Help Me With HIPAA: Recent Episodes

Donna Grindle and David Sims

In today's environment of data breaches, identity theft, fraud, and increasing connectivity, HIPAA Privacy and Security rules are a responsibility to your patients and your clients. HIPAA isn't about compliance, it's about patient care.

View Details

Most organizations have an incident response plan, but how well would it hold up if your normal communication channels suddenly couldn't be trusted? In this episode, we dive into a nationwide healthcare cybersecurity exercise that challenged participants to think beyond compliance and technical defenses, exposing just how critical preparation, collaboration, and secure communication become during a large-scale cyber crisis. Along the way, a surprising real-world AI development reminds us that tomorrow's threats may arrive sooner than anyone expects.

More info at HelpMeWithHIPAA.com/572

View Details

Regulations may move at the speed of a sleepy turtle, but patient expectations certainly don't. As healthcare organizations wait to see what the final HIPAA Privacy Rule will include, there is a surprising amount of work that can, and should, already be underway. This episode explores the practical steps you can take now, the common misconceptions that continue to create confusion, and why preparing early is far less painful than trying to outrun an approaching compliance deadline. If you start getting your ducks in a row today, it just might save you from chasing them all over the parking lot tomorrow.

More info at HelpMeWithHIPAA.com/571

View Details

Cyberattacks are expensive—but just how expensive? This episode dives into a brand-new study that finally puts real numbers behind the financial impact of data breaches, using thousands of cyber insurance claims instead of scary headlines and wild guesses. From ransomware and business interruption to cyber insurance surprises, you'll discover why the biggest cost isn't always what you think. If you've ever wondered whether your organization is truly prepared for a breach—or just hoping insurance will magically save the day—this conversation is packed with practical insights, a few laughs, and plenty of reasons to take another look at your risk management strategy.

More info at HelpMeWithHIPAA.com/570

View Details

Think cybersecurity is all about how much money you throw at the problem? Think again. In this episode, we unpack the idea of the "cybersecurity poverty line" and why being under-protected isn't always about having an empty wallet. From outdated technology to missing expertise and leadership roadblocks, you'll discover why even organizations with healthy budgets can still leave the front door wide open to cybercriminals. If you've ever wondered whether your biggest security challenge is really your budget, or something else entirely, this conversation is for you.

More info at HelpMeWithHIPAA.com/569

View Details

If you’ve ever caught yourself saying, “We’re too small to be hacked,” or “That’s why we have cyber insurance,” you might want to keep reading. This episode shines a spotlight on five cybersecurity assumptions that seem perfectly reasonable – right up until they cost you time, money, or your sanity. From misplaced confidence in vendors to the myth that restoring your systems means the crisis is over, this conversation serves up practical reality checks with just enough humor to make the hard truths a little easier to swallow.

More info at HelpMeWithHIPAA.com/568

View Details

What do lava lamps, whoopee cushions, and HIPAA have in common? More than you’d think! This week, a familiar mall retailer famous for gag gifts and lava lamps finds itself at the center of an OCR enforcement action that highlights a common misconception about employer-sponsored health plans. Along the way, you’ll learn why “we’ve never had a problem before” isn’t a cybersecurity strategy, how self-funded health plans fit into HIPAA, and why ignoring compliance can quickly become a very expensive joke.

More info at HelpMeWithHIPAA.com/567

View Details

Ever wish you could get expert HIPAA advice straight from the source – without the invoice? This episode digs into a little-known offering: the “free consulting” that the Office for Civil Rights (OCR) actually gives out, if you know where to look. We break down the seven biggest lessons buried in official OCR videos and settlement guidance, covering everything from keeping tabs on your inventory (yes, all your data – even the digital version of an old truck growing weeds) to why risk management means more than doing paperwork once a year. If you’re in healthcare and want practical tips to avoid trouble before it makes the headlines, this episode’s for you.

More info at HelpMeWithHIPAA.com/566

View Details

Healthcare is rushing to adopt AI, but most organizations haven’t figured out what it really means to keep it in check. The HSCC just released an AI governance framework aimed at helping healthcare leaders get ahead of the curve—before “shadow AI” and unapproved tools turn into a bigger problem. This episode breaks down why AI governance isn’t just IT’s job, where most organizations are getting stuck, and the surprisingly simple questions privacy and compliance teams should be asking about AI before things go sideways.

More info at HelpMeWithHIPAA.com/565

View Details

AI isn’t just a buzzword anymore—it’s showing up everywhere in healthcare, whether you realize it or not. In this episode, we get honest about what it means to live and work with AI, why so many people still feel anxious (or even a little excited) about it, and why avoiding it altogether just isn’t an option. We dig into practical ways healthcare teams can safely experiment with AI in their daily routines, what to watch out for, and how the right approach can help you solve problems instead of just creating new ones. If you’ve been wondering how AI is changing the way you work—or if it really might replace your job—this one’s for you.

More info at HelpMeWithHIPAA.com/564

View Details

Are healthcare organizations overcomplicating cybersecurity and missing the basics? In this episode, Donna and David break down the newest Verizon Data Breach Investigations Report and what it really means for hospitals, clinics, and business associates. Despite all the AI headlines and talk about new threats, most breaches still come down to old-school problems—missed patches, credential abuse, and human mistakes. The fundamentals aren’t glamorous, but they’re what keep your data safe. If you’ve ever wondered whether all the new risks really change the game for HIPAA compliance, this episode will help you cut through the noise and focus on what actually matters.

More info at HelpMeWithHIPAA.com/563

View Details

How much should we really trust the systems and people we rely on every day? This week, we’re looking at how trust itself can open the door to risk – whether it’s attackers using AI to speed up finding software flaws, insider threats turning frustration into vulnerability, or the limits of encryption we thought was unbreakable. As healthcare organizations try to keep up, these aren’t just tech problems – they’re operational headaches and policy questions that hit close to home. And yes, the pace of change is only picking up.

More info at HelpMeWithHIPAA.com/562

View Details

AI is showing up everywhere these days like ketchup at a backyard cookout — apparently it belongs on absolutely everything. But as this episode points out, tossing AI into healthcare operations without governance is basically just upgrading your chaos to premium speed. Using insights from a massive global digital health study, the conversation explores why leadership, oversight, and workforce engagement still matter far more than simply throwing AI, cloud apps, and a little “digital transformation seasoning” on every problem. From forgotten integrations and mystery AI tools to the hard truth that automating a bad process just gives you faster bad results, this episode delivers equal parts practical strategy, healthcare reality checks, and painfully accurate tech humor.

More info at HelpMeWithHIPAA.com/561

View Details

Cybercrime has officially entered its “hold my beer” era. In this episode, we break down the FBI’s annual Internet Crime Complaint Center report and the numbers are equal parts fascinating and horrifying. We’re talking over $20 billion in reported losses, exploding ransomware attacks, AI-powered scams, fake charities, romance cons, business email compromises, and criminals who apparently work harder than some middle managers. It’s a practical, eye-opening look at how modern scams actually work — and why staying skeptical online may now qualify as a survival skill.

More info at HelpMeWithHIPAA.com/560

View Details

If you’ve ever wondered what happens when ransomware, bad decisions, cyber insurance confusion, and TikTok tech advice all collide in one spectacular dumpster fire… this episode is for you. The conversation dives into four fresh OCR enforcement actions that all share one painfully common theme: nobody did a proper risk analysis until after everything caught on fire. Add in cybersecurity “professionals” secretly helping ransomware gangs and business owners trying to replace enterprise security tools with AI-generated software from TikTok, and you’ve got an episode that somehow manages to be both educational and deeply concerning.

More info at HelpMeWithHIPAA.com/559

View Details

AI isn’t coming – it’s already here, quietly working behind the scenes, updating itself, and occasionally making decisions you didn’t realize you outsourced. In this episode, we unpack the chaos (yes, chaos) of modern AI adoption, especially when it sneaks in through third-party vendors and tools you already use every day. Think less “cool futuristic tech” and more “did we just pour gasoline on our existing risks?” If you’ve ever wondered whether you’re actually using AI… spoiler alert: you are.

More info at HelpMeWithHIPAA.com/558

View Details

Ever leave a conference with a notebook full of “wait…we should probably be doing that” moments? That’s exactly the energy here. In this episode, we unpack key takeaways fresh from the HIPAA Summit - what stood out, what raised eyebrows, and what might quietly keep compliance folks up at night. Then we pivot into a timely breakdown of the latest OCR webinar on Risk Management Plans, connecting the dots between what’s being said on stage and what’s expected in practice. Think of it as part field report, part reality check.

More info at HelpMeWithHIPAA.com/557

View Details

If you thought healthcare had enough to juggle already, think again. This episode dives headfirst into the latest “Top 10 Patient Safety Concerns,” and spoiler alert—AI is sitting right at the top like it owns the place. From the growing pains of AI-assisted diagnosis to the not-so-small issue of whether anyone is double-checking the robots, things get interesting fast. Toss in cybersecurity risks, workforce shortages, and a system stretched thinner than your patience on hold with tech support, and you’ve got a conversation that’s equal parts eye-opening and “wait… are we okay?”

More info at HelpMeWithHIPAA.com/556

View Details

Let’s be honest – most of us treat our home router like a mysterious appliance that just… works. Plug it in, forget about it, and hope the internet gods stay happy. But what if that “set it and forget it” mindset is exactly the problem? With outdated firmware, questionable manufacturing origins, and zero attention for years, your router could be the weakest link in your entire digital life. And yes, that includes your work-from-home setup, your smart devices, and pretty much everything else connected to it.

More info at HelpMeWithHIPAA.com/555

View Details

Sometimes the biggest threat to your data isn’t the hackers, it’s what happens after the hackers leave. In this episode, we dive into a jaw-dropping case where 15 million patient records were exposed… and then quietly swept under the rug like a mess nobody wanted to deal with. Spoiler alert: ignoring a breach doesn’t make it disappear, it just makes the consequences louder later. If you’ve ever wondered how bad things can get when vendors drop the ball, this one’s a wild ride.

More info at HelpMeWithHIPAA.com/554

View Details

Imagine logging in one morning and - poof - everything’s gone. Not locked, not held hostage… just gone. That’s the kind of cyberattack making waves right now, and it’s not your typical “pay me in Bitcoin” situation. In this episode, we unpack the Stryker cyberattack, a real-world incident that shows how attackers are shifting from making money to making a mess, and why that should have everyone in healthcare (and beyond) just a little more on edge.

More info at HelpMeWithHIPAA.com/553

View Details

Cybersecurity awareness is at an all-time high… so why are we still clicking the same sketchy links like it’s a hobby? In this episode, we dig into the uncomfortable truth: people know what to do, they just don’t do it. Between overwhelming workloads, nonstop digital noise, and a growing sense that “it’s inevitable anyway,” security has turned into that thing we all agree is important—right before we ignore it to get our jobs done faster.

More info at HelpMeWithHIPAA.com/552

View Details

If you think a risk analysis is just another box to check on the HIPAA compliance to-do list, this episode might feel a bit like a reality check… with receipts. Using a real OCR settlement involving a phishing attack and nearly 2,000 patients’ data, this discussion digs into what regulators actually expect when they say “risk analysis.” Spoiler alert: it’s a lot more than running a quick scan and calling it a day.

More info at HelpMeWithHIPAA.com/551

View Details

Governance, Risk, and Compliance. Sounds official. Sounds structured. Sounds like you’ve got everything under control. But what if you’ve really just got the “R” and the “C” duct-taped together while governance is off somewhere on vacation? This episode breaks down why governance isn’t just policies, committees, or fancy tools—it’s the backbone that makes risk management and compliance actually work. If you’ve ever said, “We’re doing security,” but can’t quite prove who decided what, who owns it, or whether it actually got done… this one’s for you.

More info at HelpMeWithHIPAA.com/550

View Details

At first glance, these sources don’t seem related. But when you connect them, they reveal a pattern we can’t afford to ignore — and it’s more unsettling than most of us would like to admit. It’s time for an honest, slightly uncomfortable conversation about where we are — and maybe to sit down and remember what mom and dad always said about choices and consequences… even if we really didn’t want to hear it.

More info at HelpMeWithHIPAA.com/549

View Details

Cybersecurity advice is everywhere — frameworks, standards, best practices, expert opinions — enough PDFs to last you the rest of the year. But for small and mid-sized businesses, the real question isn’t “What guidance exists?” It’s “What should we actually do that lowers our chances of having a really bad cyber day?” If you’ve ever looked at a massive cybersecurity framework and thought, “This feels like studying for a final exam I didn’t sign up for,” you’re not alone. That’s where CISA’s updated Cybersecurity Performance Goals (Version 2.0) come in. Designed to be practical, prioritized, and actually usable, this streamlined approach may be the clearest cybersecurity foundation SMBs have seen yet. In this episode, we break down what changed, why it matters, and how to use it.

More info at HelpMeWithHIPAA.com/548

View Details

What happens when the company responsible for protecting everyone else becomes the one that gets hacked? Spoiler alert: it’s not just their problem. This episode dives into the uncomfortable reality that when an IT provider gets hit, the ripple effects can slam into hundreds, or even thousands, of businesses at once. From ransomware evolution to insider threats to the ever-growing AI wildcard, this conversation pulls back the curtain on why cybersecurity isn’t just an IT issue… it’s everyone’s issue.

More info at HelpMeWithHIPAA.com/547

View Details

Some things in life have a finish line. Cybersecurity is not one of them. There’s no victory lap, no tape to break, and definitely no moment where you can say, “Cool, we’re done here.” This episode dives into why cybersecurity is a never-ending process, what regulators are really telling organizations through their guidance, and how the most common security failures still come down to the basics—patching, cleaning up old systems, and actually paying attention. If you’ve ever hoped you could “set it and forget it” with security, this conversation explains why that mindset is exactly what gets people into trouble.

More info at HelpMeWithHIPAA.com/546

View Details

AI: the gift that keeps on glitching. While most folks are still marveling at how AI can write emails and fold laundry (okay, not quite yet), this episode pulls back the curtain on what happens when artificial intelligence stops being polite and starts getting dangerous. We're talking zombie agents, security holes big enough to drive a HIPAA violation through, and automated tools that might just be a little too eager to help. It's informative, a little terrifying, and more than a few chuckles along the way.

More info at HelpMeWithHIPAA.com/545

View Details

You’d think the folks steering the cybersecurity ship would be the last ones to punch holes in the hull—but nope, even the pros trip over their own policies. In this episode, we dive headfirst into a cautionary tale where a CISO (yes, the security guy) admits to becoming the insider threat he warns others about. From skipping his own software vetting procedures to triggering network alarms like it’s the 4th of July, this story is equal parts cringe and crucial. Strap in as we explore how even the most iron-clad experts are still deliciously human.

More info at HelpMeWithHIPAA.com/544

View Details

Just because your smart fridge can order milk and your thermostat knows when you're chilly doesn’t mean your home network is safe from cyber shenanigans. In this episode, we’re roasting the myth that five-star Amazon reviews mean airtight security, dragging lazy VPN habits, and exposing how your toddler’s tablet might be the real Trojan horse in your living room. From forgotten firmware to doorbells that moonlight as spies, we’re pulling back the Wi-Fi curtain on all the ways your devices could be betraying you—with or without your permission.

More info at HelpMeWithHIPAA.com/543

View Details

Ever wonder what happens when patient record requests are ignored, invoices go wild, and cybersecurity takes a coffee break? Spoiler: it ends with lawsuits, settlements, and a whole lot of legal back-and-forth. In this episode, we unpack a right of access case that dragged on longer than a season of courtroom drama, and then dive into the spaghetti mess of post-breach chaos - where class action lawsuits spring up like mushrooms and documentation (or lack thereof) can make or break you. If you thought the breach was the worst part… oh honey, it’s just getting started.

More info at HelpMeWithHIPAA.com/542

View Details

Here’s the deal: making predictions about 2026 is about as useful as a chocolate teapot. So instead of peering into a cloudy crystal ball, we’re laying down some solid groundwork for planning ahead. We’re talking AI governance, backup strategies that actually work (yes, tested ones), and why you should absolutely know if your vendor quietly stopped signing BAAs. Buckle up—it’s a 2026 survival guide with fewer guesses and more “you got this.”

More info at HelpMeWithHIPAA.com/541

View Details

It’s that time of year again where audio perfection goes to die and chaos reigns supreme! In this special episode, we celebrate ten years of podcasting excellence by showcasing the exact opposite: dogs with digestive drama, countdowns that never count down quite right, rogue microphones, clumsy kitchen accidents, and travel mics that seem personally offended by their own existence.

Expect Donna’s thumb to take a hit (thanks, chef’s knife), David to escape suspicion of living off the grid, and Bojan to quietly question all his life choices while trying to make this circus sound good from across the ocean.

More info at HelpMeWithHIPAA.com/2025BlooperShow

View Details

You know that warm fuzzy feeling you get thinking AI will solve all your business problems and let you retire early? Yeah, this episode is the cold shower you didn’t know you needed. We’re talking about why most AI projects crash harder than a Segway on launch day, how businesses keep falling into the same traps, and why treating AI like a superpowered intern (instead of your replacement) might be the smarter move.

More info at HelpMeWithHIPAA.com/540

View Details

Adulting is hard — but digital adulting? That’s a whole new level of chaos. In this episode, we dive headfirst into the “Most Wired” survey like it’s a techie BuzzFeed quiz for healthcare organizations. From cyber headaches and budget excuses to AI hype and “we’ve always done it this way” energy, we unpack the nine domains that determine whether your digital health game is fire… or just floppy disk-level tragic.

More info at HelpMeWithHIPAA.com/539

View Details

Ever wondered what really keeps the Internet running - and what happens when it all goes sideways? The latest Cloudflare outage served up a reality check, exposing just how much of our digital world hangs together with a mix of duct tape, toothpicks, and a whole lot of hope. In this episode we dive into how this outage sent shockwaves through everything from simple website clicks to healthcare payment systems, and why most folks had no idea Cloudflare was even a linchpin for their daily operations.

More info at HelpMeWithHIPAA.com/538

View Details

If you thought AI in healthcare was just about cool robots and faster diagnoses, surprise! There's a whole army of volunteers wrangling the chaos behind the scenes, and our own Donna Grindle is leading the charge. In this episode, we take a peek into the AI cyber-security kitchen of the Health Sector Coordinating Council, where they’re cooking up definitions, glossaries, and playbooks faster than AI can generate cat videos. It’s education, governance, and cyber-risk planning, all served with a side of snark and sincerity.

More info at HelpMeWithHIPAA.com/537

View Details

You thought phishing was just an email problem? Oh sweet summer child. This episode dives into the new frontier of cyber shenanigans: LinkedIn. That’s right — the land of business jargon, inspirational posts, and awkward endorsements is now a playground for scammers sliding into your DMs like they’re networking for the dark web. Get ready to learn why accepting that too-good-to-be-true board invitation from “a company in South America” might end with malware, not margaritas.

More info at HelpMeWithHIPAA.com/536

View Details

Welcome to the latest Help Me With HIPAA episode where healthcare becomes the star of a suspense thriller, except the villains are hackers, and the plot twist? They really don't care how small your practice is. We’re diving into Huntress’ 2025 Cyber Threat Report, which basically confirms that if you're in healthcare, you’ve got a giant “Hack Me” sign taped to your digital forehead. From script-based exploits to info stealers with boundary issues, this episode breaks down how cyber threats are no longer knocking on the front door - they’re already on the couch, eating your snacks, and stealing your patient data.

More info at HelpMeWithHIPAA.com/535

View Details

If you've ever wanted to throw your laptop out the window after yet another “Your password must include a hieroglyph and a drop of unicorn blood” message, you're not alone. In this episode, we tackle the chaotic circus that is password creation: the rules, the myths, and the mounting frustration of trying to remember if this is the account that wanted a number, a symbol, or your firstborn’s dental records. From the rise of passkeys to the surprising sanity of NIST’s latest guidance (finally!), we explore how security might actually be getting smarter and less likely to make you cry into your keyboard.

More info at HelpMeWithHIPAA.com/534

View Details

If you thought your Halloween playlist peaked at “Monster Mash,” get ready to level up with the Data Mash — a graveyard splash of spooky cybersecurity tales and ghastly good rhymes. In this special Halloween episode, we summon the spirits of password poltergeists, resurrect dusty old policies from the crypt, and stir up a bubbling MFA cauldron. It's cybersecurity with a spooky twist, and yes, there’s even a ransomware reaper lurking around with backup regrets. Boo and boo-hoo for bad data hygiene!

More info at HelpMeWithHIPAA.com/533

View Details

Welcome to the digital Twilight Zone, where AI is evolving faster than your weekend plans, and people are still out here using "password123!" like it's a life hack. This episode digs into the “Oh, Behave!” cybersecurity behavior report and asks the big questions: Why do we keep doing dumb things online? Can training catch up with tech? And why are Gen Zs so confident while also being the most hacked? Spoiler: it's equal parts fascinating and terrifying.

More info at HelpMeWithHIPAA.com/532

View Details

Ah, success stories—where marketing meets warm fuzzies… and sometimes federal investigations. This week, we’re dissecting how one healthcare group turned a few heartfelt patient testimonials into a compliance catastrophe. From missing consent forms to deleting everything in a panic, it’s a cautionary tale of what happens when your privacy policies are more like “guidelines” than rules. Spoiler: OCR reads your website too.

More info at HelpMeWithHIPAA.com/531

View Details

Is it still a lie if it’s only half false? Asking for a biotech company that might’ve taken “fake it till you make it” a bit too literally with their cybersecurity claims. From hard-coded admin credentials to ignoring vulnerabilities like a bad ex’s texts, this episode dives into what happens when convenience beats caution and how a $9.8 million lesson got served with a side of whistleblower justice.

More info at HelpMeWithHIPAA.com/530

View Details

Welcome to “Digital Jenga,” where the tower’s made of cloud apps, power cords, and fragile backup plans and every pulled piece brings us closer to chaos. Today’s episode is a thought experiment that feels a little too real: What happens when everything goes down but your stress levels? Grab your imaginary generator and follow along as we walk through scenarios that are way more common (and hilarious) than you'd think, because nothing says fun like discovering your entire system was balancing on one Wi-Fi signal and a prayer.

More info at HelpMeWithHIPAA.com/529

View Details

If your small business still thinks that a dusty old firewall and a sprinkle of MFA is “good enough,” this episode is your cybersecurity reality check. Picture your company as a lemonade stand with a cash box—hackers are thirsty, and you’re wide open for business. We’re diving into why SMBs are now hacker playgrounds, how AI is helping cybercriminals get sneakier, and why your robot vacuum may be more security-conscious than your network gear. It's everything you didn’t want to know about being a prime target—served up with a twist of humor, a splash of horror, and a tall glass of truth.

More info at HelpMeWithHIPAA.com/528

View Details

Ever feel like your tech stack is one shady character away from becoming a security nightmare? Yeah, same. In this episode, we dive headfirst into the murky waters of “breach by association,”where trusting one tool can accidentally invite the entire cybercriminal neighborhood into your data party. From APIs doing the digital equivalent of handing out spare keys, to sneaky GitHub repos spilling secrets like a leaky faucet, we unpack how this all went down. Spoiler: the AI-powered thieves were way too polite to trip any alarms.

More info at HelpMeWithHIPAA.com/527

View Details

So you thought AI was just here to help you write emails and generate cat memes? Think again. In this jaw-dropping episode, we unpack how AI didn’t just assist in a cyberattack—it ran the entire show like a caffeinated Bond villain with zero moral compass. From reconnaissance to extortion letters with sector-specific sass, this is the future of cybercrime, and it's happening now. Buckle up. The robots aren’t just coming—they’ve already clocked in.

More info at HelpMeWithHIPAA.com/526

View Details

Forget Mission: Impossible-style hacking - today's cyber crooks are all about manners. In this episode, we unravel how asking “pretty please” can crack open digital doors faster than any brute force attack. With tips, tales, and a touch of panic, we break down the importance of knowing your personal risk profile, locking down your accounts, and yes - finally turning on that MFA you've been ignoring.

More info at HelpMeWithHIPAA.com/525

View Details

If you thought HIPAA only applied to big hospitals and medical groups swimming in patient data, think again. In this episode, we uncover how just one record with PHI can infect your organization with full-blown HIPAA responsibilities — no vaccine required. We dive into a juicy enforcement case featuring a CPA firm that got hit with a ransomware attack and a $175K HIPAA oopsie, all because someone skipped their security risk analysis. Spoiler: ignorance is not immunity.

More info at HelpMeWithHIPAA.com/524

View Details

Strap in, folks—this episode charges into the wild frontier of cybersecurity, where Shadow AI runs loose like a toddler with admin access. Whether your security plan is airtight or held together by paperclips and prayers, this deep dive into the IBM Cost of a Data Breach 2025 report offers plenty to think about. From eye-popping breach costs to the cringe of unsecured AI, we’re covering the good, the bad, and the downright reckless. Spoiler: "we don’t use AI" might be the biggest myth since "the check’s in the mail."

More info at HelpMeWithHIPAA.com/523

View Details

You might think a single ransomware attack is just a tech hiccup—but tell that to the medical practice that shut its doors permanently because of one. In this episode, we dissect what really happens when cybersecurity goes sideways, peeling back the layers of tech jargon to expose the raw, messy fallout of a breach. It’s less “oops, I forgot my password” and more “goodbye, 12 years of business.” Let’s get real about what these incidents cost—not just in dollars, but in dignity.

More info at HelpMeWithHIPAA.com/522

View Details

What do hackers, patient scams, and IT help desks with too much trust have in common? They're all making healthcare cybersecurity a lot messier—and a lot more vomit-worthy. In this episode, we dive into how bad actors are not only stealing data but turning patients into direct targets. From sneaky social engineering tactics to “I can’t believe they answered that call” level IT fails, we explore why locking down your network is only half the battle.

More info at HelpMeWithHIPAA.com/521

View Details

If you thought AI was just about asking ChatGPT for dinner ideas, think again. This episode unpacks the next-level madness of agentic AI—those industrious bots that not only check your emails but might just decide how your healthcare practice runs. We’re talking phishing attacks on steroids, decision-making algorithms with questionable judgment, and the jaw-dropping ways AI is working for—and against—us in cybersecurity. It’s part fascinating, part terrifying, and 100% worth listening to.

More info at HelpMeWithHIPAA.com/520

View Details

You know that moment when someone casually slides a contract across the table and says, “Just sign here”? Yeah, don't do that—especially when it's a Business Associate Agreement. This episode is a deep dive into the dark corners of BAAs, the traps they hide, and why you should read every line like it’s a ransom note. From ping floods to passive-aggressive breach clauses, we unpack the weird, wild world of healthcare contracts. Oh, and stick around—because just when you think it can’t get any messier, a breach shows up to ruin everyone’s day.

More info at HelpMeWithHIPAA.com/519

View Details

Think cybersecurity laws are just for the big guys? Think again. In this episode, we unravel the patchwork of new state regulations popping up faster than a phishing scam in your inbox—Ohio, Utah, Texas, Florida, and even Iowa are throwing their hats into the compliance ring. From safe harbor perks to tiered requirements for small businesses (yes, Texas made a flowchart-worthy version), we decode what these laws mean, who they apply to, and why HIPAA entities seem to always get the “you’re fine, probably” treatment. Bonus: there's a federal bill in Congress that might actually help. Maybe.

More info at HelpMeWithHIPAA.com/518

View Details

Strap in, folks—this isn’t your average cybersecurity snoozefest. We're plugging into a conversation with Greg Garcia, the guy who's been leading healthcare's cyber crusade like it’s the season finale of a medical drama. From hospitals fending off ransomware to the chaotic ballet of patching ancient medical devices, it’s clear: in a world where tech keeps patients breathing, cyber safety is patient safety. And no, turning it off and on again won’t fix this one.

More info at HelpMeWithHIPAA.com/517

View Details

If you thought “One Phish, Two Phish” was a Dr. Seuss classic, think again—this cybercrime edition comes with a twist of ransomware, app-specific passwords, and a side of website hijacking. This week, we explore what happens when software vendors forget to patch, hackers start crafting emails better than your favorite copywriter, and your website becomes a party zone for malware. It’s an episode full of lessons, laughs, and mild panic—just the way we like it.

More info at HelpMeWithHIPAA.com/516

View Details

If you’ve ever wondered what happens when “going viral” meets “losing your license,” this episode has the answer—courtesy of a nurse who took her TikTok dreams a little too far. From cringe-worthy compliance blunders to Oklahoma’s oddly refreshing legal update, we’re diving headfirst into the murky waters of healthcare privacy, social media madness, and why reasonable security might just be your get-out-of-court-free card. It’s like HIPAA meets reality TV—minus the roses and dramatic exits.

More info at HelpMeWithHIPAA.com/515

View Details

This week on “Things That Make You Go Hmm,” we’re serving up a digital cocktail featuring disappearing network routes, dark web AI tools with a flair for phishing, and Microsoft’s bold new idea to let Copilot tinker with your system settings—what could possibly go wrong? In this episode, we dissect digital disasters and marvel at how event planners might just be outdoing some organizations when it comes to risk assessments. It’s equal parts facepalm and fascinating.

More info at HelpMeWithHIPAA.com/514

View Details

You’ve heard of phishing scams, ransomware, and all the usual cyber villains—but have you prepared for the wrath of a squirrel? In this episode, we unpack how one fuzzy-tailed offender knocked out power to 11,000 customers and sent a swim club scrambling for pencils and paper. But this isn’t just a woodland horror story. It’s a real-world reminder that sometimes, your biggest threat isn’t a hacker—it’s Alfred the squirrel with a death wish and a talent for circuit boards. We use this nutty incident to highlight the often-overlooked need for utility failure preparedness in healthcare and dig into the super-helpful (and criminally underused) ASPR TRACIE tip sheets that can keep your operations steady when nature gets twitchy.

More info at HelpMeWithHIPAA.com/513

View Details

Welcome to another episode where chaos meets cybersecurity and common sense tries to crash the party. In this digital drama, we’re untangling the curious case of a former employee with way too much access, some mysterious printed medical records, and a whole lot of "Wait... WHAT?!" moments. We also dive into the thrilling (read: terrifying) reality of outdated edge devices and how your trusty old router might just be moonlighting as a hacker’s BFF. Oh, and spoiler alert—Microsoft Recall still isn’t winning any popularity contests.

More info at HelpMeWithHIPAA.com/512

View Details

Ever wonder what would happen if a hacker walked right into your digital living room, kicked off their shoes, and hung out for three months without anyone noticing? This week’s episode dives into a jaw-dropping CISA Red Team Assessment that reads like a cybersecurity horror flick—complete with ignored alarms, forgotten passwords, and an open-door policy for digital intruders. It's not just about tech failures; it’s a full-blown case study in what happens when leadership decides “meh” is a strategy.

More info at HelpMeWithHIPAA.com/511

View Details

Let’s face it — if healthcare had a dollar for every time someone said “we need another webinar,” it might actually be able to afford cybersecurity upgrades. This episode takes aim at the overload of online presentations and instead shines a light on what healthcare providers actually need. We unpack the findings of a critical report on the unique cybersecurity challenges facing small and rural healthcare providers, who are often running on shoestring budgets, outdated tech, and a whole lot of crossed fingers.

More info at HelpMeWithHIPAA.com/510

View Details

When a cybersecurity CEO strolls into a hospital and decides to play malware magician with a couple of unlocked computers, you've got yourself a plot twist worthy of a Netflix docuseries. In this episode, we dive headfirst into bizarre breaches, finger-pointing fiascos, and the kind of contractual confusion that’ll make you want to reread your SLAs before breakfast. It’s a rollercoaster of responsibility, reputation, and really bad behavior. But at the heart of it all is the million-dollar question: who’s actually responsible when it all goes sideways?

