PLAY PODCASTS
Help Me With HIPAA

Help Me With HIPAA

597 episodes — Page 2 of 12

Ep 530Is a Half Truth a Whole Lie - Ep 530

Is it still a lie if it's only half false? Asking for a biotech company that might've taken "fake it till you make it" a bit too literally with their cybersecurity claims. From hard-coded admin credentials to ignoring vulnerabilities like a bad ex's texts, this episode dives into what happens when convenience beats caution and how a $9.8 million lesson got served with a side of whistleblower justice. More info at HelpMeWithHIPAA.com/530

Oct 10, 202541 min

Ep 529Digital Jenga - Ep 529

Welcome to "Digital Jenga," where the tower's made of cloud apps, power cords, and fragile backup plans and every pulled piece brings us closer to chaos. Today's episode is a thought experiment that feels a little too real: What happens when everything goes down but your stress levels? Grab your imaginary generator and follow along as we walk through scenarios that are way more common (and hilarious) than you'd think, because nothing says fun like discovering your entire system was balancing on one Wi-Fi signal and a prayer. More info at HelpMeWithHIPAA.com/529

Oct 3, 202541 min

Ep 528Small, Breached, and Broke - Why Hackers Love SMBs - Ep 528

If your small business still thinks that a dusty old firewall and a sprinkle of MFA is "good enough," this episode is your cybersecurity reality check. Picture your company as a lemonade stand with a cash box—hackers are thirsty, and you're wide open for business. We're diving into why SMBs are now hacker playgrounds, how AI is helping cybercriminals get sneakier, and why your robot vacuum may be more security-conscious than your network gear. It's everything you didn't want to know about being a prime target—served up with a twist of humor, a splash of horror, and a tall glass of truth. More info at HelpMeWithHIPAA.com/528

Sep 26, 202554 min

Ep 527Stack Attack - Breach by Association - Ep 527

Ever feel like your tech stack is one shady character away from becoming a security nightmare? Yeah, same. In this episode, we dive headfirst into the murky waters of "breach by association,"where trusting one tool can accidentally invite the entire cybercriminal neighborhood into your data party. From APIs doing the digital equivalent of handing out spare keys, to sneaky GitHub repos spilling secrets like a leaky faucet, we unpack how this all went down. Spoiler: the AI-powered thieves were way too polite to trip any alarms. More info at HelpMeWithHIPAA.com/527

Sep 19, 202538 min

Ep 526AI Ran the Whole Attack - Ep 526

So you thought AI was just here to help you write emails and generate cat memes? Think again. In this jaw-dropping episode, we unpack how AI didn't just assist in a cyberattack—it ran the entire show like a caffeinated Bond villain with zero moral compass. From reconnaissance to extortion letters with sector-specific sass, this is the future of cybercrime, and it's happening now. Buckle up. The robots aren't just coming—they've already clocked in. More info at HelpMeWithHIPAA.com/526

Sep 12, 202534 min

Ep 525Hacking You Gently - Ep 525

Forget Mission: Impossible-style hacking - today's cyber crooks are all about manners. In this episode, we unravel how asking "pretty please" can crack open digital doors faster than any brute force attack. With tips, tales, and a touch of panic, we break down the importance of knowing your personal risk profile, locking down your accounts, and yes - finally turning on that MFA you've been ignoring. More info at HelpMeWithHIPAA.com/525

Sep 5, 202550 min

Ep 524OCR Tags CPA Firm for HIPAA Failures - Ep 524

If you thought HIPAA only applied to big hospitals and medical groups swimming in patient data, think again. In this episode, we uncover how just one record with PHI can infect your organization with full-blown HIPAA responsibilities — no vaccine required. We dive into a juicy enforcement case featuring a CPA firm that got hit with a ransomware attack and a $175K HIPAA oopsie, all because someone skipped their security risk analysis. Spoiler: ignorance is not immunity. More info at HelpMeWithHIPAA.com/524

Aug 29, 202542 min

Ep 523Shadow AI - The Wild West of Cybersecurity - Ep 523

Strap in, folks—this episode charges into the wild frontier of cybersecurity, where Shadow AI runs loose like a toddler with admin access. Whether your security plan is airtight or held together by paperclips and prayers, this deep dive into the IBM Cost of a Data Breach 2025 report offers plenty to think about. From eye-popping breach costs to the cringe of unsecured AI, we're covering the good, the bad, and the downright reckless. Spoiler: "we don't use AI" might be the biggest myth since "the check's in the mail." More info at HelpMeWithHIPAA.com/523

