HIPAA policy and procedure templates seem to be a panacea to many people who are just trying to meet the standards and move on. However, these are not the droids you seek! Templates can be the basis for what you need to do but they shouldn't be the solution to the written policy and procedure requirements under HIPAA. See HelpMeWithHIPAA.com/57
Jun 10, 2016•33 min•Ep. 57
Two reasons for today's topic: A question we received from a listener about understanding antivirus software and a news report about a malware scan that interrupted a medical procedure. Between those two cases it felt like it was time to discuss malware protection under HIPAA. Suzie from Savannah: I would like to have a podcast or a quick answer to the different between anti-virus software releases and anti-virus definitions being up-to-date. I understand the AV definitions up to date but a litt...
Jun 03, 2016•47 min•Ep. 56
We always look at the security rule aspects of HIPAA because they deal with the easier parts for people to deal with when it comes to lowering their risk, but today we are diving into some privacy rule guidelines, because there is new HIPAA privacy guidance that has just been published. Get more info at HelpMeWithHIPAA.com/55
May 27, 2016•47 min•Ep. 55
Recently, we ended up in several discussions about HIPAA access logs and what they really require with our clients. As per usual, any topic that comes up multiple times in my “real job” becomes a discussion for HMWH. So, today we are talking about HIPAA access logs to attempt to clear up some confusion we have encountered. There are multiple types of HIPAA access logs being created in most environments and you should be dealing with pretty much all of them in some manner. Get more at HelpMeWithH...
May 20, 2016•38 min•Ep. 54
We talked about OCR audits recently because they are in the news. The audit protocol is a perfect guide for developing and maintaining your HIPAA compliance programs. In fact, the audits have been a hot topic in the industry this month. However, the fact that only 200 audits will take place really means the audit protocol is more important as a guide for what your program should look like in the event you have a breach or complaint investigation. Statistically, you are much more likely to need i...
May 13, 2016•42 min•Ep. 53
We really appreciate the support and feedback we have received for our little HIPAA podcast project known as Help Me With HIPAA. This episode marks one complete year of weekly HIPAA podcasts (counting the special bloopers holiday episode). We certainly learned a great deal since we started this little DIY project last year. Granted, David was a convert to the idea much quicker than Donna. Here we are one year later and our little HIPAA podcast is starting to gain some real momentum. That is all ...
May 06, 2016•50 min•Ep. 52
We often talk about doing the "work" of compliance. Some people seem to have the attitude that all I need to do some is annual staff training and hand out a Notice of Privacy Practices to do small office HIPAA compliance. When we try to explain there is more to it than that we often get pushback about the requirements. We always hear comments like: we don't have time, we don't have resources, we can't be expected to do this. So, how DO you do small office HIPAA compliance? Today we are going to ...
Apr 29, 2016•43 min•Ep. 51
Every website needs security. What questions should you be asking about your business websites and who should you be asking? Website security can be an open hole in your security plans. It can also be the source of lots of problems for your business if you don't pay attention to the site content or securing your message. More info on the website at helpmewithhipaa.com/50
Apr 22, 2016•38 min•Ep. 50
The recent release of the new OCR audit protocol gives us new guidance on what they expect from HIPAA compliance programs. There is a great deal of information to sift through if you are so inclined. To make it easier for you we are discussing some of the details and things we have learned from reviewing it for you! So, here is our review of the new OCR audit protocol! For more details go to our website article helpmewithhipaa.com/49...
Apr 15, 2016•46 min•Ep. 49
In the first episode in our Disaster Recovery series that we will be doing this year we are discussing planning disaster recovery plans for flooding. This episode is an interview with Ginger McCleish who experienced a real world disaster recovery flooding in the St. Louis, MO area in December 2015. Hear more at HelpMeWithHIPAA.com/48
Apr 08, 2016•36 min•Ep. 48
The latest HIPAA buzz is about things like Interoperability, Data Governance, Patient Access Rights, and, of course, OCR random audits. Donna attended HIMSS and the National HIPAA Summit recently. In this episode we discuss what kinds of things are happening in the industry relating to HIPAA. For more details visit our website at helpmewithhipaa.com/47
Apr 01, 2016•47 min•Ep. 47
So far in 2016, we have seen four HIPAA enforcement cases resolved by OCR. One involved only the second Civil Money Penalty ever assessed. The three others were resolution agreements. Add those cases to what was done in 2015 and you have the most active 12 month period of HIPAA enforcement ever. Certainly, the first quarter of 2016 has been the most active quarter ever when it comes to HIPAA enforcement announcements. In this episode we discuss the cases resolved so far in 2016 and more thoughts...