More info at HelpMeWithHIPAA.com/509

View Details

Healthcare still has a giant “Hack Me” sign taped to its back — and the latest reports from Mandiant and Verizon are here to confirm it. These cybercrime breakdowns reveal that attackers are smarter, sneakier, and spending more time poking around your network than ever before. Waiting to secure your systems until after a breach is like installing a smoke detector after the house has already burned down — by the time you smell smoke, it’s too late. From dwell times that feel more like extended Airbnb stays to small businesses learning that “we’re too small to target” isn’t a strategy, the findings hit hard and the lessons come wrapped in some well-placed snark.

More info at HelpMeWithHIPAA.com/508

View Details

If the Ponemon study were a horror flick, it’d be titled "The Login Came from Inside the System." This week’s episode dives into the alarming trend of organizations handing out privileged access like Halloween candy — only to forget who’s still got it long after the party’s over. With 59% of breaches linked to insiders or third parties, and executives confidently sailing past the iceberg of reality, we explore what happens when no one’s really sure who can still get into the network. Spoiler alert: it’s not good. So grab your flashlight and audit logs — we’re heading into the haunted house of unrevoked access.

More info at HelpMeWithHIPAA.com/507

View Details

Turns out, “they got hit, they just didn’t tell you” isn’t just a snarky title—it’s a terrifying reality. The Black Fog report basically says, “Hey, the cybersecurity iceberg is way bigger below the surface.” From undisclosed data heists to the rapid rise of ransomware attacks, this is your reminder that you don’t want to be the next plot twist in a cyber thriller. Oh, and yeah... shadow AI is watching too. Sleep tight!

More info at HelpMeWithHIPAA.com/506

View Details

Imagine your hospital gets hacked—the MRIs are down, billing’s frozen, and suddenly you’re faxing patient records like it’s 1999. No, that’s not a “Twilight Zone” rerun—it’s real life in health care. This week, we’re diving into what the Health Sector Coordinating Council (HSCC) is doing about it, including their recent trip to Congress to lay it all out. From legacy devices clinging to life like old Tamagotchis to cybersecurity plans that don’t sound half bad, we break it all down with just the right amount of snark.

More info at HelpMeWithHIPAA.com/505

View Details

Forget action-packed heist movies — the real cybersecurity heroes are the ones making their auditors yawn. In this episode, we break down why "boring and patched" should be everyone's new life goal. From AI developments that won’t sit still for five minutes to real-world cyber drama featuring surprise FBI visits (no popcorn needed), we’re serving up a crash course in staying safe, sane, and just boring enough to avoid disaster.

More info at HelpMeWithHIPAA.com/504

View Details

AI in healthcare is kind of like an overenthusiastic intern—it’s full of potential, but someone probably should be watching it a little closer. In this episode, we dive into why artificial intelligence might be more “oops” than “awesome” when it comes to patient safety. A recent ECRI report flagged AI as a top safety concern and offered up smart recommendations like stronger governance and better training. From glitchy decision-making to eyebrow-raising cybersecurity breaches, we’re unpacking why AI still needs some serious adult supervision in the healthcare world.

More info at HelpMeWithHIPAA.com/503

View Details

Think your once-a-year vulnerability scan is enough? That’s adorable. Waiting to check your security metrics until something goes wrong is like only checking your smoke alarm after the house starts smelling like burnt toast. In this episode, we peel back the layers on the top 10 security and privacy metrics every business should be tracking—whether you're the CEO, the IT person, or just someone who knows how to find the printer on the network. From patch management and MFA to phishing tests and forgotten routers older than your intern, we’ve got it all. Buckle up and get ready to verify like your digital life depends on it—because it kinda does.

More info at HelpMeWithHIPAA.com/502

View Details

Buckle up, folks—this episode is a rollercoaster of cyber chaos! We kick things off with a quick chat about the upcoming PriSec Boot Camp (because let’s be real, who doesn’t love a good security boot camp?). But then, we dive headfirst into the madness: a fresh HIPAA smackdown over right-of-access failures, a rogue IT guy who locked down an entire company out of revenge, and some seriously sketchy Bluetooth vulnerabilities that could have hackers eavesdropping on your life. And if that wasn’t enough, the 2025 SonicWall Cyber Threat Report drops some terrifying stats on ransomware, business email compromise, and how AI is making cyberattacks even more dangerous. Grab your tinfoil hat and let’s get into it.

More info at HelpMeWithHIPAA.com/501

View Details

500 episodes. A whole decade. Countless cybersecurity threats (and just as many dad jokes). Somehow, we’re still talking about the same cybersecurity nightmares—only now with fancier threats and AI-powered scams. In this milestone episode of Help Me With HIPAA, we take a trip down memory lane—reminiscing about our early struggles, the evolution of security risks, and why some lessons seem to need repeating... forever. Spoiler alert: bad guys are still bad, security is still hard, and if you’ve been with us since episode one, you’re officially a HMWH OG. If you’re new here, welcome—just know that staying out of breaches is a marathon, not a sprint.

More info at HelpMeWithHIPAA.com/500

View Details

Cybersecurity: It’s like flossing—we all know we should do it, but a shocking number of people just…don’t. This week, we’re digging into the annual cybersecurity attitudes and behaviors report, which reveals just how careless people are with their passwords, personal info, and, well, basic online survival skills. But don’t worry, AI is here to save us! Or, possibly, to make things even worse. We’ll also explore how AI tools are being used (and misused), and why a scary number of people are feeding them sensitive work info like it’s a buffet. Buckle up—this one’s got some eye-opening stats!

More info at HelpMeWithHIPAA.com/499

View Details

Cybersecurity report cards are in, and let’s just say—most companies would be grounded if their IT security grades were real school grades. With over 80% of Fortune 500s scoring a D or F, and healthcare companies hovering around the danger zone, it's clear that many organizations are securing data about as well as a cardboard vault. Just ask Warby Parker, which racked up multiple breaches over the years while seemingly skipping Cybersecurity 101. In this episode, we break down what these cybersecurity scores mean, how they were calculated, and what companies should be doing before they end up in the digital hall of shame.

More info at HelpMeWithHIPAA.com/498

View Details

AI just leveled up, and we’re here to talk about it! In this episode, we dive into DeepSeek—the AI model that shook up the stock market, gave OpenAI a run for its money (literally), and is both insanely cheap to run and totally open-source (which is equal parts exciting and terrifying). We also break down the rise of deepfake scams, AI’s growing role in cybersecurity, and why you should probably question everything you see and hear online. If you love tech, security, and a healthy dose of paranoia, buckle up—this one’s for you!

More info at HelpMeWithHIPAA.com/497

View Details

Imagine leaving your front door wide open in a neighborhood full of burglars, then acting shocked when your TV disappears. That’s basically what’s happening in healthcare cybersecurity. This week, we’re talking about why hackers are running rampant, how small healthcare practices are prime targets (no, you’re not “too small to matter”), and what basic security steps can actually make a difference. Spoiler alert: Ignoring the problem won’t make it go away.

More info at HelpMeWithHIPAA.com/496

View Details

If you’ve ever wondered what it’s like to scream into the cybersecurity void, this episode might feel oddly relatable. We dive into why “bare minimum” isn’t a security strategy—it’s more like playing Russian roulette with your data. From regulatory head-scratchers to the harsh reality that a “bare minimum” security strategy is about as effective as locking your front door while leaving the windows wide open, this episode is your wake-up call, packed with sharp insights, analogies involving go-karts on the interstate, and the occasional frustrated sigh.

More info at HelpMeWithHIPAA.com/495

View Details

If ignoring cybersecurity was a sport, some companies would be gold medalists—until they realize the prize is a hefty fine and years of regulatory headaches. It’s like leaving your car unlocked in a sketchy part of town with a neon sign that says, “Free Stuff Inside.” What could possibly go wrong? Well, in this episode, we break down six real-life cases that prove skimping on security is way more expensive than just doing it right in the first place. From ransomware attacks to patient right of access failures, we’re diving into what went wrong, why it happened, and—most importantly—how you can avoid becoming the next cautionary tale.

More info at HelpMeWithHIPAA.com/494

View Details

Buckle up, folks, because this week’s episode is a wild ride through the Cavity of Lies—where HIPAA violations, ransomware attacks, and outright absurdity collide. What happens when a dental group tries to sweep a massive breach under the rug (or, you know, hide servers in bathrooms)? Let’s just say it doesn’t end well. From a 3-year-long cover-up to servers stored in all the wrong places, we’ve got lies under oath, policies that might as well be urban legends, and enough bad decisions to make you cringe harder than hearing the dentist say “we need to talk about your flossing habits.”

More info at HelpMeWithHIPAA.com/493

View Details

Hold onto your compliance hats—big changes are brewing for HIPAA’s Security Rule! The Notice of Proposed Rulemaking (NPRM) is officially out for public comment, and it’s clear HHA and OCR are on a mission to modernize and tighten the safeguards for electronic protected health information (ePHI). From clarifying risk analysis expectations to making security requirements less, well, “vague,” these updates aim to bolster patient safety and data protection while keeping pace with today’s tech-driven world. But with great updates come great responsibilities for covered entities and business associates alike, so now’s the perfect time to weigh in and help shape the final rule before it’s set in stone.

More info at HelpMeWithHIPAA.com/492

View Details

Ready to kick off 2025 with a bang? We’re diving into the must-dos for your Q1 2025 compliance and cybersecurity checklist, sprinkling in some risk management wisdom, and why Windows 10 is about as fashionable as shoulder pads in the 2020s. Plus, we sprinkle in a hearty dose of snark to keep you entertained while you get your compliance game strong. Oh and if your incident response plan is just “hope for the best,” it’s time to tune in.

More info at HelpMeWithHIPAA.com/491

View Details

Ah, supply chain attacks—the gift that keeps on giving... headaches, fines, and catastrophic data breaches. In this episode, we unwrap three cautionary tales of organizations caught in the tangled web of digital supply chain chaos. From unpatched vulnerabilities and sneaky software backdoors to hackers casually buying network access like it’s an eBay auction, each story serves up a hard truth: you don’t want to be part of a supply chain attack, you don’t want to have a supply chain attack, and you definitely don’t want to delay dealing with a supply chain attack. So grab your metaphorical flashlight and let’s go spelunking into the murky caves of cybersecurity mishaps.

More info at HelpMeWithHIPAA.com/490

View Details

It’s the final countdown, folks—the last episode of the year! And OCR decided to end 2024 with a bang, handing out settlements like candy at a Christmas parade. But here’s the twist: the candy comes with a price tag, and it’s not cheap. This episode hones in on OCR’s new enforcement initiative targeting incomplete and outdated risk analyses. So, before you pop the champagne, let’s make sure your SRA isn’t a ticking compliance time bomb.

More info at HelpMeWithHIPAA.com/489

View Details

Welcome to the 2024 Blooper Show, where we prove once again that even after nine years, perfection is overrated and laughter is mandatory! Big shoutout to Bojan, our long suffering audio engineer extraordinaire, who turns our chaos into coherence. And of course, we can’t forget you—our amazing listeners—who tune in each week, send us your thoughts and questions, and share the chaos with your friends. Cheers to you for making this madness worth it!

More info at HelpMeWithHIPAA.com/2024blooper

View Details

Cybersecurity incidents can feel like a punch in the gut, but with the right plan, you can roll with the hits instead of flailing in panic. In this episode, we’re diving into executive strategies for tackling the unexpected, from building response teams to keeping business operations afloat when chaos strikes. Along the way, we also cover a recent corrective action plan that serves as a cautionary tale for getting your protocols in order before trouble comes knocking. This is your go-to guide for staying cool when the heat is on!

More info at HelpMeWithHIPAA.com/488

View Details

Is your healthcare organization ready for a triple threat, or are you playing a risky game of cybersecurity roulette with delayed access, ransomware demands, and a missing incident response plan? Today, we explore three tales in healthcare that are equal parts cautionary and compelling. We kick things off with the Healthcare and Public Health Sector Coordinating Council’s shiny new cyber incident response checklist—aka your cheat sheet for keeping calm in the face of chaos. Then, we give you the juicy details of a hefty civil money penalty slapped on a healthcare entity for dragging their feet on providing patient records (spoiler alert: patience isn’t a virtue when it comes to HIPAA). Finally, we unravel the saga of a ransomware attack that not only encrypted data but also emptied some wallets. Whether you’re here to learn, laugh, or just feel better about your own compliance game, this episode’s got you covered. Buckle up, because the HIPAA ride is wild!

More info at HelpMeWithHIPAA.com/487

View Details

Feeling thankful this season? Us too—especially when it comes to dodging data disasters! In this episode, Donna and David dive headfirst into some eyebrow-raising cybersecurity tales, from job application breaches exposing sensitive information to the ever-creepy risks of unsecured IoT devices (yes, even your vacuum might be plotting against you). Whether it’s researchers discovering unsecured data files or hackers turning robot vacuums into racially inappropriate terrors, we’re reminded to never take our digital safety for granted. Grab your popcorn (or an encrypted snack, if that’s a thing) and join us as we talk about what it means to truly be grateful for solid security practices this year.

More info at HelpMeWithHIPAA.com/486

View Details

Doing a half-baked risk analysis is like locking your front door but leaving all the windows wide open. What’s the point? Today, we dive into the first-ever Security Risk Assessment (SRA) violation settlement—a juicy topic for compliance nerds and healthcare pros alike. We’re talking ransomware, compliance checklists (the kind you actually need), and why a “kinda-sorta risk analysis” isn’t going to cut it with the OCR. Along the way, we’ll break down the $90K fine, the three-year corrective action plan, and what this means for everyone still winging their HIPAA risk assessments. Time to up your game folks!

More info at HelpMeWithHIPAA.com/485

View Details

Buckle up for Part 2 of our breakdown on the HHS OCR NIST healthcare security conference - because, yes, 16 hours of deep dives into AI, HIPAA compliance, and cybersecurity priorities can’t be tackled in just one episode! From wild projections about AI’s future in healthcare to OCR’s “tough love” on compliance standards, this episode peels back the curtain on the big decisions shaping healthcare data security. It’s a whirlwind tour through risks, regulations, and the occasional debate on why “just doing it the old way” won’t cut it anymore. Let’s get into it!

More info at HelpMeWithHIPAA.com/484

View Details

Buckle up, folks! Today, Donna and David are here with Part 1 of their deep dive into the recent HHS OCR NIST healthcare security virtual conference, and they're spilling all the cyber-tea. With experts from HHS, OCR, NIST, FTC, and FDA presenting, this conference covered a ton. From AI-powered hackers and QR code scams to unpatched medical devices and a spike in supply chain attacks, the discussions centered on what it takes to keep healthcare data and devices secure in a constantly evolving threat landscape. Wondering why healthcare data security feels like a game of whack-a-mole? Tune in to find out!

More info at HelpMeWithHIPAA.com/483

View Details

Ever heard someone say you need a pen test but then start wondering if they meant a pen from a spy movie? There typically is a lot of confusion between penetration testing and vulnerability assessments—a common mix-up with big consequences for your cybersecurity game. We will walk through different types of pen tests, explain how they help you spot weaknesses before the bad guys do and tackle why continuous vulnerability management can save you from surprises. Whether you’re building up your defenses or simply trying to keep up with best practices, this episode is packed with insights on staying ahead of cyber threats, one test at a time.

More info at HelpMeWithHIPAA.com/482

View Details

Ever had a root canal that felt less painful than dealing with bureaucracy? Well, buckle up, because in this episode, we sink our teeth into the 50th patient right of access enforcement action under HIPAA. That’s right—50 cases since 2019, and somehow, this one involving Dr. Gumb (yes, really) and a dental records dispute is the most absurd of the bunch. From a refusal to hand over records to racking up government fines like trading cards, this saga is a wild reminder of what happens when compliance takes a backseat.

More info at HelpMeWithHIPAA.com/481

View Details

Today we tackle the trifecta of cybersecurity headaches: Microsoft’s awkwardly ambitious recall feature, the looming HISAA regulations (because HIPAA wasn’t enough), and a juicy enforcement action following a ransomware attack. We’ll break down how Microsoft’s recall reboot went from intrusive default to opt-in relief, why HISAA could mean mandatory stress tests for healthcare providers, and what lessons we can learn from a ransomware attack that left 291,000 patient records exposed—and a corrective action plan no one wants. If you've ever wondered how healthcare security, government fines, and tech mishaps collide, this one’s for you.

More info at HelpMeWithHIPAA.com/480

View Details

Leaving your web browser open with 25 tabs is the digital version of leaving your front door unlocked? Whether it's for email, work docs, shopping, or watching cat videos, your browser is the gateway to, well, everything. But as much as we depend on them, so do hackers. From credential theft to sneaky phishing attacks, cybercriminals are finding clever ways to turn your favorite browser into a tool for their dirty work. Today, we’ll break down the wild world of browsers—how we rely on them, and how hackers are exploiting them while we casually leave 25 tabs open at once. Note to self: it’s time to update your browser (and maybe close a few tabs)!

More info at HelpMeWithHIPAA.com/479

View Details

Boo! 🎃 Halloween may not be here yet, but we’re kicking off the spooky vibes early! Donna and David dive into the eerie world of cybersecurity, where the tricks are plentiful, and the treats are hard to find. From scary ransomware attacks to the horrifying reality of business email compromises, the internet is scarier than a haunted house with no exit. Grab your digital pumpkin spice latte, because we're about to unravel some terrifying myths that will make you think twice before you click on anything!

More info at HelpMeWithHIPAA.com/478

View Details

Healthcare marketing is tricky enough without tripping over the big pitfalls that could leave you tangled up in HIPAA violations or a patient privacy disaster. Today we break down five common marketing mistakes you definitely want to steer clear of. From misinterpreting HIPAA rules to guarding patient data like it’s your grandma’s secret cookie recipe, these blunders can get you into serious trouble. We’re here to help you navigate these common missteps and protect your business from unnecessary risks.

More info at HelpMeWithHIPAA.com/477

View Details

Do you feel like cyberattacks are the world’s worst game of whack-a-mole? No matter how many you smack down, ten more pop up— and there’s no sign of it slowing anytime soon and neither is the confusion over who’s responsible when your data gets caught in the crossfire. If your supply chain and your own security safeguards aren't locked down, you might as well be rolling out the red carpet for hackers. Tune in as we break down the latest mess, and yes, it’s as frustrating as it sounds!

More info at HelpMeWithHIPAA.com/476

View Details

Ever left your front door unlocked, thinking it’s no big deal? Well, that’s what happens when you forget about facility access controls – and the consequences can be far worse than a missing TV! Today, we dive deep into a topic that often gets overlooked but is critical to any organization’s security – facility access controls. Whether it's ensuring that only authorized personnel can access sensitive areas or protecting valuable equipment from walking out the door, facility access controls are a crucial part of safeguarding not just data but also physical assets. And as much as we love talking about tech, this time it's all about locks, keys, and keeping the wrong people out.

More info at HelpMeWithHIPAA.com/475

View Details

It's that time of year again: Cybersecurity Awareness Month! We're diving into the world of cybersecurity like a hacker in a candy store—except we're here to keep the candy (your data) safe! We're breaking down how you can use the free CE Awareness Month toolkit to boost your cybersecurity game both in your business and at home. Whether you're an IT pro or someone who just learned how to turn on two-factor authentication, we've got tips, tricks, and a few laughs to help you navigate the digital wild west. So buckle up and let's secure our world, one strong password at a time!

More info at HelpMeWithHIPAA.com/474

View Details

Navigating the world of cybersecurity these days feels like walking through a minefield with clown shoes—are you stepping safely or just a step away from disaster? In this episode, we dive into the jaw-dropping National Public Data breach that's got everyone asking, "Am I a victim too?" Spoiler alert: the odds aren't in your favor. Then, we sift through the chaos of the recent CrowdStrike outage because what's a week in cybersecurity without a little mayhem? And just when you thought it couldn't get worse, we’ve got a few more terrifying tales ripped straight from the headlines to keep you on your toes. Grab your stress ball, and let’s brace ourselves for a journey into the digital dark side!

More info at HelpMeWithHIPAA.com/473

View Details

In this episode, we're diving deep into the world of Software Bill of Materials (SBOM)—basically, the recipe for your software, minus the secret sauce. If you've ever wondered what's really under the hood of your favorite apps (or been caught off guard by a sneaky ingredient), this one's for you. We’re breaking down why you should care about SBOMs, how they’re becoming a must-have in your vendor vetting process, and what it all means for the future of tech. Think of it as your crash course in making sure your software isn’t serving up any nasty surprises.

More info at HelpMeWithHIPAA.com/472

View Details

Navigating healthcare cybersecurity is like walking through a minefield—you never know which step could trigger the next explosion. In this episode, we’re diving headfirst into the bloody mess of ransomware attacks that have turned hospitals and blood banks into a logistical nightmare. Amidst the chaos, Health-ISAC and the American Hospital Association are urging special consideration for critical supply chain entities. It’s a wild ride through the chaos that one click can unleash on healthcare, and how the ripple effects can leave everyone scrambling to pick up the pieces.

More info at HelpMeWithHIPAA.com/471

View Details

How well do you really know your remote workers? With remote work increasingly becoming the norm, the complexities of securing devices and monitoring access have skyrocketed. The challenges of providing robust security measures for an increasingly dispersed workforce are immense. Real-world examples like the KnowBe4 incident, where a remote worker used a stolen identity to infiltrate company systems, highlight the necessity of layered security and proactive monitoring. Our discussion today, highlights the crucial need to grasp the subtle threats from cyber attackers, especially when dealing with sensitive patient data and HIPAA compliance.

More info at HelpMeWithHIPAA.com/470

View Details

Ever had one of those days where everything just seems to crash and burn? Well, in this episode, we dive into a tech catastrophe that sent ripples across the digital landscape. Donna and David will unravel the chaos caused by CrowdStrike's major tech outage—a meltdown that wasn’t just an ordinary hiccup, but a vendor-of-a-vendor fiasco. From blue screens of death to grounded flights, this incident highlights the domino effect a single update can have on the entire supply chain.

More info at HelpMeWithHIPAA.com/469

View Details

Ever wondered how neglecting a cybersecurity risk analysis is like leaving your front door wide open in a sketchy neighborhood? Well, buckle up because today we dig into the latest OCR ransomware settlement involving Heritage Valley Health Systems and a laundry list of potential violations. From failing to conduct a thorough risk analysis to lacking a proper contingency plan for ransomware attacks to neglecting to train their workforce on policies and procedures, this is a cautionary tale of what happens when cybersecurity isn't taken seriously.

More info at HelpMeWithHIPAA.com/468

View Details

In the HIPAA world, just because you can, doesn't mean you should – unless you’re keen on trading your business casual for prison orange. No one expects that a HIPAA violation will send them to jail, but there can be serious criminal penalties associated with HIPAA breaches, ranging from fines to imprisonment. Today, we will share real-life examples of how some people misinterpret their rights to access patient records.

More info at HelpMeWithHIPAA.com/467

View Details

How can small and medium businesses (SMBs) tackle the complexities of single sign-on (SSO) and boost their password security? A recent study from CISA highlighted the lag in SSO adoption among SMBs and why basic security measures like SSO and multi-factor authentication (MFA) should be standard. Join us as we navigate through the maze of managing multiple passwords, the pitfalls of manual methods, and the critical need for vendors to prioritize security from the get-go.

More info at HelpMeWithHIPAA.com/466

View Details

Ever wonder why staying vigilant in cybersecurity is like playing whack-a-mole? Let's dive into some wild stories that highlight the need to always be on the lookout! From hackers using legitimate websites to spread malware, to the humorous and slightly terrifying saga of employees using mouse jigglers to fake work, to cyberattacks from space, there are a lot of reasons why we should always keep our guard up in the wild world of cybersecurity!

More info at HelpMeWithHIPAA.com/465

View Details

What happens when healthcare giants falter in the face of cyber threats? Today, we dive into the critical need for better cybersecurity investments, continuous training and education and robust cybersecurity standards. We will explore the fallout from UHG’s cyber incident and break down three fiery letters from Congress demanding accountability and stricter regulations for cybersecurity practices in healthcare.

More info at HelpMeWithHIPAA.com/464

View Details

Today, we're diving into a topic that might keep you up at night and might make you reconsider your relationship with your Wi-Fi router. Picture this: your internet goes down, and it's not just a blip—it's a full-blown blackout. We're talking no Netflix, no Zoom meetings, and definitely no online shopping. We’ll unravel the chaos that ensues and discuss how you can keep your cool and your business running smoothly when the digital world decides to take a nap.

More info at HelpMeWithHIPAA.com/463

View Details

Join us as we debunked some common myths about what Security Risk Analysis isn't and then cruise through the seven essential steps to conduct a complete and thorough SRA for any organization. It’s not just a one-off IT review or a checkbox on compliance forms—it’s an ongoing, dynamic process. From identifying what you need to protect to managing how you protect it, each step builds on the last to fortify your defense against the digital wild west.

More info at HelpMeWithHIPAA.com/462

View Details

Today we dive into the world of compulsive clickers—the folks who just can't help but tap on every tantalizing link that winks at them from their inbox. It's not just a harmless habit; these clicks can lead to some pretty sketchy places. Imagine a world where every click could be a potential minefield, threatening your digital safety with every tap. But here's the kicker: can we change these click-happy habits? Let's explore whether it's possible to turn a reckless clicker into a prudent, pause-and-think-before-you-click kind of user.

More info at HelpMeWithHIPAA.com/461

View Details

Imagine juggling the intense world of cybersecurity where you're constantly putting out digital fires, with trying to keep your own mental batteries charged. It's like being a superhero who also needs to take some me-time. Our discussion dives into how we can manage the high-stakes of cybersecurity and stress-packed jobs while also making sure we don't crash and burn. We’ll talk about everything from rebooting your brain with a dose of humor to the serious implications of cyber threats on mental health. It’s a real talk on balancing the cyber chaos with personal peace, all seasoned with our personal experiences and a sprinkle of practical advice.

More info at HelpMeWithHIPAA.com/460

View Details

It is time to review the annual Verizon Data Breach Investigaton report. First we will hit the big notes from their summary. Then, we can add in a few tidbits from the bigger report details. We'll break down key statistics, discuss emerging threats, and offer insights into what these findings mean for the health sector and HIPAA privacy and security programs.

More info at HelpMeWithHIPAA.com/459

View Details

After the big cyberattack on Change Healthcare, there’s a hot debate about making Multi-Factor Authentication (MFA) a must-have for all public access points. With Congress getting involved and experts pushing for tougher security, it’s clear that better safeguards are needed to keep our healthcare data safe. This shift towards mandatory security measures shows just how serious cyber threats have become.

More info at HelpMeWithHIPAA.com/458

View Details

Who's on the hook for breach notifications in healthcare? Recent cybersecurity incidents like the massive Change Healthcare data breach have left providers scrambling and seeking clarity. The tangled relationships between Covered Entities and Business Associates make it tricky to figure out who's liable, especially when cyber incidents ripple down the vendor chain. This raises big questions about the contents of Business Associate Agreements and clarifications on who's responsible for what, ensuring everyone's ready when a data breach hits.

More info at HelpMeWithHIPAA.com/457

View Details

The U.S. healthcare sector is facing significant changes with new HIPAA rules boosting privacy protections, particularly for reproductive health. At the same time, the industry is tackling serious cybersecurity issues highlighted by a major ransomware attack on Change Healthcare. This dual focus on strengthening legal compliance and enhancing data security underscores the urgency of protecting patient information and maintaining trust in healthcare systems.

More info at HelpMeWithHIPAA.com/456

View Details

In the world of cybersecurity, small businesses have their own set of unique challenges. As AI technology becomes more common, using AI in cybersecurity sounds promising, but it's crucial to handle it wisely to avoid new risks. These tools are powerful, but they need to be used carefully because they can also open up new kinds of cyber threats. Small businesses need to build a strong culture of security, making sure everyone is up to speed and constantly testing their defenses against attacks. It's also vital for them to keep their security practices flexible to stay ahead of new threats and tech developments.

More info at HelpMeWithHIPAA.com/455

View Details

Aristotle once said, “Patience is bitter, but its fruit is sweet.” That's totally spot on when you think about cybersecurity threats and how sneaky cybercriminals can be. These attackers plant their harmful seeds and just hang back, waiting for the right time to take advantage of old weaknesses. Their patience and careful planning mean they can strike effectively, sometimes after years of waiting, showing just how tricky it is to handle digital security. It really highlights why we need to be on our toes all the time, with solid and forward-thinking security measures to guard our sensitive info from these crafty threats.

More info at HelpMeWithHIPAA.com/454

View Details

One Friday night in September last year, a massive hack at the MGM Grand caused quite a stir in Las Vegas. Cybercriminals used tricky tactics to slip through the cracks, infiltrating the network, and disrupting services at the hotel and casino. It's a wake-up call for everyone to step up their security game and stay one step ahead in this fast-changing world of cyber threats.

More info at HelpMeWithHIPAA.com/453

View Details

MSPs are like the backstage crew for your business's IT show, handling everything from network management to cybersecurity. But here's the kicker: while they're busy protecting you, they've got to make sure they're not accidentally opening the back door for trouble with their own tools and business practices in the process of delivering their services. Security is a shared responsibility.

More info at HelpMeWithHIPAA.com/452

View Details

In an increasingly interconnected and data-driven world, the importance of rigorous vendor vetting cannot be overstressed. Vendors ticking a box saying that they use a framework for data security and compliance isn’t enough anymore. It is a critical due diligence process that helps clients build secure, compliant, and mutually beneficial business relationships, minimizing risks and enhancing overall business performance. And with the recent Change Healthcare attack, vendors can expect to receive more rigorous questionnaires from their clients and the heightened expectations for transparency and accountability in handling sensitive information.

More info at HelpMeWithHIPAA.com/451

View Details

As Change Healthcare ransomware attack unfolds, concerns are escalating regarding patient care and safety, pushing the Healthcare Sector Coordinating Council's (HSCC) 5 Year Strategic Plan into the spotlight. Donna and David talk with Gary Salman, CEO of Black Talon Security, on the ongoing situation, what is known and unknown, and its potential long-term effects. With the attack exacerbating issues within the healthcare system and highlighting the urgent need for robust cybersecurity measures, we explore the implications for patient data, the healthcare industry's response, and what this means for the future of healthcare security.

More info at HelpMeWithHIPAA.com/450

View Details

For more than a decade, Donna has immersed herself in the plethora of sessions from the National HIPAA Summit, extracting a wealth of insights into the present and future landscape of HIPAA. Today, she will impart her top three takeaways from this year’s Summit, essential knowledge for navigating the road ahead. Buckle up folks, because these insights are far from trivial.

More info at HelpMeWithHIPAA.com/449

View Details

Healthcare is inherently about trust; trust between patients and providers, trust in the efficacy of treatments, and increasingly, trust in the technology that underpins modern medicine. However, this trust is under siege by an evolving landscape of cyber threats. Today, we tackle the critical status of healthcare cybersecurity and the concerted effort the Health Sector Coordinating Council Cybersecurity Working Group has developed to transition the industry to a stable posture over the next five years.

More info at HelpMeWithHIPAA.com/448

View Details

The rapid advancement of AI could soon eclipse our understanding, with its capability to predict and even manipulate human behavior. Today, we will dive into how AI is reshaping our understanding and preparedness for the digital threats lurking around the corner. Plus, NIST just released guidance that can be used to help improve the healthcare sector’s cybersecurity posture and assist with achieving compliance with the HIPAA Security Rule.