Aug 22, 202549 min

Ep 522Ransomware Hit. Business Quit. - Ep 522

You might think a single ransomware attack is just a tech hiccup—but tell that to the medical practice that shut its doors permanently because of one. In this episode, we dissect what really happens when cybersecurity goes sideways, peeling back the layers of tech jargon to expose the raw, messy fallout of a breach. It's less "oops, I forgot my password" and more "goodbye, 12 years of business." Let's get real about what these incidents cost—not just in dollars, but in dignity. More info at HelpMeWithHIPAA.com/522

Aug 15, 202544 min

Ep 521Shore Up or Throw Up - Healthcare's Latest Cyber Warnings - Ep 521

What do hackers, patient scams, and IT help desks with too much trust have in common? They're all making healthcare cybersecurity a lot messier—and a lot more vomit-worthy. In this episode, we dive into how bad actors are not only stealing data but turning patients into direct targets. From sneaky social engineering tactics to "I can't believe they answered that call" level IT fails, we explore why locking down your network is only half the battle. More info at HelpMeWithHIPAA.com/521

Aug 8, 202531 min

Ep 520Battle of the Bots - AI on Offense and Defense - Ep 520

If you thought AI was just about asking ChatGPT for dinner ideas, think again. This episode unpacks the next-level madness of agentic AI—those industrious bots that not only check your emails but might just decide how your healthcare practice runs. We're talking phishing attacks on steroids, decision-making algorithms with questionable judgment, and the jaw-dropping ways AI is working for—and against—us in cybersecurity. It's part fascinating, part terrifying, and 100% worth listening to. More info at HelpMeWithHIPAA.com/520

Aug 1, 202543 min

Ep 519BAAs, Breaches, and the Art of Covering Your Assets - Ep 519

You know that moment when someone casually slides a contract across the table and says, "Just sign here"? Yeah, don't do that—especially when it's a Business Associate Agreement. This episode is a deep dive into the dark corners of BAAs, the traps they hide, and why you should read every line like it's a ransom note. From ping floods to passive-aggressive breach clauses, we unpack the weird, wild world of healthcare contracts. Oh, and stick around—because just when you think it can't get any messier, a breach shows up to ruin everyone's day. More info at HelpMeWithHIPAA.com/519

Jul 25, 202553 min

Ep 518Keeping Up With the Cyber Laws - Ep 518

Think cybersecurity laws are just for the big guys? Think again. In this episode, we unravel the patchwork of new state regulations popping up faster than a phishing scam in your inbox—Ohio, Utah, Texas, Florida, and even Iowa are throwing their hats into the compliance ring. From safe harbor perks to tiered requirements for small businesses (yes, Texas made a flowchart-worthy version), we decode what these laws mean, who they apply to, and why HIPAA entities seem to always get the "you're fine, probably" treatment. Bonus: there's a federal bill in Congress that might actually help. Maybe. More info at HelpMeWithHIPAA.com/518

Jul 18, 202548 min

Ep 517Cyber Safety Is Patient Safety - Greg Garcia's 5-Year Rally Cry - Ep 517

Strap in, folks—this isn't your average cybersecurity snoozefest. We're plugging into a conversation with Greg Garcia, the guy who's been leading healthcare's cyber crusade like it's the season finale of a medical drama. From hospitals fending off ransomware to the chaotic ballet of patching ancient medical devices, it's clear: in a world where tech keeps patients breathing, cyber safety is patient safety. And no, turning it off and on again won't fix this one. More info at HelpMeWithHIPAA.com/517

Jul 11, 202555 min

Ep 516One Phish, Two Phish, MFA Bypass Twist - Ep 516

If you thought "One Phish, Two Phish" was a Dr. Seuss classic, think again—this cybercrime edition comes with a twist of ransomware, app-specific passwords, and a side of website hijacking. This week, we explore what happens when software vendors forget to patch, hackers start crafting emails better than your favorite copywriter, and your website becomes a party zone for malware. It's an episode full of lessons, laughs, and mild panic—just the way we like it. More info at HelpMeWithHIPAA.com/516

