Thursday, December 28, 2017

Pay Now Or Pay Even More Later - Ep 134


Is HIPAA compliance expensive?  Or, is it short-sighted to only worry about what HIPAA compliance costs?  A new report from Ponemon Institute, The True Cost of Compliance with Data Protection Regulations, looks at compliance costs across several industries and multinational organizations. The study has a lot of details as we always expect from Ponemon Institute.  

Read more at HelpMeWithHIPAA.com/134


Check out the episode!

Thursday, December 21, 2017

2017 Blooper Episode - Happy Holidays


Each year Bojan Sabioncello, our audio engineer in Split, Croatia, puts together his blooper roll to mock us.  Granted, he spends the whole year having to listen to us without a chance to respond until now.  This his only chance to respond to a year’s worth of our comments and screw-ups.

We will be back next week with a new episode.   Happy Holidays from the whole Help Me With HIPAA team!


Check out the episode!

Friday, December 15, 2017

Cybersecurity Naughty List 2017 - Ep 133


As 2017 comes to a close, we are making our lists and checking them twice.  Time to find out who we thought was more naughty than nice this year.  The Naughty List 2017 discussion includes everything from big news data breaches such as Equifax and Uber down to stolen hard drives and password issues.  Feel free to add your naughty list nominations in the comments.

More info at HelpMeWithHIPAA.com/133


Check out the episode!

Thursday, December 7, 2017

Five Phishing Findings From Google - Ep 131


A new report on phishing was recently released titled: Data Breaches, Phishing, or Malware? Understanding the Risks of Stolen Credentials. The report of findings from a study that was done by Google, University of California, Berkeley, and the International Computer Science Institute.  It was a year-long study of account hijacking, stolen credentials, phishing and malware attacks.  The findings are clear that phishing is a problem in ways we may not have thought before now.  In the study, the researchers followed other hacker methods used against email addresses they found on the darknet sites for sale. The search netted 12.4 million addresses that were determined to be potential victims of phishing kits out of the total 1.9 billion usernames and passwords exposed by data breaches. So, it is obvious that this isn’t a tiny study over a short amount of time.

For more info go to HelpMeWithHIPAA.com/131


Check out the episode!

Thursday, November 30, 2017

SOC2 certification is not HIPAA compliance - Ep 131


Recently, we have dealt with our clients struggling with vendors in the vetting process. Particularly, tech vendors of any sort. Many vendors have written off the HIPAA compliance requirements by simply saying “We are SOC2 compliant so you don’t have to worry about anything”. Often that is said by sales and management folks with a great deal of confidence. After spending some time at a recent HITRUST meeting I heard just how many people shouldn’t be so confident when making that statement. As with anything else the devil is in the details. What does SOC2 mean and how can you tell if that really means anything to you? Trust but verify is the key to answering that question for yourself.

More info: HelpMeWithHIPAA.com/131


Check out the episode!

Thursday, November 23, 2017

Black Friday Replay 8 Common HIPAA Myths


We are enjoying the holiday with our families.  But, we didn't want to miss a chance to share time with our listeners.  Today we are replaying one of our favorite episodes 8 Common HIPAA Myths.


Check out the episode!

Thursday, November 16, 2017

5 Things To Do Before Year’s End - Ep 130


Hard to believe another year is coming to an end. It is time to review 2017 and plan for 2018.  That means it is time to make your list of 5 Things To Do Before Year’s End. Just in case you need some help with that list, we made one for you!

 

HelpMeWithHIPAA.com/130


Check out the episode!

Thursday, November 9, 2017

Text messaging is not secure by default - Ep 129


Text messaging is often the preferred method of communication for many people today.  It does have great advantages with its simplicity, instant delivery, and convenience.  However, I did not mention security on that list.  Text messaging is not secure by default.  Yes, you can secure it but that requires apps, platforms, and planning.  The bottom line is the communication method most people call text messaging is not secured enough to send and receive PHI without patient authorization to use it.

For more info HelpMeWithHIPAA.com/129


Check out the episode!

Thursday, November 2, 2017

Is there a cyber storm brewing? Ep 128


Lately, there have been a lot of articles in the "nerd news" services about various problems and vulnerabilities looming on the horizon or happening right now.  Usually, there are one or two in a normal week or so that really get our attention.  The last few weeks though it seems a bit different.  Maybe it is just noise or paranoia created to drive traffic to sites.  But, sometimes it becomes overwhelming enough to take time to step back and look at the details as a whole and determine what you really are seeing here.  So, today we discuss:  is there a cyber storm brewing on the horizon?