More info at HelpMeWithHIPAA.com/447

View Details

OCR recently announced a jaw-dropping settlement that should have every healthcare professional on high alert. An insider breach that had staggering repercussions, leading to a monumental $4,750,000 settlement and a two year CAP. HHS has also released new cybersecurity resources and guidance and more is to come. There is no excuse anymore folks. Cybersecurity is everyone’s responsibility and OCR’s enforcement of privacy and security failures is picking up.

More info at HelpMeWithHIPAA.com/446

View Details

Imagine your cybersecurity measures as the immune system of your body. Just like our bodies are constantly exposed to germs and viruses, your business is exposed to a barrage of cyber threats. Cyber insurance is like health insurance for your company's digital health. We are joined today by John Miller of Sterling Seacrest Pritchard, exploring the crucial intersections of healthcare, cyber coverage, and the corporate responsibility of protecting sensitive data.

More info at HelpMeWithHIPAA.com/445

View Details

HHS has adapted CISA’s Cybersecurity Performance Goals, released in March 2023, for healthcare entities to better protect those in the healthcare sector from cyberattacks. These voluntary goals aim to strengthen cyber preparedness, improve cyber resiliency, and protect patient health information and safety. In this episode, we will review the HPH CPGs as they will be the basis of the proposed HIPAA Security Rule changes slated to be released later this year.

More info at HelpMeWithHIPAA.com/444

View Details

It’s no secret that small businesses face challenges in understanding and keeping up with the rapidly changing cyber threat landscape. Today we’ll discuss some of those challenges and review new free resources from NIST and CISA coming out in 2024 that can help SMBs manage and improve their cybersecurity programs. Buckle up, it’s going to be a busy year.

More info at HelpMeWithHIPAA.com/443

View Details

We all know that OCR is the HHS department that oversees and enforces HIPAA to ensure the protection of individuals' healthcare information. However, more and more states around the country are also making efforts to protect their constituents’ personal information and hold companies accountable for their poor data security practices. Today, we discuss recent HIPAA enforcement actions taken on businesses by the NY State Attorney General’s Office.

More info at HelpMeWithHIPAA.com/442

View Details

The number of ransomware attacks impacting critical services, compromising personal information and attackers requesting higher and higher ransoms continue to rise. Today, we discuss this pressing issue, implications of ransomware attacks, the ethical considerations of paying ransoms, and the urgent need for preventative measures.

More info at HelpMeWithHIPAA.com/441

View Details

In today’s world, it's essential to recognize the importance of safeguarding your personal information. From the moment you wake up and check your smartphone to the minute you stream your favorite show or make an online purchase, your every digital move leaves a trail of data breadcrumbs. But, you have the power to take charge of your data privacy. You can start by taking part in Data Privacy Week, sponsored by the National Cybersecurity Alliance.

More info at HelpMeWithHIPAA.com/440

View Details

It’s time to recap Donna and David’s 2023 HIPAA and cybersecurity predictions and hear what their crystal ball says about what to look out for in 2024. And, since AI exploded in 2023, we asked ChatGPT for predictions for 2024 too.

More info at HelpMeWithHIPAA.com/439

View Details

It’s no secret that healthcare is vulnerable to cybersecurity threats and patient privacy and safety are at risk. Good news! HHS recently announced a plan to enhance cybersecurity in the healthcare and public health sectors. Through various initiatives, including 405(d) and other HHS efforts, plans are starting to come together like pieces of a puzzle to help practices stay ahead in the ever-evolving landscape of cybersecurity. It's time to get informed and take action to protect your practice, business, and patients.

More info at HelpMeWithHIPAA.com/438

View Details

It's time of year again where we take some time off and let Bojan create a Help Me with HIPAA bloopers show of our mishaps and outtakes. Stick around to the end - we have a little surprise for you.

Thanks to Bojan for his skill in making us sound so good every week.

Thanks to all our listeners who have been with us and share our podcast with others. We are here because of you.

As always, remember, HIPAA is not about compliance, it is about patient care.

View Details

CISA has released a mitigation guide to combat the critical and complex cyber threats affecting the Healthcare and Public Health Sector. It provides best practices, essential strategies and insights for safeguarding our healthcare infrastructure against ever-evolving cyber threats. Join us as we navigate through this important document, breaking down its complexities and highlighting its significance in the ongoing battle against cyber threats in the healthcare sector.

More info at HelpMeWithHIPAA.com/437

View Details

You know how we say that hackers love to launch attacks during the holidays because that’s when most folks are distracted and in a hurry to begin their time off? Well guess what? There are already a few cyber attacks in the news just from this past Thanksgiving. Case in point, the recent ransomware attack that diverts ER ambulance services across multiple states.

More info at HelpMeWithHIPAA.com/436

View Details

A data breach can have significant and far-reaching consequences for both patients and businesses in the healthcare industry. Today, we delve into the impacts of a recent breach and discuss the evolving challenges of managing healthcare vendors with access to sensitive patient information. Plus, we weigh in on patient privacy concerns when it comes to the media.

More info at HelpMeWithHIPAA.com/435

View Details

It is crucial to apply mitigation strategies to reduce the likelihood and impact of ransomware incidents due to the severe and far-reaching consequences these cyber threats can have on individuals, organizations, and society as a whole. The FBI recently published a notification highlighting emerging ransomware trends involving attacking the same victims multiple times. Listen in to hear what you can do to help reduce the likelihood of becoming a victim.

More info at HelpMeWithHIPAA.com/434

View Details

Evaluating the security posture of organizations through the lens of culture, technology, risk, and people is crucial in today's complex digital landscape. Culture sets the tone for an organization's security mindset, influencing employee behavior and awareness. Today, we review ClubCISO’s Information Security Maturity Report 2023 that evaluates the security posture according to CISOs across the globe.

More info at HelpMeWithHIPAA.com/433

View Details

OCR just announced its first ransomware settlement, emphasizing the importance of proactive cybersecurity measures and the implications for business associates. Ransomware threats are increasingly common, evolving rapidly and continue to target the healthcare industry which highlights the importance of healthcare organizations and their business associates to prioritize cybersecurity.

More info at HelpMeWithHIPAA.com/432

View Details

In our rapidly evolving digital environment, cybersecurity misconfigurations pose significant threats to organizations of all sizes. Misconfigurations can expose systemic weaknesses and make organizations vulnerable to cyber attacks. In this episode, we will review a report from the NSA and CISA highlighting some of the most common misconfigurations that need to be addressed.

More info at HelpMeWithHIPAA.com/431

View Details

When vendors have incidents that disrupt their operations, it’s like having ghosts haunt a business's continuity plan, just waiting to make an eerie appearance. That's why it is crucial for businesses to include vendor-related security incidents or downtime in their business continuity plans. One company’s nightmare can be contagious to its customers.

More info at HelpMeWithHIPAA.com/430

View Details

In today's interconnected digital world, keeping up with cybersecurity alerts is like having a trusty, cyber-savvy sidekick by your side. As our reliance on technology continues to grow, staying ahead of the game is essential. Cybersecurity alerts are like the Bat-Signal of the digital realm, lighting up to warn you of impending threats. Proactive vigilance in the face of these alerts is not merely a best practice; it's an imperative in safeguarding sensitive data, privacy, and the integrity of our increasingly digital lives.

More info at HelpMeWithHIPAA.com/429

View Details

Web tracking tools that collect or share personally identifiable health information can pose significant implications when it comes to HIPAA privacy and security. Unauthorized tracking can compromise patient confidentiality and privacy, potentially exposing sensitive health data. Today, we are doing a follow up from our previous podcast on web tracking tools and discuss a few recent articles and guidance released by HHS, FTC and OCR.

More info at HelpMeWithHIPAA.com/428

View Details

For MSPs, grasping HIPAA compliance isn't just a good idea; it's a necessity. Neglecting it can lead to legal issues and lost opportunities in the healthcare IT sector. Picture unintentionally mishandling patient data and facing legal consequences – that's a risk you can't ignore. A solid understanding of HIPAA can boost your reputation and credibility within the healthcare industry. To acquire this essential knowledge, consider enrolling in the Certified in HIPAA for MSP (CHMSP) course offered by HIPAA for MSPs. It's a valuable resource that equips MSPs with the expertise needed to excel in this specialized field.

More info at HelpMeWithHIPAA.com/427

View Details

Cybersecurity Awareness Month is just around the corner. It's that time of year when we all take a moment to up our game in the digital world. Whether it's creating stronger passwords, being mindful of phishing emails, or updating our software regularly, it's a reminder that our online safety matters. So, listen to this week’s podcast to find ways to keep cybersecurity top of mind and make sure our digital lives are as secure as possible!

More info at HelpMeWithHIPAA.com/426

View Details

Assuming large organizations with lots of healthcare clients have a proper HIPAA privacy and security program in place could be disastrous. OCR recently settled investigations with LA Care, a large health plan in California, for $1.3 million and a 3 year corrective action plan. Join us as we discuss this settlement and learn from others' mistakes.

More info at HelpMeWithHIPAA.com/425

View Details

Securing older, legacy technologies from cyber threats is extremely important in today's interconnected digital world. Older devices often lack the robust security features of modern counterparts, making them vulnerable targets for hackers seeking to exploit weaknesses. Today, we review HSCC’s Health Industry Cybersecurity – Managing Legacy Technology Security (HIC-MaLTS) guide that provides recommendations to address the legacy technology challenges facing healthcare.

More info at HelpMeWithHIPAA.com/424

View Details

In the digital age, cybersecurity has become a critical concern for businesses and individuals alike. Today, we review the latest release from 405(d), Check Your Cyber Pulse. This cybersecurity cosmo quiz helps small organizations evaluate their cyber pulse regarding the 10 cybersecurity practices of HICP and decide where they should focus efforts to improve their cybersecurity behaviors.

More info at HelpMeWithHIPAA.com/423

View Details

Ransomware attacks have become a prevailing threat to businesses of all sizes, causing significant financial losses, reputational damage, and operational disruptions. In this episode, we talk with Robert Cioffi, COO and Co-Founder of Progressive Computing, who shares how they navigated through the Kaseya ransomware attack. He shares invaluable insights into their journey of resilience, recovery, and the crucial lessons learned along the way.

More info at HelpMeWithHIPAA.com/422

View Details

In a crisis situation, organizations must be prepared to communicate effectively in these challenging situations. Karen Phillips, of Phillips & Marek, joins us to discuss strategies and best practices for managing data breaches and how to communicate with stakeholders, including internal staff, patients and the media.

More info at HelpMeWithHIPAA.com/421

View Details

Are you worried about the safety of your data and the potential security risks to your organization? In this episode, we talk with Jen Stone of SecurityMetrics to explore the importance of performing technical and nontechnical evaluations of your security program. Jen helps to explain the benefits of thorough evaluations and how they can safeguard your organization against potential vulnerabilities.

More info at HelpMeWithHIPAA.com/420

View Details

As in years past, we dive into IBM’s 2023 Cost of a Data Breach Report. This annual study sheds light on the ever-evolving landscape of data breaches and provides valuable insights for organizations looking for ways to focus their efforts and money to help prevent and reduce the costs associated with a data breach.

More info at HelpMeWithHIPAA.com/419

View Details

We all know how important it is to keep our personal information and important data secure. MFA can add an extra layer of protection to our digital lives. But does HIPAA require MFA? The short answer: no, but yes. Listen in to hear how best to lock your cyber door against cyber attacks.

More info at HelpMeWithHIPAA.com/418

View Details

Verizon has released their 2023 Data Breach Investigations Report (DBIR). This year they focused more on an analysis of actual data breaches - the types of incidents causing the breaches, the motivations of bad actors, how they tend to carry out their attacks and what data they are grabbing. We always look forward to reading this report because it not only has a lot of great information, but also because it contains a good bit of humor. You know we like that.

More info at HelpMeWithHIPAA.com/417

View Details

In the epic battle between cyber threats and the healthcare industry, it's the patients who suffer the most. There is an urgent need for new regulations in the healthcare industry to address the challenges posed by outdated technology and cybersecurity threats. Today, we talk with Josh Corman about the need for new ideas and meaningful changes to protect hospitals and ensure the safety of critical healthcare functions. More info at HelpMeWithHIPAA.com/416

View Details

BAs play a vital role in healthcare organizations as they often provide services to covered entities that require them to access PHI. But, they often don’t fully understand their own HIPAA compliance obligations. OCR recently released a resolution agreement against a BA that proves BAs will be held accountable for their obligations under HIPAA.

More info at HelpMeWithHIPAA.com/415

View Details

Checklists are important for many people who deal with cybersecurity. David and Donna explain that this new checklist is not just for healthcare, but for all businesses to deal with cybersecurity. They discuss these CPGs, which are Cybersecurity Performance Goals recently published by CISA, and how they can help strengthen your cybersecurity regardless of the size and complexity of your organization.

More info at HelpMeWithHIPAA.com/414

View Details

Healthcare cybersecurity is no walk in the park! Today, we explore the release of the "Health Industry Cybersecurity Recommendations for Government Policy and Programs" by HSCC. It provides suggestions and ideas on how government policy and programs can support the health sector in beefing up their cybersecurity defenses to help keep our health systems safe from cyber threats.  

More info at HelpMeWithHIPAA.com/413

View Details

Vacation is a time to relax and get away from everyday worries, but it's important to take steps to ensure that your cybersecurity and privacy are not at risk. Today, we will review vacation and travel security tips from the National Cybersecurity Alliance to help you stay safe during your travels.

More info at HelpMeWithHIPAA.com/412

View Details

When it comes to cybersecurity, It is important to understand who your audience is and how to communicate effectively with them. Today, we discuss an article on the cybersecurity pitfalls written by Julie Haney, Usable Cybersecurity Program Lead at NIST, and the importance of involving everyone in a team approach to protecting patients' information. 

More info at HelpMeWithHIPAA.com/411

View Details

Cybersecurity is a big challenge for all businesses these days. Regardless of the size of the business or industry it’s in, hackers are continuously trying to exploit weaknesses to gain access to networks and data. NIST and CISA have some new resources and guides that can help small and medium size businesses face the growing cyber threat.

More info at HelpMeWithHIPAA.com/410

View Details

You know how people say “it’ll never happen to me”? Well, today we are covering six news stories that chances are will affect you either directly or indirectly in some way. We’ve got yet another story of a practice that doesn’t have a response plan, stories about hardware and software that are vulnerable or were hacked and even a story on how you can make a quick $10m. 

More info at HelpMeWithHIPAA.com/409

View Details

In the fast-paced world of healthcare, where even your stethoscope can connect to the internet, cybersecurity training for everyone is an absolute must. But fear not, brave healthcare professional!  There is free cybersecurity training online! Listen in and we will tell you all about two great cybersecurity training options for workforce members and clinicians.

More info at HelpMeWithHIPAA.com/408

View Details

We talk a lot about understanding the current cyber threats and risks involved in not remaining vigilant in protecting against them. Today, we review the Hospital Cyber Resiliency Initiative Landscape Analysis, recently released by 405d. It provides stats and case studies from the real world. It also gives us areas we need to work on and where we need to put our investment of time and money to protect against these threats.

More info at HelpMeWithHIPAA.com/407

View Details

Healthcare organizations are dealing with increasingly complex cybersecurity threats. With the use of technology and the presence of sensitive patient information, hackers see healthcare systems as valuable targets. Protecting healthcare systems is a major challenge. The 405(d) Task Group has updated their HICP guidance for small, medium and large organizations to help them better secure their networks and applications and manage risks to keep patient information safe.

More info at HelpMeWithHIPAA.com/406

View Details

It’s fitting that for episode 405 we talk with Erik Decker, lead on the HHS 405d Task Group, about the recently released Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients (HICP) 2023 edition. Since David and I are also on the 405d task group, we are excited to talk about the new updates and added resources FREELY available to help everyone prepare and fight against cybersecurity threats. 

More info at HelpMeWithHIPAA.com/405

View Details

Gary Salman from Black Talon Security joins David as guest host while Donna celebrates her birthday in the Keys. David and Gary will explain why not being constantly vigilant when protecting network security can lead to a false sense of security.  They will discuss the threats Black Talon is seeing in the cyber environment these days and via tabletop exercises they conduct with organizations as well as ways to help protect your organization from and prepare for cyber events and other crisis situations.

More info at HelpMeWithHIPAA.com/404

View Details

Today, we cover part two of our review of the HIPAA Summit.  We will cover notes from a privacy officer roundtable, security tips from IT’s point of view, key points from crisis vendors and a very interesting discussion around mergers and acquisitions. Listen in to pick up where we left off from part 1 of our 2023 HIPAA Summit Review.

More info at HelpMeWithHIPAA.com/403

View Details

As always the HIPAA Summit is very interesting and informative. This is the annual summit where we learn what’s going on in the “HIPAAsphere” and what things are coming down the pike. There is a lot of information to cover, so we will break this into two Help Me With HIPAA episodes. Here’s part 1 of our HIPAA Summit review.

More info at HelpMeWithHIPAA.com/402

View Details

The importance of mobile device security cannot be overstated. With our lives becoming increasingly digital, it is essential that we take the necessary steps to secure our devices. By doing so, we can protect our data and our privacy, while also preventing malicious actors from gaining access to our accounts. 

More info at HelpMeWithHIPAA.com/401

View Details

We made it to 400 episodes!  We have done, heard and learned a lot. Today, we will discuss 8 of the most important things we have learned so far.  And we still have more to learn and to share, so stay tuned!

More info at HelpMeWithHIPAA.com/400

View Details

Today’s episode we are going to do a quick recap from the PriSec Boot Camp and we will discuss the recent FTC case involving GoodRx. The PriSec Boot Camp was a lot of fun and Donna’s Bourbon and Breaches was a hit with everyone!

More info at HelpMeWithHIPAA.com/399

View Details

Earlier this month, The White House released a new National Cybersecurity Strategy aimed at building a more resilient digital environment that is easier to defend than to attack and that is secure and safe for all Americans. The focus is to shift the burden of defending the country's cyberspace towards software vendors and service providers and to stress how essential collaboration between the public and private sectors, as well as with international allies and partners, is for securing the nation against cyber threats.

More info at HelpMeWithHIPAA.com/398

View Details

Let's face it, family dynamics can be complicated and not everyone gets along. HIPAA is designed to ensure that everyone's health information is kept confidential and that only the appropriate individuals are given access. Believe it or not, HIPAA does not guarantee all relatives access to another relative's protected health information. 

More info at HelpMeWithHIPAA.com/397

View Details

Today you're going to get a twofer. We're going to discuss the two recent reports that OCR submitted to Congress on the state of compliance with Privacy and Security and the other on Report Breaches and Notifications. Let’s start by saying that OCR is really busy… I mean really busy.

More info at HelpMeWithHIPAA.com/396

View Details

Data breaches can be costly - so costly, in fact, that they can turn a business's bottom line into a roller coaster of emotion, ranging from shock and dismay to tears of dollars! But with a robust privacy and security program in place, businesses can reduce the likelihood of a data breach and the financial impact that comes with it.

More info at HelpMeWithHIPAA.com/395

View Details

Today, we are talking about a new OCR settlement that was released from a 2016 hacking attack on Banner Health’s network, causing a data breach of over 2.81 million individuals. We’ll review the OCR CAP. But suffice it to say… until we have more engagement from every person connecting to the internet, we will never make real progress in the battle against cyber criminals.

More info at HelpMeWithHIPAA.com/394

View Details

It's a story straight out of a blockbuster movie - an elite team of FBI agents infiltrating an underground network to thwart an international crime syndicate, saving over $130 million in ransom demands. Using their expert skills, the FBI agents were able to infiltrate the Hive network without detection and shut them down… at least for now.

More info at HelpMeWithHIPAA.com/393

View Details

AI is the latest nerd language spreading wildly across… well, everywhere. ChatGPT, an automated AI-powered chatbot, is designed to provide automated conversational responses to users in a friendly and natural way. Today, we discuss and show you how ChatGPT explains itself and how it could be used in healthcare.

More info at HelpMeWithHIPAA.com/392

View Details

Knowing what vendors your BAs may use to provide services to your organization is crucial. Those downstream vendors could be the cause of a breach of your data. Signing a BAA does not prove a BA is properly securing your data. Vetting your vendors is as important as making sure your vendors are vetting their vendors.

More info at HelpMeWithHIPAA.com/391

View Details

Using website tracking technology on healthcare sites can be a double-edged sword. On the one hand, it can help healthcare organizations better understand user behavior, preferences, and interests. However, if not properly secured, this technology can also put users at risk of their sensitive data being accessed and used inappropriately. 

More info at HelpMeWithHIPAA.com/390

View Details

The recent breach at the popular password manager, LastPass, has caused a lot of concern amongst its users. We ourselves have discussed whether this is the last pass we are going to give to LastPass. So, in today’s episode, we discuss what happened, what it means for LastPass users and what are some things you should do or consider doing.

More info at HelpMeWithHIPAA.com/389

View Details

For our first show of 2023 we review 2 more OCR settlements! These are the last ones released in 2022. Listen in to hear what happened so that you can learn how to avoid making the same mistakes in the new year.

More info at HelpMeWithHIPAA.com/388

View Details

This is one of our favorite episodes of the year. We will recap our 2022 privacy and security predictions and then make new predictions for 2023. Aside from the obvious predictions like “ransomware will increase”, our predictions will give you what we think you are going to be hearing about that you should worry about in 2023.

More info at HelpMeWithHIPAA.com/387

View Details

As is our custom, we take one week off each year from creating new content just to give us a break. It also gives our sound engineer, Bojan Sabioncello, a chance to shine while he goes through all the outtakes he deals with all year. He gets in front of the mic to share how awful we treat him yet, he is still around after all these years. 

Thanks to Bojan for his skill in making us sound so good every week. 

Thanks to all our listeners who have been with us and share our podcast with others. We are here because of you.

As always, remember, HIPAA is not about compliance, it is about patient care.

View Details

When you think of a power outage happening to you or your business, you probably think of an outage lasting a few hours. Not the case with the recent massive power outage experienced in Moore County NC recently. So, that begs the question, do you have a response plan for experiencing a power outage lasting a week or more?  You should.

More info at HelpMeWithHIPAA.com/386

View Details

The holidays are upon us and everyone is getting excited about buying presents for friends and loved ones. Cyber criminals are excited too because it means even more opportunities to attack us. Today, we are discussing an article from ZDnet about three new ways attackers are trying to trick you.

More info at HelpMeWithHIPAA.com/385

View Details

OCR recently released a video on their Recognized Security Practices initiative. The intent is to teach HIPAA regulated entities on what Recognized Security Practices is and what is required to prove its implementation in your organizations. We will review the video today and give you some key takeaways from it.

More info at HelpMeWithHIPAA.com/384

View Details

As we celebrate Thanksgiving, we thought it would be a good idea to cover three reasons why you should be thankful. Or better yet, three situations you should be thankful that you’re not caught up in…. unless, unfortunately, you are.

More info at HelpMeWithHIPAA.com/383

View Details

The healthcare industry is not immune to cyberattacks. In fact, it's one of the most vulnerable industries. To protect patient safety and data security, hospitals and healthcare providers need to implement better cybersecurity measures. Today, we review a paper from the office of Senator Mark Warner (VA) that discusses policy options for the healthcare sector.

More info at HelpMeWithHIPAA.com/382

View Details

What is your Incident Response Plan?  If you said “Oh, we’ll just call IT,” then you need to listen to this podcast.  We will review the October 2022 OCR Newsletter that discusses nine procedures that entities should consider including in the incident procedures.

More info at HelpMeWithHIPAA.com/381

View Details

Keeping up on ways to protect your business from a cyber attack can feel intimidating, especially because of the continuously changing methods criminals use to social engineer us. The bottom line is it only takes one click at any time by anyone to open the door to the attackers. 

More info at HelpMeWithHIPAA.com/380

View Details

As you know, each year we record a Halloween episode.  This year we are covering very scary decisions that have come back to haunt several organizations, including an organization’s decision not to report a cyber attack, an entity that thought they’d just stroke a check for fines assessed and everything would be OK, and a provider who posted PHI on social media. Listen in and learn what NOT to do.

More info at HelpMeWithHIPAA.com/379

View Details

Do you remember the saying “there’s an app for that”? Apps certainly are cool and convenient, but can you tell whether they are malicious or not? Today, we discuss and give you some vetting tips you can use before you download apps.  

More info at HelpMeWithHIPAA.com/378

View Details

More and more the healthcare industry is using connected medical devices that do cool things, like creating efficiencies in the delivery of patient care and automating tasks for healthcare providers and their staff.  But, what about the security of these connected devices? Has anyone thought about that? Well, Ponemon and Cynerio did a study on just that topic and the results are very concerning.

More info at HelpMeWithHIPAA.com/377

View Details

OCR’s right of access initiative keeps on churning with three more cases, making a total of 41 violations of patient right of access so far. Dentists are a known problem when it comes to doing anything for HIPAA privacy and security, including right of access requirements. But, they are quickly learning all about OCR enforcements of HIPAA violations.

More info at HelpMeWithHIPAA.com/376

View Details

Every year we review the Ponemon Institute’s Cost of a Data Breach report. It's always interesting because we learn that it's not just about the money. We learn what really makes a difference in our privacy and security program, what we can do that can make the biggest positive impact in the overall cost or a data breach and, more importantly, what things make the biggest negative impact.

More info at HelpMeWithHIPAA.com/375

View Details

We follow a lot of the Ponemon studies. They help us see changes and trends and make better recommendations to our clients. We are going to cover their annual cost of an insider breach study. This global study covers insider incidents and provides five signs your organization is at risk. 

More info at HelpMeWithHIPAA.com/374

View Details

The ongoing, rapidly changing cyber war has created a need for us to change our viewpoint on cybersecurity.  Yes, we need to worry about cyber hygiene and continue working on ways to secure our systems, networks and data. However, there is also a need to take the “plan for the worst but hope for the best” approach and start focusing on cyber resilience.

More info at HelpMeWithHIPAA.com/373

View Details

David admits that as a kid he would dumpster dive for “treasures” people threw away. We’ve heard more than once of clients who have gone dumpster diving to retrieve documents containing PHI that were mistakenly thrown away in the regular trash. But, a recent OCR announcement highlights one dermatology group that had quite the trashy privacy violation.

More info at HelpMeWithHIPAA.com/372

View Details

Should we be questioning other people and vendors we work with about the trust we should have in them? The answer is yes. Are they protecting and securing the patient data we entrust them with?  Trust, but verify is something we talk about a lot. So, I ask you… should you be trusted? And can you prove it?

More info at HelpMeWithHIPAA.com/371

View Details

Privacy laws are being passed in more and more states every year. Even non-healthcare businesses are finding they must follow privacy laws in the states they do business in. Conducting a privacy assessment is a great way to understand what data you have that needs protecting, what things can go wrong and then, of those things that can go wrong, which ones we can try to prevent.

More info at HelpMeWithHIPAA.com/370

View Details

In order to protect PHI, you have to know where it is stored and how it comes in, goes out and moves around your organization. This includes marketing analytic tools used on websites and patient portals. They could be transmitting PHI to social media platforms. Very unnerving, right?

More info at HelpMeWithHIPAA.com/369

View Details

It’s that time again folks! October is Cybersecurity Awareness Month. This year’s theme is “It’s easy to stay safe online” with a weekly focus on key behaviors to help protect your important data. Using these free training tools and practicing basic cybersecurity behaviors, you are much more likely to stay safe online.

More info at HelpMeWithHIPAA.com/368

View Details

A new security rule guide that we’ve all been waiting for! NIST has developed a cybersecurity resource guide on implementing the HIPAA Security Rule. It provides key activities, descriptions and sample questions to help covered entities and business associates comply with the HIPAA Security Rule.  This guide has tons of good information in it. So, listen in as we discuss some of the cool stuff we picked out.

More info at HelpMeWithHIPAA.com/367

View Details

OCR recently announced the resolution of 12 investigations. Eleven were for patient right of access violations and one was a big dollar settlement of a security incident at Oklahoma State University Center for Health Services. Lots to cover and learn in this episode. So, pay attention, folks.

More info at HelpMeWithHIPAA.com/366

View Details

Today’s podcast episode is all about why we worry about supply chain issues, why we keep talking about the HiC SCRiM guidance, and why the first day of the PriSec Boot Camp is supply chain risk management. We’ll review several supply chain breaches, one where there were 660 providers hit at once. As you probably have guessed, these breaches involved ransomware attacks.

More info at HelpMeWithHIPAA.com/365

View Details

It can be a stressful time when you are adding a new vendor or switching vendors for your critical services.  This is the time to create a plan and do a risk analysis to make sure everything gets transitioned and set up properly. Things can go wrong if there’s no plan in place. Today, we review some tips to help you prepare for a vendor transition.

More info at HelpMeWithHIPAA.com/364

View Details

When you're shopping for cybersecurity insurance, the applications can be intense. You'll need to provide a lot of details about your current security protections, and you may be asked to complete a security audit. This is because insurance companies want to be sure that they're not insuring businesses that aren't doing everything they can to protect themselves from cyber attacks. This episode we discuss what questions you may encounter on your cyber insurance applications.

View Details

Ransomware tactics are constantly changing. Understanding the protections we use today will not be enough down the road is key. We must constantly adjust and adapt our security protections to protect against these attacks. Today, we are going to discuss ransomware stats and key points from two recent reports that can help you create a response plan for ransomware attacks.

More info at HelpMeWithHIPAA.com/362

View Details

We use passwords for everything. Creating a unique, secure password for every website and application is hard to remember, right? So, why hasn’t someone figured out how to get rid of passwords? Well, today we are going to talk about the FIDO password killer solution.

More info at HelpMeWithHIPAA.com/361

View Details

How many of us know what we don’t know, or at least, willing to admit we don't know what we don't know? Today, we are going to find out as we cover a few potential data breach scenarios and ask “what would you do - report it or not?” 

More info at HelpMeWithHIPAA.com/360

View Details

Today, we are going to give you our six takeaways from the 15th annual Verizon Data Breach Investigation Report. We like these reports because they give us an indication of what's going on in the cyber world, what we need to be looking for and looking out for.

More info at HelpMeWithHIPAA.com/359

View Details

We get this question all of the time:  How do they get in?  How do the bad guys get in and attack my network? Seems like a simple question, right?  Well there’s not always a clear cut answer.  The first thing you need to understand is that cybersecurity isn't a problem you solve. It's a chronic condition that you have to manage. 

More info at HelpMeWithHIPAA.com/358

View Details

Recently, a Cybersecurity Advisory was released worldwide to MSPs and their customers. We will take a look into what this guidance is, how it applies, and what needs to be done about it.  This is BIG and we all better be paying attention.

More info at HelpMeWithHIPAA.com/357

View Details

Everybody get on board because data security laws keep getting signed in states each year.

The new Maryland and Kentucky data security laws are designed to help protect insurance companies from cyber attacks by implementing cybersecurity standards, developing, implementing, and maintaining a written information security program. Their service providers are also required to implement such programs which include a requirement to report cyber security incidents within 3 days of discovery.

For more details go to HelpMeWithHIPAA.com/356

View Details

Incident response planning is important to every business. You don’t want to figure out how to manage the business and respond to an incident on the fly.  These plans should be reviewed and updated regularly. Today we review a brand new guide from the Healthcare & Public Health Sector Coordinating Council on Operational Continuity - Cyber Incident.

