Help Me With HIPAA - podcast cover

Help Me With HIPAA

Donna Grindle and David Simshelpmewithhipaa.com
In today's environment of data breaches, identity theft, fraud, and increasing connectivity, HIPAA Privacy and Security rules are a responsibility to your patients and your clients. HIPAA isn't about compliance, it's about patient care.
Last refreshed:
Follow this podcast in the Metacast mobile app to refresh it and see new episodes.
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

3 Dental Offices Learn About OCR - Ep 376

OCR’s right of access initiative keeps on churning with three more cases, making a total of 41 violations of patient right of access so far. Dentists are a known problem when it comes to doing anything for HIPAA privacy and security, including right of access requirements. But, they are quickly learning all about OCR enforcements of HIPAA violations. More info at HelpMeWithHIPAA.com/376

Oct 07, 202248 minEp. 376

Cost of a Data Breach 2022 - Ep 375

Every year we review the Ponemon Institute’s Cost of a Data Breach report. It's always interesting because we learn that it's not just about the money. We learn what really makes a difference in our privacy and security program, what we can do that can make the biggest positive impact in the overall cost or a data breach and, more importantly, what things make the biggest negative impact. More info at HelpMeWithHIPAA.com/375

Sep 30, 202251 minEp. 375

5 Signs Your Org Is At Risk - Ep 374

We follow a lot of the Ponemon studies. They help us see changes and trends and make better recommendations to our clients. We are going to cover their annual cost of an insider breach study. This global study covers insider incidents and provides five signs your organization is at risk. More info at HelpMeWithHIPAA.com/374

Sep 23, 202247 minEp. 374

New Goal: Cyber Resilience - Ep 373

The ongoing, rapidly changing cyber war has created a need for us to change our viewpoint on cybersecurity. Yes, we need to worry about cyber hygiene and continue working on ways to secure our systems, networks and data. However, there is also a need to take the “plan for the worst but hope for the best” approach and start focusing on cyber resilience. More info at HelpMeWithHIPAA.com/373

Sep 16, 202256 minEp. 373

Trashy Privacy Violations - Ep 372

David admits that as a kid he would dumpster dive for “treasures” people threw away. We’ve heard more than once of clients who have gone dumpster diving to retrieve documents containing PHI that were mistakenly thrown away in the regular trash. But, a recent OCR announcement highlights one dermatology group that had quite the trashy privacy violation. More info at HelpMeWithHIPAA.com/372

Sep 09, 202241 minEp. 372

Should You Be Trusted? - Ep 371

Should we be questioning other people and vendors we work with about the trust we should have in them? The answer is yes. Are they protecting and securing the patient data we entrust them with? Trust, but verify is something we talk about a lot. So, I ask you… should you be trusted? And can you prove it? More info at HelpMeWithHIPAA.com/371

Sep 02, 202254 minEp. 371

Privacy Assessments - Ep 370

Privacy laws are being passed in more and more states every year. Even non-healthcare businesses are finding they must follow privacy laws in the states they do business in. Conducting a privacy assessment is a great way to understand what data you have that needs protecting, what things can go wrong and then, of those things that can go wrong, which ones we can try to prevent. More info at HelpMeWithHIPAA.com/370

Aug 26, 202246 minEp. 370

Amazon, Facebook, and PHI oh my! - Ep 369

In order to protect PHI, you have to know where it is stored and how it comes in, goes out and moves around your organization. This includes marketing analytic tools used on websites and patient portals. They could be transmitting PHI to social media platforms. Very unnerving, right? More info at HelpMeWithHIPAA.com/369

Aug 19, 202232 minEp. 369

Free Training Tools 2022 - Ep 368

It’s that time again folks! October is Cybersecurity Awareness Month. This year’s theme is “It’s easy to stay safe online” with a weekly focus on key behaviors to help protect your important data. Using these free training tools and practicing basic cybersecurity behaviors, you are much more likely to stay safe online. More info at HelpMeWithHIPAA.com/368

Aug 12, 202243 minEp. 368

New Security Rule Guide Coming - Ep 367

An updated version of the security rule guide that we’ve all been waiting for! NIST has developed a cybersecurity resource guide on implementing the HIPAA Security Rule. It provides key activities, descriptions and sample questions to help covered entities and business associates comply with the HIPAA Security Rule. This guide has tons of good information in it. So, listen in as we discuss some of the cool stuff we picked out. More info at HelpMeWithHIPAA.com/367...

