Help Me With HIPAA - podcast cover

Help Me With HIPAA

Donna Grindle and David Simshelpmewithhipaa.com
In today's environment of data breaches, identity theft, fraud, and increasing connectivity, HIPAA Privacy and Security rules are a responsibility to your patients and your clients. HIPAA isn't about compliance, it's about patient care.
Last refreshed:
Follow this podcast in the Metacast mobile app to refresh it and see new episodes.
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

Erik Decker HICP Discussion Part 2 - Ep 231

Today we share part 2 of our Erik Decker HICP discussion. Learn about more tools for small and medium organizations. The 405(d) Task Group has more work to do so learn ways you can help spread the word about using these tools to improve healthcare cybersecurity. We even ask how we can all help promote cybersecurity awareness and HICP to improve the healthcare cybersecurity. HelpMeWithHIPAA.com/231

Nov 22, 201947 minEp. 231

Talking HICP with Erik Decker Part 1 - Ep 230

We covered the release of HICP or Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients back in Feb in the episode we called 5 Threats and 10 Protection Practices – Ep 189 . HICP has now been out for a bit and the next phases of the project are in process. Today we discuss all things HICP with Erik Decker who is the Health Sector Coordinating Council Co-Lead of the 405(d) Task Group that developed this tool to help our sector follow solid cybersecurity practices. More...

Nov 15, 201952 minEp. 230

HIPAA Penalties Due To Disarray - Ep 229

HIPAA penalties are always discussed in training and presentations about HIPAA. Those discussions are usually more about an overview of what is in the law than actual information on how the law is applied. HIPAA penalties are really not seen often. Civil money penalties are not part of the settlements we usually see but OCR announced a big one in October . How do they really apply those huge numbers everyone talks about but we never see? More info at HelpMeWithHIPAA.com/229...

Nov 08, 201952 minEp. 229

HIPAA is the Floor - Ep 228

The annual conference hosted by NIST and OCR Safeguarding Health Information: Building Assurance through HIPAA Security and the repeated message on day one of the conference was “HIPAA is the floor” which started with OCR Dir Severino’s keynote. We always get information at some point that makes these conferences worth the time. What did we get from this one? More info at HelpMeWithHIPAA.com/228...

Nov 01, 201951 minEp. 228

Tales From The Dark Side Of HIPAA - Ep 227

As is our custom, each year we have a halloween-themed episode. This year we are thrilled to bring you several very real Tales From The Dark Side Of HIPAA. Thanks to our friend, Jack Rhysider from DarkNet Diaries for recording our haunting lead-in! More info at HelpMeWithHIPAA.com/227

Oct 25, 201954 minEp. 227

Social Media and PHI as Oil is to Water - Ep 226

Social media and PHI get the OCR spotlight in the latest settlement announced. Reading these settlement agreements provide the best guidance from OCR which is why we always take the time to get those details for you. How much have you considered about your social media policies and how your staff understands their responsibilities? More info at HelpMeWithHIPAA.com/226

Oct 18, 201957 minEp. 226

Bad luck breaches? - Ep 225

Is there such a thing as bad luck breaches? Most of us don’t expect luck to rule our world although I will always take good luck if I can get it. But when bad things happen sometimes we say it is due to a string of bad luck. Can data breaches be due to one of those strings of bad luck? For more info go to HelpMeWithHIPAA.com/225

Oct 11, 201939 minEp. 225

Patient Access Settlement - Ep 224

The first patient access settlement has been announced by OCR. Director Severino mentioned they would be putting an emphasis on this issue and we now have the first enforcement come through. What should you learn from this settlement? It included some interesting corrective action requirements. More HelpMeWithHIPAA.com/224

Oct 05, 201945 minEp. 224

End of Life for Windows 7 and 2008, Ready? - Ep 223

January 14, 2020 marks the end of life for Windows 7 and Windows 2008 operating systems. Have you done your SRA to make sure you have things covered? What about home computers, should you be worried about those? In this episode we review what this end of life for Windows OS means and what you should be doing in the 4th quarter of 2019 to prepare for it. More at HelpMeWithHIPAA.com/223

