
Help Me With HIPAA
597 episodes — Page 5 of 12
Ep 3833 Reasons To Be Thankful - Ep 383
As we celebrate Thanksgiving, we thought it would be a good idea to cover three reasons why you should be thankful. Or better yet, three situations you should be thankful that you're not caught up in…. unless, unfortunately, you are. More info at HelpMeWithHIPAA.com/383
Ep 382Cybersecurity Is Patient Safety - Ep 382
The healthcare industry is not immune to cyberattacks. In fact, it's one of the most vulnerable industries. To protect patient safety and data security, hospitals and healthcare providers need to implement better cybersecurity measures. Today, we review a paper from the office of Senator Mark Warner (VA) that discusses policy options for the healthcare sector. More info at HelpMeWithHIPAA.com/382
Ep 3819 Incident Response Procedures - Ep 381
What is your Incident Response Plan? If you said "Oh, we'll just call IT," then you need to listen to this podcast. We will review the October 2022 OCR Newsletter that discusses nine procedures that entities should consider including in the incident procedures. More info at HelpMeWithHIPAA.com/381
Ep 380One Click That's All - Ep 380
Keeping up on ways to protect your business from a cyber attack can feel intimidating, especially because of the continuously changing methods criminals use to social engineer us. The bottom line is it only takes one click at any time by anyone to open the door to the attackers. More info at HelpMeWithHIPAA.com/380
Ep 379Decisions Coming Back to Haunt You - Ep 379
As you know, each year we record a Halloween episode. This year we are covering very scary decisions that have come back to haunt several organizations, including an organization's decision not to report a cyber attack, an entity that thought they'd just stroke a check for fines assessed and everything would be OK, and a provider who posted PHI on social media. Listen in and learn what NOT to do. More info at HelpMeWithHIPAA.com/379
Ep 3783 Vetting Tips Before You Download That App - Ep 378
Do you remember the saying "there's an app for that"? Apps certainly are cool and convenient, but can you tell whether they are malicious or not? Today, we discuss and give you some vetting tips you can use before you download apps. More info at HelpMeWithHIPAA.com/378
Ep 377Are Connected Devices Secure? - Ep 377
More and more the healthcare industry is using connected medical devices that do cool things, like creating efficiencies in the delivery of patient care and automating tasks for healthcare providers and their staff. But, what about the security of these connected devices? Has anyone thought about that? Well, Ponemon and Cynerio did a study on just that topic and the results are very concerning. More info at HelpMeWithHIPAA.com/377
Ep 3763 Dental Offices Learn About OCR - Ep 376
OCR's right of access initiative keeps on churning with three more cases, making a total of 41 violations of patient right of access so far. Dentists are a known problem when it comes to doing anything for HIPAA privacy and security, including right of access requirements. But, they are quickly learning all about OCR enforcements of HIPAA violations. More info at HelpMeWithHIPAA.com/376
Ep 375Cost of a Data Breach 2022 - Ep 375
Every year we review the Ponemon Institute's Cost of a Data Breach report. It's always interesting because we learn that it's not just about the money. We learn what really makes a difference in our privacy and security program, what we can do that can make the biggest positive impact in the overall cost or a data breach and, more importantly, what things make the biggest negative impact. More info at HelpMeWithHIPAA.com/375
Ep 3745 Signs Your Org Is At Risk - Ep 374
We follow a lot of the Ponemon studies. They help us see changes and trends and make better recommendations to our clients. We are going to cover their annual cost of an insider breach study. This global study covers insider incidents and provides five signs your organization is at risk. More info at HelpMeWithHIPAA.com/374
Ep 373New Goal: Cyber Resilience - Ep 373
The ongoing, rapidly changing cyber war has created a need for us to change our viewpoint on cybersecurity. Yes, we need to worry about cyber hygiene and continue working on ways to secure our systems, networks and data. However, there is also a need to take the "plan for the worst but hope for the best" approach and start focusing on cyber resilience. More info at HelpMeWithHIPAA.com/373
