Managing your vendors, or your supply chain, has become increasingly more important these days. As we’ve seen in the news just in the last several months, data and system breaches can come as a result of the vendors you work with. So, we felt like it was time to revisit this topic by reviewing the recent update to the HIC SCRiM guide that includes 6 steps for vendor management. More info at HelpMeWithHIPAA.com/317
Aug 13, 2021•41 min•Ep. 317
Every year we cover the most recent report released on the cost of a data breach. No surprise from this year’s report that the cost continues to rise. And healthcare breaches cost the most across all industries. Listen in as we go through IBM’s Cost of Data Breach Report 2021. More info at HelpMeWithHIPAA.com/316
Aug 06, 2021•37 min•Ep. 316
There’s a new data breach notification bill in Congress that will affect the business community as a whole, not just healthcare. It will create a new data breach disclosure requirement for federal agencies, federal contractors and critical infrastructure companies. It’s time to let folks know when breaches happen. We can’t protect ourselves from things we don’t know about. More info at HelpMeWithHIPAA.com/315
Jul 30, 2021•48 min•Ep. 315
There is so much happening in the cyber world today that we couldn’t decide on just one topic to cover in this episode. So, we will be jumping around and covering a lot of different cyber topics, hence the title of the podcast, Cyber Sqwerl. So, listen fast folks… we’ve got a lot to cover. More info at HelpMeWithHIPAA.com/314
Jul 23, 2021•41 min•Ep. 314
Summertime, holidays and long weekends, where many of us are taking time off, are prime times for cyber attacks. The bad guys are counting on people being in a hurry and letting their guard down so it’ll make it easier to suck you into their attack. July 4th 2021 was no different. An MSP was attacked by cyber criminals. Although this is still an active incident, we will cover what we know in today’s podcast. More info at HelpMeWithHIPAA.com/313...
Jul 16, 2021•49 min•Ep. 313
Offshore services are a popular option for many businesses. The ability to work around the clock from different sides of the planet is one thing but the cost savings are the primary driving force for this solution. When it comes to HIPAA Business Associates, though, there are a lot of variables that must be considered when deciding whether to offshore or not. More at HelpMeWithHIPAA.com/312
Jul 09, 2021•40 min•Ep. 312
Securing your business is not always the easiest thing to do nor the cheapest. Today we will review a Cisco study on small and medium sized businesses and their security best bets. In other words, the things that you can do that will help you to most likely attain success and get you the most bang for your buck. More info at HelpMeWithHIPAA.com/311
Jul 02, 2021•47 min•Ep. 311
The Department of Labor (DOL) Employee Benefits Security Administration (EBSA) issued its very first cybersecurity guidance in April 2021and they sound remarkably like all the things that we recommend doing under HIPAA, HICP and the NIST cybersecurity framework. Let’s check it out! More info at HelpMeWithHIPAA.com/310
Jun 25, 2021•1 hr 5 min•Ep. 310
They say ignorance is bliss. Ignorance can also leave you vulnerable to cyber attacks and patient safety issues. As we see news about cyber attacks coming from everywhere, you might ask “Is it really that bad?” Yes, yes it is. And it continues to get worse. More info at HelpMeWithHIPAA.com/309
Jun 18, 2021•59 min•Ep. 309
Privacy and security should be a part of all organizations day-to-day activity and company culture. But how do you know how mature your privacy and security program really is? By using one of the many maturity models. Today, we are discussing the new DoD Cybersecurity Maturity Model Certification (CMMC) that breaks controls into levels so you can see what implementation level or maturity level your program is at any given moment. More info at HelpMeWithHIPAA.com/308...
Jun 11, 2021•54 min•Ep. 308
It’s been a while since we’ve reviewed an OCR settlement that wasn’t about the patient right of access initiative. Things are a changin', and in more ways than one. OCR announced the Peachstate settlement just this week that got our attention. How this case ended up being investigated in the first place is interesting. And as usual, the headline doesn’t tell the whole story. So, let’s dive in and check it out. More info at HelpMeWithHIPAA.com/307...
Jun 04, 2021•53 min•Ep. 307
One of the biggest security problems on the Internet is a ransomware attack. Ransomware can impact all our lives. Just take the Scripps Health and Colonial Pipeline ransomware attacks that we discussed in recent podcast episodes. Last week we gave you 6 tips for planning for a ransomware attack. And today we are going to discuss 6 points from the recently released cybersecurity Executive Order. More info at HelpMeWithHIPAA.com/306
May 28, 2021•57 min•Ep. 306
Ransomware is just not going away. Falling victim to a ransomware attack will have a BIG impact on you, your business, your clients and your patients. So, today we share some ransomware planning tips. It’s important to know what things you should be doing and should at least consider so that you don’t get caught with your proverbial “pants down.” More info at HelpMeWithHIPAA.com/305
May 21, 2021•55 min•Ep. 305
We’ve talked about how damaging a ransomware attack can be in healthcare, not only for the practice or health facility but also for patients and the integrity and availability of their data. Today, we discuss an active ransomware attack affecting a health system that is not just making the local news, but also is blowing up on social media and creating a number of privacy concerns. The implications for their patients is terrifying. More info at HelpMeWithHIPAA.com/304...
