
Help Me With HIPAA
597 episodes — Page 11 of 12
Ep 92HIPAA Hodge Podge - RDP FAXing Dumpsters - Ep 92
HIPAA news stories are sometimes so short we need to bundle them together. Some listeners questions are also addressed today. So, we have a little bit of everything in this episode. So stick with us as we go through our HIPAA hodge podge. For more details go to HelpMeWithHIPAA.com/92
Ep 91What is HIPAA privacy anyway - Ep 91
What is HIPAA privacy anyway? The annual reporting deadline for little breaches is up at the end of Feb. That means all those little privacy violations in 2016 must be reported on the HHS website soon if you haven't already done it. Since those little ones often mean so much more than the big ones it made me think it would be a good time to talk about privacy. A recent bizarre case in an Atlanta suburb made me realize just how much we value our privacy but may not realize it until it has been taken from us. More at HelpMeWithHIPAA.com/91
Ep 90First HIPAA Settlements of 2017 - Ep 90
OCR continues releasing new settlement agreements on their new pace. There have been two announced in January 2017. We have no idea what will happen now but since these two brought in over $2.6m there may not be a reason we will see them stop their pace. As always, we believe in learning from other's mistakes (not schadenfreude, though). Time to learn what these two can teach us.... HelpMeWithHIPAA.com/90
Ep 89Understanding Cybersecurity Insurance With John Miller of Sterling Risk Advisors - Ep 89
More reasons to have this coverage pop up every day. Whether it is your own business risk management or those required by a business partner in a contract, all businesses should at least evaluate getting cybersecurity coverage. To help us share information on that we have a guest on this episode. Interview with John Miller II, Founding Principal, Sterling Risk Advisors
Ep 888 Common HIPAA Myths - Ep 88
We reviewed the OCR/HHS list of common HIPAA compliance myths when we first started the podcast. Their list is so long that it spread across 3 episodes. Those episodes are still fairly popular today. For today, though, we are covering our own list of common HIPAA compliance myths that we hear. Common HIPAA Compliance Myths Our list may be very similar to all the other lists out there but it is important to cover those because they are clearly STILL being passed along. Why do we keep hearing the same things over and over? More at HelpMeWithHIPAA.com/88
Ep 87Healthcare Breaches Continue in 2017 - Ep 87
At the beginning of 2016, we did some speculation about what the year would be like in the cybersecurity and HIPAA worlds. Today we plan to review how we did for 2016 and explain expect healthcare breaches continue in 2017. More at https://HelpMeWithHIPAA.com/87
Ep 86MACRA and HIPAA - Ep 86
We've talked before about HIPAA showing up in lots of other places. That trend has continue. Now, you will see HIPAA questions on cyber security insurance applications, certification programs from other entities, and now in payment model reforms. Today we are going to talk a little bit about MACRA and HIPAA requirements. If you don't know what MACRA, APMs, and MIPS is all about we may not cover enough to explain it all be we will certainly touch on MACRA and HIPAA crossing paths starting in 2017. More information at HelpMeWithHIPAA.com/86
Ep 852017 Compliance Management Plans - Ep 85
Last January, we did an episode with a 2016 Compliance Management Plan. We even created a reminder poster for it you could download. The episode was about providing a compliance management plan guideline for compliance officers who are trying to find a way to fit this in your with all your other job duties. That episode was very popular and the poster was downloaded by new folks even in December. This episode reviews that compliance management plan and adds a bit more to it for "extra credit". We also added a second poster and compliance management plan for a more aggressive approach than just the bare minimum. Get the downloads and more information at HelpMeWithHIPAA.com/85
Ep 84Healthcare Cyber Attacks - Ep 84
Every day it seems we read about more healthcare cyber attacks. As the news keeps breaking with more details on the wide variety of cases, we have plenty of work to do just to keep up. Today, there are so many cases to talk about we couldn't even decide what to call the episode. More details at https://HelpMeWithHIPAA.com/84
2016 Blooper Show - Happy Holidays!
bonusListen in to outtakes from this year's episodes. We need something lighter to celebrate the holidays!