More info at HelpMeWithHIPAA.com/128


Check out the episode!

Thursday, October 26, 2017

HIPAA Horror Stories V3 Ep - 127


Each year we have done a special scary episode for Halloween.  Last year we took you on a tour of a haunted house.  This year for HIPAA Horror Stories V3 we get to hear a campfire horror story.  So gather around and hear how scary HIPAA mishaps can be for us all!

For more info go to HelpMeWithHIPAA.com/127


Check out the episode!

Thursday, October 19, 2017

Social Media, Marketing, and HIPAA - Ep 126


When it comes to social media, marketing, and HIPAA things can get a little dicey. There are certainly many cases where using social media has gone awry in health care cases.  However, when handled correctly, you can actually use social media, marketing, and HIPAA in a sentence without getting chills down your spine.  Today, Janet Kennedy joins us for a discussion on the positive reasons you should be active on social media and the precautions you should take to make sure everything stays in a positive light.

More at HelpMeWithHIPAA.com/126


Check out the episode!

Thursday, October 12, 2017

On-boarding and Termination Checklists - Ep 125


During the onboarding and termination process is where many mistakes are made that lead to security incidents and even reportable breaches.  Today we discuss why they are important and the kinds of things you should consider having in yours.

For more information HelpMeWithHIPAA.com/125


Check out the episode!

Thursday, October 5, 2017

Talk To The Boss About HIPAA - Ep 124


How do you talk to the boss about HIPAA? That is a regular question we get around here.  The staff responsible for compliance gets trained and understands what needs to be done but they don't get leadership support.  Over the years we have had to have those conversations many times.  It is never easy but there are some key pointers to making ground with your argument and turning the tide for supporting your efforts.  Today we cover a few of our ideas on how to broach the subject effectively when you need to talk to your boss about HIPAA.

More details at HelpMeWithHIPAA.com/124


Check out the episode!

Thursday, September 28, 2017

OCR Audit Updates Phase 2 - Ep 123


During the NIST OCR HIPAA Security Conference we covered in the last two episodes, there was also a session on OCR Audit Updates. OCR gave an update on the information gleaned so far from the compliance desk audits that were started in 2016. Their presentation included some interesting details. Today we cover the information they shared so you can compare and contrast those details against your own program.

For more details HelpMeWithHIPAA.com/123


Check out the episode!

Thursday, September 21, 2017

NIST and OCR Security Conference Part Deux – Ep 122


This is the second episode covering the things David has to share from the Safeguarding Health Information conference. There are many great points he picked up. As we review them we keep coming back to the reminder that HIPAA is about patient care now.  Join us as we discuss everything from ransomware requirements to security for a small practice on this episode.

More info at HelpMeWithHIPAA.com/122


Check out the episode!

Tuesday, September 19, 2017

NIST and OCR Security Conference - Ep 121


The annual NIST and OCR security conference has come around again.  This year, David attended the conference via webcast and shares his notes on the first day of the conference.  

Before the conference discussion, we have to touch on the announcement from Equifax about their HUGE data breach.

For more information go to HelpMeWithHIPAA.com/121


Check out the episode!

Thursday, September 7, 2017

Disaster Recovery Preparations Ep - 120


We recorded this episode on the day that Harvey was hitting Houston and had no idea just how bad that disaster would eventually become for those on the gulf coast.  On the day we publish this episode, we are both personally involved in the evacuations and preparations in advance of Irma. She is forecast to hit Florida, Georgia, and the Carolinas in the next few days. The timing for this discussion could not be more appropriate from a news perspective but this planning should have already taken place prior to this date for those in the paths of these deadly storms.  

As you listen to this episode, know that we had no idea just how bad things were about to become for the millions of people under the stress of these major natural disasters.  Take care in your planning now if you haven't been in these areas, your turn may be next and there is no way you want to be dealing with anything similar without a plan.

What do you have in your disaster recovery plans?

For more info HelpMeWithHIPAA.com/120 

Email us at contact@HelpMeWithHIPAA.com


Check out the episode!

