Security Advice
Here are some simple rules you should carefully follow when using your credentials:
- Safeguard your access credentials carefully, as they are strictly personal, and prevent third parties from gaining access to them.
- Do not write your access credentials visibly on documents that could be lost or stolen.
- Do not store your username and password in any browser you use on any of your access devices.
- Change your passwords periodically using a combination of numbers, letters, symbols, uppercase and lowercase characters, avoiding similarities with your username. In Administration > Users/Doctors, you can configure the security level of your credentials.
- Do not save your access credentials on your personal computer, smartphone, or tablet in unencrypted files.
- Never share your access credentials, not even in case of phone requests from third parties. No employee or collaborator of Ofimedic will ever ask you for your credentials.
- You will only need to enter your access credentials when you want to log into your environment via our website http://www.ofimedic.uk.
On your part, you can strengthen security by taking some simple precautions:
- We recommend that you always use a secure computer, tablet, or smartphone to connect to the Ofimedic website.
- When accessing Ofimedic over the Internet, make sure the address is http://www.ofimedic.uk.
- Avoid working from computers, tablets, or smartphones that you are not familiar with, such as those in Internet cafes or public access points.
- It is important that the computers used to connect to the Internet are adequately protected: we recommend periodically updating your computer, tablet, or smartphone by following these simple measures:
- Update the operating system
- Update the browser
- Update the antivirus software
- Use a personal firewall, if possible
Your session
When you finish using the Ofimedic internet services, it is advisable to log out of your session by clicking the Logout link.
If you have connected to Ofimedic via the mobile app, remember to always close it once you have finished your activities, so that if someone accesses your smartphone, they cannot enter without your credentials. Do not store your Ofimedic access credentials in any text file on your smartphone.
You can confidentially change your access credentials whenever you wish. We recommend changing your credentials at least every 3 months and whenever you have even the slightest doubt that someone may have gained unauthorized knowledge of them.
Most attacks occur during nighttime and on weekends, so we recommend configuring your team members'' access by granting data export permissions only to users who have antivirus or anti-malware systems installed. Additionally, you can configure which users can access the system outside or within working hours. Both configurations would prevent an attacker, in case of password theft, from accessing and exporting data at unusual times.
Multi-factor authentication (MFA)
Most unauthorized access to computer systems occurs because of stolen passwords. In the healthcare sector, a data breach is extremely serious due to the nature of the information involved, which implies a high level of risk and may lead to severe consequences, both financial and social. The fact that a doctor can access Cloud models from any computer means access outside the “secure environment” of their practice, medical centre or hospital.
Having MFA means:
- Blocking unauthorized access: a simple password is not enough against techniques such as phishing or credential theft. MFA adds an extra barrier that an attacker cannot overcome.
- Legal and regulatory compliance: handling sensitive information requires compliance with strict legislation (European GDPR) and sector regulations, and non-compliance carries severe penalties.
- Protection against ransomware: the healthcare sector is a prime target for cybercriminals. MFA prevents attackers from hijacking corporate networks, which could even put patients’ lives at risk through cancelled surgeries or equipment failures.
- Security in telemedicine: with the rise of remote consultations and hybrid working, MFA ensures that only authorised staff can access the centre’s networks from any location.
To limit this risk, in Ofimedic you should apply an authentication factor for:
- Access to Ofimedic
- Exports of data (only for users with privileges to do so)
This means that once one of the two previous actions has been performed, Ofimedic will request either a code sent to your email, to a mobile phone by SMS, or to both. You can choose which method to apply generally and also at user level so that each user has their preferred method. This is intended to ensure that, in the event of malicious access due to stolen passwords, attackers will neither be able to access the system nor export any data unless they also have access to the email account or mobile phone.
To make this possible, each system user must have:
- A unique email address that cannot be shared with other users of your Ofimedic
- A unique mobile phone number that also cannot be shared with other users of your Ofimedic
We are aware that applying these methods often causes some resistance among users, but they should remember that it will help them protect information, comply with current legislation, and be prepared for audits and certification processes.
Restrict access to working hours
Another recommended measure to protect the information stored in Ofimedic is to restrict access strictly to the doctor’s working hours. Most malicious attacks occur outside working hours, whether at night, on weekends or during holidays. If user access is limited to their working day, then in the event of stolen credentials, access to email, or mobile phone theft, the attacker will not be able to obtain the MFA keys and therefore will not be able to access the system.