Ep 83HIPAA 21st Century Cures Act - Ep 83
For a change there was a bipartisan bill passed with some big impacts on healthcare. HIPAA 21st Century Cures Act implications are, of course, our focus. Today, we review some thoughts on the bill that was signed into law this week. More notes at https://HelpMeWithHIPAA.com/83
Ep 82OCR Phishing And More Announcements - Ep 82
Recorded during our first live broadcast, this episode covers several OCR announcements. We start with the OCR phishing alert. Followed by that we discuss OCR's guidance that said you should consider multi-factor authentication in your risk analysis. There have also been more resolution agreements that we haven't covered on an episode so we hit those, as well. Since it was a live show we also take some questions! For more: https://HelpMeWithHIPAA.com/82
Ep 81Phishing Attacks In Healthcare - Ep 81
Phishing attacks in healthcare are on the rise just like every other industry. However, unlike many other targets, phishing attacks in healthcare have a much higher return on investment if the phisherman gets anyone to take the bait. We've talked multiple times how healthcare is now a major target for hackers. Then, it only makes sense that we will see a continued rise in efforts aimed at phishing attacks in healthcare. Types of phishing: Phishing - spray and pray - grab an email list and let it rip - big net phishing Spear phishing - Aimed directly at you. Everything makes it look like it should be in your email meant for you from someone you know Whaling - Pointed directly at upper management of a company with an urgent business matter Soft targeting - send to people with a certain job that they would expect, like HR gets a resume but financial team gets a spreadsheet Telephone phishing - Just call you up and act like they should be asking you for login information For more info: https://HelpMeWithHIPAA.com/81
Ep 81 Is Being Held For Ransom
bonusWe are holding episode 81 for ransom during the Thanksgiving holiday. For our black Friday episode we hope you enjoy this replay of our most popular episode. Stay tuned! Episode 81 will be released next Friday. We will be discussing the different types of phishing, how they work and how you can resist the bait.
Ep 80HIPAA Compliant Cloud - Ep 80
In early Oct the long awaited guidance on HIPAA Compliant Cloud was released by HHS / OCR. There wasn't a lot of shocking information for us since it just restated, maybe more clearly, that cloud services providers (CSPs) must sign a BAA and meet certain obligations as a BA. Hopefully, this will address all the cases where some CSPs would use "slight of hand" with phrasing to claim they didn't have to be a HIPAA compliance cloud provider. The amount of "all ya gotta do is" type of misinformation only makes things harder to get done. Let's look at what the guidance addressed. For more details go to HelpMeWithHIPAA.com/80
Ep 79OCR Audits and Enforcement 2016 - Ep 79
This week is basically part 2 from last week. We left off just before reviewing the OCR audits and enforcement updates announced at the NIST / OCR Security Conference 2016. Get more details at HelpMeWithHIPAA.com/79
Ep 78HIPAA Security Conference 2016 - Ep 78
Donna shares information from the 2016 NIST/OCR Annual Conference on Safeguarding Healthcare Information. Learn what she thought was interesting to share with you. More information at https://HelpMeWithHIPAA.com/78
Ep 77HIPAA Halloween Haunted House - Ep 77
We tour the HIPAA haunted house in this year's Halloween episode! Cybersecurity has become a big concern over the last 18 months. Breaches in 2015 have given way to ransomware along with more daring breaches in 2016. What is really happening on your computers, networks, and the Internet every second is terrifying in several ways. There are plenty of amazing and good things happening at the speed of light but so are the bad ones..... For more details go to HelpMeWithHIPAA.com/77
Ep 76Ransomware and HIPAA - Ep 76
Ransomware and HIPAA have been a topic on the podcast multiple times. They are some of our most popular episodes, in fact. Recently, we realized we haven't discussed the OCR guidance on ransomware and HIPAA. On July 11, 2016, HHS.gov featured a new post from Jocelyn Samuels the Director of the Office for Civil Rights (OCR). The title is catchy: Your Money or Your PHI: New Guidance on Ransomware. This episode is a review of that post and the fact sheet with OCR guidance on ransomware and HIPAA that the post announced. . For more information http://HelpMeWithHIPAA.com/76