Thursday, August 31, 2017

Should I use a local, data center, or cloud server? - Ep 119


Every time we discuss server security issues it opens a debate about where is the best place to keep your servers.  There are three options and we are going to discuss them today.  Local hosting vs data center hosting vs cloud servers under HIPAA.

For more details HelpMeWithHIPAA.com/119

email us: contact@helpmewithhipaa.com


Check out the episode!

Thursday, August 24, 2017

What is reasonable and appropriate? Ep 118


What is reasonable and appropriate?

The HIPAA legal reference and guidance mentions reasonable and appropriate all over the place. Many times that concept creates confusion. How do you determine what is reasonable or appropriate for any environment?

More at HelpMeWithHIPAA.com/118


Check out the episode!

Wednesday, August 16, 2017

Alexa and HIPAA Plus Other Questions - Ep 117


Can a doctor have Alexa in OR to play music?  

Is it a HIPAA violation for staff to look at their own records or is it an internal policy violation?

I am a small company BA do I really have to do all of HIPAA compliance requirements?

If I know my upstream BA or CE isn't following their HIPAA compliance obligations what am I legally obligated to do?

Why would you make daily copies of your visitor logs?

More info at HelpMeWithHIPAA.com/117


Check out the episode!

Thursday, August 10, 2017

Security Incident Investigations Find More Than Expected - Ep 116


Sometimes following the news lets you find things like security incident investigations with interesting details.  But, these cases were different than most.  Even better than that, we learned how can a fish tank help hackers!  There were just too many parts of these stories that got my attention to pass them up.  When something occurs and the investigation uncovers way more to the story than you normally see we should all learn from them.

More details at HelpMeWithHIPAA.com/116


Check out the episode!

Thursday, August 3, 2017

Incident Response Plans V2 - Ep 115


Incident response plans have been a topic of our show several times. But, these days we just can't get enough of a good thing!

Actually, there is a reason we are covering it in this episode.  I was reviewing a Business Associate Due Diligence from a software provider. In the questionnaire, we always ask if you have a written incident response plan and trained incident response team. They responded Yes, with a comment of "we have an engineering department".

More info at HelpMeWithHIPAA.com/115


Check out the episode!

Thursday, July 27, 2017

Compliance Officer Personal Liability? - EP 114


There has always been a concern from many people we work with about compliance officer personal liability. Specifically, is a compliance officer personally liable for the compliance of the company?

The recent settlement agreement between the FTC and the Chief Compliance Officer of Moneygram has created interesting conversations for compliance circles. In this case, the Chief Compliance Officer of Moneygram was able to reach a settlement in the liability case against him but it included a $250,000 penalty payment and 3 years restriction on working in that industry. Yep, that is enough to make you sit up and take notice.

More details at HelpMeWithHIPAA.com/114


Check out the episode!

Thursday, July 20, 2017

OCR Mic Drop For Cloud Providers - EP 113


The monthly OCR Cyber Newsletter for June had some interesting points.  The fact that OCR mentions multiple times and in multiple ways that they do not endorse, certify, or recommend specific technology or products should serve as their "OCR mic drop moment" on this discussion.  We can dream, can't we!  Today we are going to review that newsletter and how they have pointed these things out once again.

Before we close out the episode we are also covering some questions and comments from listeners.  Hang around for those just after the 30-minute mark.

More info at HelpMeWithHIPAA.com/113


Check out the episode!

Friday, July 14, 2017

NotPetya, Windows, and Ransomware - Ep 112


This is not another episode about preventing and responding to the NotPetya ransomware. There are countless articles about those topics.  We are discussing the bigger picture today.  In this episode, NotPetya, Windows, and Ransomware, we discuss what happened in the case but also what does all of this really mean in the big picture of cyber attacks.  If you don't stay proactive in evaluating what the criminals may do next then you don't have a chance of being anything but reactive.

In light of these recent global attacks, we have many questions.  Are we experiencing a shift in the criminal's intentions or are they just bumbling around with new toys?  If is it no longer just about taking our money then what is really about?  If you haven't cared about protecting your data so far, how about protecting your data from becoming a pawn in the latest cyberwarfare battle?

For more information go to HelpMeWithHIPAA.com/112


Check out the episode!

