July is our annual ACUF campaign for donations to help offset the cost of the board. Please click the link below for more details.
Amazing Charts User Forum Donation Campaign

Goal $650 Dollars
ACUF Campaign

July is our annual ACUF campaign for donations to help offset the cost of the board. Please click the link below for more details.

Most Recent Posts
Strangest Thing I Have Ever Seen
by beagle - 07/11/2025 2:29 PM
AC Billing Software
by Sabbath - 07/09/2025 9:53 PM
Full Visit Template
by Bert - 07/07/2025 6:45 AM
July Contribution
by Bert - 07/06/2025 4:38 PM
Can someone please tell me what is going on here!
by Shrinkrap - 07/04/2025 9:19 AM
Archiving Old Data Solution
by JamesNT - 06/28/2025 12:06 AM
Need Advice regarding Data Archiving
by JamesNT - 06/28/2025 12:06 AM
Member Spotlight
Bert
Bert
Maine
Posts: 12,888
Joined: September 2003
Newest Members
ozonr666, ESMI, It's me, Paradise Family, MedCode
4,595 Registered Users
Previous Thread
Next Thread
Print Thread
Rate Thread
Joined: Sep 2010
Posts: 369
Likes: 6
beagle Offline OP
Member
OP Offline
Member
Joined: Sep 2010
Posts: 369
Likes: 6
Trying to close security holes.

Running Windows 2012 r2 server. Workstations use Chrome browser. Staff inadvertently installs chrome browser extensions including shady redirecting ones. They do not have admin privileges.

How do I disable adding chrome extensions beyond the ones I choose? Group policy possible?


Larry
Solo IM
Midwest
Joined: Dec 2009
Posts: 1,201
Likes: 8
Member
Offline
Member
Joined: Dec 2009
Posts: 1,201
Likes: 8


James Summerlin
My personal site: http://www.dataintegrationsolutions.net
james@dataintegrationsolutions.net
Joined: Sep 2010
Posts: 369
Likes: 6
beagle Offline OP
Member
OP Offline
Member
Joined: Sep 2010
Posts: 369
Likes: 6
thanks i'll try it and report back!

knew i could count on the experts here.

i also bought chromebooks for the employees, all personal websurfing and email to be on those not the workstations. they are on the my office network, thoughts?


Larry
Solo IM
Midwest
Joined: Sep 2003
Posts: 12,888
Likes: 34
Member
Offline
Member
Joined: Sep 2003
Posts: 12,888
Likes: 34
Hi Larry,

A few thoughts. First, wow. Good for you. Many on here, and I understand will say do not let employees play with email and web surfing at all, but you do, so let's go with that.

I don't know if you are talking wireless or wired, but either way, I like this idea the best. Personally, I would make sure it is a COMPLETELY different network with a completely different subnet. Absolutely no way of someone hacking in. So, I am sure you have a modem connected to a router connected to a switch which supplies all of clients and server with connection to the network and Internet, etc.

You can get a small Netgear switch and connect the modem to that switch. Now run an Ethernet cable to your network router. You now have the same network you started with. Take another Ethernet patch cable, run it from the small switch to a router, which is going to be the router/firewall for the isolated network. You can connect that to a different switch to the Chromebooks or you can connect to one of the patch panels that runs to an Ethernet jack of your office, which could be wireless.

Yes, you could do a similar thing with a VLAN on your switch, separating the two. I just do it this way, because there is absolutely no way to get into my network this way.

One idea I will throw at you. I used to block the Internet with some very good software. I haven't lately. I use it for discipline, shutting it down for two days. No cell phones are allowed. I don't allow Facebook at all except lunch, and I do NOT allow personal email, mainly web mail such as Gmail.

I allow the use of personal email on Outlook ONLY. Only one employee abused it. The reason I do it this way is because my Exchange is set up for email accounts for each user. There is also an archive account, which gets a copy of any email going out/in or most importantly, between users in the office. The employees know, and it is written down, that the computers are the office's and all email belongs to the office and can be subject to inspection at any time. I don't look at it, but I can. I got burned once by an employee and a bogus harassment suit. One other employee tried to do the same, and there were quite a few emails from her to other employees and to friends about lying about it. Any deleted emails, besides being backed up, are always in the archives. They don't know that. Plus, while maybe not yet, many businesses such as banks, etc. are required by law to have backups of all emails. Having the archives set up is helpful. Just a thought.

The other thought is that with Exchange and using Outlook, all email is encrypted and at least going out, but all email in the office is HIPAA compliant, because it only runs over the network. Do you think that employees may write stuff about patients and then take them home or it be less secure?


Bert
Pediatrics
Brewer, Maine

Joined: Mar 2011
Posts: 837
Likes: 10
Member
Offline
Member
Joined: Mar 2011
Posts: 837
Likes: 10
We gave up on the ADSL from QWEST, and switched to Charter -- generally much better, but it has its own problems.
Kept QWEST as a backup, but now we use it for the employees and public browsing. Absolutely no connection to the office LAN.


Tom Duncan
Family Practice
Astoria OR
Joined: Jun 2009
Posts: 1,811
Member
Offline
Member
Joined: Jun 2009
Posts: 1,811
Originally Posted by beagle
thanks i'll try it and report back!

knew i could count on the experts here.

i also bought chromebooks for the employees, all personal websurfing and email to be on those not the workstations. they are on the my office network, thoughts?

what is optimal is to split the network at the provider device, e.g. cable-modem with a switch as Bert suggested.

a separate wifi router for staff personal use, patient use, along with activate hours (only usable during office hours) keeps folks from "riding" the public network off-hours. This model has worked well for the practices we have implemented.


Indy
"Boss"

Indy's Blog

www.BestForYourPractice.com
Our Name is Our Creed

Moderated by  ChrisFNP, DocGene, JBS, Wendell365 

Link Copied to Clipboard
2025 ACUF Annual July Contributions
Help fund this site.
ACUF Donation
ShoutChat
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Who's Online Now
0 members (), 51 guests, and 31 robots.
Key: Admin, Global Mod, Mod
Top Posters(30 Days)
Bert 11
beagle 4
ACZ 1
Top Posters
Bert 12,888
JBS 2,986
Wendell365 2,366
Sandeep 2,316
ryanjo 2,084
Leslie 2,002
Wayne 1,889
This board is dedicated to the memory of Michael "Indy" Astleford. February 6, 1961 -- April 16, 2019




SiteLock
Powered by UBB.threads™ PHP Forum Software 7.7.5