Ep 75Disaster Recovery Planning Under HIPAA - Ep 75
Everything going on today with hurricanes and such makes it is a great time to talk about this. We mention it all the time but this episode is going to be just about what DR/BC means and what you can do to be prepared in advance. So, this episode covers disaster recovery planning under HIPAA but any business can learn from our topics! What is DR/BC Planning? Who should do it? Is this another big expense? What is involved in building and maintaining DR/BC plans? General elements of a plan Get more details at http://HelpMeWithHIPAA.com/75
Ep 74HIPAA Security Updates Recommended In New Report - Ep 74
Last year Sen. Lamar Alexander and Sen. Patty Murray asked for answers to some questions concerning cybersecurity in healthcare. They were interested in understanding what CMS and HHS were doing to protect patients from fraud. It seems as though they were wondering if HIPAA security updates where needed. We discussed the Senators request in episode 31 : https://helpmewithhipaa.com/episode-31-enforcement-efforts-ocr-increase-2016/ Their letter asked: What CMS and HHS is doing to monitor medical identity fraud What is CMS and/or OCR actually doing, if anything, to track cases of ID theft and fraud OCR uses the data collected from covered-entities to monitor potential breach victims and find out if their data have in fact been used by criminals They also want to know whether any education materials or help are offered to breach victims by the CMS and OCR The report was presented to the committee on August 6, 2016 and made public on Sept 26.
Ep 73Business Associate Security Issues - EP 73
BAs are in the HIPAA spotlight now more than ever. TheDarkOverlord was clearly using some BA applications to infiltrate networks and exfiltrate PHI. OIG reviewed Alaska VA system after breaches and the report specifically points to the need to monitor BAs OCR audits of BAs are about to start. Previously said end of September but now saying October In this episode we discuss what all this means. More at HelpMeWithHIPAA.com/73
Ep 72HIPAA Penalties Increasing - Ep 72
Did you hear that maximum penalties for HIPAA violations are being adjusted for inflation? It has quietly happened. Here is how. Check out the Federal Register entry from September 6, 2016. If you aren't in to reading yourself, don't worry, you know Donna did it. Well, at least the HIPAA parts. Learn more at: HelpMeWithHIPAA.com/72
Ep 71OCR small breach investigations increasing - Ep 71
OCR recently released another memo concerning compliance enforcement efforts. They say effective August 2016, they have started an initiative to more widely investigate breaches involving under 500 patients. That means that OCR small breach investigations will begin happening immediately. In the past, the policy had been to investigate all breaches over 500 patients but not under. More information at HelpMeWithHIPAA.com/71
Ep 70Insider Threats: Do you know who your employees are? - Ep 70
OCR published a memo on Aug 1, 2016. The title is "Do you know who your employees are?". It is a great reminder about insider threats that we should all worry about regularly. Quoted directly from the memo. ============================ Although all insider threats are not malicious or intentional, the effect of these threats can be damaging to a Covered Entity and Business Associate and have a negative impact on the confidentiality, integrity, and availability of its ePHI. According to a survey recently conducted by Accenture and HfS Research, 69% of organization representatives surveyed had experienced an insider attempt or success at data theft or corruption. Further, it was reported by a Covered Entity that one of their employees had unauthorized access to 5,400 patient's ePHI for almost 4 years. For more visit: HelpMeWithHIPAA.com/70
Ep 69OCR 2016 settlements keep coming - Ep 69
So far in 2016 there have been 10 resolution agreements announced. One more and this year will equal the number of agreements in all of 2015 & 2014! The latest two also include the largest one announced yet - $5.5m with Advocate Health. Before that though was The University of Mississippi Medical Center - Ole Missto those of us in the SEC world. It wasn't something to "shake a stick at" with a$2.75m resolution amount. The total amount for those 10 announcements so far in 2016 = $20,314,800 Of course the details are what we usually pay more attention to since it tells us exactly what OCR has a problem with in each case. It makes it clear what OCR wants all of us to learn from these folks mistakes. For more visit HelpMeWithHIPAA.com/69