More info at HelpMeWithHIPAA.com/355

View Details

Over the last couple years, we’ve had some high-profile cybersecurity compromises and data breaches. And this trend is not slowing down. Today, we review a recent study of the top cyber threats to healthcare organizations. The results reinforce that PriSec teams require everyone to participate.

More info at HelpMeWithHIPAA.com/354

View Details

Recently, we’ve had a couple things come up which involved tricky places that HIPAA has applied that most people might not think of. So, we thought we'd throw them out there and have a little bit of fun discussing them.

More info at HelpMeWithHIPAA.com/353

View Details

Cybercrime is a booming business. In 2021, the US experienced an unprecedented increase in cyber attacks with criminals making $6.9 billion online. In today’s podcast, we review the FBI’s Internet Crime Report for 2021.

More info at HelpMeWithHIPAA.com/352

View Details

It is crucial for every business to understand the security practices of their vendors. And also to make sure that those vendors are vetting their vendors.  A cyber attack at a link in your supply chain can drastically affect your business. Evidence: the Okta breach.

More info at HelpMeWithHIPAA.com/351

View Details

Have you heard the one about three dentists and a psychiatrist walk into... an OCR investigation? OCR has announced their first set of enforcement actions of 2022, and just in time for our 350th episode.  These involve patient right of access and improper disclosure violations. More info at HelpMeWithHIPAA.com/350

View Details

Donna made many notes from the HIPAA Summit. Today, she and David will share six of her top picks, including the difference between an incident and a breach, how a “check the box compliance program” is not a privacy and security program, importance of understanding what your vendor’s incident response plans are and more.

More info at HelpMeWithHIPAA.com/349

View Details

If you are a regular listener of the podcast, you know how Donna loves to “HIPAA-geek out” over the National HIPAA Summit each year. This year’s National HIPAA Summit did not disappoint. Today, we discuss a few points made concerning enforcement of HIPAA related cases by three arms of the federal government.

More info at HelpMeWithHIPAA.com/348

View Details

Cyber threats are a growing risk that is becoming increasingly difficult to avoid. Small and medium businesses are not immune to these cyber threats. They are a growing business risk. The first step in preventing cyber threats is awareness. 

More info at HelpMeWithHIPAA.com/347

View Details

Security events can have a significant impact on your business. It’s important to understand the magnitude of what’s going on and what the risks are. Having a plan in place to deal with privacy and security events can make it better, but not having one can make it worse. 

More info at HelpMeWithHIPAA.com/346

View Details

The harsh realities of cybersecurity are not always easy to hear, but they are the one thing that we cannot compromise on as they can have a huge impact on our lives. We must remain cyber aware and be vigilant in order to combat cyber threats.

More info at HelpMeWithHIPAA.com/345

View Details

Kardon, Help Me With HIPAA and HIPAA for MSPs is hosting the first PriSec Boot Camp in Louisville, KY on Sep 12, 13, 14 and 15. This ain’t yo Momma’s privacy and security. It is a one of a kind event designed for those who need to understand and manage a privacy and security program.  Listen to today’s podcast to learn all about it.

More info at HelpMeWithHIPAA.com/344

View Details

Encryption can give you a false sense of security. Just because your device or your data is encrypted doesn’t mean it is secure.  You have to understand how encryption works in order to understand how it doesn't work.

More info at HelpMeWithHIPAA.com/343

View Details

Securing your website is often overlooked in planning discussions and business risk management decisions. Building a website is pretty easy these days, but keep in mind users expect to have a safe online experience too. Just like with social media sites, a lot can go wrong with a forgotten website.

More info at HelpMeWithHIPAA.com/342

View Details

More and more SMBs are turning to MSPs to help secure their networks, protect their assets from cyber attacks and meet compliance obligations.  MSPs are looking to add new services to meet the SMB market demand.  Today, we review a few of our observations for SMBs and MSPs from a recent report on the focus for small businesses in the next few years.

More info at HelpMeWithHIPAA.com/341

View Details

Honeypots are an important tool in the cybersecurity arsenal. They can be used to observe how attackers work and what their activities, intentions and strategies are. This information can help organizations better understand and defend against cyber attacks.

More info at HelpMeWithHIPAA.com/340

View Details

Social media has become a very important part of our lives. It is the easiest way to connect with friends, family and even promote your business. If not secured properly, it can also be an easy way for someone to hack into your account and become “you” or be the spokesperson for your business. 

More info at HelpMeWithHIPAA.com/339

View Details

A proper incident response plan is one that details your response to a data breach, cyber attack or other event.  Without a proper plan, things can go horribly awry.  In this episode, we discuss the steps to properly respond to a security incident and then give you seven ways you can completely screw it up.

More info at HelpMeWithHIPAA.com/338

View Details

The unknown is the most dangerous. It's a saying that should be taken into account when protecting your most valuable asset - your data.  Today we talk about why creating an asset inventory of your hardware, software and data is an important first step to being able to protect it.

More info at HelpMeWithHIPAA.com/337

View Details

A new year is right around the corner. The good news is 2021 wasn’t as unpredictable as 2020, but 2022 could be tricky to navigate. It’s time for the review of our 2021 predictions and for us to set new ones for 2022.  So, let’s get started.

More info at HelpMeWithHIPAA.com/336

View Details

Well, another year is coming to a close. No one will forget living through 2020.  Then, 2021 said "Hold my beer." As with every year, there were ups and downs. Who knows what we will be in for in 2022. Regardless, we will continue to adjust.

Thanks to Bojan and our teams who help make this podcast a success. And special thanks to all our podcast listeners. We appreciate everyone’s continued support of our efforts to educate and entertain.

As we do at the end of each year, we let Bojan create a podcast of our bloopers and behind the scenes silliness.  Enjoy his 2021 Blooper Show. It gives us a week off and gives him a chance to get back at us for the whole year of crap.

More data privacy and security madness coming your way next year!  Happy Holidays and Happy New Year to you all!

View Details

OCR has released resolutions to five cases in its HIPAA Patient Right of Access Initiative. This brings the total cases to 25 since the initiative began. These cases continue to underscore the importance of this initiative.

More info at HelpMeWithHIPAA.com/335

View Details

SaaS continues to grow as a popular way to deploy business applications. It is crucial for businesses to understand what data they are storing in their SaaS cloud applications and how to protect it from data breaches. So, listen to us discuss securing your SaaS.

More info at HelpMeWithHIPAA.com/334

View Details

Protecting your company’s data is no longer optional. With so many changes in how people work today and where they are working from, keeping a low profile when it comes to protecting data won’t cut it anymore. Today, we review a recent report released by Shred-it, a secure information destruction company, called Data Protection Report 2021.

More info at HelpMeWithHIPAA.com/333

View Details

For the Thanksgiving episode this year, we talk to the Kardon Team about the recent social engineering attack; a follow up from our Halloween episode, We Are Under Attack - Ep 328. We find out what they experienced and how they felt during and after the attack.  And, because it’s Thanksgiving, we each share what we are thankful for in 2021. 

More info at HelpMeWithHIPAA.com/332

View Details

Use of legacy software and devices plague healthcare. OCR’s recent newsletter focuses on why legacy systems are still used in healthcare organizations and provides guidance on ways to manage the risks of these systems.

More info at HelpMeWithHIPAA.com/331

View Details

The HITECH Act added that state attorney generals can take on cases on behalf of their constituents under HIPAA.  We haven’t seen that many cases from the states thus far, but that may be changing.  Today we discuss a recent New Jersey case regarding fraud, deceit, misrepresentation and professional misconduct. This is an eye opening state level case that everyone should pay attention to.

More info at HelpMeWithHIPAA.com/330

View Details

Insider threats are dangerous for any organization, not just healthcare. As a result, healthcare organizations need to be extra vigilant when it comes to protecting patient data. Today, we talk with Ray Ribble, CEO of SPHER, to hear some stories about why it’s important to review EHR logs and how his company can help you identify potential insider threats.

More info at HelpMeWithHIPAA.com/329

View Details

It’s time for our annual Halloween episode!  This year we will tell you a scary, true story of how our two companies were actively targeted and attacked by a cybercriminal. Hear what happened and how our teams reacted to the cyber attack.

More info at HelpMeWithHIPAA.com/328

View Details

In today’s episode, we talk with Josh Corman, Chief Strategist Cybersecurity and Infrastructure Security Agency (CISA) at the Department of Homeland Security. We will learn about CISA and what information and freely available services they provide to help healthcare businesses and other organizations within the nation’s 16 critical infrastructure sectors from cyber attacks. 

More info at HelpMeWithHIPAA.com/327

View Details

Email is a great tool for communication. It is quick, simple, and it has the potential to reach so many people in so little time. But, it can also be an easy way for hackers to get their hands on your personal information if you're not being careful. Phishing scams are one of the most popular ways that hackers use email as a tool to steal your information and cause data breaches.  Email is evil!

More info at HelpMeWithHIPAA.com/326

View Details

IT and cybersecurity services are not the same. If you are in the market to purchase managed services or security services from an IT firm, you’ll want to listen to this podcast to understand how they are different, why they are different and why you need to understand those differences to better protect your organization from cyber attacks.

More info at HelpMeWithHIPAA.com/325

View Details

In a world where people are more dependent on technology but lack the expertise to manage their own networks and systems effectively and efficiently, they turn to Managed Service Providers (MSPs). CISA has released a guide, Risk Considerations For Managed Service Provider Customers, that outlines risk considerations organizations need to consider when they partner with a MSP. We will cover this in today’s episode and we are making a big announcement that you’ll want to hear.

More info at HelpMeWithHIPAA.com/324

View Details

There are many challenges that come with preparing for and responding to a ransomware attack. Ransomware gangs are constantly changing their tactics in order to get to your organization's data. Therefore, as the ransomware landscape continues to evolve, so too must the preparations and responses of businesses.

More info at HelpMeWithHIPAA.com/323

View Details

You know how we love to pass along guides and resources that can help you improve your organization's privacy and security programs. Today, we are going to review a recent resource guide put out by HHS’ ASPR TRACIE office called Healthcare System Cybersecurity - Readiness and Response Considerations. This guide is packed with very helpful tips, best practices, and resources surrounding cybersecurity and responding to cyber incidents. And it’s FREE!

More info at HelpMeWithHIPAA.com/322

View Details

Social media is full of people who speak “confidently” about topics that they simply do not fully understand. HIPAA is one of those topics. Today, we are covering 7 HIPAA facts that we hope will set the record straight about frequently misunderstood HIPAA topics.

More at HelpMeWithHIPAA.com/321

View Details

Learn 'tricks of the trade' from a real social engineering tester. We interview William Price of Cyberx.tech to learn how they are able to successfully penetrate a company's defenses and get access to their most critical information. How likely would your organization be vulnerable to these same methods?

More info at HelpMeWithHIPAA.com/320

View Details

Have you ever heard tech folks refer to a computer problem as an ID10T error? You probably thought it was some highly technical term geeks use. Well, it’s not and today we are going to talk about a couple posts and articles where folks’ are flying their ID10T flag high and proud. And hopefully try to prevent you from making an ID10T error.

More info at HelpMeWithHIPAA.com/319

View Details

It’s that time of year again. Time to start preparing for National Cybersecurity Awareness Month coming up in October. Do Your Part. #BeCyberSmart is the theme again this year. Be a Cybersecurity Awareness Month Champion for your business, your community and your family.

More info at HelpMeWithHIPAA.com/318

View Details

Managing your vendors, or your supply chain, has become increasingly more important these days.  As we’ve seen in the news just in the last several months, data and system breaches can come as a result of the vendors you work with.  So, we felt like it was time to revisit this topic by reviewing the recent update to the HIC SCRiM guide that includes 6 steps for vendor management.

More info at HelpMeWithHIPAA.com/317

View Details

Every year we cover the most recent report released on the cost of a data breach.  No surprise from this year’s report that the cost continues to rise. And healthcare breaches cost the most across all industries.  Listen in as we go through IBM’s Cost of Data Breach Report 2021.

More info at HelpMeWithHIPAA.com/316

View Details

There’s a new data breach notification bill in Congress that will affect the business community as a whole, not just healthcare. It will create a new data breach disclosure requirement for federal agencies, federal contractors and critical infrastructure companies. It’s time to let folks know when breaches happen. We can’t protect ourselves from things we don’t know about.

More info at HelpMeWithHIPAA.com/315

View Details

There is so much happening in the cyber world today that we couldn’t decide on just one topic to cover in this episode.  So, we will be jumping around and covering a lot of different cyber topics, hence the title of the podcast, Cyber Sqwerl. So, listen fast folks… we’ve got a lot to cover.

More info at HelpMeWithHIPAA.com/314

View Details

Summertime, holidays and long weekends, where many of us are taking time off, are prime times for cyber attacks.  The bad guys are counting on people being in a hurry and letting their guard down so it’ll make it easier to suck you into their attack.  July 4th 2021 was no different.  An MSP was attacked by cyber criminals.  Although this is still an active incident, we will cover what we know in today’s podcast.

More info at HelpMeWithHIPAA.com/313

View Details

Offshore services are a popular option for many businesses. The ability to work around the clock from different sides of the planet is one thing but the cost savings are the primary driving force for this solution. When it comes to HIPAA Business Associates, though, there are a lot of variables that must be considered when deciding whether to offshore or not.

More at HelpMeWithHIPAA.com/312

View Details

Securing your business is not always the easiest thing to do nor the cheapest. Today we will review a Cisco study on small and medium sized businesses and their security best bets. In other words, the things that you can do that will help you to most likely attain success and get you the most bang for your buck.

More info at HelpMeWithHIPAA.com/311

View Details

The Department of Labor (DOL) Employee Benefits Security Administration (EBSA) issued its very first cybersecurity guidance in April 2021and they sound remarkably like all the things that we recommend doing under HIPAA, HICP and the NIST cybersecurity framework. Let’s check it out!

More info at HelpMeWithHIPAA.com/310

View Details

They say ignorance is bliss. Ignorance can also leave you vulnerable to cyber attacks and patient safety issues. As we see news about cyber attacks coming from everywhere, you might ask “Is it really that bad?” Yes, yes it is. And it continues to get worse.

More info at HelpMeWithHIPAA.com/309

View Details

Privacy and security should be a part of all organizations day-to-day activity and company culture. But how do you know how mature your privacy and security program really is? By using one of the many maturity models. Today, we are discussing the new DoD Cybersecurity Maturity Model Certification (CMMC) that breaks controls into levels so you can see what implementation level or maturity level your program is at any given moment.

More info at HelpMeWithHIPAA.com/308

View Details

It’s been a while since we’ve reviewed an OCR settlement that wasn’t about the patient right of access initiative. Things are a changin', and in more ways than one. OCR announced the Peachstate settlement just this week that got our attention. How this case ended up being investigated in the first place is interesting. And as usual, the headline doesn’t tell the whole story. So, let’s dive in and check it out.

More info at HelpMeWithHIPAA.com/307

View Details

One of the biggest security problems on the Internet is a ransomware attack.  Ransomware can impact all our lives.  Just take the Scripps Health and Colonial Pipeline ransomware attacks that we discussed in recent podcast episodes. Last week we gave you 6 tips for planning for a ransomware attack. And today we are going to discuss 6 points from the recently released cybersecurity Executive Order.

More info at HelpMeWithHIPAA.com/306

View Details

Ransomware is just not going away. Falling victim to a ransomware attack will have a BIG impact on you, your business, your clients and your patients. So, today we share some ransomware planning tips. It’s important to know what things you should be doing and should at least consider so that you don’t get caught with your proverbial “pants down.”

More info at HelpMeWithHIPAA.com/305

View Details

We’ve talked about how damaging a ransomware attack can be in healthcare, not only for the practice or health facility but also for patients and the integrity and availability of their data. Today, we discuss an active ransomware attack affecting a health system that is not just making the local news, but also is blowing up on social media and creating a number of privacy concerns. The implications for their patients is terrifying.

More info at HelpMeWithHIPAA.com/304

View Details

We’ve all seen the websites of companies that claim to have a “HIPAA compliant” app, product or service. But does that really mean anything? The short answer is NO! There is no such thing. Today, we answer a listener question about products and services with these types of claims. And, as you can imagine, we have a lot to say about this topic.

More info at HelpMeWithHIPAA.com/303

View Details

We talk about patching pretty frequently on the podcast, but there is still a misconception that your IT or MSP team is patching everything. Systems are not designed to patch all hardware and software all of the time. There is a level of responsibility that falls on us to understand what is being patched by IT, what isn’t and what we do about those unpatched applications.

More info at HelpMeWithHIPAA.com/302

View Details

Basic Cyber Hygiene is a fairly new term, but I realized we have mentioned it several times over the last few weeks. What do we really intend people to see when we talk about it? That may be helpful if we think it would solve most of our cyber attack problems, huh.

More info at HelpMeWithHIPAA.com/301

View Details

Hard to believe that this is our official 300th episode! We are still a tiny podcast in a huge sea but we are pretty sure you can not find a longer running podcast about HIPAA Privacy and Security. To celebrate we have some very special guests, Dave Bittner and Ben Yellen from the CyberWire Caveat podcast. They are joining us for a discussion about where we all see things going in the future for data privacy laws and cybersecurity protections.

More info at HelpMeWithHIPAA.com/300

View Details

Each year the National HIPAA Summit 2021 is a regular event for us. It was held last year just before the shutdown. The event this year was loaded with discussions about what had happened in the previous 12 months and the massive list of things happening in the next 12 months. That is A LOT of HIPAA! Today we cover part 2 of news of note from the conference.

More at HelpMeWithHIPAA.com/299

View Details

If you are a regular listener of the podcast, you know how Donna loves to “HIPAA-geek out” over the HIPAA Summit each year. Things are no different this year as the virtual conference stretched 3 full days and another half day. Needless to say Donna got TONS of information to share - so much so we won’t be able to fit it all in this one podcast. So, let’s get to Part 1 of the HIPAA Summit 2021.

More info at HelpMeWithHIPAA.com/298

View Details

Cyber attacks keep on coming and there is no expectation that they’ll ever stop. Attacks are coming from everywhere - vulnerabilities in software applications, insecure IoT devices connected on the internet, email attacks and phishing, etc. Protecting your systems from cyber attacks is not a “one and done,” “set it and forget it” project. It is a critical and continuous business process that every organization must address. And, surprise surprise, it also requires vetting your vendors as many attacks are coming through your supply chain.

More info at HelpMeWithHIPAA.com/297

View Details

Reports are coming out evaluating cyber threats with stats and details documenting the aftermath of attacks happening in 2020 and the outlook for 2021. Let’s just say they are all on brand with what you expect from anything related to 2020. As you can guess, it isn’t looking good for 2021 based on where we are right now. We reviewed some of the articles and reports evaluating cyber threats so you don’t have to... unless you must.

More at HelpMeWithHIPAA.com/296

View Details

Isn’t it always the little things that make a big difference? That’s true not only in life, but also when it comes to protecting your data and network from attacks. And, it is often the small things that when overlooked can become a big problem. So, today we are talking about some of the things that you need to be looking for and that can make a big difference in your privacy and security programs.

For more info HelpMeWithHIPAA.com/295

View Details

Supply chain cyber threats are happening so often it seems like they keep showing up in the news daily. The list of cases keeps growing every month. So much is still slowly being learned about the SolarWinds attack it is getting hard to keep up with how far it goes. Now we have water systems and more healthcare breaches trickling in. This week I even saw a case we covered before about exposed PACS images. It’s time for us to talk about what these supply chain attacks mean to the rest of us.

For more info HelpMeWithHIPAA.com/294

View Details

Supply chain cyber threats are happening so often they keep showing up in the news. The list keeps growing every month. So much is still slowly being learned about the SolarWinds attack it is getting hard to keep up. Now we have water systems and more healthcare breaches trickling in. It’s time for us to talk about what these supply chain attacks mean to the rest of us.

More at HelpMeWithHIPAA.com/293

View Details

Smart cyber habits are part of a new initiative introduced by CISA they have titled Reduce the Risk of Ransomware Awareness Campaign that will be running for a new month now. The campaign includes a lot of great educational information and a toolkit among other things they have planned. Certainly worth us sharing with you guys because you can’t have too many chances to find something that will connect with leadership or your workforce.

More at HelpMeWithHIPAA.com/292

View Details

HHS's Office for Civil Rights published their proposed changes to the HIPAA Privacy Rule. The changes include some required to make HIPAA better align with the requirements of 21st Century Cures Act for patient access to their records. There's a few other changes to note, as well. Let's check them out, shall we?

More into at HelpMeWithHIPAA.com/291

View Details

During NCSAM Kardon signed up for the Terranova Phishing Tournament - much to everyone’s surprise. Great news is we didn’t have anyone clicking on the link. What did they learn in the tournament?

More at HelpMeWithHIPAA.com/290

View Details

The OCR enforcement announcements keep coming. Our reviews of not only the new announcements but news on some of the older ones are the topic for today. Did you know one from 2018 is still being reviewed in the courts while we get new ones already in 2021?

More at HelpMeWithHIPAA.com/289

View Details

Always great to talk cybersecurity insurance coverage with John Miller of Sterling Seacrest Partners. Threats are constantly evolving for all of us. That means cyber liability coverage must also evolve.

Have you evaluated what your cyber policy will really cover when you are attacked? There are certainly several areas John brings up for us all to consider in our cybersecurity policies.

More info at HelpMeWithHIPAA.com/288

View Details

Making annual predictions is always a little bit guessing and a lot of luck by the end of the year. No way any of us could have predicted where we would go throughout the year we just call 2020. Only history will tell us will give us the distance to understand the last 12 months. Who knows where we will go next but what the umm heck. We figured we would do it again.

More info at HelpMeWithHIPAA.com/287

View Details

A new HIPAA safe harbor rule is out there floating around now. A safe harbor is a legal term that refers to laws and regulations that specify that certain actions will be considered not to violate a given rule. It is often used to clarify big standards like HIPAA. Encryption is one of those things under the breach rules. Do you know about HR 7898?

More at HelpMeWithHIPAA/286

View Details

A hospital President, after being hit by a cyber attack, said “We really did not anticipate the scope or the impact the attack had on our system and how far-reaching it was.”

This is just the beginning. Get prepared for more to come. Especially, with the success of the major SolarWinds infiltration. We knew things were getting worse weeks ago when we recorded this one. Where do we see things going?

More at HelpMeWithHIPAA.com/285

View Details

What a year it has been! Say what you will but none of us will EVER forget living through 2020. As we have all adjusted throughout the year we appreciate everyone's continued support of our efforts to educate and entertain.

As is our custom, our editor, Bojan, gets his annual 15 minutes of fame.  Enjoy his year end Blooper Show edition that gives us a week off and gives him a chance to get back at us for the whole year of crap.

More data privacy and security madness coming your way next year which is actually next week!  Happy Holidays, Happy New Year, and Happy End of 2020!

View Details

The value of the HICP guides is really beginning to be realized as we approach the 2nd anniversary of it's release. Erik Decker, Chief Information Security Officer and Chief Privacy Officer, University of Chicago Medical Center (and 405d Task Force industry lead and co-chair) was kind enough to join us again to discuss what's coming next for HICP and what he sees in healthcare cybersecurity management as we head into 2021.

More at HelpMeWithHIPAA.com/284

View Details

Amazon is rolling out a new “feature” called Sidewalk. If you have any Alexa devices or certain Ring devices on a network we say get off the Sidewalk! At least until you figure out how it can be secured.

More at HelpMeWithHIPAA.com/283

View Details

With so much going on this year things that would have been big news are slipping by with little notice. Back in 2016 The 21st Century Cures Act was passed which included a lot of healthcare IT updates to improve patient access to their information. A specific section was all about how to prevent information blocking. What is it, why do you care and when will things happen? That’s the topic today.

More at HelpMeWithHIPAA.com/282

View Details

Each year we take the week off on Thanksgiving and share a replay of an episode we want to share. This year it seemed appropriate to share our original predictions for 2020 that we did just before the world turned upside down with a pandemic.

In a few weeks we will evaluate how we did but for now, catch up on how naive we all were just a few months ago.

View Details

Just because a story isn’t about healthcare or HIPAA doesn’t mean they don’t offer some important news for folks in healthcare to take note. Marriott and Zoom cybersecurity cases were just in the news. We all need to take note of them and pay close attention to what happened. Oh, and there is a new one in healthcare that does include a vendor.

More info at HelpMeWithHIPAA.com/281

View Details

Every time we think we get ahead of the current news more things happen! More enforcement news, more ransomware specific warnings, more cyber threats to worry about. Let’s get to it!

More info at HelpMeWithHIPAA.com/280

View Details

Tamika Bass joins us today to discuss the importance of effective communication skills. We have spent a lot of time discussing that it is everyone’s responsibility to participate in cybersecurity protections. One big issue in making that happen is to have tech teams communicate effectively with non-tech teams. As Tamika says “if there is no understanding then communication didn’t happen”.

More info at HelpMeWithHIPAA.com/279

View Details

Hard to believe that we are rolling out our 6th Halloween episode! This year you get to help figure out the costumes at the network office party. Can you guess what all the cyber costumes are saying?

More notes at HelpMeWithHIPAA.com/278

View Details

More HIPAA COVID examples, another OCR action announced and it is the last week of Cybersecurity Awareness Month. Time to get informed and #BeCyberSmart about connected devices.

More info at HelpMeWithHIPAA.com/277

View Details

We get to week 3 of #BeCyberSmart NCSAM. We had no idea when we made this plan that OCR would start dropping settlements at the same time. After a pretty quiet year they announced more settlements in September than they ever had in a single month before. Again, we have a lot to review! Reminds me of one of my favorite movie quotes:

“Life moves pretty fast. If you don't stop and look around once in a while, you could miss it.”  Ferris Bueller

More info at HelpMeWithHIPAA.com/276

View Details

Our commitment to include #BeCyberSmart each week this month did not anticipate that OCR would set a record for resolution announcements in September. This week we give you info to plan for next week’s activities for NCSAM plus a review of the Athens Orthopedic resolution agreement. A lot to cover!

More at HelpMeWithHIPAA.com/275

View Details

The first week of National Cybersecurity Awareness Month (NCSAM) 2020 is next week. The theme: If You Connect It, Protect It. How can you use it in your organization? We cover that plus OCR’s 5 resolutions in one announcement reiterating their commitment to patient access rights.

For more info: HelpMeWithHIPAA.com/274

View Details

We missed the boat on National Insider Threat Awareness month in Sept: Insider Threat Mitigation but we are not going to miss NCSAM this year. Do Your Part. #BeCyberSmart and If You Connect It, Protect It. are going to be all over the place here in October.

More at HelpMeWithHIPAA.com/273

View Details

There is so much going on right now it is hard to keep up. I know there is a lot of activity when we can’t keep an eye on everything! There are several stories that I think we should all be aware of but the big headline one is about HIPAA changes coming in 2020. However, it isn’t the only one about changes that you should be aware of also.

More info at HelpMeWithHIPAA.com/272

View Details

This episode is the continuation of our Cybersecurity Tales Part 1 last week. We get into more discussions about real world cases involving cyber attacks the team at Black Talon have been called for data breach response. This part is where David really started getting scared!

More info at HelpMeWithHIPAA.com/271

View Details

Recently we talked with Gary Salman, CEO of Black Talon Security. Our discussion was lively and full of great stories and tips. There was so much there we decided to break this into two episodes. This is part 1 and next week we will share part 2. Let’s get started on cybersecurity tales!

More at HelpMeWithHIPAA.com/270

View Details

After teaching our 3-day HIPAA Boot Camp we were pretty exhausted. In this episode we are discussing the interesting things David found when reading articles about cybersecurity myths.

More info at HelpMeWithHIPAA.com/269

View Details

Today we are going to cover what we expected to see start happening after the rush to convert us all to work from home. The discussions about our concern that no one was paying attention except the criminals is starting to come to fruition.

More info at HelpMeWithHIPAA.com/268

View Details

Everywhere we turn this year we are dealing with chaos and stress. Can we all just sing Kumbaya and make it go away? If it was only that easy. Just because craziness has happened doesn't mean HIPAA goes out the window. As we all try to navigate the unknown we can not forget that the criminals thrive on chaos like this. If you aren’t protecting your information a data breach becomes almost inevitable. It is important to understand the data breach costs you are looking at when one occurs.

More info at HelpMeWithHIPAA.com/267

View Details

These new settlements from OCR should be new required reading. There is very little guessing about their expectations in these CAPs. Specifically mentioning encryption requirements and mobile device management is not ambiguous at all. Things are getting real folks!

More info at HelpMeWithHIPAA.com/266

View Details

There are plenty of things happening that you should be aware of including a new settlement announcement from OCR. This and more things happening out there you should know about!

More info at HelpMeWithHIPAA.com/265

View Details

So happy that we are finally doing this show in time to remind you to use the free security awareness training resources available for October which is National Cybersecurity Awareness Month (NCSAM). There are a lot of free resources available to promote security awareness under that program released each year. Today we are discussing how to use these resources to work out a plan for your training through out October!

More at HelpMeWithHIPAA.com/264

View Details

The threat of ransomware continues to be a major issue for all businesses. MSPs were a gateway for mass cyber attacks in 2019. Make sure your IT provider is using the new guide specifically for them produced by NIST and NCCoE: PROTECTING DATA FROM RANSOMWARE AND OTHER DATA LOSS EVENTS. While we are at it there are a couple of articles relating to ransomware’s impact on insurance coverage that we need to bring to your attention.

More at HelpMeWithHIPAA.com/263

View Details

The annual Verizon data breach report was recently released for 2020. Learning from other’s mistakes is always the best way to learn vs the alternatives. These reports always offer very specific details that we find very enlightening and helpful in making business decisions relating to security in all businesses.

More at HelpMeWithHIPAA.com/262

View Details

COVID-19 Testing vs HIPAA is starting to play out all over the country as businesses reopen and the virus continues to spread. Today we will discuss some of the confusion about all the COVID-19 testing and HIPAA.

More at HelpMeWithHIPAA.com/261

View Details

So far 2020 has the whole world turned upside down. A true global pandemic, global economic fallout still happening from a shutdown caused by the pandemic and a level of global social unrest that hasn’t been seen in 40-50 years. Yes, it is overwhelming. But, it is also very clear that the criminal factors and nation-state attackers are well aware no one is watching the hen house too.

More info at HelpMeWithHIPAA.com/260

View Details

Too often our human selves will happily put off some responsibilities on others if we can find any small reason for doing so. It may not be our best quality but it is certainly one that bonds most of us together. I personally can’t name anyone that would say sorry I would like to take responsibility for something I think is your responsibility. In our world today we all need to take responsibility for helping protect the group as a whole. The NICE team from NIST published something about just that when it comes to cybersecurity. Time to get ready to discuss it is everyone’s responsibility, not just a select few.

More at HelpMeWithHIPAA.com/259

View Details

If you are a fan of horror flicks you know the story. Even if you are not a fan you probably know the line from When A Stranger Calls: “the calls are coming from a phone inside the house”. That stuff happens in the opening. Personally, I have never made it through that part much less through the whole thing. Today we have a whole new horror flick to discuss: cyberattacks coming from inside the network. Maybe we should hold this until Halloween but who knows what will happen then, we need to cover this because it is happening now.

More info at HelpMeWithHIPAA.com/258

View Details

Perfect timing rarely happens these days but we have been discussing updating incident response plans based on what we have learned in the last two months. In fact, we ended our last episode saying the response plan update is one of the most important things you should do. Like magic Erik Decker posts on LinkedIn this week that the HIC group has finished a new guide specifically about crisis response.

More info at HelpMeWithHIPAA.com/257

View Details

We always know when serious stuff has happened behind the scenes and OCR got involved. Some major violations of privacy rights must have happened when we see the OCR notice reminding everyone that you can not share patient information with the media without authorization.