Ep 372Trashy Privacy Violations - Ep 372
David admits that as a kid he would dumpster dive for "treasures" people threw away. We've heard more than once of clients who have gone dumpster diving to retrieve documents containing PHI that were mistakenly thrown away in the regular trash. But, a recent OCR announcement highlights one dermatology group that had quite the trashy privacy violation. More info at HelpMeWithHIPAA.com/372
Ep 371Should You Be Trusted? - Ep 371
Should we be questioning other people and vendors we work with about the trust we should have in them? The answer is yes. Are they protecting and securing the patient data we entrust them with? Trust, but verify is something we talk about a lot. So, I ask you… should you be trusted? And can you prove it? More info at HelpMeWithHIPAA.com/371
Ep 370Privacy Assessments - Ep 370
Privacy laws are being passed in more and more states every year. Even non-healthcare businesses are finding they must follow privacy laws in the states they do business in. Conducting a privacy assessment is a great way to understand what data you have that needs protecting, what things can go wrong and then, of those things that can go wrong, which ones we can try to prevent. More info at HelpMeWithHIPAA.com/370
Ep 369Amazon, Facebook, and PHI oh my! - Ep 369
In order to protect PHI, you have to know where it is stored and how it comes in, goes out and moves around your organization. This includes marketing analytic tools used on websites and patient portals. They could be transmitting PHI to social media platforms. Very unnerving, right? More info at HelpMeWithHIPAA.com/369
Ep 368Free Training Tools 2022 - Ep 368
It's that time again folks! October is Cybersecurity Awareness Month. This year's theme is "It's easy to stay safe online" with a weekly focus on key behaviors to help protect your important data. Using these free training tools and practicing basic cybersecurity behaviors, you are much more likely to stay safe online. More info at HelpMeWithHIPAA.com/368
Ep 367New Security Rule Guide Coming - Ep 367
An updated version of the security rule guide that we've all been waiting for! NIST has developed a cybersecurity resource guide on implementing the HIPAA Security Rule. It provides key activities, descriptions and sample questions to help covered entities and business associates comply with the HIPAA Security Rule. This guide has tons of good information in it. So, listen in as we discuss some of the cool stuff we picked out. More info at HelpMeWithHIPAA.com/367
Ep 366OCR Mic Drops With 12 Cases - Ep 366
OCR recently announced the resolution of 12 investigations. Eleven were for patient right of access violations and one was a big dollar settlement of a security incident at Oklahoma State University Center for Health Services. Lots to cover and learn in this episode. So, pay attention, folks. More info at HelpMeWithHIPAA.com/366
Ep 365660 Providers Hit At Once - Ep 365
Today's podcast episode is all about why we worry about supply chain issues, why we keep talking about the HiC SCRiM guidance, and why the first day of the PriSec Boot Camp is supply chain risk management. We'll review several supply chain breaches, one where there were 660 providers hit at once. As you probably have guessed, these breaches involved ransomware attacks. More info at HelpMeWithHIPAA.com/365
Ep 3646 Vendor Transition Tips - Ep 364
It can be a stressful time when you are adding a new vendor or switching vendors for your critical services. This is the time to create a plan and do a risk analysis to make sure everything gets transitioned and set up properly. Things can go wrong if there's no plan in place. Today, we review some tips to help you prepare for a vendor transition. More info at HelpMeWithHIPAA.com/364
Ep 363Cyber Insurance Applications Are Intense - Ep 363
When you're shopping for cybersecurity insurance, the applications can be intense. You'll need to provide a lot of details about your current security protections, and you may be asked to complete a security audit. This is because insurance companies want to be sure that they're not insuring businesses that aren't doing everything they can to protect themselves from cyber attacks. This episode we discuss what questions you may encounter on your cyber insurance applications.