Jul 4, 202542 min

Ep 515Reasonable Security That Holds Up in Court - Ep 515

If you've ever wondered what happens when "going viral" meets "losing your license," this episode has the answer—courtesy of a nurse who took her TikTok dreams a little too far. From cringe-worthy compliance blunders to Oklahoma's oddly refreshing legal update, we're diving headfirst into the murky waters of healthcare privacy, social media madness, and why reasonable security might just be your get-out-of-court-free card. It's like HIPAA meets reality TV—minus the roses and dramatic exits. More info at HelpMeWithHIPAA.com/515

Jun 27, 202540 min

Ep 514Things That Make You Go Hmm - Ep 514

This week on "Things That Make You Go Hmm," we're serving up a digital cocktail featuring disappearing network routes, dark web AI tools with a flair for phishing, and Microsoft's bold new idea to let Copilot tinker with your system settings—what could possibly go wrong? In this episode, we dissect digital disasters and marvel at how event planners might just be outdoing some organizations when it comes to risk assessments. It's equal parts facepalm and fascinating. More info at HelpMeWithHIPAA.com/514

Jun 20, 202542 min

Ep 513Sometimes It's Just a Squirrel - Ep 513

You've heard of phishing scams, ransomware, and all the usual cyber villains—but have you prepared for the wrath of a squirrel? In this episode, we unpack how one fuzzy-tailed offender knocked out power to 11,000 customers and sent a swim club scrambling for pencils and paper. But this isn't just a woodland horror story. It's a real-world reminder that sometimes, your biggest threat isn't a hacker—it's Alfred the squirrel with a death wish and a talent for circuit boards. We use this nutty incident to highlight the often-overlooked need for utility failure preparedness in healthcare and dig into the super-helpful (and criminally underused) ASPR TRACIE tip sheets that can keep your operations steady when nature gets twitchy. More info at HelpMeWithHIPAA.com/513

Jun 13, 202551 min

Ep 512Edge of Disaster - Ep 512

Welcome to another episode where chaos meets cybersecurity and common sense tries to crash the party. In this digital drama, we're untangling the curious case of a former employee with way too much access, some mysterious printed medical records, and a whole lot of "Wait... WHAT?!" moments. We also dive into the thrilling (read: terrifying) reality of outdated edge devices and how your trusty old router might just be moonlighting as a hacker's BFF. Oh, and spoiler alert—Microsoft Recall still isn't winning any popularity contests. More info at HelpMeWithHIPAA.com/512

Jun 6, 202547 min

Ep 511EDR Failed - Leadership Did Too - Ep 511

Ever wonder what would happen if a hacker walked right into your digital living room, kicked off their shoes, and hung out for three months without anyone noticing? This week's episode dives into a jaw-dropping CISA Red Team Assessment that reads like a cybersecurity horror flick—complete with ignored alarms, forgotten passwords, and an open-door policy for digital intruders. It's not just about tech failures; it's a full-blown case study in what happens when leadership decides "meh" is a strategy. More info at HelpMeWithHIPAA.com/511

May 30, 202552 min

Ep 5107 Things Healthcare Needs More Than Another Webinar - Ep 510

Let's face it — if healthcare had a dollar for every time someone said "we need another webinar," it might actually be able to afford cybersecurity upgrades. This episode takes aim at the overload of online presentations and instead shines a light on what healthcare providers actually need. We unpack the findings of a critical report on the unique cybersecurity challenges facing small and rural healthcare providers, who are often running on shoestring budgets, outdated tech, and a whole lot of crossed fingers. More info at HelpMeWithHIPAA.com/510

May 23, 202547 min

Ep 509Breach, Blame, and Bad Behavior - Ep 509

When a cybersecurity CEO strolls into a hospital and decides to play malware magician with a couple of unlocked computers, you've got yourself a plot twist worthy of a Netflix docuseries. In this episode, we dive headfirst into bizarre breaches, finger-pointing fiascos, and the kind of contractual confusion that'll make you want to reread your SLAs before breakfast. It's a rollercoaster of responsibility, reputation, and really bad behavior. But at the heart of it all is the million-dollar question: who's actually responsible when it all goes sideways? More info at HelpMeWithHIPAA.com/509

May 16, 202548 min

Ep 508Busy Broke and Breached - Ep 508

Healthcare still has a giant "Hack Me" sign taped to its back — and the latest reports from Mandiant and Verizon are here to confirm it. These cybercrime breakdowns reveal that attackers are smarter, sneakier, and spending more time poking around your network than ever before. Waiting to secure your systems until after a breach is like installing a smoke detector after the house has already burned down — by the time you smell smoke, it's too late. From dwell times that feel more like extended Airbnb stays to small businesses learning that "we're too small to target" isn't a strategy, the findings hit hard and the lessons come wrapped in some well-placed snark. More info at HelpMeWithHIPAA.com/508