More info at HelpMeWithHIPAA.com/256

View Details

We mentioned in the last episode that we would put together a checklist of sorts for what to do as everyone switches back to the old way of doing business or sets up under new remote models. While this isn’t exactly a copy and paste checklist it does give you food for thought as to what to consider for your own reboot checklist.

More at HelpMeWithHIPAA.com/255

View Details

When can we stop talking about ransomware? Apparently, never. One of the things we can list as part of our “new normal” is new ways ransomware is going to be impacting us differently. Things are worse today than when we discussed ransomware just a couple of months ago. The pandemic has opened up so many ways for the criminals to attack they are having a field day.

More at HelpMeWithHIPAA.com/254

View Details

Like it or not we have to face new realities on our threat lists as we figure out our new normal in the post COVID-19 landscape. The privacy and security risks have changed just like everything else during the crisis. Threat lists used for your SRA must be updated and addressed. You do not want to be hit with data breaches and privacy breaches just as you get things back up and running, do you?

More at HelpMeWithHIPAA.com/253

View Details

Before things went all COVID on us this episode was planned out. It may be even more worthy of an episode now. Have you been evaluating your MSPs response to your current state of business? We knew there were some MSP issues in 2019 but now, in 2020, you must have a reliable trusted MSP partner more than ever. What kinds of things do you need to know about your tech needs, your MSP and where you both plan for the future?

More at HelpMeWithHIPAA.com/252

View Details

So many scams and so little time to keep up with them. Yes, that is what it feels like these days. There are so many coronavirus scams we have to take some time to update you guys. There have been cybercrime alerts and stupid people stories galore. Here are the coronavirus scams and crimes we have on our radar this week.

More at HelpMeWithHIPAA.com/251

View Details

With the national crisis still in play, cybersecurity is essential to operating businesses which are now online more than ever before. Small businesses without any apps before are going online to survive. Telehealth, remote learning, telework are all standard right now. With so much going on we are trying to keep our eye on cyber stories to prepare ourselves and our clients for what is happening out there. Today let’s discuss 3 cyber stories we are watching right now.

More at HelpMeWithHIPAA.com/250

View Details

There is a lot of confusion along the way as there always will be in a crisis like this one. We are going to share some of the good information and do our best to clear up some of the misinformation. No matter what, though, it could all change in the two short weeks between when we record this and when we publish it for you guys. Our plan is to provide as much solid information that we know to be true and accurate today.

More at HelpMeWithHIPAA.com/249

View Details

We are all doing our best to focus on what we can do during this national crisis. It is certain that we will bounce back at some point and be able to get back to business. When we do this national reboot, what kinds of things will we need to do? Spend time now planning for the coming business reboot.

More at HelpMeWithHIPAA.com/248

View Details

In Oct 2019 another document was released by the Health Sector Coordinating Council Joint Cybersecurity Working Group. Health Industry Cybersecurity Supply Chain Risk Management Guide or HIC SCRiM for short is aimed at helping small and medium sized healthcare organizations manage their supply chain vendors. If you haven’t had a chance to check it out, we are reviewing it for you today. If you do review it you will see why we think that HIC SCRiM should wake up vendors.

More info at HelpMeWithHIPAA.com/247

View Details

Opening the 2020 enforcement list for OCR is a doctor’s office who reported a breach due to a business associate issue and then did nothing. The settlement wasn’t due to the BA but because the office had no SRA in place. Let’s break down the settlement with Steven A. Porter, M.D., P.C. a sole gastroenterologist practice in Ogden, UT. Time to learn from their mistakes.

More at HelpMeWithHIPAA.com/246

View Details

Does your SRA include something like COVID-19? Your business continuity plans include it? Do you need an SRA that includes virus outbreaks? Yes, you do. If your risk analysis didn’t include these kinds of things you should revisit your method for doing an SRA. What should you do about this risk and what else is missing from your SRA? Let’s talk about privacy, security and COVID-19.

More info at HelpMeWithHIPAA.com/245

View Details

Cybersecurity misconceptions are pretty common both in personal life and business. There are definitely enough cases of misinformation coming through our offices on a regular basis to make it obvious just how confused people can be about what should be done. We have pointed out many times that the government has been releasing information for years to assist both businesses and individuals. You can find a lot of information that is very helpful at StaySafeOnline.org. Today we are going to discuss one directed at SMBs explaining several cybersecurity misconceptions.

More at HelpMeWithHIPAA.com/244

View Details

This story has been going around since September 2019. Images exposed on the internet from PACS systems around the world available to anyone that wanted to see them. Images exposed included x-rays, MRI scans and more. It still hasn’t been locked down after all these months. That means it’s time to talk about it instead of keeping it quiet.

More info at HelpMeWithHIPAA.com/243

View Details

Another report comes out that says insiders are a huge problem.  You have to worry about the people, people. We have been saying this for years.  The lastest news on that front is in the 2020 Cost Of Insider Threats Global Report released by the Ponemon Institute and sponsored by ObserveIT and IBM.  It does tell us a lot of things we already knew but the details including those about how it is growing are important to note.

More info at HelpMeWithHIPAA.com/242

View Details

Wearables, medical devices and HIPAA are just some of the questions we have gotten recently. Today’s episode is privacy and security news plus listener questions.

More at HelpMeWithHIPAA.com/241

View Details

Is HIPAA ambiguous? That is the way many people refer to anything that has to do with HIPAA regulations. It comes from doctors, nurses, lawyers, managers, supervisors, even compliance officers. But, is it really the way we should refer to the law? Should we say it is flexible or reasonable instead?

More at HelpMeWithHIPAA.com/240

View Details

There have been a lot of headlines lately about Windows 7 end of life and Windows 10 security patches.  Let’s discuss why supported software and security patching matters in general. Then, we can talk about why it matters under HIPAA.  

More at HelpMeWithHIPAA.com/239

View Details

We have mentioned ransomware warnings over and over on HMWH. To the point ransomware shows up in a search on 56 different episodes before this one. That means we’ve talked about ransomware warnings in 24% of our episodes. Guess what - clearly we need to talk about it again!

More info at HelpMeWithHIPAA.com/238

View Details

As we anticipated there was one more OCR settlement announcement before the end of 2019. This one popped in at the end of December and was yet another one in our backyard. The ambulance company settlement seemed simple at first but once we read the details there is a lot to unpack in the CAP. Let’s get to it then!

More info at HelpMeWithHIPAA.com/237

View Details

We need to get on the record with our 2020 predictions even if we both agree we have no freaking idea what is going to happen in 2020. If anyone out there says they honestly believe they have a true beat on it, check them out. We do have a few 2020 predictions that we feel sure enough about to say it outloud to you guys.

More info at HelpMeWithHIPAA.com/236

View Details

Here we go with two more OCR enforcement settlements. As we expected, the end of the year included a flurry of enforcement announcements from OCR. Just as this was about to be recorded they announced the second patient access settlement. So we can we get both done in one episode! Both of these cases are related to some costly PHI mistakes so let’s get down to business.

More info at HelpMeWithHIPAA.com/235

View Details

We have made it most of the way through 2019. Now is the time to see how we did when we released our HIPAA privacy and security predictions for 2019 in episode 186 way back on Jan 11. There were so many things that transpired this year just when thinking about the threat landscape much less all of our HIPAA discussions it feels long ago in a galaxy far, far away.

For more info HelpMeWithHIPAA.com/234

View Details

Enjoy Bojan's 2019 version of our annual blooper show.  Yes, some things really are as crazy behind the scenes as it seems.

Thanks for all your support in 2019.  Enjoy whatever holiday you celebrate this time of year to the fullest!

View Details

A Business Associate Agreement isn’t just another simple bit of paperwork. The liability commitments in your BAA and the business relationship it defines are very serious and very important in defining clearly the responsibilities of both parties. Lately, we have had to ask a lot of questions like what is in your BAA and today we discuss what we have been seeing out there in the wild, so to speak.

More info at HelpMeWithHIPAA.com/233

View Details

OCR has been busy closing out investigations lately. They announced 2 more enforcement actions in early November. One was a settlement in NY, but the other was a civil money penalty with Texas HHSC. Let’s review these 2 new OCR enforcement actions to see what we need to learn from the details released.

More info at HelpMeWithHIPAA.com/232

View Details

Happy Thanksgiving from the HMWH team.  Since we just talked with Erik Decker the last two weeks about HICP it seemed fitting that our Thanksgiving replay this year is the discussion we had about our initial review of HICP earlier in 2019.  That was episode 189.

Thanks for listening and enjoy the Holiday season!

View Details

Today we share part 2 of our Erik Decker HICP discussion. Learn about more tools for small and medium organizations. The 405(d) Task Group has more work to do so learn ways you can help spread the word about using these tools to improve healthcare cybersecurity. We even ask how we can all help promote cybersecurity awareness and HICP to improve the healthcare cybersecurity.

HelpMeWithHIPAA.com/231

View Details

We covered the release of HICP or Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients back in Feb in the episode we called 5 Threats and 10 Protection Practices – Ep 189. HICP has now been out for a bit and the next phases of the project are in process. Today we discuss all things HICP with Erik Decker who is the Health Sector Coordinating Council Co-Lead of the 405(d) Task Group that developed this tool to help our sector follow solid cybersecurity practices.

More info at HelpMeWithHIPAA.com/230

View Details

HIPAA penalties are always discussed in training and presentations about HIPAA. Those discussions are usually more about an overview of what is in the law than actual information on how the law is applied. HIPAA penalties are really not seen often. Civil money penalties are not part of the settlements we usually see but OCR announced a big one in October. How do they really apply those huge numbers everyone talks about but we never see?

More info at HelpMeWithHIPAA.com/229

View Details

The annual conference hosted by NIST and OCR Safeguarding Health Information: Building Assurance through HIPAA Security and the repeated message on day one of the conference was “HIPAA is the floor” which started with OCR Dir Severino’s keynote. We always get information at some point that makes these conferences worth the time. What did we get from this one?

More info at HelpMeWithHIPAA.com/228

View Details

As is our custom, each year we have a halloween-themed episode. This year we are thrilled to bring you several very real Tales From The Dark Side Of HIPAA. Thanks to our friend, Jack Rhysider from DarkNet Diaries for recording our haunting lead-in!

More info at HelpMeWithHIPAA.com/227

View Details

Social media and PHI get the OCR spotlight in the latest settlement announced. Reading these settlement agreements provide the best guidance from OCR which is why we always take the time to get those details for you. How much have you considered about your social media policies and how your staff understands their responsibilities?

More info at HelpMeWithHIPAA.com/226

View Details

Is there such a thing as bad luck breaches? Most of us don’t expect luck to rule our world although I will always take good luck if I can get it. But when bad things happen sometimes we say it is due to a string of bad luck. Can data breaches be due to one of those strings of bad luck?

For more info go to HelpMeWithHIPAA.com/225

View Details

The first patient access settlement has been announced by OCR. Director Severino mentioned they would be putting an emphasis on this issue and we now have the first enforcement come through. What should you learn from this settlement? It included some interesting corrective action requirements.

More HelpMeWithHIPAA.com/224

View Details

January 14, 2020 marks the end of life for Windows 7 and Windows 2008 operating systems. Have you done your SRA to make sure you have things covered? What about home computers, should you be worried about those? In this episode we review what this end of life for Windows OS means and what you should be doing in the 4th quarter of 2019 to prepare for it.

More at HelpMeWithHIPAA.com/223

View Details

We always talk about the need for a culture of compliance or culture of privacy and security. Today we talk about 6 things you notice when you have built a culture of compliance. The 6 comes from 3 x 2 which means there is clearly no rhyme or reason for the selection today.

More at HelpMeWithHIPAA.com/222

View Details

When working on a plan for this episode I had two different sources drop some insider breach issues in my lap. When I added those to the news stories we are already following involving insider issues, it was clear the topic was meant to be. Multiple cases and reports are out — the topic I must cover is because I am reading about insider breaches everywhere around me.

More at HelpMeWithHIPAA.com/221

View Details

October is National Cybersecurity Awareness Month (NCSAM) and it is a perfect tool to feature security awareness with your workforce and clients. You can not beat an opportunity to run a month long awareness program that provides EVERYTHING you need for free. Today we discuss what the program includes and how to use it in your office.

More at HelpMeWithHIPAA.com/220

View Details

We discussed the patient rights to access medical records a few episodes ago. Since then, a new study came out that says a majority of providers are not complying with patient medical records requests. I have also gotten more questions about law firms demanding to pay only $6.50 for medical records requests. We are discussing these issues with specifics about fees for patient requests in this episode.

More at HelpMeWithHIPAA.com/219

View Details

When you work with outsourced IT or Managed Service Providers (MSPs) you need to vet them closely to make sure they truly do understand what HIPAA requires from your organization. Here are seven questions to ask your IT team about HIPAA.

For more info go to HelpMeWithHIPAA.com/218

View Details

The Ponemon Institute has produced an annual study of data breach costs. This is the 14th year. We have used it as a guide for a lot of information over the years. The data has consistently been helpful for us to understand what are the key drivers in data breach costs, remediation, and response. If you can find what the major factors include, it is a great way to determine your priorities in investing resources with the biggest impact. Let’s see what we learned from the 2019 version sponsored by IBM.

More info at HelpMeWithHIPAA.com/217

View Details

Who is a business associate? A listener asked for an episode on it. Turns out we haven't done one since episode 2. Wow! So, maybe there is more we have to add to that topic in 2019 after 214 other episodes. Today, let’s talk about how to determine who is your Business Associates or BA.

More info at HelpMeWithHIPAA.com/216

View Details

We have gotten a flurry of listener questions and comments lately. Since it is so much easier to do an episode based you listener questions that writing up a whole plan we are definitely doing those today. We really do read and respond to as many as we can. So here we go.

More info at HelpMeWithHIPAA.com/215

View Details

If you haven’t heard of it before there is a thing called the California Consumer Privacy Act (CCPA). It is considered the first version of a GDPR-type legislation on this side of the pond. It becomes effective Jan 1, 2020. There are many folks that think the CCPA isn’t something for them to worry about. Well... Maybe you should take a second to reconsider that position.

More at HelpMeWithHIPAA.com/214

View Details

Today we discuss 5 medical record uses and disclosures rules that I have been covering recently in training. Medical records are always around for those of us in healthcare. It is so easy to forget that the rules apply to more than just data breaches and social media. There are some very basic concepts that people who have been dealing with medical records for years are surprised to learn. Here are five of them we use the most.

More at HelpMeWithHIPAA.com/213

View Details

We need to keep up with our education just like everyone else to keep up with cybersecurity tips and trends. Donna hit some training at SecureWorld and sat in on a 6-hr online seminar offered by Dark Reading. All of that thinking and learning means we have cybersecurity tips and trends to share in this episode. This is not just for those who worry about HIPAA.

More info at HelpMeWithHIPAA.com/212

View Details

The debate continues in ransomware attacks, do you make the ransom payment or not? Lately, we have seen many payments being announced. This should be in your incident response plan ransomware playbook. These decisions should be discussed now, not when an attack happens. What are the pros and cons to paying and what should be in your ransomware response plans?

More info on Help Me With HIPAA blog post.

View Details

False claims settlements over meaningful use money have popped into the news again. The provider was sued by whistleblowers and the DOJ for not doing a security risk analysis but attesting to one to get the meaningful use payments anyway. There is whistleblower's angle in this case which makes it even more interesting. If you know anyone that has received any meaningful use money they should check out this episode!

More info at HelpMeWithHIPAA.com/210

View Details

This new BA guidance from OCR is important because it defines clearly all the things we hear misstated over and over. Several of our Top 10 Wrong HIPAA Statements episode are addressed in the simple ten item list. Today we will discuss the announcement and what does that mean to BAs and their privacy and security programs.

More info at HelpMeWithHIPAA.com/209

View Details

The multi-state settlement with Medical Informatics Engineering makes the OCR settlement seem like a cake walk. The vendor agrees to pay OCR $100,000 with a standard 2-year corrective action plan. The states get $900,000 plus 5 years of very specific corrective action requirements. Vendors need to pay attention to this case and take appropriate action now.

More info at HelpMeWithHIPAA.com/208

View Details

Sanction policies are often vague or even overlooked in many privacy and security programs.  The whole point of a sanction policy is to list out the consequences for failure to follow our policies and procedures.  With a vague or non-existent policy consequences aren’t clear which leads to a lack of concern for failure to follow the policy in the first place.  You will never build a culture that worries about protecting information without it being clear that is a requirement for inclusion in our culture. How do you sanction?  

More at HelpMeWithHIPAA.com/207

View Details

Maturity is something we expect from respected folks or grown folks but what about your privacy and security program, do you check it’s maturity? You have all of these plans, policies, procedures, and training but is it actually meeting your needs? Time to talk maturity assessments.

More at HelpMeWithHIPAA.com/206

View Details

The latest HIPAA violation settlement with OCR was announced recently.  Ironically, the settlement with Touchstone Medical Imaging was for $3,000,000 and announced just after the reduction of maximum penalties was announced by HHS.  Just how bad was this violation to get hit with this level of penalties plus the 2-year corrective action plan?

More at HelpMeWithHIPAA.com/205

View Details

Headlines everywhere are telling us all that the HIPAA penalties are being “slashed” or “capped” or “reduced”. What is the real story and what does it mean to the rest of us? Great time to talk about what you should consider if you think you will be facing any HIPAA penalties.

More info at HelpMeWithHIPAA.com/204

View Details

We have talked many times about vetting business associates. When people talk about supply chain security it isn’t just the business associate you contract with you have to worry about. It is all the vendors that they use. Today we are going to review 3 supply chain stories that explain how complex your supply chain unbeknownst to you.

More at HelpMeWithHIPAA.com/203

View Details

We are all being watched. Cameras are everywhere today. With the advent of dashcams, home security camera systems, CCTV in cities and businesses we are caught on camera somewhere every day. What does that mean when you have privacy concerns to address like, I don’t know, HIPAA?

More info HelpMeWithHIPAA.com/202

View Details

We discussed this whole Alexa and HIPAA thing before. This week came the big announcement from Amazon that had headlines telling us that Alexa is HIPAA compliant with some slick new medical skills. Time to talk about her again. Let’s see what the announcement really said. While we are at it we will also look into the story that Amazon also has thousands of people sitting around listening to Alexa requests all day long.

More info at HelpMeWithHIPAA.com/201

View Details

It is hard to believe we are recording our 200th episode. Some might even say it is close to a miracle that David and Donna could stay focused on one thing for this long. Probably very true. Our passion for what we do here is more than most people would think. We truly do believe that tagline we use in every episode “HIPAA is not about compliance; it’s about patient care.”.

More at HelpMeWithHIPAA.com/200

View Details

Medical record release is becoming a heated topic.  There are several parties involved in the discussion.  Of course, the patient and their rights to the medical record comes first.  Then, you have the providers trying to meet their obligations to supply the records.  But, there are also lawyers and medical record release of information companies and, of course, OCR involved.  Today we will try to make some sense out of the mess.

More at HelpMeWithHIPAA.com/199

View Details

We come bearing news from the 2019 HIPAA Summit, today. Officially, it was The 28th Annual National HIPAA Summit. The event happened in March from Washington, DC. Thankfully, they have offered a webcast option along with onsite attendance for years. I sat in on the HIPAA Summit sessions again via webcast and there is much to share.

For more info go to HelpMeWithHIPAA.com/198

View Details

We are fans of the podcast DarkNet Diaries, “True stories from the dark side of the Internet”. As fans, it explains why we are excited to have Jack Rhysider, the host of DarkNet Diaries, on the podcast with us today. Prepare to be surprised by some of these real hacker stories.

More info at HelpMeWithHIPAA.com/197

View Details

It is important to think about what could happen if one of your vendors is the reason you become another business listed in data breach statistics. Third-party data breaches can impact your business even when it doesn't involve your data. These stories show how many different angles you should use when reviewing their impact on your business.

More info at HelpMeWithHIPAA.com/196

View Details

John Miller, CEO of Sterling Seacrest Partners, was with us back at the beginning of our podcast experiment. Over 100 episodes ago, in February 2017 on episode 89, we first talked with him about cyber insurance policies. Today we’ve brought John back to discuss how cyber insurance coverage has changed over the last two years.

More info at HelpMeWithHIPAA.com/195

View Details

Ransomware is getting scarier even if you don’t know it yet. It appears that the lull we enjoyed through the last bit of 2018 may be over. Not only are the incidents increasing but the mechanisms and ransom demands are changing. Yes, no matter how we looked at it we had to say ransomware is getting scarier than it has been since the beginning of 2018.

More info at HelpMeWithHIPAA.com/194

View Details

There are several recent studies and articles that discuss the world from the viewpoint of the people who have the cybersecurity roles in your IT staff. Their days are packed just trying to keep everything working and secure. As much as we have been after IT folks lately it is important to note that many times they take care of problems that you never even see. Today we are taking the time to remember that cybersecurity roles are tough. Really all IT roles involved in protecting our valuable information resources are tough jobs. It takes everyone to defend our data so your cybersecurity team needs your support!

More details at HelpMeWithHIPAA.com/193

View Details

If you spend time every day worrying about the risks in using email, you might be a security professional.  Email is very risky even if you don’t realize it.  Imagine that you are just walking along a bridge safely.  What you don’t realize is the pit that is just a few inches below the bridge is filled with snakes, gators, and poison spikes.  One small mistake could mean - dum, dah, dum, dum, duuummmm.  Email is dangerous, seriously it is.

More info at HelpMeWithHIPAA.com/192

View Details

OCR got to toot its own horn in a big press release on Feb 7.  Not only did they announce another settlement that happened in December that we had not heard about but they also recapped the record-setting year they had with enforcement cases in 2018. Time to learn from other's mistakes.

More info at HelpMeWithHIPAA.com/191

View Details

As with many things, HIPAA “experts” are everywhere.  There is also a lot of misinformation, confusion, and downright bad advice being handed out by people who think they understand HIPAA more than they actually do.  Wrong HIPAA statements can be found on a lot of discussion boards and just out in the world talking to people. We deal with those issues on a regular basis. Sometimes we can laugh about it.  Other times we just have to take very deep breaths before we find ourselves responding inappropriately. Our intent here is to educate, always educate even when you are dealing with someone that may not know they need educating.

More at HelpMeWithHIPAA.com/190

View Details

The Cybersecurity Act of 2015 (CSA) called for adapting our critical infrastructure to better handle cybersecurity issues using private and public partnerships. Section 405(d) of CSA calls for “Aligning Health Care Industry Security Approaches.” A task force has been working on doing that since May 2017. On December 28, 2018, they published the information we have been excited to see in their document Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients (HICP). Let’s review this important information, shall we?

More info at HelpMeWithHIPAA.com/189.

View Details

Let’s be #PrivacyAware in today’s episode. Privacy Day has been around for a while. It is “international effort to empower individuals and business to respect privacy, safeguard data and enable trust”. At HMWH, we are all about trust here and certainly aim to empower those who are willing to respect privacy.

For more info HelpMeWithHIPAA.com/188

View Details

Passwords are a necessary evil in our online and digital world. There are lots of tools out there that help us deal with them but you have to use them every day in some way unless you are completed unsecured or off the grid. LastPass recently released an interesting report about the use of passwords. Let’s see what new trouble we can find in these details about our daily password battle and discuss some options we have found for dealing with them.

More at HelpMeWithHIPAA.com/187

View Details

Today we cover the things we are keeping an eye on for 2019.  Yes, it is 2019, I can not believe how quickly we have gone through almost 2 decades of the 21st century. Our top 7 predictions for 2019 may not surprise you.  But, that shouldn't stop us from throwing them out there.

More at HelpMeWithHIPAA.com/186

View Details

In case you have missed it there have been several headlines about HIPAA changes in the last month.  What is that all about and what should you worry about? Today we are discussing if HIPAA changes are will be coming this year.  Even better we will tell you what we plan to do with the information.

More at HelpMeWithHIPAA.com/185

View Details

OCR continued to hand out settlements to close out 2018. These last few announcements came out so quickly vs normal rates it is definitely raining settlements! While these last two do pale in comparison to the huge Anthem settlement, they certainly bring home more messages. What lessons are they trying to teach us with the Florida and Colorado settlements announced in December?

More info at HelpMeWithHIPAA.com/184

View Details

Each year our Croatian sound editor, Bojan, compiles his favorite package of our issues to share his pain with our listeners.  Listen in to hear how much he has to work to make us sound so much better than we should.

Thanks, Bojan for all the hard work!

For all our listeners, Happy Holidays and thanks for your support this year and in the future!

View Details

The allergy practice settlement that was recently announced will be known as the “no comment” settlement in my mind. As always, there are lessons to be learned from this announcement and the way OCR handled it. This settlement brings up a lot of discussions about handling patient public comments.

More at HelpMeWithHIPAA.com/183

View Details

There have been several announcements about cybersecurity agencies and offices lately. Some announcements are from the Department of Homeland Security (DHS) and some are from Health and Human Services (HHS). What are they talking about and what does it mean to you?

More at HelpMeWithHIPAA.com/182

View Details

It is hard to believe we are coming to the end of another year. Seems like just yesterday we recorded 7 Educated Guesses About 2018. Today we review our 2018 predictions, ummmm, educated guesses for 2018 and see how we did.

More info at HelpMeWithHIPAA.com/181

View Details

This holiday we are both taking time off to celebrate with our friends and families.  In our absence, please enjoy a replay of our previous Gift Giving Guide for compliance officers.

View Details

Listener message potpourri means we will be hitting several different topics in this episode. We get emails and messages from listeners a lot these days. While we do our best to respond we can't say we are consistent. That is why we do these episodes periodically.  If we've missed yours, don't hesitate to point it out to us in another message.  

More info at HelpMeWithHIPAA.com/180

View Details

In the recent NIST OCR security conference, a panel member said the terms “HIPAA compliant” and “HIPAA certified” made her cringe. We agree. The Anthem settlement has a lot of people asking about certifications for cybersecurity since Anthem was technically HITRUST Certified when the hacker first broke into their network. Let’s talk certifications and what they really mean under HIPAA, shall we?

More info at HelpMeWithHIPAA.com/179

View Details

The 2015 Anthem data breach could have been a watershed moment for HIPAA privacy and security in many ways. It remains to be seen if the settlement with OCR turns out to be another one. Either way, the historic breach and historic settlement have many lessons for us to learn. Let's discuss Anthem settlement lessons today.

More info at HelpMeWithHIPAA.com/178

View Details

Time for the annual Halloween episode! 5 horror movie quotes are this year’s theme. We have 5 horror movie quotes that are matched up to data breach stories.

More info at HelpMeWithHIPAA.com/177

View Details

We are #CyberAware is the tag for the National Cybersecurity Awareness Month campaign. Each year this campaign is run by the National Cybersecurity Alliance. In 2018, Kardon, Security First IT, and HMWH are all signed up to be champions and publish information for the campaign. Today, we will review what these campaigns are about and how you can use these and more like them to augment your education program.

More at HelpMeWithHIPAA.com/176

View Details

What should we learn from the recent OCR settlement? This time it was three settlements in one that related to a fourth. There is more here than the headline-grabbing dollar amounts. These settlements are the best specific guidance you can get from OCR. As always, we do the analysis for you!

For more info go to HelpMeWithHIPAA.com/175

View Details

Often tech folks will say that they understand HIPAA. What that really means is that they understand the technical requirements of HIPAA. The overconfidence sometimes works against them. Today we cover 3 stories tech should hear. It is important that they learn there is more than just their tech knowledge.

View Details

CIS 20 or SANS 20 is the name to reference a list of security controls that are intended to be used in the absence of any framework like NIST or HIPAA requirements. If you are trying to get the most bang for your buck and you know you are way behind on your security program CIS 20 may be the thing for you.

For more info go to HelpMeWithHIPAA.com/173

View Details

Have you seen the report about consumer online digital trust and what it means to all businesses? The report is The Global State of Online Digital Trust  A Frost & Sullivan White Paper which was commissioned by ca technologies and published in July 2018.  This survey study was done to compare perceptions about consumer trusts that executives and security professionals have vs the actual consumer trust findings when surveying consumers.  Would you believe there is a disconnect across the three perceptions?

For more go to HelpMeWithHIPAA.com/172

View Details

I can tell you from experience snooping is a serious problem that haunts all entities with health information to protect. Even if you don’t know it is haunting you, it is. You will learn to fear it eventually. The extent of improper record access goes well beyond what most people imagine. The image of a healthcare professional keeping patient information confidential is something we all assume is happening. In the real world, most workers know someone who has improperly accessed records if they haven’t done it themselves.

More info at HelpMeWithHIPAA.com/171

View Details

Securing home networks matters more now than ever before. We are a very connected society. That creates great opportunities and new challenges every day. Especially, for those tasked with securing all that connectivity. One opportunity that gets a lot of people talking is teleworking, telecommuting, working remotely, or working from home (WFH) - all seem to mean the same thing to most people. Our whole company is built on the ability of our systems to be secured and also be able to connect and work from anywhere in the world. Many groups forget to worry about those home networks that are connecting to your office network and even using your office applications, and data on a regular basis.

More at HelpMeWithHIPAA.com/170

View Details

We live in a world of instant communications. During a crisis, our normal standards of communications can be very limited. How many different issues have you addressed for communications in a crisis in your plans? We mention the business continuity and disaster recovery plans that everyone should have often in episodes. This is just one element of the plan that can make or break the business in a crisis. If you can’t communicate effectively with each other the chance of you being able to keep things running drops significantly.

For more go to HelpMeWithHIPAA.com/169

View Details

It may not occur to many of you that a hacktivist should be on your security risk analysis (SRA). They must be on there in this digital age. You never know what could trigger a hacktivist to focus on your business and put you under attack. Why you may ask - well we will discuss that now.

For more text go to KardonHQ.com/168

View Details

The FBI released an alert on July 12 titled Business E-mail Compromise E-mail Account Compromise The 12 Billion Dollar Scam that should be on your radar. BEC-EAC stands for Business Email Compromise - Email Account Compromise. If you haven’t learned about this particular threat it is important that you review it and assess the risk it brings to your company. That’s why we review these increasing threats and what you need to do about them in this episode.

For more go to HelpMeWithHIPAA.com/167

View Details

We often get questions from both the tech staff and security officers about what should be documented regularly and why it should be done. There are 3 reports you need to get from your tech team on a regular basis IMHO. Today, we will discuss those three reports, why you need them and what to do with them.

More at HelpMeWithHIPAA.com/166

View Details

One of the discussions you must always be prepared to have is that size does not matter when it comes to privacy and security issues.  Does size matter? Not as much as most people think and not in the ways that most people think either.

More at https://HelpMeWithHIPAA.com/165

View Details

Want to know how to save money in a data breach? You have to have a plan before you have the data breach to keep you from making costly mistakes. Everyone knows a data breach can be expensive but there are studies that show us what makes them more expensive and what helps you save money. The annual Ponemon cost of a data breach study has been published. IBM sponsors the study each year and it is one of the best tools for us to prepare for the cost of a data breach. If you have any valuable data at all you should review the report to get an estimate of what the cost of a data breach would be for your organization. Let’s dig into some numbers and add a bit of perspective, shall we?

Go to HelpMeWithHIPAA.com/164 for more details.

View Details

Our most downloaded episode Is from way back in May of 2016.  HIPAA Access Logs Audits was our 54th episode. It is hard to believe it was that long ago!  Today we are doing a deeper dive into how many layers exist when it comes to access logs to see if you have thought of all of them. Which of the logs really matter and what do you do with them?

