Tip: Do your research before your practice donates cash. Helping a worthy charity or bolstering a struggling community in the aftermath of a disaster is important. Charitable contributions promote the spirit of giving — and represent the foundation of the healthcare industry. However, not every email request is on the up-and-up, and that’s why it’s critical to do your homework before you give out sensitive practice information. Review: Dating as far back as Hurricane Katrina in 2005, the Federal Bureau of Investigation (FBI) started noticing fake websites and charities popping up after disasters. The scammers preyed on unsuspecting victims, stealing private data, according to a Department of Health and Human Services (HHS) Office for Civil Rights (OCR) Cybersecurity Newsletter report. In the wake of such terrible 2018 disasters as Hurricanes Florence and Michael and the California wildfires, covered entities (CEs) should prepare for social engineering schemes. Also, during the holiday season, when practices are more likely to have their guards down and give to charities, the activities of hackers and social engineers only increases. Consider this OCR advice before you donate and hand out credit card information and sensitive data: Reminder: “Social engineering tactics are designed to obtain secure information (login, customer, patient, or corporate data) by conning a person into revealing the information,” explains Michael Whitcomb, CEO of the IT security and regulatory compliance firm Loricca in Tampa, Florida. These types of attacks exploit the overly trusting nature of most people. But remember with a combination of training, concrete policies, and skepticism, social engineers can be stopped in their tracks. Resource: Review the OCR’s Cybersecurity Newsletter at www.hhs.gov/sites/default/files/august-2017-ocr-cyber-newsletter.pdf.