Ep 3624 Ransomware Stats For Planning - Ep 362
Ransomware tactics are constantly changing. Understanding the protections we use today will not be enough down the road is key. We must constantly adjust and adapt our security protections to protect against these attacks. Today, we are going to discuss ransomware stats and key points from two recent reports that can help you create a response plan for ransomware attacks. More info at HelpMeWithHIPAA.com/362
Ep 361No More Passwords FIDO - Ep 361
We use passwords for everything. Creating a unique, secure password for every website and application is hard to remember, right? So, why hasn't someone figured out how to get rid of passwords? Well, today we are going to talk about the FIDO password killer solution. More info at HelpMeWithHIPAA.com/361
Ep 360What Would You Do? - Ep 360
How many of us know what we don't know, or at least, willing to admit we don't know what we don't know? Today, we are going to find out as we cover a few potential data breach scenarios and ask "what would you do - report it or not?" More info at HelpMeWithHIPAA.com/360
Ep 3596 Takeaways 2022 Verizon DBIR - Ep 359
Today, we are going to give you our six takeaways from the 15th annual Verizon Data Breach Investigation Report. We like these reports because they give us an indication of what's going on in the cyber world, what we need to be looking for and looking out for. More info at HelpMeWithHIPAA.com/359
Ep 358How Do They Get In? - Ep 358
We get this question all of the time: How do they get in? How do the bad guys get in and attack my network? Seems like a simple question, right? Well there's not always a clear cut answer. The first thing you need to understand is that cybersecurity isn't a problem you solve. It's a chronic condition that you have to manage. More info at HelpMeWithHIPAA.com/358
Ep 357MSP Customer Alert - Ep 357
Recently, a Cybersecurity Advisory was released worldwide to MSPs and their customers. We will take a look into what this guidance is, how it applies, and what needs to be done about it. This is BIG and we all better be paying attention. More info at HelpMeWithHIPAA.com/357
Ep 356Everybody get on board! - Ep 356
Everybody get on board because data security laws keep getting signed in states each year. The new Maryland and Kentucky data security laws are designed to help protect insurance companies from cyber attacks by implementing cybersecurity standards, developing, implementing, and maintaining a written information security program. Their service providers are also required to implement such programs which include a requirement to report cyber security incidents within 3 days of discovery. For more details go to HelpMeWithHIPAA.com/356
Ep 35510 Roles of Operational Continuity - Ep 355
Incident response planning is important to every business. You don't want to figure out how to manage the business and respond to an incident on the fly. These plans should be reviewed and updated regularly. Today we review a brand new guide from the Healthcare & Public Health Sector Coordinating Council on Operational Continuity - Cyber Incident. More info at HelpMeWithHIPAA.com/355
Ep 354PriSec Teams Require Everyone - Ep 354
Over the last couple years, we've had some high-profile cybersecurity compromises and data breaches. And this trend is not slowing down. Today, we review a recent study of the top cyber threats to healthcare organizations. The results reinforce that PriSec teams require everyone to participate. More info at HelpMeWithHIPAA.com/354
Ep 3533 Tricky Places HIPAA Applied - Ep 353
Recently, we've had a couple things come up which involved tricky places that HIPAA has applied that most people might not think of. So, we thought we'd throw them out there and have a little bit of fun discussing them. More info at HelpMeWithHIPAA.com/353
Ep 3526 Ways To Make Money Online - Ep 352
Cybercrime is a booming business. In 2021, the US experienced an unprecedented increase in cyber attacks with criminals making $6.9 billion online. In today's podcast, we review the FBI's Internet Crime Report for 2021. More info at HelpMeWithHIPAA.com/352
Ep 3514 Takeaways from Okta Breach? - Ep 351
It is crucial for every business to understand the security practices of their vendors. And also to make sure that those vendors are vetting their vendors. A cyber attack at a link in your supply chain can drastically affect your business. Evidence: the Okta breach. More info at HelpMeWithHIPAA.com/351

Ep 3504 OCR Cases For Us - Ep 350
Have you heard the one about three dentists and a psychiatrist walk into... an OCR investigation? OCR has announced their first set of enforcement actions of 2022, and just in time for our 350th episode. These involve patient right of access and improper disclosure violations. More info at HelpMeWithHIPAA.com/350
Ep 3496 Points from HIPAA Summit - Ep 349
Donna made many notes from the HIPAA Summit. Today, she and David will share six of her top picks, including the difference between an incident and a breach, how a "check the box compliance program" is not a privacy and security program, importance of understanding what your vendor's incident response plans are and more. More info at HelpMeWithHIPAA.com/349
Ep 3483 HIPAA Enforcement Arms - Ep 348
If you are a regular listener of the podcast, you know how Donna loves to "HIPAA-geek out" over the National HIPAA Summit each year. This year's National HIPAA Summit did not disappoint. Today, we discuss a few points made concerning enforcement of HIPAA related cases by three arms of the federal government. More info at HelpMeWithHIPAA.com/348