For more go to HelpMeWithHIPAA.com/163

View Details

We all live in a world that revolves around communication tools today. Messaging failures are often the reason privacy breaches occur. In fact, we have 3 to share with you today. Messaging failures can occur in ways you never dreamed of until it happens to someone you know - not you, of course. Today’s episode covers 4 different stories about messaging failures.

For more go to HelpMeWithHIPAA.com/162

View Details

OCR continues setting examples with the recent announcement of the $4,348,000 civil money penalty (CMP) that they imposed on MD Anderson. A review of the details shows us once again that the enforcement of HIPAA obligations is not something they decide to do in a willy-nilly way. It is specific and designed to set examples of what is expected. Most headlines are about that $4.3 million in penalties but to us, that is not what is the most interesting and important thing to note in this case.

More at HelpMeWithHIPAA.com/161

View Details

Medical device inventory is a challenge for most organizations. Just as with computers and mobile devices, though, you can’t understand your risks and security requirements if you don’t know what you have out there. A medical device treasure hunt is what it turns out to be when you make a dedicated effort to find them all in your organization. How do you find them all and how do you worry about protecting them all?

More information at HelpMeWithHIPAA.com/160

View Details

It happens out of the blue. You get a letter that tells you that there has been a complaint filed and an investigation has been opened by OCR. That may not be the best day of your life. Just the thought of opening one of those letters can make some people feel queasy. If you have ever experienced that moment you don’t have it high on your lists of things to do again. Let’s review the kinds of things you may be asked to answer when under and investigation.

For more go to HelpMeWithHIPAA.com/159

View Details

In the past few weeks, the nerd news has been full of network security alerts and discussions about issues potentially lurking on every network, especially smaller ones. These are not the things we normally worry about either. You usually think Windows, Office, Adobe, etc patches are the main alerts to worry about on your network. These are new alerts that could be in every network you use including home, public wifi, and work. Per usual, we are here to explain them as best we can - in English. Tech folks you should listen up to what we expect you to be doing for our listeners who rely on you, too.

For more information go to HelpMeWithHIPAA.com/158

View Details

Secureworld Atlanta just finished up. Turns out cyber experts do agree about many of the same issues we discuss here. Two days of discussions amongst CISOs, ISOs, security techies, etc. about what to worry about and what to do for cyber protections. Yes, there was a lot of really nerdy discussions but the good news is the central themes do not require geek speak to share with you.

Learn more at HelpMeWithHIPAA.com/157

View Details

Have you considered that there are other valuable information assets to protect than just PHI? Most healthcare privacy and security programs only focus on PHI and HIPAA requirements. If you are already doing the work why not include all of your valuable information assets. It is time to ask yourself what data should we protect?

For more go to HelpMeWithHIPAA.com/156

View Details

This time of year many of us think about cleaning out closets and switching seasons.  By clearing out your digital clutter you can double check the security of your devices and reduce your attack surface at the same time.  Plus, it is way easier than cleaning out the old hall closet that may have monsters lurking in the back of it.  Make the time to clean your digital clutter at least once or twice a year and you will feel better for it.  Why not do digital spring cleaning, too?

For more go to HelpMeWithHIPAA.com/155

View Details

There is a frequent issue with people understanding what a Security Risk Analysis includes. In fact, there is so much confusion we often see documents presented as a risk analysis that is actually a gap analysis. It happens so often that OCR is trying to address it in their April newsletter. We are going to take a stab at explaining what gap analysis reports look like vs what a security risk analysis report really includes when done properly.

For more information: HelpMeWithHIPAA.com/154

View Details

Back in January, I read an article in Forbes titled: The Five Laws Of Cybersecurity.  When reading it I realized that it was a great message to our listeners but it needed a HIPAA flavor added it to it.  This episode we add our thoughts to his article and turn it into 5 Laws of HIPAA Cybersecurity.

For more details HelpMeWithHIPAA.com/153

View Details

More news on the insider front makes it necessary to point out, again, how susceptible healthcare is to insider failures.

HelpMeWithHIPAA.com/152

View Details

The American Medical Association (AMA) did a survey of physicians and their thoughts about privacy and security practices. It was interesting to hear their responses. Also, when a group of Security Officers gets together for a chat some people glaze over. For nerds like us, it is an exciting discussion. Today we are going to discuss the Security Officer panel topics and the AMA report presentation from the National HIPAA Summit.

HelpMeWithHIPAA.com/151

View Details

Are you ready for extreme vendor vetting? Many vendors have been pushing back against any covered entity or business associate that asked them to answer questions about their privacy and security programs. They believe signing a business associate agreement (BAA) meets the legal requirements and that is all they must do. Well, the times they are a changing - again. There are many different factors making it necessary to ask these type questions and not just accept a BAA as reasonable assurances. What are those factors and how things are changing are the topics we discuss in this episode.

For more go to HelpMeWithHIPAA.com/150

View Details

The National HIPAA Summit always features some interesting news from OCR concerning guidance, enforcement, and audits. This year was no different. In this episode, we discuss the highlights as we interpreted them anyway.

More at HelpMeWithHIPAA.com/149

View Details

Cybersecurity trends sound scary when you hear us talk about some of this stuff.  Cyberscary is actually what we decided to call it.  The good news is we do talk about other things sometimes. There are two reports that came out in recent weeks have gotten my attention and just have to be discussed with you guys.

More info at HelpMeWithHIPAA.com/148

View Details

Cybersecurity legal requirements keep changing at the state, federal, and international level. Most of the changes are just trying to keep up with the constantly changing landscape of threats in cyberspace. Today we call in an expert, Mitzi Hill, to talk to us about those cybersecurity legal requirements. How those changes may impact your business and your privacy and security program is certainly something we don’t want to lose track of in the mix.

More information at HelpMeWithHIPAA.com/147

View Details

We get questions from listeners on a pretty regular basis.  When they come in from an email we do our best to reply with an answer.  Sometimes they get backed up for us to get them on the show, however. Today we are covering some of those, in fact, we are covering 6 listener questions.

HelpMeWithHIPAA.com/146

View Details

News abounds about Uber and other ride-sharing services taking people to their doctor appointments. They say they have it covered and Uber Health HIPAA compliance is solid. Today we look at what they are saying about HIPAA here and what that means to us.

More info at HelpMeWithHIPAA.com/145

View Details

If cybercrime truly is the number one problem with mankind and healthcare is the number one cyber attacked industry is it because healthcare sucks at cybersecurity?

For more info HelpMeWithHIPAA.com/144

View Details

If it seems like cyber issues are around every corner these days, you aren’t imagining things. In episode 128 way back in November 2017, we discussed the fact that we thought there were signs of a coming cyber storm. Today we look at what is going on and see if we may actually be in the midst of that storm or is it still building.

For more: HelpMeWithHIPAA.com/143

View Details

Information privacy and security requirements in various laws are coming up in legal cases more often these days. Part of that is because we have more of those type laws. Although HIPAA has been in effect for over a decade, I don’t recall seeing it used in lawsuits and legal cases as frequently as I do now. Maybe I am just paying more attention but there are certainly plenty of cases in the courts today. Most are civil cases but some are even criminal cases. After hearing these you will probably know the answer to the question “Do I need a lawyer”. Probably, maybe, that is a fact-specific determination. Honestly, though, the answer is you probably will if you are not taking information privacy and security seriously today.

More at HelpMeWithHIPAA.com/142

View Details

As expected, OCR has continued to announce enforcement actions in 2018. This one is a bit different than any previous resolution in that there are 5 different cases across multiple locations in a single organization. It is also important to note that all 5 of these issues data back to 2012. Almost 6 years since the first one occurred, we have the resolution agreement.

HelpMeWithHIPAA.com/141

View Details

HIPAA made easy is a topic we have discussed many times before but today we are going to cover it specifically. So often we get requests for the “easiest way” to do HIPAA. This isn’t something to check off a list and have it done. It is something that you do every day as part of your business. The idea that you can make HIPAA easy is similar to saying that doing all of your accounting and taxes for your business is easy. Maybe if there is one person to pay and that is you but handling your finances correctly isn’t something many people find easy. Yes, the data can be gathered and entered into systems. But, do you know all the forms to complete, documents to save, follow up to do, classifications to determine, etc. It isn’t easy but it is doable. So is HIPAA.

For more HelpMeWithHIPAA.com/140

View Details

Cybersecurity is in the news a lot lately. Particularly a lot of news just since the beginning of the year. As usual, we review all the news looking for important things to share with our clients and listeners. There are just so many different stories to choose from this week, we decided to cover several of them in one episode. So, here are 6 cybersecurity lessons in the news. Some of them may be things you saw before but all of them were worth discussing what we should be aware of and learn from all the information coming in for 2018.

For more go to HelpMeWithHIPAA.com/139

View Details

In December, the OCR newsletter was titled Cybersecurity While on Holiday.  First, how very British of them!  Second, is it just when on holiday?  The same rules apply anytime you are on the road with technology and access to the internet.  We see this as something you should review no matter when you plan to access information outside the office.  While some think the corner coffee shop is a great work space others work in hotels and conference rooms all over town without being on holiday at all.  In this episode, we review the suggestions in the newsletter but drill down a bit more into how much of this applies when you are working mobile from home or just down the street as well.  

More at HelpMeWithHIPAA.com/138

View Details

At the beginning of 2017 OCR announced several settlements. Then, the settlement announcements stopped in May as their were leadership changes that continue to happen. In fact, the only reason this announcement seemed to come out was because it was included in a bankruptcy court filing earlier this month.

For more go to HelpMeWithHIPAA.com/137

View Details

Unless you never listen to nerd-speak you have to have heard the discussion about Meltdown and Spectre over the last few weeks. It is a perfect time to talk about what patch management really means in your cybersecurity protections. We try our best to discuss it with less geek speak and more English.

For more info HelpMeWithHIPAA.com/136

View Details

Here we go for another year!  It is amazing that this is the third new year we have covered on HMWH.  There are so many things that have happened over that time and as we head into 2018, so many things to look into our crystal ball and make 7 educated guesses about 2018.  We may not be predicting the future but we both have some opinions about what we see happening out there in the world of HIPAA, privacy, and cybersecurity in the coming months.

Get more at HelpMeWithHIPAA.com/135

View Details

Is HIPAA compliance expensive? Or, is it short-sighted to only worry about what HIPAA compliance costs? A new report from Ponemon Institute, The True Cost of Compliance with Data Protection Regulations, looks at compliance costs across several industries and multinational organizations. The study has a lot of details as we always expect from Ponemon Institute.

Read more at HelpMeWithHIPAA.com/134

View Details

Each year Bojan Sabioncello, our audio engineer in Split, Croatia, puts together his blooper roll to mock us.  Granted, he spends the whole year having to listen to us without a chance to respond until now.  This his only chance to respond to a year’s worth of our comments and screw-ups.

We will be back next week with a new episode.   Happy Holidays from the whole Help Me With HIPAA team!

View Details

As 2017 comes to a close, we are making our lists and checking them twice. Time to find out who we thought was more naughty than nice this year. The Naughty List 2017 discussion includes everything from big news data breaches such as Equifax and Uber down to stolen hard drives and password issues. Feel free to add your naughty list nominations in the comments.

More info at HelpMeWithHIPAA.com/133

View Details

A new report on phishing was recently released titled: Data Breaches, Phishing, or Malware? Understanding the Risks of Stolen Credentials. The report of findings from a study that was done by Google, University of California, Berkeley, and the International Computer Science Institute. It was a year-long study of account hijacking, stolen credentials, phishing and malware attacks. The findings are clear that phishing is a problem in ways we may not have thought before now. In the study, the researchers followed other hacker methods used against email addresses they found on the darknet sites for sale. The search netted 12.4 million addresses that were determined to be potential victims of phishing kits out of the total 1.9 billion usernames and passwords exposed by data breaches. So, it is obvious that this isn’t a tiny study over a short amount of time.

For more info go to HelpMeWithHIPAA.com/132

View Details

Recently, we have dealt with our clients struggling with vendors in the vetting process. Particularly, tech vendors of any sort. Many vendors have written off the HIPAA compliance requirements by simply saying “We are SOC2 compliant so you don’t have to worry about anything”. Often that is said by sales and management folks with a great deal of confidence. After spending some time at a recent HITRUST meeting I heard just how many people shouldn’t be so confident when making that statement. As with anything else the devil is in the details. What does SOC2 mean and how can you tell if that really means anything to you? Trust but verify is the key to answering that question for yourself.

More info: HelpMeWithHIPAA.com/131

View Details

We are enjoying the holiday with our families.  But, we didn't want to miss a chance to share time with our listeners.  Today we are replaying one of our favorite episodes 8 Common HIPAA Myths.

View Details

Hard to believe another year is coming to an end. It is time to review 2017 and plan for 2018. That means it is time to make your list of 5 Things To Do Before Year’s End. Just in case you need some help with that list, we made one for you!

HelpMeWithHIPAA.com/130

View Details

Text messaging is often the preferred method of communication for many people today.  It does have great advantages with its simplicity, instant delivery, and convenience.  However, I did not mention security on that list.  Text messaging is not secure by default.  Yes, you can secure it but that requires apps, platforms, and planning.  The bottom line is the communication method most people call text messaging is not secured enough to send and receive PHI without patient authorization to use it.

For more info HelpMeWithHIPAA.com/129

View Details

Lately, there have been a lot of articles in the "nerd news" services about various problems and vulnerabilities looming on the horizon or happening right now. Usually, there are one or two in a normal week or so that really get our attention. The last few weeks though it seems a bit different. Maybe it is just noise or paranoia created to drive traffic to sites. But, sometimes it becomes overwhelming enough to take time to step back and look at the details as a whole and determine what you really are seeing here. So, today we discuss: is there a cyber storm brewing on the horizon?

More info at HelpMeWithHIPAA.com/128

View Details

Each year we have done a special scary episode for Halloween. Last year we took you on a tour of a haunted house. This year for HIPAA Horror Stories V3 we get to hear a campfire horror story. So gather around and hear how scary HIPAA mishaps can be for us all!

For more info go to HelpMeWithHIPAA.com/127

View Details

When it comes to social media, marketing, and HIPAA things can get a little dicey. There are certainly many cases where using social media has gone awry in health care cases.  However, when handled correctly, you can actually use social media, marketing, and HIPAA in a sentence without getting chills down your spine.  Today, Janet Kennedy joins us for a discussion on the positive reasons you should be active on social media and the precautions you should take to make sure everything stays in a positive light.

More at HelpMeWithHIPAA.com/126

View Details

During the onboarding and termination process is where many mistakes are made that lead to security incidents and even reportable breaches. Today we discuss why they are important and the kinds of things you should consider having in yours.

For more information HelpMeWithHIPAA.com/125

View Details

How do you talk to the boss about HIPAA? That is a regular question we get around here. The staff responsible for compliance gets trained and understands what needs to be done but they don't get leadership support. Over the years we have had to have those conversations many times. It is never easy but there are some key pointers to making ground with your argument and turning the tide for supporting your efforts. Today we cover a few of our ideas on how to broach the subject effectively when you need to talk to your boss about HIPAA.

More details at HelpMeWithHIPAA.com/124

View Details

During the NIST OCR HIPAA Security Conference we covered in the last two episodes, there was also a session on OCR Audit Updates. OCR gave an update on the information gleaned so far from the compliance desk audits that were started in 2016. Their presentation included some interesting details. Today we cover the information they shared so you can compare and contrast those details against your own program.

For more details HelpMeWithHIPAA.com/123

View Details

This is the second episode covering the things David has to share from the Safeguarding Health Information conference. There are many great points he picked up. As we review them we keep coming back to the reminder that HIPAA is about patient care now.  Join us as we discuss everything from ransomware requirements to security for a small practice on this episode.

More info at HelpMeWithHIPAA.com/122

View Details

The annual NIST and OCR security conference has come around again. This year, David attended the conference via webcast and shares his notes on the first day of the conference.

Before the conference discussion, we have to touch on the announcement from Equifax about their HUGE data breach.

For more information go to HelpMeWithHIPAA.com/121

View Details

We recorded this episode on the day that Harvey was hitting Houston and had no idea just how bad that disaster would eventually become for those on the gulf coast. On the day we publish this episode, we are both personally involved in the evacuations and preparations in advance of Irma. She is forecast to hit Florida, Georgia, and the Carolinas in the next few days. The timing for this discussion could not be more appropriate from a news perspective but this planning should have already taken place prior to this date for those in the paths of these deadly storms.

As you listen to this episode, know that we had no idea just how bad things were about to become for the millions of people under the stress of these major natural disasters. Take care in your planning now if you haven't been in these areas, your turn may be next and there is no way you want to be dealing with anything similar without a plan.

What do you have in your disaster recovery plans?

For more info HelpMeWithHIPAA.com/120

Email us at contact@HelpMeWithHIPAA.com

View Details

Every time we discuss server security issues it opens a debate about where is the best place to keep your servers. There are three options and we are going to discuss them today. Local hosting vs data center hosting vs cloud servers under HIPAA.

For more details HelpMeWithHIPAA.com/119

email us: contact@helpmewithhipaa.com

View Details

What is reasonable and appropriate? The HIPAA legal reference and guidance mentions reasonable and appropriate all over the place. Many times that concept creates confusion. How do you determine what is reasonable or appropriate for any environment?

More at HelpMeWithHIPAA.com/118

View Details

Can a doctor have Alexa in OR to play music?

Is it a HIPAA violation for staff to look at their own records or is it an internal policy violation?

I am a small company BA do I really have to do all of HIPAA compliance requirements?

If I know my upstream BA or CE isn't following their HIPAA compliance obligations what am I legally obligated to do?

Why would you make daily copies of your visitor logs?

More info at HelpMeWithHIPAA.com/117

View Details

Sometimes following the news lets you find things like security incident investigations with interesting details.  But, these cases were different than most.  Even better than that, we learned how can a fish tank help hackers!  There were just too many parts of these stories that got my attention to pass them up.  When something occurs and the investigation uncovers way more to the story than you normally see we should all learn from them.

More details at HelpMeWithHIPAA.com/116

View Details

Incident response plans have been a topic of our show several times. But, these days we just can't get enough of a good thing!

Actually, there is a reason we are covering it in this episode. I was reviewing a Business Associate Due Diligence from a software provider. In the questionnaire, we always ask if you have a written incident response plan and trained incident response team. They responded Yes, with a comment of "we have an engineering department".

More info at HelpMeWithHIPAA.com/115

View Details

There has always been a concern from many people we work with about compliance officer personal liability. Specifically, is a compliance officer personally liable for the compliance of the company?

The recent settlement agreement between the FTC and the Chief Compliance Officer of Moneygram has created interesting conversations for compliance circles. In this case, the Chief Compliance Officer of Moneygram was able to reach a settlement in the liability case against him but it included a $250,000 penalty payment and 3 years restriction on working in that industry. Yep, that is enough to make you sit up and take notice.

More details at HelpMeWithHIPAA.com/114

View Details

The monthly OCR Cyber Newsletter for June had some interesting points.  The fact that OCR mentions multiple times and in multiple ways that they do not endorse, certify, or recommend specific technology or products should serve as their "OCR mic drop moment" on this discussion.  We can dream, can't we!  Today we are going to review that newsletter and how they have pointed these things out once again.

Before we close out the episode we are also covering some questions and comments from listeners.  Hang around for those just after the 30-minute mark.

More info at HelpMeWithHIPAA.com/113

View Details

This is not another episode about preventing and responding to the NotPetya ransomware. There are countless articles about those topics.  We are discussing the bigger picture today.  In this episode, NotPetya, Windows, and Ransomware, we discuss what happened in the case but also what does all of this really mean in the big picture of cyber attacks.  If you don't stay proactive in evaluating what the criminals may do next then you don't have a chance of being anything but reactive.

In light of these recent global attacks, we have many questions.  Are we experiencing a shift in the criminal's intentions or are they just bumbling around with new toys?  If is it no longer just about taking our money then what is really about?  If you haven't cared about protecting your data so far, how about protecting your data from becoming a pawn in the latest cyberwarfare battle?

For more information go to HelpMeWithHIPAA.com/112

View Details

In June, the NY State Attorney General announced a settlement with CoPilot, a healthcare services company that illegally deferred notice of breach of more than 220,000 patient records. Another annual report was also just released with the latest numbers : 2017 Cost of a Data Breach Study from Ponemon Institute and IBM. Today, we are going to discuss how the two of them can help us all make better decisions where potential breaches of PHI are concerned. Breach reporting costs and decisions in 2017 are proving to be something you should understand before a crisis, not after one hits.

For more info: HelpMeWithHIPAA.com/111

View Details

Mobile devices are susceptible to malware attacks, phishing, and other security vulnerabilities just the same as laptops and desktops.  The systems most of us have in place are directed at managing the security for laptops and desktops, however.  It is important to expand your security controls to address the growing threat that mobile devices introduce to your network and systems regularly.  

In most cases, it is important to have a "home base" tool that can talk to and monitor the mobile devices.  That is where MDM comes into play.  For most people that brings us to the question: What is MDM and why do I want it?

For more: HelpMeWithHIPAA.com/110

View Details

There are countless times we have covered the "my EHR vendor handles HIPAA for me" misconception. The recent $155 million whistleblower lawsuit settlement between eClinicalWorks (eCW) and the government really brings it home how wrong you can be about EHR vendors.

Meaningful Use attestations relied heavily on the vendors supplying proper information. eCW set up thousands of organizations to take a major hit based on the details in this case and it's settlement. Especially, when you take into account that eCW is one of the biggest EHR vendors out there.

CIA of PHI is the objective of the entire Security Rule under HIPAA. Unreliable data created by an application is clearly a data Integrity issue. If you can't trust the data can you trust the system at all?

If you have knowledge of this kind of stuff going on somewhere you should review it closely. It includes civil payments by developers and project managers not just the C-Suite folks involved.

For more information: HelpMeWithHIPAA.com/109

View Details

The 5 stages of grief during a cyber attack really do follow the process of dealing with grief in those familiar 5 stages. Many don't realize that ransomware attacks aren't always just the result of someone clicking in an email and running a program.  As Erie County Medical Center found out recently, ransomware attacks can come from a hacker being active in your network too.  Those 5 stages of grief during a cyber attack for them and others we have seen is what we will be discussing today.  

We have a special guest with us for today's discussion too.  David Benton with Altep is joining us.  David is a super IT forensics dude.  The CSI of the nerds, so to speak.  He is helping us review this topic.

More information at HelpMeWithHIPAA.com/108

View Details

A major breach of PHI was announced by a Beverly Hills plastic surgeon's office on Jun 1. There are so many things about this case from the fact that it involved a malicious insider to how many different ways proper HIPAA policies and procedures would have stopped it, if not prevented it completely. Celebrity patients records breached in this case may make it hit home with a lot of folks who haven't worried too much about those protections until now.

We have talked about insiders as a major vulnerability a lot lately and this one really makes it big news! 15,000 files with medical and personal information. Added to that are pictures including those of celebrity patients records breached without them even know the pictures existed!

More info at HelpMeWithHIPAA.com/107

View Details

OCR continued their enforcement trend for 2017 with 2 more settlements announced in May.  These stand out on their own because the focus is specific disclosure of PHI instead of major breaches.  A total of three patients were involved in these large settlements.  This week we review what transpired and what OCR found as violations of privacy for these three patients.

For more information go to HelpMeWithHIPAA.com/106

View Details

A wide variety of questions have come in from listeners over the last few weeks. The list is so good we have a whole episode devoted just to answering listener questions.  At least one of these will likely apply to you if not several.

For more information go to HelpMeWithHIPAA.com/105

View Details

All of those ransomware outbreaks we have been dealing with since last year were overshadowed this past week by WannaCry.  This has been called called the most destructive attack ever.  The most concerning part is that was how bad it was but the US wasn't hit that hard.  When these kinds of things happen it is always a good idea to review what you learned from the outbreak and any necessary changes you need to make to protect you from this one happening to you.  The is the topic of the day.  What should we learn from WannaCry?

Learn more at HelpMeWithHIPAA.com/104

View Details

You may not even know about all the applications and support logins that vendors use on your applications, systems, and networks. Vendors may set up admin passwords and share them with their whole staff to support you. If they have unlimited access to the systems out there and the usernames and passwords never expire or log off automatically that is certainly not secure. How do you manage all of those?  If there are things that automatically log in and run, what about those?

More details at HelpMeWithHIPAA.com/103

View Details

April has had three more OCR resolution announcements. That's a total of 7 cases for $14.3m in 2017 so far. When we covered resolutions recently I kept waiting for another one to come out and gave up. Then, BAM, three in a row!

For more info go to HelpMeWithHIPAA.com/102

View Details

Are we creating a crisis of trust in healthcare? A business partner put that question out to us recently. We have already been looking at several angles to discuss the patient part in all of this breach and ransomware news. This question seems like the perfect way to approach it. Let's look at the topic and see what we think - Are we creating a crisis of trust in healthcare?

For more information on this podcast and how to win $100 Amazon gift card go to HelpMeWithHIPAA.com/101

View Details

For our 100th episode we wanted to do a Top 10 list.  After some thought, we landed on the Top 10 HIPAA Lessons we hope you get from our little podcast.  

It is hard to believe that we are publishing our 100th episodes of Help Me With HIPAA!  Two years ago we started out with this little idea that has become a really exciting venture for both of us.  We truly enjoy the responses and interaction from our listeners.  Well, first, we are thrilled to HAVE listeners.  But more importantly, we love hearing how much people learn and laugh at the same time.  That combination has been our show objective since the very beginning.

Another big thing we are doing with this episode is a chance to win a $100 Amazon gift card if you help share and promote us with you social networks.  Listen in or go to the website for more details on how to win! 

More info at: HelpMeWithHIPAA.com/100

View Details

OCR Resolutions 3 and 4 for 2017 were released in February.  Examples of what not to do from OCR were released AGAIN.  We kept waiting for another resolution to be announced and lump them together.  Once we gave up and recorded this episode to review those two you know another one was announced.  We will hit that one next time.  For now, we review what happened in these cases that resulted in OCR resolutions after a breach notification started an investigation.  They are so kind to give us examples of what not to do from OCR without us paying for it!

For more details go to HelpMeWithHIPAA.com/99

View Details

Recently, New Mexico passed a new data breach notification law in March. Once it is signed there will only be 2 states that don't have their own notification rules, Alabama and South Dakota. What do all the state laws mean when you are also required to do HIPAA notifications.

Most of them say that if you are subject to GLBA or HIPAA the notification laws do not apply to you. But, it is always best to be sure you know what your state requires.

HIPAA says that as long as it is more strict than state laws then HIPAA takes precedence but many times states are now enacting stronger legislation in some areas.

California and Texas developed some pretty extensive requirements that apply to CEs and BAs in their states. Massachusetts also added their own twist beyond HIPAA.

More info at HelpMeWithHIPAA.com/98

View Details

All the news about ransomware and hackers usually gets the biggest headlines.  But, the ones that fly under the radar may be something you should pay more attention to than the big splashy news.  Insiders usually don't have to work hard to plot ways to break into your data, you have invited them in and given them access. A damaging assumption is that you don't have to worry about your insiders.

Get more info at HelpMeWithHIPAA.com/97

View Details

Call it teleworking, remote access, or mobile access if you have any access to PHI outside of your office, you should have a HIPAA mobile access policy. Any person that accesses you systems and data outside of your internal network should be trained and sign off on commitments to protect your PHI.

We've never specifically covered the topic of what should be included in a HIPAA mobile access policy. It is about time we did just that.

Learn more at HelpMeWithHIPAA.com/96

View Details

Building a culture of a compliance is something we have talked about many times in this podcast.  We never looked at it as a community problem.  The things we heard about training the human element to build a cyber security culture were very exciting to us.  Well, at least to Donna.  The concepts they covered about training not just the workforce but training the community as a whole to better understand what cybersecurity really means.

We also followed that up with a session that explained some more scary darknet activity.  Your machine could be for sell on the darknet and you don't even know it.

More information at HelpMeWithHIPAA.com/95

View Details

If you saw the movie Catch Me If You Can then you know some of Frank Abagnale's story. Maybe you even read his book Catch Me If You Can: The True Story of a Real Fake.

Tom Hanks said "Abagnale’s lecture may be the best one-man show you will ever see." He WAS NOT KIDDING!

The famous con man in his youth eventually became a white hat working for the FBI and others to combat fraud and ID theft for over 40 years. Now, he works as a consultant, writer, and speaker on the subject as he continues working with the United States Government

The information he shared with us during his #HIMSS17 session blew us away. That means we have to tell you guys about it!

Learn more at https://HelpMeWithHIPAA.com/94

View Details

The first full day of HIMSS17 HIPAA had a big session. It featured Deven McGraw, Deputy Director for Health Information Privacy at the HHS Office for Civil Rights (OCR).  She is also Acting Chief Privacy Officer for the Office of the National Coordinator for Health IT (ONC).  Clearly, it was one of the sessions at the top of the list for us to attend.  We got there early enough to be perched on the front row.  In this episode, we review what McGraw covered in her session and our thoughts on it.

For more details and timestamps go to HelpMeWithHIPAA.com/93

View Details

HIPAA news stories are sometimes so short we need to bundle them together. Some listeners questions are also addressed today. So, we have a little bit of everything in this episode. So stick with us as we go through our HIPAA hodge podge.

For more details go to HelpMeWithHIPAA.com/92

View Details

What is HIPAA privacy anyway? The annual reporting deadline for little breaches is up at the end of Feb. That means all those little privacy violations in 2016 must be reported on the HHS website soon if you haven't already done it. Since those little ones often mean so much more than the big ones it made me think it would be a good time to talk about privacy.

A recent bizarre case in an Atlanta suburb made me realize just how much we value our privacy but may not realize it until it has been taken from us.

More at HelpMeWithHIPAA.com/91

View Details

OCR continues releasing new settlement agreements on their new pace. There have been two announced in January 2017. We have no idea what will happen now but since these two brought in over $2.6m there may not be a reason we will see them stop their pace.

As always, we believe in learning from other's mistakes (not schadenfreude, though). Time to learn what these two can teach us....

HelpMeWithHIPAA.com/90

View Details

More reasons to have this coverage pop up every day. Whether it is your own business risk management or those required by a business partner in a contract, all businesses should at least evaluate getting cybersecurity coverage. To help us share information on that we have a guest on this episode.

Interview with John Miller II, Founding Principal, Sterling Risk Advisors 

View Details

We reviewed the OCR/HHS list of common HIPAA compliance myths when we first started the podcast. Their list is so long that it spread across 3 episodes. Those episodes are still fairly popular today. For today, though, we are covering our own list of common HIPAA compliance myths that we hear.

Common HIPAA Compliance Myths Our list may be very similar to all the other lists out there but it is important to cover those because they are clearly STILL being passed along. Why do we keep hearing the same things over and over?

More at HelpMeWithHIPAA.com/88

View Details

At the beginning of 2016, we did some speculation about what the year would be like in the cybersecurity and HIPAA worlds.  Today we plan to review how we did for 2016 and explain expect healthcare breaches continue in 2017.

More at https://HelpMeWithHIPAA.com/87

View Details

We've talked before about HIPAA showing up in lots of other places. That trend has continue. Now, you will see HIPAA questions on cyber security insurance applications, certification programs from other entities, and now in payment model reforms. Today we are going to talk a little bit about MACRA and HIPAA requirements. If you don't know what MACRA, APMs, and MIPS is all about we may not cover enough to explain it all be we will certainly touch on MACRA and HIPAA crossing paths starting in 2017.