Aug 05, 202243 minEp. 367

OCR Mic Drops With 12 Cases - Ep 366

OCR recently announced the resolution of 12 investigations. Eleven were for patient right of access violations and one was a big dollar settlement of a security incident at Oklahoma State University Center for Health Services. Lots to cover and learn in this episode. So, pay attention, folks. More info at HelpMeWithHIPAA.com/366

Jul 29, 20221 hrEp. 366

660 Providers Hit At Once - Ep 365

Today’s podcast episode is all about why we worry about supply chain issues, why we keep talking about the HiC SCRiM guidance, and why the first day of the PriSec Boot Camp is supply chain risk management. We’ll review several supply chain breaches, one where there were 660 providers hit at once. As you probably have guessed, these breaches involved ransomware attacks. More info at HelpMeWithHIPAA.com/365...

Jul 22, 202251 minEp. 365

6 Vendor Transition Tips - Ep 364

It can be a stressful time when you are adding a new vendor or switching vendors for your critical services. This is the time to create a plan and do a risk analysis to make sure everything gets transitioned and set up properly. Things can go wrong if there’s no plan in place. Today, we review some tips to help you prepare for a vendor transition. More info at HelpMeWithHIPAA.com/364

Jul 15, 202246 minEp. 364

Cyber Insurance Applications Are Intense - Ep 363

When you're shopping for cybersecurity insurance, the applications can be intense. You'll need to provide a lot of details about your current security protections, and you may be asked to complete a security audit. This is because insurance companies want to be sure that they're not insuring businesses that aren't doing everything they can to protect themselves from cyber attacks. This episode we discuss what questions you may encounter on your cyber insurance applications.

Jul 08, 202254 minEp. 363

4 Ransomware Stats For Planning - Ep 362

Ransomware tactics are constantly changing. Understanding the protections we use today will not be enough down the road is key. We must constantly adjust and adapt our security protections to protect against these attacks. Today, we are going to discuss ransomware stats and key points from two recent reports that can help you create a response plan for ransomware attacks. More info at HelpMeWithHIPAA.com/362

Jul 01, 202239 minEp. 362

No More Passwords FIDO - Ep 361

We use passwords for everything. Creating a unique, secure password for every website and application is hard to remember, right? So, why hasn’t someone figured out how to get rid of passwords? Well, today we are going to talk about the FIDO password killer solution. More info at HelpMeWithHIPAA.com/361

Jun 24, 202250 minEp. 361

What Would You Do? - Ep 360

How many of us know what we don’t know, or at least, willing to admit we don't know what we don't know? Today, we are going to find out as we cover a few potential data breach scenarios and ask “what would you do - report it or not?” More info at HelpMeWithHIPAA.com/360

Jun 17, 202248 minEp. 360

6 Takeaways 2022 Verizon DBIR - Ep 359

Today, we are going to give you our six takeaways from the 15th annual Verizon Data Breach Investigation Report. We like these reports because they give us an indication of what's going on in the cyber world, what we need to be looking for and looking out for. More info at HelpMeWithHIPAA.com/359

Jun 10, 202253 minEp. 359

How Do They Get In? - Ep 358

We get this question all of the time: How do they get in? How do the bad guys get in and attack my network? Seems like a simple question, right? Well there’s not always a clear cut answer. The first thing you need to understand is that cybersecurity isn't a problem you solve. It's a chronic condition that you have to manage. More info at HelpMeWithHIPAA.com/358

