via USB, and away you go.

DAMIEN:

Let's move on to staff awareness and security culture. We've talked a bit about this, but we have an approach at Zanda, so it'd be worth you taking us through a few things people can do for their clinics and what they should keep in mind.

PAUL:

In one of those earlier slides we talked about all the different security and privacy standards we comply with, and a lot of that is externally audited. We have a whole process for managing our compliance, with annual audits. But a key part of those programs, and I'm talking about ISO 27001 and HIPAA, is the security culture within the organisation, making sure people are really aware of security, thinking about it and conscious of it.

The most important part of that is talking about it, and in a sense that's what we're doing right now. This is not a plug for Zanda, it's about how to keep your system secure. So talk about it, and talk about it regularly.

Those phishing email examples we showed were shared internally, and we commented on them and shared them as widely as we could. We do that with anything we see or learn about, or media coverage of attacks that have occurred elsewhere. We share that irrespective of whether it's connected to healthcare, just to raise people's awareness of how often it happens and the way it happens.

They're very simple things you can do to get people thinking: that's a weird email, that's a weird phone call, maybe I should stop and ask or think about it a bit more.

DAMIEN:

We become more aware when we see examples of it happening. It's not about making people anxious, it's about saying, here's what happened and how it happened, so it makes people alert. We're part of a connected world and anyone can email you. We use Google Workspace internally, and it let that phishing email through. Some of them it doesn't, they go to spam, but not all.

PAUL:

Having a culture and awareness within your practice, across all the team members, is really one of the best things you can do to make a difference.

There are a couple of other things as well. Make sure your team know that their actions are logged. Inside Zanda, as an example, everything that's done is automatically recorded by the system. You can go into the activity log and see it yourself: you created this appointment, you moved it, you changed the time, you updated the name. There's a log of the action that's happened, which is really important for helping diagnose issues, but it also has a really important security element, so that every time something was viewed there's a record of it.

The other thing is that where it's appropriate we do police checks and security checks for all of our team members. Different jurisdictions and different types of practices may have different requirements, but it helps in an obvious way and it also helps set the tone that privacy and security are really important.

DAMIEN:

In our experience over the years there have been a number of circumstances where we're aware of customers who've had problems with team members they hired without doing a background check. It can happen to anyone. Someone might have a problem with gambling or something that affects them personally, and then they act really out of character. You never want to think the worst of people, but if a police check becomes part of a routine process that everyone does, it can at least detect if there are issues.

In the circumstances we've been aware of, it's usually been around theft of money, or the patient list, which can run you into a real frenzy of thinking they've stolen a whole lot of data.

PAUL:

And the logging systems I talked about before provide evidence of that.

DAMIEN:

Absolutely, and the IP address from which it was accessed. So it puts people in a very strong position to say: this is what happened, this is who, this is the user, this is the location, the whole lot. They're simple things, but they really do make a difference.

Moving on to communication with patients, there are a few things to keep in mind. When we're communicating, or allowing appointments to be booked, we should be using encrypted portals and not collecting information via systems that aren't designed to collect health information.

One that's really important is your website. Let's say WordPress, which is a perfectly good platform for websites. But remember, it isn't designed to collect personal health information. We'll often see people add a plug-in for a contact form, which looks great and works well, but depending on how you configure it that information can not only be sent through to the practice as you intend, but there's often a tick box to save the form data on your web server.

Web servers people use for websites are often cheap shared machines with some inherent security vulnerabilities. For a standard website that isn't hugely problematic, but if you're storing patient information on those web servers it becomes an issue. We've certainly seen things pop up where it's just been a lack of awareness of how those contact forms work, and people don't realise they're breaching a bunch of regulations simply by ticking or unticking a box in WordPress. And there are lots of others as well.

PAUL:

And if that data becomes public or ends up in the hands of the wrong people, it could be used as part of an extortion attempt against a clinic.