More information at HelpMeWithHIPAA.com/86

View Details

Last January, we did an episode with a 2016 Compliance Management Plan.  We even created a reminder poster for it you could download.  The episode was about providing a compliance management plan guideline for compliance officers who are trying to find a way to fit this in your with all your other job duties.

That episode was very popular and the poster was downloaded by new folks even in December.  

This episode reviews that compliance management plan and adds a bit more to it for "extra credit".   We also added a second poster and compliance management plan for a more aggressive approach than just the bare minimum.

Get the downloads and more information at HelpMeWithHIPAA.com/85

View Details

Every day it seems we read about more healthcare cyber attacks.  As the news keeps breaking with more details on the wide variety of cases, we have plenty of work to do just to keep up.  Today, there are so many cases to talk about we couldn't even decide what to call the episode.

More details at https://HelpMeWithHIPAA.com/84

View Details

Listen in to outtakes from this year's episodes.  We need something lighter to celebrate the holidays!

View Details

For a change there was a bipartisan bill passed with some big impacts on healthcare.  HIPAA 21st Century Cures Act implications are, of course, our focus.  Today, we review some thoughts on the bill that was signed into law this week.

More notes at https://HelpMeWithHIPAA.com/83

View Details

Recorded during our first live broadcast, this episode covers several OCR announcements.  We start with the OCR phishing alert.  Followed by that we discuss OCR's guidance that said you should consider multi-factor authentication in your risk analysis.  

There have also been more resolution agreements that we haven't covered on an episode so we hit those, as well.

Since it was a live show we also take some questions!

For more: https://HelpMeWithHIPAA.com/82

View Details

Phishing attacks in healthcare are on the rise just like every other industry. However, unlike many other targets, phishing attacks in healthcare have a much higher return on investment if the phisherman gets anyone to take the bait. We've talked multiple times how healthcare is now a major target for hackers. Then, it only makes sense that we will see a continued rise in efforts aimed at phishing attacks in healthcare.


Types of phishing: * Phishing - spray and pray - grab an email list and let it rip - big net phishing * Spear phishing - Aimed directly at you. Everything makes it look like it should be in your email meant for you from someone you know * Whaling - Pointed directly at upper management of a company with an urgent business matter * Soft targeting - send to people with a certain job that they would expect, like HR gets a resume but financial team gets a spreadsheet * Telephone phishing - Just call you up and act like they should be asking you for login information

For more info: https://HelpMeWithHIPAA.com/81

View Details

We are holding episode 81 for ransom during the Thanksgiving holiday.  For our black Friday episode we hope you enjoy this replay of our most popular episode.

Stay tuned! Episode 81 will be released next Friday.  We will be discussing the different types of phishing, how they work and how you can resist the bait.

View Details

In early Oct the long awaited guidance on HIPAA Compliant Cloud was released by HHS / OCR. There wasn't a lot of shocking information for us since it just restated, maybe more clearly, that cloud services providers (CSPs) must sign a BAA and meet certain obligations as a BA.

Hopefully, this will address all the cases where some CSPs would use "slight of hand" with phrasing to claim they didn't have to be a HIPAA compliance cloud provider. The amount of "all ya gotta do is" type of misinformation only makes things harder to get done. Let's look at what the guidance addressed.

For more details go to HelpMeWithHIPAA.com/80

View Details

This week is basically part 2 from last week.  We left off just before reviewing the OCR audits and enforcement updates announced at the NIST / OCR Security Conference 2016.  

Get more details at HelpMeWithHIPAA.com/79

View Details

Donna shares information from the 2016 NIST/OCR Annual Conference on Safeguarding Healthcare Information.

Learn what she thought was interesting to share with you.

More information at https://HelpMeWithHIPAA.com/78

View Details

We tour the HIPAA haunted house in this year's Halloween episode!

Cybersecurity has become a big concern over the last 18 months. Breaches in 2015 have given way to ransomware along with more daring breaches in 2016. What is really happening on your computers, networks, and the Internet every second is terrifying in several ways. There are plenty of amazing and good things happening at the speed of light but so are the bad ones.....

For more details go to HelpMeWithHIPAA.com/77

View Details

Ransomware and HIPAA have been a topic on the podcast multiple times. They are some of our most popular episodes, in fact.  Recently, we realized we haven't discussed the OCR guidance on ransomware and HIPAA.  On July 11, 2016, HHS.gov featured a new post from Jocelyn Samuels the Director of the Office for Civil Rights (OCR).  The title is catchy: Your Money or Your PHI: New Guidance on Ransomware.

This episode is a review of that post and the fact sheet with OCR guidance on ransomware and HIPAA that the post announced.

.

For more information http://HelpMeWithHIPAA.com/76

View Details

Everything going on today with hurricanes and such makes it is a great time to talk about this. We mention it all the time but this episode is going to be just about what DR/BC means and what you can do to be prepared in advance.  So, this episode covers disaster recovery planning under HIPAA but any business can learn from our topics!

  • What is DR/BC Planning?
  • Who should do it?
  • Is this another big expense?
  • What is involved in building and maintaining DR/BC plans?
  • General elements of a plan

Get more details at http://HelpMeWithHIPAA.com/75

View Details

Last year Sen. Lamar Alexander and Sen. Patty Murray asked for answers to some questions concerning cybersecurity in healthcare.  They were interested in understanding what CMS and HHS were doing to protect patients from fraud.  It seems as though they were wondering if HIPAA security updates where needed.

We discussed the Senators request in episode 31 : https://helpmewithhipaa.com/episode-31-enforcement-efforts-ocr-increase-2016/

Their letter asked:

  • What CMS and HHS is doing to monitor medical identity fraud
  • What is CMS and/or OCR actually doing, if anything, to track cases of ID theft and fraud
  • OCR uses the data collected from covered-entities to monitor potential breach victims and find out if their data have in fact been used by criminals
  • They also want to know whether any education materials or help are offered to breach victims by the CMS and OCR

The report was presented to the committee on August 6, 2016 and made public on Sept 26.

View Details

BAs are in the HIPAA spotlight now more than ever.

  • TheDarkOverlord was clearly using some BA applications to infiltrate networks and exfiltrate PHI.
  • OIG reviewed Alaska VA system after breaches and the report specifically points to the need to monitor BAs
  • OCR audits of BAs are about to start. Previously said end of September but now saying October

In this episode we discuss what all this means.

More at HelpMeWithHIPAA.com/73

View Details

Did you hear that maximum penalties for HIPAA violations are being adjusted for inflation? It has quietly happened. Here is how.

Check out the Federal Register entry from September 6, 2016. If you aren't in to reading yourself, don't worry, you know Donna did it. Well, at least the HIPAA parts.

Learn more at: HelpMeWithHIPAA.com/72

View Details

OCR recently released another memo concerning compliance enforcement efforts.  They say effective August 2016, they have started an initiative to more widely investigate breaches involving under 500 patients.  That means that OCR small breach investigations will begin happening immediately.  In the past, the policy had been to investigate all breaches over 500 patients but not under.  

More information at HelpMeWithHIPAA.com/71

View Details

OCR published a memo on Aug 1, 2016.  The title is "Do you know who your employees are?".  It is a great reminder about insider threats that we should all worry about regularly.

Quoted directly from the memo.
============================
Although all insider threats are not malicious or intentional, the effect of these threats can be damaging to a Covered Entity and Business Associate and have a negative impact on the confidentiality, integrity, and availability of its ePHI.

According to a survey recently conducted by Accenture and HfS Research, 69% of organization representatives surveyed had experienced an insider attempt or success at data theft or corruption. Further, it was reported by a Covered Entity that one of their employees had unauthorized access to 5,400 patient’s ePHI for almost 4 years.

For more visit: HelpMeWithHIPAA.com/70

View Details

So far in 2016 there have been 10 resolution agreements announced. One more and this year will equal the number of agreements in all of 2015 & 2014!

The latest two also include the largest one announced yet - $5.5m with Advocate Health.

Before that though was The University of Mississippi Medical Center - Ole Missto those of us in the SEC world. It wasn't something to "shake a stick at" with a$2.75m resolution amount.

The total amount for those 10 announcements so far in 2016 = $20,314,800

Of course the details are what we usually pay more attention to since it tells us exactly what OCR has a problem with in each case. It makes it clear what OCR wants all of us to learn from these folks mistakes.

For more visit HelpMeWithHIPAA.com/69

View Details

The OCR audits have begun.  On Wednesday, July 13, audit selected CEs where invited to a webinar. OCR staff walked through the processes they can expect for the audit and expectations for their participation.  The OCR published information from the webinar so we had to check it out and share what we learned with you guys.

For more details visit HelpMeWithHIPAA.com/68

View Details

Say it ain't so! Pokemon and a HIPAA breach really? REALLY!

Creatures are showing up in offices and hospitals just like everywhere else. The concept of keeping people active and engaged with their surroundings while playing a video game seems like a great idea from a healthcare standpoint. And then you actually do a risk assessment of it - this is where the wheels fall off that good idea train.

Get more details as HelpMeWithHIPAA.com/67

View Details

We first talked about this in Ep 62. Darknet sale of healthcare records. Now, more information is coming out and it gets more unfortunate for patients every time we read more.

Deep Dot Web broke the news: https://www.deepdotweb.com/2016/06/26/655000-healthcare-records-patients-being-sold/

We picked it up on Data Breaches.net because they were trying to figure out who the entities actually were in each case: https://www.databreaches.net/damn-anyone-know-what-facilities-these-are/

Get more info at https://HelpMeWithHIPAA.com/66

View Details

What happened? * March 23, 2013 Oregon Health & Science University notified HHS of a breach due to a stolen unencrypted laptop. * May 1, 2013 OCR notifies them they are investigating the incident * July 28, 2013 Oregon Health & Science University notified HHS of another breach resulting from storing ePHI at an internet-based service provider without a business associate agreement * November 8, 2013 OCR notifies them they are investigating the new incident * July 18, 2016 settlement announced for $2.7 million and a 3 year CAP

What can we learn from this?  Go to Help Me WithHIPAA.com/65

View Details

OCR recently sent out a message on their listserv asking if your CE or BA was ready for an incident. We have been discussing security incidents a lot lately so it is nice that OCR has brought it up. Because we have seen various Incident response reports recently, so we were working on an episode anyway.  So this episode is a review of Security Incident Response Plan development.

Let's first be clear, this isn't just about HIPAA. We also have been reviewing the Economist Intelligence Unit 2013 (EIU) report: Cyber incident response: Are business leaders ready?, which is asking the very same question.

For more information go to HelpMeWithHIPAA.com/64

View Details

There has been a lot of news and industry discussions about Medical Device security. Medical Devices are just like a computer, so they also need security to protect the information on them.

For more go to HelpMeWithHIPAA.com/63

View Details

A business associate is getting this OCR resolution, $650,000 and a two-year settlement.  CHCS in Philadelphia is a BA to 6 skilled nursing clinics in the Philadelphia area. Entities like this do the business part of healthcare and the other clinics don’t have to worry about it. An unencrypted iPhone that wasn’t password protected had PHI on it.  

Patterson Dental Supply Inc. helps manage dental practice information for various providers. One of the clinics they help service is Massachusetts General Hospital, and 4,300 patients had their PHI hacked and compromised.

For more info: HelpMeWithHIPAA.com/62

View Details

Since 2010, ID Experts has sponsored this Ponemon Institute study which has been tracking data breach trends of patient data at healthcare organizations. The annual economic impact of a data breach has risen over the past six years, as has the frequency of data breaches. Criminal attacks and internal threats are the leading cause of healthcare breaches. Evolving cyber attack threats such as ransomware and malware are of primary concern for 2016. At the same time, internal issues such as employee negligence, third-party snafus, and stolen computing devices continue to put patient data at risk.

For more info on this episode go to helpmewithhipaa.com/61

28w47ezq

View Details

As always, during times of crisis and chaos things do become confused and incorrect statements are made. It is a normal occurrence in troubling situations. But, we need to address it specifically to clear up a few points.

  1. There was no "special waiver from the White House". There was no need for one at all.
  2. People, even in a crisis, should not be invoking HIPAA over caring for the patient properly.
  3. The hospitals talked about implementing their crisis plan - why wasn't HIPAA addressed in the plan. It should be!

For more details go to HelpMeWithHIPAA.com/60

View Details

Today’s podcast is a little different from our normal ones. We are covering a wide variety of subjects involving HIPAA, OCR, HHS, and PHI rather than one specific topic.

For more go to HelpMeWithHIPAA.com/59

View Details

Preventing ransomware is a major concern for every business today.  If not, it should be.  This episode covers understanding ransomware and methods for preventing it.

  • Is ransomware a phi breach?
  • April record number of cases and not slowing down
  • 8 hospitals (more by the time we record) already hit.
  • Training and vigilance is best defense
  • Ransomware attacks continue to evolve to be "smarter"

For more see HelpMeWithHIPAA.com/58

View Details

HIPAA policy and procedure templates seem to be a panacea to many people who are just trying to meet the standards and move on. However, these are not the droids you seek! Templates can be the basis for what you need to do but they shouldn't be the solution to the written policy and procedure requirements under HIPAA.

See HelpMeWithHIPAA.com/57

View Details

Two reasons for today's topic: A question we received from a listener about understanding antivirus software and a news report about a malware scan that interrupted a medical procedure. Between those two cases it felt like it was time to discuss malware protection under HIPAA.

  1. Suzie from Savannah: I would like to have a podcast or a quick answer to the different between anti-virus software releases and anti-virus definitions being up-to-date. I understand the AV definitions up to date but a little fuzzy on AV software releases and examples please....
  2. Report came out about malware scan stopping a medical procedure

View Details

We always look at the security rule aspects of HIPAA because they deal with the easier parts for people to deal with when it comes to lowering their risk, but today we are diving into some privacy rule guidelines, because there is new HIPAA privacy guidance that has just been published.

Get more info at HelpMeWithHIPAA.com/55

View Details

Recently, we ended up in several discussions about HIPAA access logs and what they really require with our clients. As per usual, any topic that comes up multiple times in my “real job” becomes a discussion for HMWH.  So, today we are talking about HIPAA access logs to attempt to clear up some confusion we have encountered.  There are multiple types of HIPAA access logs being created in most environments and you should be dealing with pretty much all of them in some manner.

Get more at HelpMeWithHIPAA.com/54

View Details

We talked about OCR audits recently because they are in the news. The audit protocol is a perfect guide for developing and maintaining your HIPAA compliance programs. In fact, the audits have been a hot topic in the industry this month.

However, the fact that only 200 audits will take place really means the audit protocol is more important as a guide for what your program should look like in the event you have a breach or complaint investigation. Statistically, you are much more likely to need it for that reason.

Read more at HelpMeWithHIPAA.com/53

View Details

We really appreciate the support and feedback we have received for our little HIPAA podcast project known as Help Me With HIPAA.  This episode marks one complete year of weekly HIPAA podcasts (counting the special bloopers holiday episode).  We certainly learned a great deal since we started this little DIY project last year.  Granted, David was a convert to the idea much quicker than Donna.  

Here we are one year later and our little HIPAA podcast is starting to gain some real momentum.  That is all thanks to you, our listeners, for sticking with us through our growing pains as we fumbled through figuring it all out.  Keep on sending in your questions and suggestions, we appreciate your help and support!

Also, a special shout out to the silent member of our team Bojan Sabioncello for making us sound so much better once he came on board!  

After saying all of that, what are we doing for this special episode?  We are interviewing each other to discuss how we ended up together and what we do in our "real jobs".  this HIPAA podcast is a huge part of what we do but it isn't the only thing you get from us.

For more information go to HelpMeWithHIPAA.com/52

View Details

We often talk about doing the "work" of compliance. Some people seem to have the attitude that all I need to do some is annual staff training and hand out a Notice of Privacy Practices to do small office HIPAA compliance. When we try to explain there is more to it than that we often get pushback about the requirements.

We always hear comments like:

  • we don't have time,
  • we don't have resources,
  • we can't be expected to do this.

So, how DO you do small office HIPAA compliance? Today we are going to talk to someone who is definitely doing the work of HIPAA compliance in a small office.  We are doing an interview with Erien Fryer of Medical Direct Care in Clarksville, TN to discuss small office HIPAA compliance issues, obstacles, and how to just get it done.

For more details go to HelpMeWithHIPAA.com/51

View Details

Every website needs security. What questions should you be asking about your business websites and who should you be asking?  Website security can be an open hole in your security plans.  It can also be the source of lots of problems for your business if you don't pay attention to the site content or securing your message.

More info on the website at helpmewithhipaa.com/50

View Details

The recent release of the new OCR audit protocol gives us new guidance on what they expect from HIPAA compliance programs.  There is a great deal of information to sift through if you are so inclined.  To make it easier for you we are discussing some of the details and things we have learned from reviewing it for you! So, here is our review of the new OCR audit protocol!

For more details go to our website article helpmewithhipaa.com/49

View Details

In the first episode in our Disaster Recovery series that we will be doing this year we are discussing planning disaster recovery plans for flooding.  This episode is an interview with Ginger McCleish who experienced a real world disaster recovery flooding in the St. Louis, MO area in December 2015.

Hear more at HelpMeWithHIPAA.com/48

View Details

The latest HIPAA buzz is about things like Interoperability, Data Governance, Patient Access Rights, and, of course, OCR random audits.  Donna attended HIMSS and the National HIPAA Summit recently.  In this episode we discuss what kinds of things are happening in the industry relating to HIPAA.

For more details visit our website at helpmewithhipaa.com/47

View Details

So far in 2016, we have seen four HIPAA enforcement cases resolved by OCR.  One involved only the second Civil Money Penalty ever assessed. The three others were resolution agreements.  Add those cases to what was done in 2015 and you have the most active 12 month period of HIPAA enforcement ever.  Certainly, the first quarter of 2016 has been the most active quarter ever when it comes to HIPAA enforcement announcements.

In this episode we discuss the cases resolved so far in 2016 and more thoughts on what is coming up for 2016.  

Read more at our website HelpMeWithHIPAA.com/46

View Details

Many times people ask: Why do we need HIPAA?  Is HIPAA really necessary?  The short answer is yes, we do need HIPAA and the reason is without it there is no baseline for protecting patient privacy.

Learn more at http://helpmewithhipaa.com/45

View Details

Social media can be the source of many issues if you don't have a clear policy for use.  HIPAA social media policies requires some serious thought and commitment from your management staff.  What things are good use of social media and what things should be avoided through policy enforcement?  

Read more about HIPAA Social Media Policies at our website: helpmewithhipaa.com/44

View Details

It is clear that HIPAA disaster recovery and business continuity plans should include some level of ransomware response planning after the attack that shut down Hollywood Presbyterian Hospital.  What kinds of issues should you expect and how can you mitigate the damage from a ransomware attack?

Read more about our ransomware attack planning discussion on our website at helpmewithhipaa.com/43

View Details

To be certain you are protecting the health information in your organization you must identify where it lives and moves about around the network and workforce.  A risk analysis can't be done properly without making that list first.

Where should you look for PHI?  If you don't store it do you store access TO it?  Get more information for this podcast at HelpMeWithHIPAA.com/42

View Details

Trust but verify is the new standard when it comes to Business Associate relationships today.  Yes, they must sign a BAA but you really need to ask some questions to confirm those BAs understand and are doing the things they have agreed to do for you.

Covered Entities (CEs) haven't really worried about the details of the contracts too much as along as the vendors would sign them.  Many vendors have signed, and continue to sign, BAAs without any concerns at all for what the contract actually says they are going to do in their business.  For so many years a BAA was just something you had to sign in order to do the work in healthcare.  It didn't matter at all if you did anything with it other than put it in the file with other ones you had signed.  The new world of HIPAA compliance, huge data breaches, and civil fines and penalties means neither side of the contract can function that way any longer.  It is imperative that HIPAA compliant vendors are vetted in some manner to confirm you really are protecting your patients, clients, business, and reputation.

Get all the details at http://helpmewithhipaa.com/41

View Details

Get all the details at HelpMeWithHIPAA.com/40

View Details

More notes and links on the website at HelpMeWithHIPAA.com/39

View Details

More details on our website 

Also at the Atlanta's Most Trusted Advisors page: 

View Details

Brittney Wilson, The Nerdy Nurse, joins us to discuss the clinical staff's HIPAA perspectives.

More details at helpmewithhipaa.com/38

View Details

More details at helpmewithhipaa.com/37

View Details

HIPAA may show up in areas you haven't seen before.  If you are assessed by any other organization or for any other reason, HIPAA questions may start showing up.

We have heard about it being brought up in many areas:

  • Insurance Policy Applications
  • Partnership Negotiations
  • Funding discussions
  • URAC accredidation (formerly known as the Utilization Review Accreditation Commission)

This episode is a discussion on why it is showing up in other places and why we expect that trend to continue.

More details at helpmewithhipaa.com/36

View Details

ID Experts is in the business of dealing with privacy breaches.  They have a variety of incident response services and tools.

We discuss breach topics with Jeremy Henley, Director of Breach Services, ID Experts in today's episode.

Detailed notes from the show can be found on our website at helpmewithhipaa.com/35

View Details

New Years Resolutions can be simple commitments to yourself and your compliance program effectiveness.  When you have so many job responsibilities compliance often gets set to the side or "on the front left corner of my desk".  These tiny changes can help you keep things moving forward without forcing you to spend a day or two a week.

Detailed notes on the show can be found on our website at helpmewithhipaa.com/36

View Details

Since this episodes is being released on a holiday for all of us at Help Me With HIPAA, we are sharing a special blooper episode our audio editor Bojan Sabioncello created specially for us.  When you hear our recordings from his perspective, you will see what a great job he does making us sound so professional.

View Details

Compliance officers need all kinds of help to get their jobs done.  We came up with a list of ideas for gifts to help them out this holiday season.

More details at helpmewithhipaa.com/32

View Details

Enforcement of HIPAA is changing There are many indicators that make us believe that we will see a distinct uptick in OCR enforcement activity.  The last two OIG reports say OCR isn't doing enough, the news points out issues with enforcement, and even Congress is getting in the mix. In this episode, we discuss why this makes us think you don't want to wait around to see IF OCR starts doing anything differently.

More details at helpmewithhipaa.com/31

View Details

The HIPAA legislation itself does not include the option for individual patients to sue any CE or BA that may violate their privacy protections included in the law.

HITECH added the ability for the States Attorney General offices to file a cased on behalf of their constituents, however.  

The biggest change, however, is the ruling by several State Supreme Courts that allows a complaint to use HIPAA as a legal standard of care.  That opens the door for all kinds of options.

More details at helpmewithhipaa.com/30

View Details

Everyone is ready for the great deals retailers offer on Black Friday and Cyber Monday. We have a list of low-cost and no-cost deals on HIPAA Security & Privacy tools for you!  Episode 29: HIPAA Black Friday Sale

More details at helpmewithhipaa.com/29

View Details

The Internet of Things (IoT) is already here, it isn't something that is coming. It is here and it is the future, it will just become more prominent in our daily lives.

View Details

If you expect your IT company to do certain things as a HIPAA compliant vendor you are more likely to have the level of support you need.  If you don't ask then they may not be fully aware of what you need or what it requires to be HIPAA compliant themselves.

View Details

We review the latest OCR settlement CAP details.

View Details

This week we get in the Halloween spirit and share some scary stories that make you have those compliance nightmares.

View Details

Description Business Associates and required BAAs are discussed often but not resolved quickly. Let's talk about some ideas and issues that go with BAAs.

Links FindHealthcareIT

HIPAAforMSPS.com

Kardon Compliance

Notes Who is a BA? * A business partner who provides a service to a CE or BA that requires them to CReMaT PHI. + Anyone with persistent access to ePHI whether they do anything with it or not is irrelevant - the fact that they CAN do things is what matters. * Complexity is increasing + Dietitians at hospital needs info on the scripts for the diet but the employer never stores, accesses, or has persistent access to it but the workforce needs to see it. CE should train them on Privacy rules.
BA means it is not your data but you have it or have access to it from the owner of CE. + Medical director could be a BA or could be workforce member depending on the contract they have with the employer. * ACO formed by hospital as a completely separate legal entity + But the ACO is staffed by hospital employees + Plus the hospital provides IT services to the ACO legal entity + Now that would make the hospital a BA of the ACO which is really the hospital. - So, the hospital is a BA to itself * Maintaining PHI vs. maintaining facilities with PHI + Data center where you store your servers. Are they a BA? - NO. They are just the landlord for your server - so they aren't a BA - YES. Physical, Administrative, Technical Safeguards are used to protect it, though * You are outsourcing part of your obligations because they are doing a all of the physical safeguards for you so you should make them a BA + Can be argued both ways but 2 out of 3 lawyers said BA plus a poll of room says they are a BA not just a landlord - BCBS of TN left drives at old office and landlord was securing the site * Why is there was no BAA if that is the case was the OCR response * Resolution didn't mention the BA argument but it was an expensive fine that clearly showed the OCR lawyers didn't see they were protected sitting in a closet of the facility you used to lease. * If you sell server space and store encrypted PHI you are a BA under current guidance. + Many will argue this point though. + You have to be prepared to decide for yourself * Even if you don't treat them like a BA, then you should have an agreement of some sort that protects the PHI * OCR working on Cloud Computing Guidance + Security Rule from early in this century couldn't really consider all the things that are done today + Before cloud computing when everyone has their own servers in their offices or owned huge data centers * You can't just counter this issue with making everyone sign a BAA, though. + Bad for the business that signs them and either fails to comply or does the work they may not need to be doing. + Bad for you because you are managing contracts that don't need to be managed and opening up cans of worms we haven't even found yet. + Make a decision about your business and be prepared to explain your logic * If you are doing the work of a BA you are still a BA without signing a BAA

Included in BAA * We are not lawyers but we are talking about the contracts just a little bit here + Ask your attorney for advice on this stuff, don't relay on us or any other consultant for that advice + Also, get a HIPAA attorney - not a tax attorney * You should be reading these things, not just sign them * Indemnification can be included and you need to know what you are committing to * Insurance requirements + Yours, mine, ours for cybersecurity + What does it really cover - not just if you have it + New complexity to negotiations because you don't cover a max level that your big groups need * State law requirements * 60 days - how far down the BA tail could it go with 60 days to notify + Shorten the days but not too short + But give them time to figure stuff out unless you want to know about incidents that turn out to be ok * Breach notification responsibilities + Can the BA notify a huge number of people within 60 days - do they even have the resources to make that happen? * De-identification of PHI clause is there to prevent selling of data + They don't have to take out the doctor's name if they take out all other PHI - That means some of your valuable info could end up in a file that gets sold because it has no PHI in it. * Indemnification + What liability limits are you going to include + If I am acting reasonable then I shouldn't have to bear the whole burden but if I am reckless then it is fair to put most of the burden on you * The Security Rule may not go far enough but you can up the ante in your agreements + Should you require encryption be used both at rest and in transit + Agreements may start to specify exactly what security standards you must adopt which creates new problems

Assessing BAs * I have a BAA so I don't have to worry - not a good idea * Does HIPAA even apply if they are off shore? + US Law doesn't apply in other countries - do you know where your PHI really lives? * CE is not responsible for acts of BA with a signed BAA but + If you are aware of a pattern of non-compliance then you would be liable + How much do you want to be unaware of vs aware of in advance of a problem happening * What PHI are you talking about is key in assessing each situation + Medical only + Demographics + SSN and Credit Cards + Is it mental health, domestic abuse, STDs, etc with special limitations * Just because you have SAS70, SSAE16, or SOC 1, 2, or 3 assessment doesn't mean it was a good assessment nor does it mean that it covers what you need covered for HIPAA + Does provide a benchmark but that isn't necessarily enough for HIPAA * A sophisticated BA questionnaire is where most CEs are moving until standards are made more specific + Provides more specifics about the compliance programs - Training - Who is really in charge for you to deal with in a crisis * Do you audit the BA after the fact? + Once you learn problems you have to deal with them + Would you rather know or not know, that is the question * Easiest / Quickest way to know is just let the tech geeks talk to each other and form their own opinions of what is happening + Let us handle the questions to ask + We have to deal with each other any way + No one else really understands * If you are a BA then have something you can show the CE/BA clients proactively before they ask

View Details

Description We explained the concepts of encryption in Episode 2: Let’s Talk Encryption but people continue to ask more about what they really need to do with encryption.

Links FindHealthcareIT

HIPAAforMSPS.com

Kardon Compliance

Episode 2: Let’s Talk Encryption

The government and privacy advocates can’t agree on what ‘strong’ encryption even means

Notes First, what can encryption do for you and what it can't do for you.

  1. VPN, HTTPS, SSL, SFTP, etc. Protect communications from prying eyes.
  2. Everything else is about encrypting data on the devices themselves.

If you encrypt data on a device but you are hacked when you are logged into the device, encryption isn't too helpful. Encryption is helpful when someone tries to access the data on the device without your key (or password).

Strong Encryption is also subjective - there is no solid authority on what is really strong encryption because law enforcement wants a back door.

What does HIPAA say about encryption? Encryption (Addressable). Implement a mechanism to encrypt electronic protected health information whenever deemed appropriate.

Not very helpful.......

What does OCR say about it? At NIST / OCR HIPAA 2015 conference: If it moves it should be encrypted.

Now that's a line that can be drawn.

  • Encryption of your files stored in the cloud (certainly something that moves)
  • File encryption by an app on the computer over specific files like 7Zip
  • Windows built in encryption - Bitlocker, EFS
  • NAS and Flash drives with built-in encryption
  • Encryption on your phone built-in
  • Cloud based encryption management - MDM - Alertboot, MaaS360, Manage Engine https://www.manageengine.com/mobile-device-management/

Create an encryption plan:

  • Includes all devices - laptops, phones, external drives, etc.
  • Specs required like AES 128 or FIPS should be written down
  • Methods used for implementation on all types of devices
  • Encryption key management plan
  • Audits and verification plans

View Details

Cybersecurity coverage being challenged in court has some important points that all businesses should consider.

Links FindHealthcareIT

HIPAAforMSPS.com

Kardon Compliance

Help Me With HIPAA

Notes COLUMBIA CASUALTY COMPANY v. COTTAGE HEALTH SYSTEM

Data breach occurred * Breach announcement said: Between October 8, 2013 and December 2, 2013, PHI of approximately 32,500 patients on the CEs servers weredisclosed to the public via the internet. * Hospital got voicemail message from a third party, who informed it that he was able to read the PHI online. * Patients seen Sept. 29, 2009, to Dec. 2, 2013 included names, addresses, DOB, MR#, Acct#, diag, lab results and procedures performed. No financial information or Social Security numbers were involved * Insync, their IT vendor at the time, left anonymous access for FTP traffic active on an internet servers on or about Oct. 8, 2012. The change allowed ePHI to become available to the public via Google's internet search engine. The server was taken offline immediately on Dec 2 once the call came in. + Insync doesn't mention healthcare on their website any more + People make mistakes even the IT folks - theirs are just big ones

Law Suits and Investigations * Civil Suit filed January 27, 2014 and settled December 2014 + $4,125 million along with related expenses and attorneys'
fees + 50,917 patients included in the settlement * On-going investigation for HIPAA violations currently + Involves CA Dept of Justice and likely OCR + The DOJ Proceeding will determine whether Cottage complied with its
obligations under HIPAA and any other pertinent state and federal laws and may potentially result in the imposition of fines, sanctions or penalties.