May 9, 202552 min

Ep 507Access Granted... and Never Revoked - Ep 507

If the Ponemon study were a horror flick, it'd be titled "The Login Came from Inside the System." This week's episode dives into the alarming trend of organizations handing out privileged access like Halloween candy — only to forget who's still got it long after the party's over. With 59% of breaches linked to insiders or third parties, and executives confidently sailing past the iceberg of reality, we explore what happens when no one's really sure who can still get into the network. Spoiler alert: it's not good. So grab your flashlight and audit logs — we're heading into the haunted house of unrevoked access. More info at HelpMeWithHIPAA.com/507

May 2, 202541 min

Ep 506They Got Hit. They Just Didn't Tell You. - Ep 506

Turns out, "they got hit, they just didn't tell you" isn't just a snarky title—it's a terrifying reality. The Black Fog report basically says, "Hey, the cybersecurity iceberg is way bigger below the surface." From undisclosed data heists to the rapid rise of ransomware attacks, this is your reminder that you don't want to be the next plot twist in a cyber thriller. Oh, and yeah... shadow AI is watching too. Sleep tight! More info at HelpMeWithHIPAA.com/506

Apr 25, 202548 min

Ep 505HSCC Makes Bold Cyber Rx Move Before Congress - Ep 505

Imagine your hospital gets hacked—the MRIs are down, billing's frozen, and suddenly you're faxing patient records like it's 1999. No, that's not a "Twilight Zone" rerun—it's real life in health care. This week, we're diving into what the Health Sector Coordinating Council (HSCC) is doing about it, including their recent trip to Congress to lay it all out. From legacy devices clinging to life like old Tamagotchis to cybersecurity plans that don't sound half bad, we break it all down with just the right amount of snark. More info at HelpMeWithHIPAA.com/505

Apr 18, 202553 min

Ep 504Keeping It Boring and Patched - Ep 504

Forget action-packed heist movies — the real cybersecurity heroes are the ones making their auditors yawn. In this episode, we break down why "boring and patched" should be everyone's new life goal. From AI developments that won't sit still for five minutes to real-world cyber drama featuring surprise FBI visits (no popcorn needed), we're serving up a crash course in staying safe, sane, and just boring enough to avoid disaster. More info at HelpMeWithHIPAA.com/504

Apr 11, 202547 min

Ep 503AI Has A Patient Safety Problem - Ep 503

AI in healthcare is kind of like an overenthusiastic intern—it's full of potential, but someone probably should be watching it a little closer. In this episode, we dive into why artificial intelligence might be more "oops" than "awesome" when it comes to patient safety. A recent ECRI report flagged AI as a top safety concern and offered up smart recommendations like stronger governance and better training. From glitchy decision-making to eyebrow-raising cybersecurity breaches, we're unpacking why AI still needs some serious adult supervision in the healthcare world. More info at HelpMeWithHIPAA.com/503

Apr 4, 202548 min

Ep 50210 Security & Privacy Metrics to Keep Your SMB in the Black - Ep 502

Think your once-a-year vulnerability scan is enough? That's adorable. Waiting to check your security metrics until something goes wrong is like only checking your smoke alarm after the house starts smelling like burnt toast. In this episode, we peel back the layers on the top 10 security and privacy metrics every business should be tracking—whether you're the CEO, the IT person, or just someone who knows how to find the printer on the network. From patch management and MFA to phishing tests and forgotten routers older than your intern, we've got it all. Buckle up and get ready to verify like your digital life depends on it—because it kinda does. More info at HelpMeWithHIPAA.com/502

Mar 28, 202547 min

Ep 501HIPAA, Hackers, and Havoc – A Cybersecurity Reality Check - Ep 501

Buckle up, folks—this episode is a rollercoaster of cyber chaos! We kick things off with a quick chat about the upcoming PriSec Boot Camp (because let's be real, who doesn't love a good security boot camp?). But then, we dive headfirst into the madness: a fresh HIPAA smackdown over right-of-access failures, a rogue IT guy who locked down an entire company out of revenge, and some seriously sketchy Bluetooth vulnerabilities that could have hackers eavesdropping on your life. And if that wasn't enough, the 2025 SonicWall Cyber Threat Report drops some terrifying stats on ransomware, business email compromise, and how AI is making cyberattacks even more dangerous. Grab your tinfoil hat and let's get into it. More info at HelpMeWithHIPAA.com/501