Ep 68OCR Desk Audit Details - Ep 68
The OCR audits have begun. On Wednesday, July 13, audit selected CEs where invited to a webinar. OCR staff walked through the processes they can expect for the audit and expectations for their participation. The OCR published information from the webinar so we had to check it out and share what we learned with you guys. For more details visit HelpMeWithHIPAA.com/68
Ep 67Pokemon Go and HIPAA Breaches - Ep 67
Say it ain't so! Pokemon and a HIPAA breach really? REALLY! Creatures are showing up in offices and hospitals just like everywhere else. The concept of keeping people active and engaged with their surroundings while playing a video game seems like a great idea from a healthcare standpoint. And then you actually do a risk assessment of it - this is where the wheels fall off that good idea train. Get more details as HelpMeWithHIPAA.com/67
Ep 66Healthcare Hack: PHI For Sell On The DarkNet - Ep 66
We first talked about this in Ep 62. Darknet sale of healthcare records. Now, more information is coming out and it gets more unfortunate for patients every time we read more. Deep Dot Web broke the news: https://www.deepdotweb.com/2016/06/26/655000-healthcare-records-patients-being-sold/ We picked it up on Data Breaches.net because they were trying to figure out who the entities actually were in each case: https://www.databreaches.net/damn-anyone-know-what-facilities-these-are/ Get more info at https://HelpMeWithHIPAA.com/66
Ep 65OCR resolution agreement - OHSU - EP 65
What happened? March 23, 2013 Oregon Health & Science University notified HHS of a breach due to a stolen unencrypted laptop. May 1, 2013 OCR notifies them they are investigating the incident July 28, 2013 Oregon Health & Science University notified HHS of another breach resulting from storing ePHI at an internet-based service provider without a business associate agreement November 8, 2013 OCR notifies them they are investigating the new incident July 18, 2016 settlement announced for $2.7 million and a 3 year CAP What can we learn from this? Go to Help Me WithHIPAA.com/65
Ep 64Security Incident Response Plan - Ep 64
OCR recently sent out a message on their listserv asking if your CE or BA was ready for an incident. We have been discussing security incidents a lot lately so it is nice that OCR has brought it up. Because we have seen various Incident response reports recently, so we were working on an episode anyway. So this episode is a review of Security Incident Response Plan development. Let's first be clear, this isn't just about HIPAA. We also have been reviewing the Economist Intelligence Unit 2013 (EIU) report: Cyber incident response: Are business leaders ready?, which is asking the very same question. For more information go to HelpMeWithHIPAA.com/64
Ep 63Medical Device Security - Ep 63
There has been a lot of news and industry discussions about Medical Device security. Medical Devices are just like a computer, so they also need security to protect the information on them. For more go to HelpMeWithHIPAA.com/63
Ep 62Business Associate Breaches In The News - Ep 62
A business associate is getting this OCR resolution, $650,000 and a two-year settlement. CHCS in Philadelphia is a BA to 6 skilled nursing clinics in the Philadelphia area. Entities like this do the business part of healthcare and the other clinics don't have to worry about it. An unencrypted iPhone that wasn't password protected had PHI on it. Patterson Dental Supply Inc. helps manage dental practice information for various providers. One of the clinics they help service is Massachusetts General Hospital, and 4,300 patients had their PHI hacked and compromised. For more info: HelpMeWithHIPAA.com/62
Ep 61Healthcare Data Breach Study - Ep 61