Sep 27, 201944 minEp. 223

6 Signs Of HIPAA Program Maturity - Ep 222

We always talk about the need for a culture of compliance or culture of privacy and security. Today we talk about 6 things you notice when you have built a culture of compliance. The 6 comes from 3 x 2 which means there is clearly no rhyme or reason for the selection today. More at HelpMeWithHIPAA.com/222

Sep 20, 201950 minEp. 222

Insider Breaches Everywhere - Ep 221

When working on a plan for this episode I had two different sources drop some insider breach issues in my lap. When I added those to the news stories we are already following involving insider issues, it was clear the topic was meant to be. Multiple cases and reports are out — the topic I must cover is because I am reading about insider breaches everywhere around me. More at HelpMeWithHIPAA.com/221

Sep 13, 201955 minEp. 221

National Cybersecurity Awareness Month Workforce Training - Ep 220

October is National Cybersecurity Awareness Month (NCSAM) and it is a perfect tool to feature security awareness with your workforce and clients. You can not beat an opportunity to run a month long awareness program that provides EVERYTHING you need for free. Today we discuss what the program includes and how to use it in your office. More at HelpMeWithHIPAA.com/220

Sep 06, 201956 minEp. 220

Six fifty is not required - Ep 219

We discussed the patient rights to access medical records a few episodes ago. Since then, a new study came out that says a majority of providers are not complying with patient medical records requests. I have also gotten more questions about law firms demanding to pay only $6.50 for medical records requests. We are discussing these issues with specifics about fees for patient requests in this episode. More at HelpMeWithHIPAA.com/219

Aug 30, 201952 minEp. 219

7 Questions To Ask IT - Ep 218

When you work with outsourced IT or Managed Service Providers (MSPs) you need to vet them closely to make sure they truly do understand what HIPAA requires from your organization. Here are seven questions to ask your IT team about HIPAA. For more info go to HelpMeWithHIPAA.com/218

Aug 23, 20191 hrEp. 218

Cost of a Data Breach 2019 Study - Ep 217

The Ponemon Institute has produced an annual study of data breach costs. This is the 14th year. We have used it as a guide for a lot of information over the years. The data has consistently been helpful for us to understand what are the key drivers in data breach costs, remediation, and response. If you can find what the major factors include, it is a great way to determine your priorities in investing resources with the biggest impact. Let’s see what we learned from the 2019 version sponsored b...

Aug 16, 201956 minEp. 217

Who is a Business Associate? - Ep 216

Who is a business associate? A listener asked for an episode on it. Turns out we haven't done one since episode 2. Wow! So, maybe there is more we have to add to that topic in 2019 after 214 other episodes. Today, let’s talk about how to determine who is your Business Associates or BA. More info at HelpMeWithHIPAA.com/216

Aug 09, 201953 minEp. 216

Listener Questions and Input - Ep 215

We have gotten a flurry of listener questions and comments lately. Since it is so much easier to do an episode based you listener questions that writing up a whole plan we are definitely doing those today. We really do read and respond to as many as we can. So here we go. More info at HelpMeWithHIPAA.com/215

Aug 02, 201952 minEp. 215

CCPA and HIPAA Require Consideration - Ep 214

If you haven’t heard of it before there is a thing called the California Consumer Privacy Act (CCPA) . It is considered the first version of a GDPR-type legislation on this side of the pond. It becomes effective Jan 1, 2020. There are many folks that think the CCPA isn’t something for them to worry about. Well... Maybe you should take a second to reconsider that position. More at HelpMeWithHIPAA.com/214...

Jul 26, 201944 minEp. 214

5 Medical Records Uses and Disclosures Rules - Ep 213

Today we discuss 5 medical record uses and disclosures rules that I have been covering recently in training. Medical records are always around for those of us in healthcare. It is so easy to forget that the rules apply to more than just data breaches and social media. There are some very basic concepts that people who have been dealing with medical records for years are surprised to learn. Here are five of them we use the most. More at

Jul 19, 201941 minEp. 213

Cybersecurity Tips and Trends - Ep 212

We need to keep up with our education just like everyone else to keep up with cybersecurity tips and trends. Donna hit some training at SecureWorld and sat in on a 6-hr online seminar offered by Dark Reading. All of that thinking and learning means we have cybersecurity tips and trends to share in this episode. This is not just for those who worry about HIPAA. More info at HelpMeWithHIPAA.com/212

Jul 12, 201953 minEp. 212

Consider ransom payments BEFORE attacks - Ep 211

The debate continues in ransomware attacks, do you make the ransom payment or not? Lately, we have seen many payments being announced. This should be in your incident response plan ransomware playbook. These decisions should be discussed now, not when an attack happens. What are the pros and cons to paying and what should be in your ransomware response plans? More info on Help Me With HIPAA blog post.