Ep 347One SMBs Cyber Survey - Ep 347
Cyber threats are a growing risk that is becoming increasingly difficult to avoid. Small and medium businesses are not immune to these cyber threats. They are a growing business risk. The first step in preventing cyber threats is awareness. More info at HelpMeWithHIPAA.com/347
Ep 3466 Impacts - 1 Event - Ep 346
Security events can have a significant impact on your business. It's important to understand the magnitude of what's going on and what the risks are. Having a plan in place to deal with privacy and security events can make it better, but not having one can make it worse. More info at HelpMeWithHIPAA.com/346
Ep 3453 Harsh Realities - Ep 345
The harsh realities of cybersecurity are not always easy to hear, but they are the one thing that we cannot compromise on as they can have a huge impact on our lives. We must remain cyber aware and be vigilant in order to combat cyber threats. More info at HelpMeWithHIPAA.com/345
Ep 344Help Me With PriSec - Ep 344
Kardon, Help Me With HIPAA and HIPAA for MSPs is hosting the first PriSec Boot Camp in Louisville, KY on Sep 12, 13, 14 and 15. This ain't yo Momma's privacy and security. It is a one of a kind event designed for those who need to understand and manage a privacy and security program. Listen to today's podcast to learn all about it. More info at HelpMeWithHIPAA.com/344
Ep 3433 Ways Encryption Fails - Ep 343
Encryption can give you a false sense of security. Just because your device or your data is encrypted doesn't mean it is secure. You have to understand how encryption works in order to understand how it doesn't work. More info at HelpMeWithHIPAA.com/343
Ep 342Why Does Website Security Matter? - Ep 342
Securing your website is often overlooked in planning discussions and business risk management decisions. Building a website is pretty easy these days, but keep in mind users expect to have a safe online experience too. Just like with social media sites, a lot can go wrong with a forgotten website. More info at HelpMeWithHIPAA.com/342
Ep 3414 Observations for SMBs and MSPs- Ep 341
More and more SMBs are turning to MSPs to help secure their networks, protect their assets from cyber attacks and meet compliance obligations. MSPs are looking to add new services to meet the SMB market demand. Today, we review a few of our observations for SMBs and MSPs from a recent report on the focus for small businesses in the next few years. More info at HelpMeWithHIPAA.com/341
Ep 340Honeypots Get Quick Attention - Ep 340
Honeypots are an important tool in the cybersecurity arsenal. They can be used to observe how attackers work and what their activities, intentions and strategies are. This information can help organizations better understand and defend against cyber attacks. More info at HelpMeWithHIPAA.com/340
Ep 3395 Steps For Securing Your Social Media - Ep 339
Social media has become a very important part of our lives. It is the easiest way to connect with friends, family and even promote your business. If not secured properly, it can also be an easy way for someone to hack into your account and become "you" or be the spokesperson for your business. More info at HelpMeWithHIPAA.com/339
Ep 3387 Ways To Screw Up Incident Response - Ep 338
A proper incident response plan is one that details your response to a data breach, cyber attack or other event. Without a proper plan, things can go horribly awry. In this episode, we discuss the steps to properly respond to a security incident and then give you seven ways you can completely screw it up. More info at HelpMeWithHIPAA.com/338
Ep 337Why You Need Asset Inventories - Ep 337
The unknown is the most dangerous. It's a saying that should be taken into account when protecting your most valuable asset - your data. Today we talk about why creating an asset inventory of your hardware, software and data is an important first step to being able to protect it. More info at HelpMeWithHIPAA.com/337
Ep 336Annual Predictions Review - Ep 336
A new year is right around the corner. The good news is 2021 wasn't as unpredictable as 2020, but 2022 could be tricky to navigate. It's time for the review of our 2021 predictions and for us to set new ones for 2022. So, let's get started. More info at HelpMeWithHIPAA.com/336
2021 Blooper Show
Well, another year is coming to a close. No one will forget living through 2020. Then, 2021 said "Hold my beer." As with every year, there were ups and downs. Who knows what we will be in for in 2022. Regardless, we will continue to adjust. Thanks to Bojan and our teams who help make this podcast a success. And special thanks to all our podcast listeners. We appreciate everyone's continued support of our efforts to educate and entertain. As we do at the end of each year, we let Bojan create a podcast of our bloopers and behind the scenes silliness. Enjoy his 2021 Blooper Show. It gives us a week off and gives him a chance to get back at us for the whole year of crap. More data privacy and security madness coming your way next year! Happy Holidays and Happy New Year to you all!
Ep 3355 More Patient's Rights Cases - Ep 335
OCR has released resolutions to five cases in its HIPAA Patient Right of Access Initiative. This brings the total cases to 25 since the initiative began. These cases continue to underscore the importance of this initiative. More info at HelpMeWithHIPAA.com/335