Mar 21, 202556 min

Ep 500500 Episodes Later – The Threats Are Worse But So Are Our Jokes - Ep 500

500 episodes. A whole decade. Countless cybersecurity threats (and just as many dad jokes). Somehow, we're still talking about the same cybersecurity nightmares—only now with fancier threats and AI-powered scams. In this milestone episode of Help Me With HIPAA, we take a trip down memory lane—reminiscing about our early struggles, the evolution of security risks, and why some lessons seem to need repeating... forever. Spoiler alert: bad guys are still bad, security is still hard, and if you've been with us since episode one, you're officially a HMWH OG. If you're new here, welcome—just know that staying out of breaches is a marathon, not a sprint. More info at HelpMeWithHIPAA.com/500

Mar 14, 202544 min

Ep 499AI Tools Making AI Fools - Ep 499

Cybersecurity: It's like flossing—we all know we should do it, but a shocking number of people just…don't. This week, we're digging into the annual cybersecurity attitudes and behaviors report, which reveals just how careless people are with their passwords, personal info, and, well, basic online survival skills. But don't worry, AI is here to save us! Or, possibly, to make things even worse. We'll also explore how AI tools are being used (and misused), and why a scary number of people are feeding them sensitive work info like it's a buffet. Buckle up—this one's got some eye-opening stats! More info at HelpMeWithHIPAA.com/499

Mar 7, 202542 min

Ep 498Big Money Breaches & Bad Security Grades - Ep 498

Cybersecurity report cards are in, and let's just say—most companies would be grounded if their IT security grades were real school grades. With over 80% of Fortune 500s scoring a D or F, and healthcare companies hovering around the danger zone, it's clear that many organizations are securing data about as well as a cardboard vault. Just ask Warby Parker, which racked up multiple breaches over the years while seemingly skipping Cybersecurity 101. In this episode, we break down what these cybersecurity scores mean, how they were calculated, and what companies should be doing before they end up in the digital hall of shame. More info at HelpMeWithHIPAA.com/498

Feb 28, 202545 min

Ep 497DeepSeek, Deepfakes and AI's Big Game Moment - Ep 497

AI just leveled up, and we're here to talk about it! In this episode, we dive into DeepSeek—the AI model that shook up the stock market, gave OpenAI a run for its money (literally), and is both insanely cheap to run and totally open-source (which is equal parts exciting and terrifying). We also break down the rise of deepfake scams, AI's growing role in cybersecurity, and why you should probably question everything you see and hear online. If you love tech, security, and a healthy dose of paranoia, buckle up—this one's for you! More info at HelpMeWithHIPAA.com/497

Feb 21, 202540 min

Ep 496Healthcare Has A Kick Me Sign - Ep 496

Imagine leaving your front door wide open in a neighborhood full of burglars, then acting shocked when your TV disappears. That's basically what's happening in healthcare cybersecurity. This week, we're talking about why hackers are running rampant, how small healthcare practices are prime targets (no, you're not "too small to matter"), and what basic security steps can actually make a difference. Spoiler alert: Ignoring the problem won't make it go away. More info at HelpMeWithHIPAA.com/496

Feb 14, 202545 min

Ep 495Bare Minimum Isn't a Security Strategy - Ep 495

If you've ever wondered what it's like to scream into the cybersecurity void, this episode might feel oddly relatable. We dive into why "bare minimum" isn't a security strategy—it's more like playing Russian roulette with your data. From regulatory head-scratchers to the harsh reality that a "bare minimum" security strategy is about as effective as locking your front door while leaving the windows wide open, this episode is your wake-up call, packed with sharp insights, analogies involving go-karts on the interstate, and the occasional frustrated sigh. More info at HelpMeWithHIPAA.com/495

Feb 7, 202536 min

Ep 494From $10K to $3M: The Price Tag of Neglecting Cybersecurity - Ep 494

If ignoring cybersecurity was a sport, some companies would be gold medalists—until they realize the prize is a hefty fine and years of regulatory headaches. It's like leaving your car unlocked in a sketchy part of town with a neon sign that says, "Free Stuff Inside." What could possibly go wrong? Well, in this episode, we break down six real-life cases that prove skimping on security is way more expensive than just doing it right in the first place. From ransomware attacks to patient right of access failures, we're diving into what went wrong, why it happened, and—most importantly—how you can avoid becoming the next cautionary tale. More info at HelpMeWithHIPAA.com/494