DAMIEN:

The pathway we see for that is people hiring remote contractors to do their web development or configure some email settings, and providing credentials to their WordPress site and hosting environment. Maybe someone from an outsourcing service logs in to make a change to the website, not realising they're being given credentials to a whole bunch of stored health information.

Someone who knows what they're doing doesn't have to look very far. They just look at the contact form: are they storing the data? Yes. And there are years of contact information where people may have put their medical information, their referrals, the whole lot. Access to that has suddenly been provided to an overseas-based outsourced service provider who hasn't been vetted. Those are the sorts of things we see and that you need to be careful about.

The broader point is to be mindful of where you're collecting health information and to make sure it's in a system intended for that use, because then it should have the right security in place.

The other comment we've got here is about separating your personal email and phone from your professional ones. It's good security hygiene to keep things distinct. For communication with patients, having messages come from a consistent phone number rather than ones that keep changing, and making sure it's one used professionally, keeps things clean. There are ethical reasons why that's a good idea anyway, as a lot of people will be aware. But from a security point of view it's better not to put your professional email details into every site you sign up to in your personal life, so you're not exposing your details and you reduce the pathways for people to misuse them.

In terms of how we approach security, and this goes back to the psychology of it, it needs to be ongoing. After you watch this webinar it might raise your awareness and prompt you to talk to your team. But where we get the most benefit is making sure it's built into a regular range of practices.

So have an annual review of security for your practice. Rotate your passwords. Audit access and look at who has access to your systems, and whether they still all need it. Using the house analogy, when you move into a house you typically change the locks, because you don't want previous owners or tenants to have a set of keys. It's the same here: routinely review all the systems you use, make sure you don't have former team members still there, and that the level of access provided is suitable for each person's role. Maybe you elevated someone's access at one point because you were going on holidays and wanted them to be able to do certain things. Now you're back, it's important to drop that access down again so you're not leaving an ongoing security risk.

Industry bodies are great for monitoring. Subscribe to their emails and keep an eye out, because they'll often detect things that are happening and alert you, so it's a way of keeping a constant information feed relevant to your industry. And like anything, take a continuous improvement approach. It's not one and done, it's about incrementally improving your approach and your internal education programs, so that over time things get better rather than letting complacency sneak back in.

I'll hand this over to you, Paul.

PAUL:

Important software, such as Zanda or your email, and other systems that are really important to the operation of your business, have a really important role. They hold data where it's very important that it doesn't get leaked. So it's really important to make good choices about who provides your important pieces of technology.

I won't go through the whole list, but if anyone's interested you can have a look. Something that's really important is right at the bottom: having externally audited security systems. Two of the big examples are ISO 27001 and SOC 2, which are somewhat similar. It means independent experts have looked hard at the system and the processes, and if you've achieved that certification then a lot of the items listed above have been ticked off. Not all, but most of the really important things.

For example, having an external security company come and attempt to hack into your system, which is called a penetration test. That's a requirement, and we have it done once a year under those programs. So if a company has that, you can be quite confident their security practices will be good.

DAMIEN:

One comment to make is to watch out for providers that try to borrow the credibility of those certifications. A good example is saying, we use ISO 27001 cloud servers, with the implication that therefore they're basically ISO 27001 certified.

That's overtly misleading, because with ISO 27001 a lot of it, as we've been discussing, is about making sure the way the technology provider operates complies. It's like saying, yes, I have a house with all the locks and fancy things, but no one is actually trained to lock the doors, there are no processes to make sure everything's locked up tightly, and it's not routinely checked.

So what you want to look for, and it's often a really big flag, is people trying to borrow credibility from these audits based on their choice of technology partners. We use Azure or Amazon, therefore they have ISO, therefore it's like we have it. You want to look at whether the actual technology provider holds that certification themselves. If they don't and they're pretending they do, that's a really big flag, because it means they're aware of what they should be doing, they're not doing it, and they're deliberately making claims that mislead people who aren't well-versed in the space.