Mar 25, 2016•35 min•Ep. 46
Many times people ask: Why do we need HIPAA? Is HIPAA really necessary? The short answer is yes, we do need HIPAA and the reason is without it there is no baseline for protecting patient privacy. Learn more at http://helpmewithhipaa.com/45
Mar 18, 2016•39 min•Ep. 45
Social media can be the source of many issues if you don't have a clear policy for use. HIPAA social media policies requires some serious thought and commitment from your management staff. What things are good use of social media and what things should be avoided through policy enforcement? Read more about HIPAA Social Media Policies at our website: helpmewithhipaa.com/44
Mar 11, 2016•41 min•Ep. 44
It is clear that HIPAA disaster recovery and business continuity plans should include some level of ransomware response planning after the attack that shut down Hollywood Presbyterian Hospital. What kinds of issues should you expect and how can you mitigate the damage from a ransomware attack? Read more about our ransomware attack planning discussion on our website at helpmewithhipaa.com/43
Mar 04, 2016•44 min•Ep. 43
To be certain you are protecting the health information in your organization you must identify where it lives and moves about around the network and workforce. A risk analysis can't be done properly without making that list first. Where should you look for PHI? If you don't store it do you store access TO it? Get more information for this podcast at HelpMeWithHIPAA.com/42
Feb 26, 2016•34 min•Ep. 42
Trust but verify is the new standard when it comes to Business Associate relationships today. Yes, they must sign a BAA but you really need to ask some questions to confirm those BAs understand and are doing the things they have agreed to do for you. Covered Entities (CEs) haven't really worried about the details of the contracts too much as along as the vendors would sign them. Many vendors have signed, and continue to sign, BAAs without any concerns at all for what the contract actually says t...
Feb 19, 2016•47 min•Ep. 41
Get all the details at HelpMeWithHIPAA.com/40
Feb 12, 2016•36 min•Ep. 40
More notes and links on the website at HelpMeWithHIPAA.com/39
Feb 05, 2016•32 min•Ep. 39
More details on our website Also at the Atlanta's Most Trusted Advisors page :
Feb 03, 2016•46 min
Brittney Wilson, The Nerdy Nurse , joins us to discuss the clinical staff's HIPAA perspectives. More details at helpmewithhipaa.com/38
Jan 29, 2016•39 min•Ep. 38
More details at helpmewithhipaa.com/37
Jan 22, 2016•32 min•Ep. 37
HIPAA may show up in areas you haven't seen before. If you are assessed by any other organization or for any other reason, HIPAA questions may start showing up. We have heard about it being brought up in many areas: Insurance Policy Applications Partnership Negotiations Funding discussions URAC accredidation (formerly known as the Utilization Review Accreditation Commission) This episode is a discussion on why it is showing up in other places and why we expect that trend to continue. More detail...
Jan 15, 2016•32 min•Ep. 36
ID Experts is in the business of dealing with privacy breaches. They have a variety of incident response services and tools. We discuss breach topics with Jeremy Henley, Director of Breach Services, ID Experts in today's episode. Detailed notes from the show can be found on our website at helpmewithhipaa.com/35
Jan 08, 2016•43 min•Ep. 35
New Years Resolutions can be simple commitments to yourself and your compliance program effectiveness. When you have so many job responsibilities compliance often gets set to the side or "on the front left corner of my desk". These tiny changes can help you keep things moving forward without forcing you to spend a day or two a week. Detailed notes on the show can be found on our website at helpmewithhipaa.com/36
Jan 01, 2016•31 min•Ep. 34
Since this episodes is being released on a holiday for all of us at Help Me With HIPAA, we are sharing a special blooper episode our audio editor Bojan Sabioncello created specially for us. When you hear our recordings from his perspective, you will see what a great job he does making us sound so professional.
Dec 25, 2015•10 min•Ep. 33
Compliance officers need all kinds of help to get their jobs done. We came up with a list of ideas for gifts to help them out this holiday season. More details at helpmewithhipaa.com/32
Dec 18, 2015•33 min•Ep. 32
Enforcement of HIPAA is changing There are many indicators that make us believe that we will see a distinct uptick in OCR enforcement activity. The last two OIG reports say OCR isn't doing enough, the news points out issues with enforcement, and even Congress is getting in the mix. In this episode, we discuss why this makes us think you don't want to wait around to see IF OCR starts doing anything differently. More details at helpmewithhipaa.com/31
Dec 11, 2015•30 min•Ep. 31
The HIPAA legislation itself does not include the option for individual patients to sue any CE or BA that may violate their privacy protections included in the law. HITECH added the ability for the States Attorney General offices to file a cased on behalf of their constituents, however. The biggest change, however, is the ruling by several State Supreme Courts that allows a complaint to use HIPAA as a legal standard of care . That opens the door for all kinds of options. More details at helpmewi...
Dec 04, 2015•27 min•Ep. 30
Everyone is ready for the great deals retailers offer on Black Friday and Cyber Monday. We have a list of low-cost and no-cost deals on HIPAA Security & Privacy tools for you! Episode 29: HIPAA Black Friday Sale More details at helpmewithhipaa.com/29
Nov 27, 2015•38 min•Ep. 29