Since 2010, ID Experts has sponsored this Ponemon Institute study which has been tracking data breach trends of patient data at healthcare organizations. The annual economic impact of a data breach has risen over the past six years, as has the frequency of data breaches. Criminal attacks and internal threats are the leading cause of healthcare breaches. Evolving cyber attack threats such as ransomware and malware are of primary concern for 2016. At the same time, internal issues such as employee negligence, third-party snafus, and stolen computing devices continue to put patient data at risk. For more info on this episode go to helpmewithhipaa.com/61 28w47ezq
Ep 60HIPAA Rules In A Crisis - Ep 60
As always, during times of crisis and chaos things do become confused and incorrect statements are made. It is a normal occurrence in troubling situations. But, we need to address it specifically to clear up a few points. There was no "special waiver from the White House". There was no need for one at all. People, even in a crisis, should not be invoking HIPAA over caring for the patient properly. The hospitals talked about implementing their crisis plan - why wasn't HIPAA addressed in the plan. It should be! For more details go to HelpMeWithHIPAA.com/60
Ep 59HIPAA, HHS, OCR, and PHI - Ep 59
Today's podcast is a little different from our normal ones. We are covering a wide variety of subjects involving HIPAA, OCR, HHS, and PHI rather than one specific topic. For more go to HelpMeWithHIPAA.com/59
Ep 58Preventing Ransomware - Ep 58
Preventing ransomware is a major concern for every business today. If not, it should be. This episode covers understanding ransomware and methods for preventing it. Is ransomware a phi breach? April record number of cases and not slowing down 8 hospitals (more by the time we record) already hit. Training and vigilance is best defense Ransomware attacks continue to evolve to be "smarter" For more see HelpMeWithHIPAA.com/58
Ep 57HIPAA Policy and Procedure Templates - Ep 57
HIPAA policy and procedure templates seem to be a panacea to many people who are just trying to meet the standards and move on. However, these are not the droids you seek! Templates can be the basis for what you need to do but they shouldn't be the solution to the written policy and procedure requirements under HIPAA. See HelpMeWithHIPAA.com/57
Ep 56Malware Protection under HIPAA - Ep 56
Two reasons for today's topic: A question we received from a listener about understanding antivirus software and a news report about a malware scan that interrupted a medical procedure. Between those two cases it felt like it was time to discuss malware protection under HIPAA. Suzie from Savannah: I would like to have a podcast or a quick answer to the different between anti-virus software releases and anti-virus definitions being up-to-date. I understand the AV definitions up to date but a little fuzzy on AV software releases and examples please.... Report came out about malware scan stopping a medical procedure
Ep 55New HIPAA Privacy Rules Guidance - Ep 55
We always look at the security rule aspects of HIPAA because they deal with the easier parts for people to deal with when it comes to lowering their risk, but today we are diving into some privacy rule guidelines, because there is new HIPAA privacy guidance that has just been published. Get more info at HelpMeWithHIPAA.com/55
Ep 54HIPAA Access Log Audits - Ep 54
Recently, we ended up in several discussions about HIPAA access logs and what they really require with our clients. As per usual, any topic that comes up multiple times in my "real job" becomes a discussion for HMWH. So, today we are talking about HIPAA access logs to attempt to clear up some confusion we have encountered. There are multiple types of HIPAA access logs being created in most environments and you should be dealing with pretty much all of them in some manner. Get more at HelpMeWithHIPAA.com/54
Ep 53What does a data breach cost? - Ep 53
We talked about OCR audits recently because they are in the news. The audit protocol is a perfect guide for developing and maintaining your HIPAA compliance programs. In fact, the audits have been a hot topic in the industry this month. However, the fact that only 200 audits will take place really means the audit protocol is more important as a guide for what your program should look like in the event you have a breach or complaint investigation. Statistically, you are much more likely to need it for that reason. Read more at HelpMeWithHIPAA.com/53
Ep 52Ep 52: HIPAA Podcast One Year Anniversary Interview