Jan 31, 202540 min

Ep 493Cavity of Lies: Westend Dental's HIPAA Coverup - Ep 493

Buckle up, folks, because this week's episode is a wild ride through the Cavity of Lies—where HIPAA violations, ransomware attacks, and outright absurdity collide. What happens when a dental group tries to sweep a massive breach under the rug (or, you know, hide servers in bathrooms)? Let's just say it doesn't end well. From a 3-year-long cover-up to servers stored in all the wrong places, we've got lies under oath, policies that might as well be urban legends, and enough bad decisions to make you cringe harder than hearing the dentist say "we need to talk about your flossing habits." More info at HelpMeWithHIPAA.com/493

Jan 24, 202541 min

Ep 492HIPAA Security Changes Are Here: We Saw This Coming - Ep 492

Hold onto your compliance hats—big changes are brewing for HIPAA's Security Rule! The Notice of Proposed Rulemaking (NPRM) is officially out for public comment, and it's clear HHA and OCR are on a mission to modernize and tighten the safeguards for electronic protected health information (ePHI). From clarifying risk analysis expectations to making security requirements less, well, "vague," these updates aim to bolster patient safety and data protection while keeping pace with today's tech-driven world. But with great updates come great responsibilities for covered entities and business associates alike, so now's the perfect time to weigh in and help shape the final rule before it's set in stone. More info at HelpMeWithHIPAA.com/492

Jan 17, 202556 min

Ep 491PriSec Priorities Q1 2025 - Ep 491

Ready to kick off 2025 with a bang? We're diving into the must-dos for your Q1 2025 compliance and cybersecurity checklist, sprinkling in some risk management wisdom, and why Windows 10 is about as fashionable as shoulder pads in the 2020s. Plus, we sprinkle in a hearty dose of snark to keep you entertained while you get your compliance game strong. Oh and if your incident response plan is just "hope for the best," it's time to tune in. More info at HelpMeWithHIPAA.com/491

Jan 10, 202547 min

Ep 490Supply Chain Attacks: The Risks Keep Growing - Ep 490

Ah, supply chain attacks—the gift that keeps on giving... headaches, fines, and catastrophic data breaches. In this episode, we unwrap three cautionary tales of organizations caught in the tangled web of digital supply chain chaos. From unpatched vulnerabilities and sneaky software backdoors to hackers casually buying network access like it's an eBay auction, each story serves up a hard truth: you don't want to be part of a supply chain attack, you don't want to have a supply chain attack, and you definitely don't want to delay dealing with a supply chain attack. So grab your metaphorical flashlight and let's go spelunking into the murky caves of cybersecurity mishaps. More info at HelpMeWithHIPAA.com/490

Jan 3, 202550 min

Ep 489Phishing Fails, SRA Woes and the OCR Hammer - Ep 489

It's the final countdown, folks—the last episode of the year! And OCR decided to end 2024 with a bang, handing out settlements like candy at a Christmas parade. But here's the twist: the candy comes with a price tag, and it's not cheap. This episode hones in on OCR's new enforcement initiative targeting incomplete and outdated risk analyses. So, before you pop the champagne, let's make sure your SRA isn't a ticking compliance time bomb. More info at HelpMeWithHIPAA.com/489

Dec 27, 202451 min

2024 Holiday Blooper Show

Welcome to the 2024 Blooper Show, where we prove once again that even after nine years, perfection is overrated and laughter is mandatory! Big shoutout to Bojan, our long suffering audio engineer extraordinaire, who turns our chaos into coherence. And of course, we can't forget you—our amazing listeners—who tune in each week, send us your thoughts and questions, and share the chaos with your friends. Cheers to you for making this madness worth it! More info at HelpMeWithHIPAA.com/2024blooper

Dec 20, 202413 min

Ep 488Incident Panic to Plan for SMB Execs - Ep 488

Cybersecurity incidents can feel like a punch in the gut, but with the right plan, you can roll with the hits instead of flailing in panic. In this episode, we're diving into executive strategies for tackling the unexpected, from building response teams to keeping business operations afloat when chaos strikes. Along the way, we also cover a recent corrective action plan that serves as a cautionary tale for getting your protocols in order before trouble comes knocking. This is your go-to guide for staying cool when the heat is on! More info at HelpMeWithHIPAA.com/488