Let's start to wrap up with some quick reminders about secure use of Zanda. Some really basic things to check: make sure everyone has a unique user account. We don't charge for additional user accounts, and we do that on purpose so everyone can have their own login and credentials. Make sure you've got 2FA activated. Limit access, because you can customise exactly what people can see and do, and audit that periodically to make sure it makes sense for each person's role.

There's a privacy mode you can use if there's a risk of someone seeing your screen. You click a little button in the calendar and it hides all the appointment details. We've all had the situation where a patient leans over to look at the calendar because they're trying to find a gap, and there's that tendency for you both to look at the calendar together. I'm sure most people have had that experience and it's quite awkward. If you've got that scenario, or you need to step out of the room with the calendar up, you can lock it or turn privacy mode on and it hides all the identifying information.

Get rid of any unused accounts, and run periodic spot checks using the activity log. You can filter by user and check every now and again that what people are viewing makes sense and there isn't anything that looks a little odd. We all want to trust our staff, and 99 per cent of the time it's fine, but it's a good practice to do and to see if anything stands out as unusual. Anything else to add, Paul, before we finish up?

PAUL:

The unique accounts: simple, obvious, and it tracks who's doing what. We don't charge for it at all. We ourselves use software where they do charge by the account and it's really annoying. Security should not come at the expense of cost, and that's why we don't charge. So make as many user accounts as you have people who access it, and set up 2FA.

DAMIEN:

Absolutely. Now, a couple of announcements for Zanda. Some shameless plugs, but they are really useful things.

We've got the ideas board. This is relatively new and it's been a huge hit. If you log into your account and go to the help menu you'll see "submit an idea." That takes you to a board where you can see all the different ideas people are submitting and the feature requests. You can comment on them and add votes, so if you see something you really want you can add your vote, or you can add new ideas. We introduced this to be really transparent about what people are asking for, to give people a way of communicating with us. Our product team look at this every day, and every week it gets a review that feeds right into our roadmap.

PAUL:

We see a summary every day of all the activity on the ideas board. Every comment and every suggestion people have made comes through to Damien and myself, and we look at that formally, very regularly.

DAMIEN:

The success of Zanda, for those who've been with us for some time, is all based around listening to our customers and developing the things that are going to make the biggest difference. This is an extremely powerful tool for us to keep in touch, and for you to communicate directly with the product team and with us about what you're after. And you can all see how popular an idea is, which is what we're looking at as well.

We've also made it so you don't have to log in separately, because we wanted people to be able to just click through. You can go straight in and vote, and it automatically tracks that it came from you, so we can follow up. Sometimes we have questions about a feature or how you'd use it, and our product team will reach out for clarification. We've tried to make it as low friction as possible so you can really be part of that evolution process for Zanda.

We have the Zanda Academy, and if you haven't visited it, it's a really great place to get the most out of Zanda and train new team members. We have courses on there and we've had really good feedback. Again, relatively new, but if you want to get people up to speed on using Zanda, whether new team members or existing ones who want to get more out of it, jump on there.

And finally, one last shameless plug: we have a practice management book coming out, The Nine Secrets of Successful Health Practices. We've written a book capturing some of the key themes we see as commonalities that lead to success in health practice management and growth. That's coming out in the not too distant future, so we're starting to let people know about it.

If there's anything else we can help you with, you can contact us in a bunch of different ways: email, the website, and we've got live chat as well. There's also now the Practice Hive. If you click the little hive icon in the top menu of your Zanda account you can go in and see a whole bunch of things, including all the new releases we put out. I update this nearly every day when we're putting things out, so you can see what's new and what's happening. Lots of ways to get in contact and stay up to date.

Thank you very much for joining. Thank you, Paul, for sharing your expertise with us and with the Zanda family today. And thank you everyone for watching, do reach out if there's anything we can help with.

PAUL:

Thank you.