Jul 05, 201959 minEp. 211

False Claims Settlement - No Risk Analysis - Ep 210

False claims settlements over meaningful use money have popped into the news again. The provider was sued by whistleblowers and the DOJ for not doing a security risk analysis but attesting to one to get the meaningful use payments anyway. There is whistleblower's angle in this case which makes it even more interesting. If you know anyone that has received any meaningful use money they should check out this episode! More info at HelpMeWithHIPAA.com/210...

Jun 28, 201945 minEp. 210

Specific BA Liabilities - Ep 209

This new BA guidance from OCR is important because it defines clearly all the things we hear misstated over and over. Several of our Top 10 Wrong HIPAA Statements episode are addressed in the simple ten item list. Today we will discuss the announcement and what does that mean to BAs and their privacy and security programs. More info at HelpMeWithHIPAA.com/209...

Jun 21, 201957 minEp. 209

Vendor Pays $1 Million Plus 5 Yr Action Plans - Ep 208

The multi-state settlement with Medical Informatics Engineering makes the OCR settlement seem like a cake walk. The vendor agrees to pay OCR $100,000 with a standard 2-year corrective action plan. The states get $900,000 plus 5 years of very specific corrective action requirements. Vendors need to pay attention to this case and take appropriate action now. More info at HelpMeWithHIPAA.com/208

Jun 14, 201953 minEp. 208

How do you sanction? - Ep 207

Sanction policies are often vague or even overlooked in many privacy and security programs. The whole point of a sanction policy is to list out the consequences for failure to follow our policies and procedures. With a vague or non-existent policy consequences aren’t clear which leads to a lack of concern for failure to follow the policy in the first place. You will never build a culture that worries about protecting information without it being clear that is a requirement for inclusion in our c...

Jun 07, 201958 minEp. 207

Maturity Assessments - Ep 206

Maturity is something we expect from respected folks or grown folks but what about your privacy and security program, do you check it’s maturity? You have all of these plans, policies, procedures, and training but is it actually meeting your needs? Time to talk maturity assessments. More at HelpMeWithHIPAA.com/206

May 31, 201944 minEp. 206

No PHI exposed. Really? - Ep 205

The latest HIPAA violation settlement with OCR was announced recently. Ironically, the settlement with Touchstone Medical Imaging was for $3,000,000 and announced just after the reduction of maximum penalties was announced by HHS. Just how bad was this violation to get hit with this level of penalties plus the 2-year corrective action plan? More at HelpMeWithHIPAA.com/205

May 24, 201948 minEp. 205

HIPAA Penalties Dropping - Ep 204

Headlines everywhere are telling us all that the HIPAA penalties are being “slashed” or “capped” or “reduced”. What is the real story and what does it mean to the rest of us? Great time to talk about what you should consider if you think you will be facing any HIPAA penalties. More info at HelpMeWithHIPAA.com/204

May 17, 201951 minEp. 204

3 Supply Chain Security Stories - Ep 203

We have talked many times about vetting business associates. When people talk about supply chain security it isn’t just the business associate you contract with you have to worry about. It is all the vendors that they use. Today we are going to review 3 supply chain stories that explain how complex your supply chain unbeknownst to you. More at HelpMeWithHIPAA.com/203

May 10, 201951 minEp. 203

Smile You Are On Camera - Ep 202

We are all being watched. Cameras are everywhere today. With the advent of dashcams, home security camera systems, CCTV in cities and businesses we are caught on camera somewhere every day. What does that mean when you have privacy concerns to address like, I don’t know, HIPAA? More info HelpMeWithHIPAA.com/202

May 03, 201942 minEp. 202
Hosted on Libsyn
For the best experience, listen in Metacast app for iOS or Android