Dec 13, 202450 min

Ep 487Access Delayed, Ransom Paid, Cyber Aid Conveyed - Ep 487

Is your healthcare organization ready for a triple threat, or are you playing a risky game of cybersecurity roulette with delayed access, ransomware demands, and a missing incident response plan? Today, we explore three tales in healthcare that are equal parts cautionary and compelling. We kick things off with the Healthcare and Public Health Sector Coordinating Council's shiny new cyber incident response checklist—aka your cheat sheet for keeping calm in the face of chaos. Then, we give you the juicy details of a hefty civil money penalty slapped on a healthcare entity for dragging their feet on providing patient records (spoiler alert: patience isn't a virtue when it comes to HIPAA). Finally, we unravel the saga of a ransomware attack that not only encrypted data but also emptied some wallets. Whether you're here to learn, laugh, or just feel better about your own compliance game, this episode's got you covered. Buckle up, because the HIPAA ride is wild! More info at HelpMeWithHIPAA.com/487

Dec 6, 202454 min

Ep 486Thankful It Is Not Me - Ep 486

Feeling thankful this season? Us too—especially when it comes to dodging data disasters! In this episode, Donna and David dive headfirst into some eyebrow-raising cybersecurity tales, from job application breaches exposing sensitive information to the ever-creepy risks of unsecured IoT devices (yes, even your vacuum might be plotting against you). Whether it's researchers discovering unsecured data files or hackers turning robot vacuums into racially inappropriate terrors, we're reminded to never take our digital safety for granted. Grab your popcorn (or an encrypted snack, if that's a thing) and join us as we talk about what it means to truly be grateful for solid security practices this year. More info at HelpMeWithHIPAA.com/486

Nov 29, 202438 min

Ep 485First SRA Violation Settlement - Ep 485

Doing a half-baked risk analysis is like locking your front door but leaving all the windows wide open. What's the point? Today, we dive into the first-ever Security Risk Assessment (SRA) violation settlement—a juicy topic for compliance nerds and healthcare pros alike. We're talking ransomware, compliance checklists (the kind you actually need), and why a "kinda-sorta risk analysis" isn't going to cut it with the OCR. Along the way, we'll break down the $90K fine, the three-year corrective action plan, and what this means for everyone still winging their HIPAA risk assessments. Time to up your game folks! More info at HelpMeWithHIPAA.com/485

Nov 22, 202445 min

Ep 484OCR NIST Part 2 - Ep 484

Buckle up for Part 2 of our breakdown on the HHS OCR NIST healthcare security conference - because, yes, 16 hours of deep dives into AI, HIPAA compliance, and cybersecurity priorities can't be tackled in just one episode! From wild projections about AI's future in healthcare to OCR's "tough love" on compliance standards, this episode peels back the curtain on the big decisions shaping healthcare data security. It's a whirlwind tour through risks, regulations, and the occasional debate on why "just doing it the old way" won't cut it anymore. Let's get into it! More info at HelpMeWithHIPAA.com/484

Nov 15, 20241h 1m

Ep 483OCR NIST Conference Part 1 - Ep 483

Buckle up, folks! Today, Donna and David are here with Part 1 of their deep dive into the recent HHS OCR NIST healthcare security virtual conference, and they're spilling all the cyber-tea. With experts from HHS, OCR, NIST, FTC, and FDA presenting, this conference covered a ton. From AI-powered hackers and QR code scams to unpatched medical devices and a spike in supply chain attacks, the discussions centered on what it takes to keep healthcare data and devices secure in a constantly evolving threat landscape. Wondering why healthcare data security feels like a game of whack-a-mole? Tune in to find out! More info at HelpMeWithHIPAA.com/483

Nov 8, 202457 min

Ep 482Sell Me This Pen - Ep 482

Ever heard someone say you need a pen test but then start wondering if they meant a pen from a spy movie? There typically is a lot of confusion between penetration testing and vulnerability assessments—a common mix-up with big consequences for your cybersecurity game. We will walk through different types of pen tests, explain how they help you spot weaknesses before the bad guys do and tackle why continuous vulnerability management can save you from surprises. Whether you're building up your defenses or simply trying to keep up with best practices, this episode is packed with insights on staying ahead of cyber threats, one test at a time. More info at HelpMeWithHIPAA.com/482

Nov 1, 202453 min