May 14, 2021•58 min•Ep. 304
We’ve all seen the websites of companies that claim to have a “HIPAA compliant” app, product or service. But does that really mean anything? The short answer is NO! There is no such thing. Today, we answer a listener question about products and services with these types of claims. And, as you can imagine, we have a lot to say about this topic. More info at HelpMeWithHIPAA.com/303
May 07, 2021•46 min•Ep. 303
We talk about patching pretty frequently on the podcast, but there is still a misconception that your IT or MSP team is patching everything. Systems are not designed to patch all hardware and software all of the time. There is a level of responsibility that falls on us to understand what is being patched by IT, what isn’t and what we do about those unpatched applications. More info at HelpMeWithHIPAA.com/302
Apr 30, 2021•40 min•Ep. 302
Basic Cyber Hygiene is a fairly new term, but I realized we have mentioned it several times over the last few weeks. What do we really intend people to see when we talk about it? That may be helpful if we think it would solve most of our cyber attack problems, huh. More info at HelpMeWithHIPAA.com/301
Apr 23, 2021•50 min•Ep. 301
Hard to believe that this is our official 300th episode! We are still a tiny podcast in a huge sea but we are pretty sure you can not find a longer running podcast about HIPAA Privacy and Security. To celebrate we have some very special guests, Dave Bittner and Ben Yellen from the CyberWire Caveat podcast. They are joining us for a discussion about where we all see things going in the future for data privacy laws and cybersecurity protections. More info at HelpMeWithHIPAA.com/300...
Apr 16, 2021•59 min•Ep. 300
Each year the National HIPAA Summit 2021 is a regular event for us. It was held last year just before the shutdown. The event this year was loaded with discussions about what had happened in the previous 12 months and the massive list of things happening in the next 12 months. That is A LOT of HIPAA! Today we cover part 2 of news of note from the conference. More at HelpMeWithHIPAA.com/299
Apr 09, 2021•55 min•Ep. 299
If you are a regular listener of the podcast, you know how Donna loves to “HIPAA-geek out” over the HIPAA Summit each year. Things are no different this year as the virtual conference stretched 3 full days and another half day. Needless to say Donna got TONS of information to share - so much so we won’t be able to fit it all in this one podcast. So, let’s get to Part 1 of the HIPAA Summit 2021. More info at HelpMeWithHIPAA.com/298
Apr 02, 2021•1 hr 5 min•Ep. 298
Cyber attacks keep on coming and there is no expectation that they’ll ever stop. Attacks are coming from everywhere - vulnerabilities in software applications, insecure IoT devices connected on the internet, email attacks and phishing, etc. Protecting your systems from cyber attacks is not a “one and done,” “set it and forget it” project. It is a critical and continuous business process that every organization must address. And, surprise surprise, it also requires vetting your vendors as many at...
Mar 26, 2021•52 min•Ep. 297
Reports are coming out evaluating cyber threats with stats and details documenting the aftermath of attacks happening in 2020 and the outlook for 2021. Let’s just say they are all on brand with what you expect from anything related to 2020. As you can guess, it isn’t looking good for 2021 based on where we are right now. We reviewed some of the articles and reports evaluating cyber threats so you don’t have to... unless you must. More at HelpMeWithHIPAA.com/296...
Mar 19, 2021•1 hr•Ep. 296
Isn’t it always the little things that make a big difference? That’s true not only in life, but also when it comes to protecting your data and network from attacks. And, it is often the small things that when overlooked can become a big problem. So, today we are talking about some of the things that you need to be looking for and that can make a big difference in your privacy and security programs. For more info HelpMeWithHIPAA.com/295...
Mar 12, 2021•45 min•Ep. 295
Supply chain cyber threats are happening so often it seems like they keep showing up in the news daily. The list of cases keeps growing every month. So much is still slowly being learned about the SolarWinds attack it is getting hard to keep up with how far it goes. Now we have water systems and more healthcare breaches trickling in. This week I even saw a case we covered before about exposed PACS images. It’s time for us to talk about what these supply chain attacks mean to the rest of us. For ...
Mar 05, 2021•46 min•Ep. 294
Supply chain cyber threats are happening so often they keep showing up in the news. The list keeps growing every month. So much is still slowly being learned about the SolarWinds attack it is getting hard to keep up. Now we have water systems and more healthcare breaches trickling in. It’s time for us to talk about what these supply chain attacks mean to the rest of us. More at HelpMeWithHIPAA.com/293
Feb 26, 2021•1 hr 1 min•Ep. 293
Smart cyber habits are part of a new initiative introduced by CISA they have titled Reduce the Risk of Ransomware Awareness Campaign that will be running for a new month now. The campaign includes a lot of great educational information and a toolkit among other things they have planned. Certainly worth us sharing with you guys because you can’t have too many chances to find something that will connect with leadership or your workforce. More at HelpMeWithHIPAA.com/292...
Feb 19, 2021•44 min•Ep. 292
HHS's Office for Civil Rights published their proposed changes to the HIPAA Privacy Rule. The changes include some required to make HIPAA better align with the requirements of 21st Century Cures Act for patient access to their records. There's a few other changes to note, as well. Let's check them out, shall we? More into at HelpMeWithHIPAA.com/291
Feb 12, 2021•54 min•Ep. 291
During NCSAM Kardon signed up for the Terranova Phishing Tournament - much to everyone’s surprise. Great news is we didn’t have anyone clicking on the link. What did they learn in the tournament? More at HelpMeWithHIPAA.com/290
Feb 05, 2021•58 min•Ep. 290
The OCR enforcement announcements keep coming. Our reviews of not only the new announcements but news on some of the older ones are the topic for today. Did you know one from 2018 is still being reviewed in the courts while we get new ones already in 2021? More at HelpMeWithHIPAA.com/289
Jan 29, 2021•46 min•Ep. 289
Always great to talk cybersecurity insurance coverage with John Miller of Sterling Seacrest Partners. Threats are constantly evolving for all of us. That means cyber liability coverage must also evolve. Have you evaluated what your cyber policy will really cover when you are attacked? There are certainly several areas John brings up for us all to consider in our cybersecurity policies. More info at HelpMeWithHIPAA.com/288
Jan 22, 2021•1 hr 2 min•Ep. 288