BCP: Cyber Defense Strategies for DMEPOS: What’s Your Plan?

This presentation outlines essential cybersecurity practices for DMEPOS facility owners and managers. It reviews common threats—including phishing, ransomware, malware, insider risks, and IoT vulnerabilities—and their impacts on patient data, finances, operations, and reputation. Key regulatory requirements such as HIPAA and HITECH will be covered, along with best practices like firewalls, antivirus tools, data encryption, and secure communication. Attendees will learn how to build a comprehensive cybersecurity strategy, conduct risk assessments, ensure secure data storage and backups, train staff, manage third‑party risks, and prepare incident response plans. The session also highlights emerging threats and innovative solutions to strengthen long‑term security.

Learning Objectives:

  1. Identify and assess cybersecurity threats — including phishing, ransomware, malware, and IoT vulnerabilities — that present operational and financial risk to DMEPOS businesses, and evaluate their potential impact on patient data security, revenue continuity, and organizational reputation.
  2. Apply regulatory compliance requirements (HIPAA, HITECH) to develop a comprehensive cybersecurity strategy for a DMEPOS facility, incorporating risk assessments, network security controls, secure data storage, incident response planning, and staff awareness programs aligned with business management best practices.
  3. Evaluate and manage third-party vendor risks and emerging cybersecurity threats — including AI-based attacks and advanced persistent threats — and formulate proactive governance strategies that protect business operations and support long-term organizational resilience within the O&P business environment. 

This is a Business Certificate Program elective under the Healthcare Operations pillar. Note: At the end of this course, you will receive a certificate for CE credit upon successful completion of the quiz.  Please note that is a certificate for CE credits only and not the IIOP and AOPA O&P Business Certificate. The IIOP and AOPA O&P Business Certificate requires enrollment in and successful completion of four AOPA electives (one from each pillar) and four IIOP core courses. Upon successful completion of the Business Certificate Program, AOPA will reach out to you about receiving your O&P Business Certificate. 

Individuals not participating in the AOPA and IIOP Business Certificate Program are still welcome to take this course for CE credit and/or educational purposes. If you have not expressed interest in the Business Certificate Program and would like to participate and use this course as one of the required electives, please email onlineeducation@aopanet.org. 

This content will not be available until 08/24/2026 at 12:00 AM (EDT)