We really appreciate the support and feedback we have received for our little HIPAA podcast project known as Help Me With HIPAA. This episode marks one complete year of weekly HIPAA podcasts (counting the special bloopers holiday episode). We certainly learned a great deal since we started this little DIY project last year. Granted, David was a convert to the idea much quicker than Donna. Here we are one year later and our little HIPAA podcast is starting to gain some real momentum. That is all thanks to you, our listeners, for sticking with us through our growing pains as we fumbled through figuring it all out. Keep on sending in your questions and suggestions, we appreciate your help and support! Also, a special shout out to the silent member of our team Bojan Sabioncello for making us sound so much better once he came on board! After saying all of that, what are we doing for this special episode? We are interviewing each other to discuss how we ended up together and what we do in our "real jobs". this HIPAA podcast is a huge part of what we do but it isn't the only thing you get from us. For more information go to HelpMeWithHIPAA.com/52
Ep 51Ep 51: Small Office HIPAA Compliance
We often talk about doing the "work" of compliance. Some people seem to have the attitude that all I need to do some is annual staff training and hand out a Notice of Privacy Practices to do small office HIPAA compliance. When we try to explain there is more to it than that we often get pushback about the requirements. We always hear comments like: we don't have time, we don't have resources, we can't be expected to do this. So, how DO you do small office HIPAA compliance? Today we are going to talk to someone who is definitely doing the work of HIPAA compliance in a small office. We are doing an interview with Erien Fryer of Medical Direct Care in Clarksville, TN to discuss small office HIPAA compliance issues, obstacles, and how to just get it done. For more details go to HelpMeWithHIPAA.com/51
Ep 50Ep 50: Website Security Questions
Every website needs security. What questions should you be asking about your business websites and who should you be asking? Website security can be an open hole in your security plans. It can also be the source of lots of problems for your business if you don't pay attention to the site content or securing your message. More info on the website at helpmewithhipaa.com/50
Ep 49Ep 49: New OCR Audit Protocol Review
The recent release of the new OCR audit protocol gives us new guidance on what they expect from HIPAA compliance programs. There is a great deal of information to sift through if you are so inclined. To make it easier for you we are discussing some of the details and things we have learned from reviewing it for you! So, here is our review of the new OCR audit protocol! For more details go to our website article helpmewithhipaa.com/49
Ep 48Ep 48: Disaster Recovery for Flooding
In the first episode in our Disaster Recovery series that we will be doing this year we are discussing planning disaster recovery plans for flooding. This episode is an interview with Ginger McCleish who experienced a real world disaster recovery flooding in the St. Louis, MO area in December 2015. Hear more at HelpMeWithHIPAA.com/48
Ep 47Ep 47: Latest HIPAA Buzz
The latest HIPAA buzz is about things like Interoperability, Data Governance, Patient Access Rights, and, of course, OCR random audits. Donna attended HIMSS and the National HIPAA Summit recently. In this episode we discuss what kinds of things are happening in the industry relating to HIPAA. For more details visit our website at helpmewithhipaa.com/47
Ep 46Ep 46: HIPAA Enforcement 2016
So far in 2016, we have seen four HIPAA enforcement cases resolved by OCR. One involved only the second Civil Money Penalty ever assessed. The three others were resolution agreements. Add those cases to what was done in 2015 and you have the most active 12 month period of HIPAA enforcement ever. Certainly, the first quarter of 2016 has been the most active quarter ever when it comes to HIPAA enforcement announcements. In this episode we discuss the cases resolved so far in 2016 and more thoughts on what is coming up for 2016. Read more at our website HelpMeWithHIPAA.com/46
Ep 45Ep 45: Why Do We Need HIPAA
Many times people ask: Why do we need HIPAA? Is HIPAA really necessary? The short answer is yes, we do need HIPAA and the reason is without it there is no baseline for protecting patient privacy. Learn more at http://helpmewithhipaa.com/45