Insurer Columbia Casualty filed suit * Saying they shouldn't have to pay the claim for the $4.1 nor any expense they have or will incur over this case + Columbia also seeks a declaration of its entitlement to reimbursement in full from Cottage for any and all attorney's fees or related costs or expenses Columbia has paid or will pay in connection with the defense and settlement of the class action lawsuit and any related proceedings and an award of damages consistent with such declaration. * INSYNC, the IT company, does not maintain sufficient liquid assets to contribute towards the proposed settlement fund and does not maintain liability insurance that applies with respect to the privacy claims asserted in the Underlying Action.

Why does Columbia think they shouldn't pay? * The Columbia Policy contains the following exclusion: Whether in connection with any First Party Coverage or any Liability Coverage, the Insurer shall not be liable to pay any Loss: Failure to Follow Minimum Required Practices based upon, directly or indirectly arising out of, or in any way involving... Any failure of an Insured to continuously implement the procedures and risk controls identified in the Insured's application for this Insurance and all related information submitted to the Insurer in conjunction with such application whether orally or in writing; This Policy shall be null and void if the Application contains any misrepresentation or omission: a. made with the intent to deceive, or b. which materially affects either the acceptance of the risk or the hazard assumed by the Insurer under the
Policy. * The Columbia Policy application contained the following questions that were answered by the hospital + Do you check for security patches to your systems at least weekly
and implement them within 30 days? • Yes + Do you replace factory default settings to ensure your information
security systems are securely configured? • Yes + Do you re-assess your exposure to information security and
privacy threats at least yearly, and enhance your risk controls in
response to changes? • Yes + Do you outsource your information security management to a
qualified firm specializing in security or have staff responsible for
and trained in information security? • Yes + Whenever you entrust sensitive information to 3rd parties do
you... - contractually require all such 3rd parties to protect this
information with safeguards at least as good as your own • Yes - perform due diligence on each such 3rd party to ensure that
their safeguards for protecting sensitive information meet your standards (e.g. conduct security/privacy audits or review findings of independent security/privacy auditors) • Yes - Audit all such 3rd parities at least once per year to ensure that
they continuously satisfy your standards for safeguarding
sensitive information? • Yes - Require them to either have sufficient liquid assets or
maintain enough insurance to cover their liability arising from
a breach of privacy or confidentiality. • Yes (Which INSYNC did not) - Do you have a way to detect unauthorized access or attempts to
access sensitive information? • Yes - Do you control and track all changes to your network to ensure it
remains secure? • Yes * Failure to Follow Minimum Required Practices is clear according to the ins company which is why they shouldn't have to pay + failure to replace factory default settings its failure to ensure that its information security systems were securely configured + failure to regularly check and maintain security patches on its systems + failure to regularly re-assess its information security exposure and enhance risk controls + failure to have a system in place to detect unauthorized access or attempts to access sensitive information stored on its servers + failure to control and track all changes to its network to ensure it remains secure

Final Notes * If you don't have coverage you really should be looking at it because this isn't going to get easier as these things continue to occur. * If you do have coverage you should revisit that application and check that you are following the standards you said you were doing in the policy. This probably won't be the first time this kind of thing comes up. * If you are a BA, you should check yourself and your coverage because your clients may start asking you what you have covered in order to do business with them.

View Details

Show Notes

If they were shocked that no one was actually watching for security holes at Ashley Madison you can bet they will be shocked that you haven't been looking because Healthcare is supposed to be private.

Ashley Madison: Nobody was watching

Top 10 Tech Companies with Ashley Madison Accounts

What kinds of things do you need to do to actually be considered looking for them, though?

  • HIPAA Compliant IT
  • Router / Firewall test showed 600% Increase in Unique Vulnerabilities Discovered Last Year (OCR / NIST conference)
    • Within hours or days of a release of software (firmware) vulnerabilities will be identified.
    • Keep firmware up-to-date
  • UTM - what is a UTM
    • not just a router off the shelf at best buy
    • IPS
    • Antivirus
    • Support Subscription!
  • Reporting each month - look at what is going on - if you have IT they can do it but you should be asking them for reports.
  • Printers / Copiers easy for hackers to get to first
    • Smart TVs
  • Patching helps when
  • Hackers
    • Start with "low hanging fruit"
    • Beginning hackers look for easy challenges to practice their skills
    • Vulnerabilities for sale to each other
    • They just want in to see what you have and then see where they can go
    • Hacktivist - target you because of who works there or who you treat or your type of business
  • There is no way to know how many different parts of software are used from all over the world on any device or in any given application today
    • No list of ingredients on the back of your router or mobile device
  • None of this is new
    • We have all talked about it but no one listening to the security people until it happens at your business, office, or home
  • 10 vulnerabilities account for nearly 97% of all exploits
  • Write little script yourself you could be opening a hole because you don't realize there are security implications to what you just wrote

Doctor convicted of illegally accessing medical records Doctor having an affair and looked at the mistress' medical records. Looking to see if she had STDs. Plead guilty in federal court and kept his license but must be monitored.

View Details

Show Notes When it comes to securing anything the weakest link in the chain is always people. People are the ones who make mistakes, over-share, and are also the criminals. This episode talks about what people can manage to do so you have to think of all kinds of things outside the norm.

University of Pittsburgh MC BA breach after being hacked the year beforeEmployee of the billing service call center copied personal information from the billing system. 2,259 patients were then passed on to a third-party. Notification that it happened came from FBI. Last year UPMC was hacked and employee information taken for all 62,000 employees. Over 800 employees reported ID theft.

Oakwood Healthcare worker fired for HIPAA-violating Facebook commentsTerminated after posting disparaging comments about a patient on her Facebook page. Worked at a hospital that had to treat a suspect in a police shooting. Her posts were pointing out her disgust in having to treat him. It is still a violation.

Roanoke, Va. Carilion Clinic - 14 employees admitted snooping Found it by random log reviews. Previously, only checked on patients where a big new story was happening.

Physician Suffers Second 2015 Data Breach Break-in in Jan requires breach notification to 350 patients. Break-in again in March they got computers and patient charts. The computers were not encrypted and they had patient info OTHER THAN THE LETTERS to the 350 patients. This time the total patients involved are 1,342. At this point they hire a security guard who stops a third break-in. The doctor is moving their office to a new town. Encryption could have saved a lot here, increased security after the first break-in would be the most obvious requirement. That is a simple decision that was just not made. Now over 4 times the number of patients are involved.

Doctor convicted of illegally accessing medical records Doctor having an affair and looked at the mistress' medical records. Looking to see if she had STDs. Plead guilty in federal court and kept his license but must be monitored.

Final Note Medical is years and years behind other industries on security requirements and criminals are figuring that out. Plus, those that are way ahead are getting breaches like Home Depot, Target, and more. In all those cases there was a person somewhere involved in the process, in some cases several people made mistakes are took the wrong action.

View Details

Mobile devices are vulnerable just like your network, servers, laptops, and desktops. Your risk analysis should include checking on any types of messages, pictures, or access to your data that can be done on your smartphones. Even if you don't put PHI on them they may be able to be used against you in some way to crack your network and your PHI.

Patches * Android updates and know your version of Android + Wipe leaves some stuff on old Android versions * iOS updates and know your version + Windows is so small market share but mention it

Encryption * Android + Option to encrypt this device + Lock screen setting to wipe device after X failed logins * iOS + data protection turns on with password set - set to wipe if after X number failed logins

MDM - Mobile Device Management * What is it * What can you do with it

BYOD - Bring Your Own Device * Set rules to follow * Do checks for software updates * Don't let kids play with phone * MDM?

Backup If you lose the phone or it dies will you lose important things?  Figure out a backup plan but make sure it is properly secured too.

Unsecured WiFi and Bluetooth * Try not to use it unless necessary * Bluetooth can be used to connect to your phone within 30 feet * Personal WAN can be used to jump on your connection and use your data plans

Final Notes Understand this is the new frontier for hackers. Ransomware and malware for smartphones are growing quickly

View Details

Let's review email systems and how they can be secured for ePHI and other sensitive data.

Find Healthcare IT

HIPAA For MSPs

Kardon Compliance

Alston Article on Email Security

Notes Leigh from Florida sent us an email asking for us to explain some more specifics about email. She had been listening to Episode 8: HIPAA Myths Part 2 which mentioned it but she had specific questions how can email be secured. This couldn't be covered in a quick 5 minute HIPAA answer episode so we are doing a whole episode.

  • How does email work - for "real people" to understand
    • Compare to the post office since that is the way it was originally modeled to match
  • Why that isn't secure at all, really
    • http://www.healthcareitnews.com/news/hipaa-breach-letters-go-out-after-email-hack (article on email hacked and it had patient info in it)
    • open transmissions and many different servers
  • Misconceptions
    • I use a password so it is secure
    • I use https so it is secure
    • I use TLS so it is secure
    • I use updated Outlook with Hosted Exchange so that should be secure
  • Secure email via
    • End to end encryption tools - each party knows the key
    • Messaging system - you get an email telling you to log in to get the secure email
    • Hosted services that allow for specific types of messaging
      • Hosted exchange
      • Plug-in apps
    • Secured internal only messaging systems
      • Very specific set up to secure the mail database on your internal server
      • Controls you have in place to prevent email to other domains outside the secure system (usually software required)
      • Some systems are automatic encryption / others require you to hit a button on the mail to send it secured.
  • Secure messaging systems for internal discussions that don't use email

    • whole new way of communications in forums / chats instead of email
    • Texting also matters but that is a different episode we can touch on it here
    • A word about spear phishing - excellent example this week from a client

View Details

Links ComplyAssistant

FindHealthcareIT

HIPAAforMSPS.com

Kardon Compliance

Notes * Who is Gerry Blass + Been in healthcare for the long ride + Consultant for years + Now consultant and software company * ComplyAssistant - when did you start development and what was your vision for it? What kinds and size of clients do you have - hospital, practices, BAs and CEs of all types * ComplyAssistant features + Due Diligence for BAs + Contract management + Incident Management + Project Management + Documentation, Documentation, Documentation Management * Importance of having a documentation and management system of some sort in place + Why ComplyAssistant instead of using a spreadsheet / folder approach?

View Details

Culture of compliance is the phrase OCR uses when defining what they are looking for in an audit or investigation. They also use the phrase robust compliance program in the same manner. Using these steps is a great way to make sure your organization is following their lead.

Links ComplyAssistant Compliance Management Solution

Spher EHR Access Monitoring Solution

FindHealthcareIT

HIPAAforMSPS.com

Kardon Compliance

Notes 7 steps to improving your Privacy & Security policies and procedures and nurturing a Culture of Compliance:

  1. Designate a Compliance (Privacy & Security) Officer
    First, the law requires you do this. But, if no one is in charge then nothing will happen, we all know that to be the case. Or, in a vacuum of leadership someone else will take charge and handle things the way they think they should be done without the support of management.
  2. Train and educate your staff and BA partners
    Constantly restating the same information over and over in a variety of ways may be annoying to some but that means they have heard it! Also, don't forget to work with your BA partners to confirm they actually understand what HIPAA compliance requires in their organizations.
  3. Implement an ongoing Compliance maintenance solution
    This is what we talk about using tools such as ComplyAssistant, Spher, and professional MSP monitoring and management applications. Either use the tools or develop manual internal controls and processes to accomplish those same documentation and audit tasks on a regular basis.
  4. Conduct regular and complete audits and monitoring of all ePHI systems If you are ignoring it then so will everyone else in your organization.
  5. Monitor and respond to Incidents in a timely manner (State & Federal regulations)
    We all freak out together as soon as we know something could havehappened to our PHI.
  6. Adhere to a strict breach remediation protocol
    Define your breach plan and use it every time. After any case that it was used, then review it to make sure you don't need to change or add things in the plan.
  7. Create a open line of communication for management and staff
    The law requires you to never retaliate towards any person who files a complaint or reports a problem including a breach. If you don't make it clear that you fully support that rule and all workforce members are free to ask any question, file any complaint, and report any concern then you will likely be missing things just because someone was afraid to tell.

View Details

In 2014 NIST introduced the National Cybersecurity Framework (CSF). It is designed for all businesses, large and small, to know things they should be doing to protect their businesses, data, customers, and more. Just how does it compare to HIPAA?

Notes NIST Cybersecurity Framework

DHS Getting Started for Small and Midsize Businesses (SMB)

US Chamber of Commerce: Internet Security Essentials for Business 2.0

C3 Voluntary Program: Begin the Conversation: Understand the Threat Environment

FindHealthcareIT

HIPAAforMSPS.com

Kardon Compliance

Notes It's not just HIPAA. All the different guides spell out the same basic concepts.
For example:

  • NIST - Cybersecurity Framework
  • US Chamber of Commerce: Internet Security Essentials for Business 2.0
    • STRONG SECURITY IS SMART FOR BUSINESS AND THE NATION COMMON THREATS TO BUSINESS INFORMATION
    • Hacking and Malware
    • Lost or Stolen Physical Storage Media
    • Insider Threat and Human Error
    • Accidents and Natural Disasters
    • CYBERCRIME ON THE RISE
      INTERNET SAFETY AND SECURITY FUNDAMENTALS
    • Set Up a Secure System
    • Protect Business Data
    • Train Your Workforce
    • Be Prepared
    • ADD BUSINESS VALUE THROUGH INFORMATION SECURITY
    • NATIONAL AND PRIVATE SECTOR PERSPECTIVES

Cyber Essentials to Protect Your Business: Managing Cyber Risks in a Time of State and Non-State Threats to Business Security and Resilience - Hosted by US Chamber of Commerce

  • FBI - Deputy Director
  • DHS - Undersecretary for Cybersecurity
  • Secret Service - Atlanta Office Cybersecurity Team
  • Army Lt Col - Cybersecurity Command

View Details

An interview with Ray Ribble discussing the AMS Spher product. We learn how Spher can automatically "learn" what access patterns are normal and ask you when something isn't right. Your HIPAA compliance requirement to audit access logs may be solved with this tool. Your very own HIPAA Breach Detection Service!

Links The AMS SPHER™ Solution

FindHealthcareIT

HIPAAforMSPS.com

Kardon Compliance

Notes Who is AMS and Ray Ribble? Tell us about The AMS SPHER™ Solution. Behaviorial Analytics SPHER leverages pattern recognition algorithms to determine if there was suspicious behavior on the EHR. It does this by comparing past behaviors to behaviors in the audit log file SPHER is currently reviewing. For example, SPHER may have learned over the past months that an EHR user named John is typically active between 8 AM and 4 PM. In the current audit log file, SPHER notices that John was active on the EHR from 4 PM to 12 midnight which causes SPHER to send you an unusual time of access alert.

It Learns! You know that John’s shift recently changed from 8 PM to 4 AM. Going through the SPHER incident resolution process, you indicate that this behavior is Normal and Permitted. Based on this feedback, SPHER has now learned that this is normal EHR behavior for John and will not send an alert the next time it sees EHR activity for John during this new time span. As normal behavior on your EHR changes, SPHER learns and does not send false alerts for behaviors you’ve already indicated are normal.

View Details

Description What a HIPAA Risk Analysis includes and why you need it for your cybersecurity risk management.

Glossary CReMaT'ed - Create, Receive, Maintain, Transmit CIA - Confidentiality, Integrity, Availability

Links JPP Medical Record

OCR Guidance on Risk Analysis

Training Documentation for this episode

FindHealthcareIT

HIPAAforMSPS.com

Kardon Compliance

Notes Not a simple checklist it requires a lot of thought, data collection, and analysis.

The analysis part

  • Define where e-PHI is CReMaT'ed in your organization.
    • Not just the server that holds the EMR.
    • Cloud apps used, messaging tools, mobile devices, USB storage devices, home computers
    • Practice Management system and data analysis tools
    • Don't forget to include downloads folders and temp folders on all PCs.
  • Do you need to worry about vendors or consultants - your BAs that may move data around your network, systems, etc.
    • If they handle it for you do you even know where it is going?
  • What are the threats to the CIA of the PHI that you have located and identified above?
    • Human
    • Natural
    • Environmental
  • What would be the impact to your business if the threat did act against your PHI?
    • Would it be a bump in the road or a sinkhole?
  • What is the likelihood this threat will actually act against your PHI?
    • Very likely down to not likely at all
  • With all this considered what level risk do you think this threat creates to your PHI?
    • High, Medium, or Low
  • Based on everything you know then you decide what you are going to do about the threat and the risk it presents?
    • Accept the risk is just part of doing business
    • Address the risk with some type of safeguards in your organization
    • Outsource the risk by hiring another company to handle managing it for you

The assessment part

  • At this point, you review that plan you have just made to address risks against what you are actually doing
    • Are doing everything you can to protect the PHI and meet your obligations under HIPAA laws from all those threats?
    • If you are outsourcing threat management, have you made sure your BAAs are in order?
    • If you are handling it internally do you have all the written policies and procedures
    • Is your staff trained to respond accordingly?
  • Once you complete that process you draw up your final report on what was determined during your analysis and assessment.
    • What actions need to take place to address those threats and what priority should be applied to them?

This is your full analysis and assessment report that you will use to inform your decision making process for your security policies and procedures.

It is also the report you will review and update on a regular basis. Sometimes minor updates are needed but other times you will need to do most of the whole thing over if there is a major change in your business.

View Details

We have a listener who called in with an example situation to find out what we thought. Is the company a Business Associate? Listen to Donna's answer in Episode A2.

These short "answer episodes" are released weekly on Tuesday mornings when we have them come in.

Send us your questions and we will publish them with our thoughts and the best answers we can muster!

Use the Website form or Speakpipe voicemail You can also find all our social media contact information at HelpMeWithHIPAA.com.

View Details

Description A Breach Response plan is a required element of your compliance program since HITECH became effective. Everyone must have a written plan and know what needs to be done.

Glossary NIST National Institute of Standards and Technology

Links NIST SP 800-61 Revision 2 - Computer Security Incident Handling Guide

APDerm Resolution Agreement See item 2(2)

FindHealthcareIT

HIPAAforMSPS.com

Kardon Compliance

Notes Establishing an incident response capability should include the following actions:

  • Creating an incident response policy and plan
    • Written required - already had an OCR resolution that mentioned not having one (APDerm - $150,000)
  • Developing procedures for performing incident handling and reporting
    • Who is your "go to" team for forensics
  • Setting guidelines for communicating with outside parties regarding incidents
    • PR will be critical for reputation managment
  • Selecting a team structure and staffing model
    • Someone has to be in charge of the whole thing and then others in charge of the parts.
  • Establishing relationships and lines of communication between the incident response team and other groups, both internal (e.g., legal department) and external (e.g., law enforcement agencies)
    • Bigger organizations need to know who is responsible for talking with each department.
  • Determining what services the incident response team should provide
    • How far is the team going through the process? Will they pass off follow up or will they do all the activity required from beginning to end. Again, large organizations need to worry about this.
  • Staffing and training the incident response team
    • Make a written list and have the team meet regularly to review how to respond to any incident that may come up in the organization.

View Details

How do I get rid of my printers properly? Find out in HIPAA Answers Episode A1.

Thanks for our listener questions that are coming in! It took us a bit to work out the best way to get back to you, so sorry for the delay.

Today we introduce, HIPAA Answers episodes. These short "answer episodes" will be released weekly on Tuesday mornings.

Send us your questions and we will get them answered. Lots of ways to contact us below!

Website form or Speakpipe voicemail

Twitter

LinkedIn

Facebook

Google+

Send us an email

View Details

Description A discussion of the findings in the recently released study concerning healthcare breaches in 2014.

Glossary A managed service provider (MSP) is a third-party contractor that is under contract (usually a monthly fee) to provide on-going technology support to other organizations.

Links Fourth Annual Benchmark Study on Patient Privacy and Data Security

Criminal Attacks: The New Leading Cause of Data Breach in Healthcare

FindHealthcareIT

HIPAAforMSPS.com

Kardon Compliance

Notes Represented in this study are 90 CE and 88 BAs.

This year is the first time BAs were added to the study data. Previous fours years only CEs were included.

A security incident is defined as a violation of an organization’s security or privacy policies involving protected information such as social security numbers or confidential medical information.

A data breach is an incident that meets specific legal definitions per applicable breach law(s). Data breaches require notification to the victims and may result in regulatory investigation, corrective actions, and fines.

Points to note:

  • There has been a 125% increase in breaches due to criminal attacks on healthcare data over last 5 years.
  • Only 40% of healthcare organizations and 35% of BAs are concerned about cyber attackers even though it is now the number one reason for breaches and increasing rapidly.
  • Security incidents that aren’t breaches are also primarily criminal attacks: 78 percent of healthcare organizations and 82 percent for BAs security incidents.
    • 87% of BAs had multiple security incidents in the past 2 years involving the exposure, theft or misuse of electronic information.
      • 70% say they have had between 11 and 30 electronic information-based security incidents.
    • Most involved the exposure of less than 100 PHI records.
  • Medical identity theft has nearly doubled in five years, from 1.4 million adult victims to over 2.3 million in 2014.
  • Employee negligence remains a top concern when it comes to exposing patient data inappropriately.
  • Many victims of medical identity theft report they spent an average of $13,500 to:
    • Restore their credit,
    • Reimburse their healthcare provider for fraudulent claims and
    • Correct inaccuracies in their health records.
  • According to the findings of this research, the average cost of a data breach for healthcare organizations is estimated to be more than $2.1 million.
  • No healthcare organization, regardless of size, is immune from data breach.
  • The average cost of a data breach to BAs represented in this research is more than $1 million.
  • Even though organizations are slowly increasing their budgets and resources to protect healthcare data, they continue to believe not enough investment is being made to meet the changing threat landscape.

Interesting question details:

View Details

ONC recently published an updated guide for Privacy and Security of Electronic Health Information. This episode David and Donna discuss what that guide calls the Seven-Step Approach for Implementing a Security Management Process.

Links

Guide to Privacy and Security of Electronic Health Information

FindHealthcareIT

HIPAAforMSPS.com

Kardon Compliance

Notes

The 7 Steps

Step 1: Lead Your Culture, Select Your Team, and Learn

Assign your officers, make sure they are trained, show compliance is a top down commitment

Step 2: Document Your Process, Findings, and Actions

If you can't prove it then it didn't happen. Document your decisions, plans and activity

Step 3: Review Existing Security of ePHI (Perform Security Risk Analysis)

Review or perform your Security Risk Analysis and current security assessment

Step 4: Develop an Action Plan

The plan needs to address all the things you identified in your assessments, policies, and procedures

Step 5: Manage and Mitigate Risks

This is where your project management skills come into play making sure you have addressed all the risks in your Analysis and new ones aren't showing up

Step 6: Attest for Meaningful Use Security­Related Objective

If you are attesting make sure you have done the previous steps

Step 7: Monitor, Audit, and Update Security on an Ongoing Basis

Remember it isn't a project that has a beginning and ending date

View Details

We finish up our discussion about some common myths (or points of confusion) surrounding HIPAA compliance requirements.

Glossary
Myth is a widely held but false belief or idea.

Links

HealthIT.gov Top 10 Myths of Security Risk Analysis
HealthIT.gov Guide to Privacy and Security of Electronic Health Information Analysis

Notes 1 - 7 of 10 Covered in two previous episodes.

  1. HIPAA covers all PHI no matter who possesses the information. False. HIPAA law applies to entities that are health plans, healthcare clearinghouses, and most healthcare providers and the businesses that create, receive, maintain, or transmit PHI on their behalf. Not every person or organization that possesses PHI falls under the CE or BA categories of HIPAA.
  2. A one hour video course is all that a compliance officer needs to implement HIPAA in any organization. Mostly false. The law requires you have an educated person in charge of privacy and security compliance. It does not define what that education should contain. I can't imagine how anyone could do it with such little training. Nor do any others who do the job themselves. Training is essential to understanding the requirements enough to perform them.
  3. HIPAA training requirements are met with an annual training for all employees. Mostly false. It could be argued that all is required is a quick reminder/refresher course. However, the amount of training provided for privacy and security awareness is directly related to the results you will get from your workforce. If you don't worry about it more than once a year, neither will they.

View Details

We continue our discussion about some common myths (or points of confusion) surrounding HIPAA compliance requirements.

Glossary
Myth is a widely held but false belief or idea.

Links

HealthIT.gov Top 10 Myths of Security Risk Analysis
HealthIT.gov Guide to Privacy and Security of Electronic Health Information Analysis

Notes 1-3 In previous episode

  1. Communicating with patients via email, fax, or telephone violates HIPAA. Actually, not true. But.... reasonable and appropriate safeguards must be in place.
  2. HIPAA compliance is just like all the other compliance rules for other industries. You learn the requirements and you do what they say. Not at all true. HIPAA rules were designed to allow for every size and type of healthcare entity and business associate to use one set of regulations. That means there are phrases like "reasonable and appropriate" thrown all over them. Every single organization can determine what is reasonable and appropriate for their environment as long as they document how they are addressing the standards. Not even a risk analysis has one method to be performed across all organization.
  3. A website is HIPAA compliant if it uses HTTPS. False. There are two parts of electronic compliance security. You must secure data in motion (like when it is transmitted to a web page via HTTPS). You must also secure the data at reset (what happens to the data once it gets to the server on the other end). Just letting a web designer throw up a registration form or appointment request form will not meet the compliance standards for HIPAA by simply adding HTTPS.
  4. If a vendor signs a Business Associate Agreement there is nothing else for me to worry about concerning them. False. If you have knowledge that a vendor is not compliant and you continue to use their services simply because they signed a BAA you aren't much better off than if you never signed one. Your liability is still tied to the fact that you don't have a compliant BA. By working with them while knowing (or doubting) their compliance understanding and commitment makes you complicit in any failures they may have with PHI. Perform a due diligence of some sort to get assurances they actually have a compliance program in place.

8-10 In next episode

View Details

we discuss some common myths (or points of confusion) surrounding HIPAA compliance requirements.

Glossary
Myth is a widely held but false belief or idea.

Links

HealthIT.gov Top 10 Myths of Security Risk Analysis
HealthIT.gov Guide to Privacy and Security of Electronic Health Information Analysis

Notes

  1. Providers are not allowed to share information about a patient with others unless authorized by the patient to do so. False. Providers can share:

With anyone the patient identifies as a caregiver

When the information is directly relevant to the involvement of spouse, family member, friends, or caregivers. (Ebola for example)

When necessary to notify a caregiver about a change in condition or location of a patient (as long as the patient doesn't object)

When in the best interest of the patient regardless of their ability to object or not 2. The security risk analysis is optional for small providers and business associates. False. Everyone is required to abide by the Security Rule which specifically requires a security risk analysis. 3. A checklist will suffice for the risk analysis requirement. False.Checklists are tools for doing the analysis and gathering your data but they aren't enough to meet the risk analysis requirement. A Security Risk Analysis must include three main elements (according to OCR guidance):

A. Identification of all PHI sources
B. Human, electronic and environmental threats to the PHI
C. Review of current security measures to protect the PHI from those

View Details

In this episode we discuss technology support requirements under HIPAA and why professional, HIPAA compliant IT services are an important part of managing your security compliance.

The Security Rule has so many specific technical things to consider it really requires professional technology services to handle it properly. We discuss why that is needed and what to expect from a HIPAA Compliant IT company.

Glossary A managed service provider (MSP) is a third-party contractor that is under contract (usually a monthly fee) to provide on-going technology support to other organizations.

Links FindHealthcareIT

HIPAAforMSPS.com

Kardon Compliance

Notes

View Details

In this episode we discuss the importance of documentation for your HIPAA compliance program. You can be doing everything right but without documentation there is now way for you to show anyone else that is the case. If you can't prove it then you aren't doing it as far as OCR is concerned.

Glossary A managed service provider (MSP) is a third-party contractor that is under contract (usually a monthly fee) to provide on-going technology support to other organizations.

Links FindHealthcareIT

HIPAAforMSPS.com

KardonCompliance.com

ComplyAssistant.com

Notes * OCR says "don't just tell me you are compliant, show me you are" * What do you need to document + Policies and Procedures, including archive history + Risk Analysis and Risk Assessment + Training for workforce (who, what, where, when) + Risk Mitigation project plans + Issue/Incident details + BAAs and BA Due Diligence + Activity monitoring reports and logs + Audit plans and results + Assessment plans and results + Inventories of software, hardware, etc + Breach response plans and documentation * Spreadsheets and documents in folders or document management tools * Compliance Management tools

View Details

In this episode we discuss how to take the first steps to building a "culture of compliance" in your organization. Every project has to start somewhere but where do you start with something as big and complicated as HIPAA? Well.... Just like the joke goes "How do you eat an elephant?" "One bite at a time."

How do you break HIPAA Compliance into bite sized pieces and get your project moving? We have some tips for you.

Glossary

A culture of compliance is when an organization establishes standards, rules, and policies that aren't simply distributed to the workforce. The organization as a whole takes their compliance serious at a personal level. Each person agrees to abide by the standards, rules, and policies set forth and holds themselves accountable to each other for doing so. This culture can only be accomplished if it is done from the CEO all the way down the organization to the volunteers and/or temporary employees.

Links

Posts From Donna's Blog SmallProviderHIPAA.com

How do you create a culture of HIPAA compliance?

HIPAA Documentation AKA Telling Your Compliance Story

How long will it take to get HIPAA compliant?

Simple HIPAA Checklist – Well Sort of

5 Tips to Just Get Your Risk Analysis Done

Please, Just Do My HIPAA For Me!

Notes

  • What is a culture of compliance?
  • What are the parts I need to build a culture of compliance?
    • Established and supported by Senior Mgmt
    • Integrated into all training and education done for the workforce
    • Programs are designed to reward compliance
    • Sanctions are applied equally to all levels for failure to comply
    • All technology is reviewed and managed with compliance in mind
    • Every decision, project, addition, and subtraction to the business includes considerations for compliance
  • How can you really break HIPAA into small bites?
    • Documentation management plan
    • Business Associates
    • Privacy
    • Security
    • Breach
  • How to motivate myself to take the first bite of the elephant?
    • Every single week start with one task that must be completed
      • Policy or procedure reviewed
      • BA evaluated and audited
      • Procedure audited
      • Training class attended
    • Allocate time to complete a task each week
      • It isn't something you do last, it should be something that is as important as completing you accounting reports, payroll, accounts receivable management, etc.
      • Build the habit or assign it to someone who has the time to apply to getting it done.
    • Build on what you started
      • HIPAA compliance is never "done"

View Details

HIPAA requires encryption in transit and lists encryption at rest as addressable.  What does all that mean?

View Details

Help Me with HIPAA does have a point and vision even if it doesn't seem like it sometimes.  Learn about your hosts and the plan for the show.

View Details

In this episode we discuss the definition of a Business Associate. How do you find your Business Associates and what should your process for managing them include.

Glossary A managed service provider (MSP) is a third-party contractor that is under contract (usually a monthly fee) to provide on-going technology support to other organizations.

Notice of Privacy Practices (NPP) is the document CEs provide to patients when they begin treatment or coverage. It is the document that defines the CEs Privacy, Security, and Breach Rule commitments to the patient.

Links WEDI BA Decision Tree

WEDI Business Associates & HITECH Deep Dive

FindHealthcareIT

HIPAAforMSPS.com

Kardon Compliance

Notes 1. Anyone that CReMaTs PHI on behalf of a CE or another BA

Another way to think of it Produced, Received, Saved, Transferred

  1. Upstream and Downstream BAs

  2. BAAs and what they really mean

  3. What are BAs supposed to do?

  4. Security Rule,

  5. Breach Plan,
  6. Portions of the Privacy rule.
  7. OCR - do what CEs are required to do.

  8. BA Due Diligence

  9. Finding them in your organization.

  10. 1099s,

  11. subcontractors,
  12. software vendors.

  13. Don't go crazy making everyone a BA - Incidental exposure applies for electricians and others.