Jun 03, 202249 minEp. 358

MSP Customer Alert - Ep 357

Recently, a Cybersecurity Advisory was released worldwide to MSPs and their customers. We will take a look into what this guidance is, how it applies, and what needs to be done about it. This is BIG and we all better be paying attention. More info at HelpMeWithHIPAA.com/357

May 27, 202255 minEp. 357

Everybody get on board! - Ep 356

Everybody get on board because data security laws keep getting signed in states each year. The new Maryland and Kentucky data security laws are designed to help protect insurance companies from cyber attacks by implementing cybersecurity standards, developing, implementing, and maintaining a written information security program. Their service providers are also required to implement such programs which include a requirement to report cyber security incidents within 3 days of discovery. For more ...

May 20, 202252 minEp. 356

10 Roles of Operational Continuity - Ep 355

Incident response planning is important to every business. You don’t want to figure out how to manage the business and respond to an incident on the fly. These plans should be reviewed and updated regularly. Today we review a brand new guide from the Healthcare & Public Health Sector Coordinating Council on Operational Continuity - Cyber Incident. More info at HelpMeWithHIPAA.com/355

May 13, 20221 hrEp. 355

PriSec Teams Require Everyone - Ep 354

Over the last couple years, we’ve had some high-profile cybersecurity compromises and data breaches. And this trend is not slowing down. Today, we review a recent study of the top cyber threats to healthcare organizations. The results reinforce that PriSec teams require everyone to participate. More info at HelpMeWithHIPAA.com/354

May 06, 202259 minEp. 354

3 Tricky Places HIPAA Applied - Ep 353

Recently, we’ve had a couple things come up which involved tricky places that HIPAA has applied that most people might not think of. So, we thought we'd throw them out there and have a little bit of fun discussing them. More info at HelpMeWithHIPAA.com/353

Apr 29, 202245 minEp. 353

6 Ways To Make Money Online - Ep 352

Cybercrime is a booming business. In 2021, the US experienced an unprecedented increase in cyber attacks with criminals making $6.9 billion online. In today’s podcast, we review the FBI’s Internet Crime Report for 2021. More info at HelpMeWithHIPAA.com/352

Apr 22, 202239 minEp. 352

4 Takeaways from Okta Breach? - Ep 351

It is crucial for every business to understand the security practices of their vendors. And also to make sure that those vendors are vetting their vendors. A cyber attack at a link in your supply chain can drastically affect your business. Evidence: the Okta breach. More info at HelpMeWithHIPAA.com/351

Apr 15, 202246 minEp. 351

4 OCR Cases For Us - Ep 350

Have you heard the one about three dentists and a psychiatrist walk into... an OCR investigation? OCR has announced their first set of enforcement actions of 2022, and just in time for our 350th episode. These involve patient right of access and improper disclosure violations. More info at HelpMeWithHIPAA.com/350

Apr 08, 202244 minEp. 350

6 Points from HIPAA Summit - Ep 349

Donna made many notes from the HIPAA Summit. Today, she and David will share six of her top picks, including the difference between an incident and a breach, how a “check the box compliance program” is not a privacy and security program, importance of understanding what your vendor’s incident response plans are and more. More info at HelpMeWithHIPAA.com/349

Apr 01, 202244 minEp. 349

3 HIPAA Enforcement Arms - Ep 348

If you are a regular listener of the podcast, you know how Donna loves to “HIPAA-geek out” over the National HIPAA Summit each year. This year’s National HIPAA Summit did not disappoint. Today, we discuss a few points made concerning enforcement of HIPAA related cases by three arms of the federal government. More info at HelpMeWithHIPAA.com/348

Mar 25, 202259 minEp. 348

One SMBs Cyber Survey - Ep 347

Cyber threats are a growing risk that is becoming increasingly difficult to avoid. Small and medium businesses are not immune to these cyber threats. They are a growing business risk. The first step in preventing cyber threats is awareness. More info at HelpMeWithHIPAA.com/347

Mar 18, 202252 minEp. 347
Hosted on Libsyn
For the best experience, listen in Metacast app for iOS or Android