Thursday, July 13, 2017

Breach reporting costs and decisions for 2017 - Ep 111


In June, the NY State Attorney General announced a settlement with CoPilot, a healthcare services company that illegally deferred notice of breach of more than 220,000 patient records.  Another annual report was also just released with the latest numbers : 2017 Cost of a Data Breach Study from Ponemon Institute and IBM.  Today, we are going to discuss how the two of them can help us all make better decisions where potential breaches of PHI are concerned.  Breach reporting costs and decisions in 2017 are proving to be something you should understand before a crisis, not after one hits.

For more info: HelpMeWithHIPAA.com/111


Check out the episode!

Thursday, June 29, 2017

What is MDM and why do I want it? - Ep 110


Mobile devices are susceptible to malware attacks, phishing, and other security vulnerabilities just the same as laptops and desktops.  The systems most of us have in place are directed at managing the security for laptops and desktops, however.  It is important to expand your security controls to address the growing threat that mobile devices introduce to your network and systems regularly.  

In most cases, it is important to have a "home base" tool that can talk to and monitor the mobile devices.  That is where MDM comes into play.  For most people that brings us to the question: What is MDM and why do I want it?

 

For more: HelpMeWithHIPAA.com/110


Check out the episode!

Friday, June 23, 2017

eCW Whistleblower Made The Difference - Ep 109


There are countless times we have covered the "my EHR vendor handles HIPAA for me" misconception. The recent $155 million whistleblower lawsuit settlement between eClinicalWorks (eCW) and the government really brings it home how wrong you can be about EHR vendors.

Meaningful Use attestations relied heavily on the vendors supplying proper information. eCW set up thousands of organizations to take a major hit based on the details in this case and it's settlement. Especially, when you take into account that eCW is one of the biggest EHR vendors out there.

CIA of PHI is the objective of the entire Security Rule under HIPAA. Unreliable data created by an application is clearly a data Integrity issue. If you can't trust the data can you trust the system at all?

If you have knowledge of this kind of stuff going on somewhere you should review it closely. It includes civil payments by developers and project managers not just the C-Suite folks involved.

 

For more information: HelpMeWithHIPAA.com/109


Check out the latest episode!

Friday, June 16, 2017

5 Stages Of Grief During A Cyber Attack - Ep 108


The 5 stages of grief during a cyber attack really do follow the process of dealing with grief in those familiar 5 stages. Many don't realize that ransomware attacks aren't always just the result of someone clicking in an email and running a program.  As Erie County Medical Center found out recently, ransomware attacks can come from a hacker being active in your network too.  Those 5 stages of grief during a cyber attack for them and others we have seen is what we will be discussing today.  

We have a special guest with us for today's discussion too.  David Benton with Altep is joining us.  David is a super IT forensics dude.  The CSI of the nerds, so to speak.  He is helping us review this topic.

More information at HelpMeWithHIPAA.com/108


Check out the latest episode!

Friday, June 9, 2017

10 Ways HIPAA Should Have Stopped Rodeo Drive Breach - Ep 107


A major breach of PHI was announced by a Beverly Hills plastic surgeon's office on Jun 1. There are so many things about this case from the fact that it involved a malicious insider to how many different ways proper HIPAA policies and procedures would have stopped it, if not prevented it completely. Celebrity patients records breached in this case may make it hit home with a lot of folks who haven't worried too much about those protections until now.

We have talked about insiders as a major vulnerability a lot lately and this one really makes it big news! 15,000 files with medical and personal information. Added to that are pictures including those of celebrity patients records breached without them even know the pictures existed!

More info at HelpMeWithHIPAA.com/107


Check out the latest episode!

Friday, June 2, 2017

Disclosure of PHI in May OCR settlements - Ep 106


OCR continued their enforcement trend for 2017 with 2 more settlements announced in May.  These stand out on their own because the focus is specific disclosure of PHI instead of major breaches.  A total of three patients were involved in these large settlements.  This week we review what transpired and what OCR found as violations of privacy for these three patients.

 

For more information go to HelpMeWithHIPAA.com/106

 


Check out the latest episode!

Friday, May 26, 2017

Answering Listener Questions - Ep 105


A wide variety of questions have come in from listeners over the last few weeks. The list is so good we have a whole episode devoted just to answering listener questions.  At least one of these will likely apply to you if not several.

For more information go to HelpMeWithHIPAA.com/105


Check out the latest episode!

Friday, May 19, 2017

What should we learn from WannaCry? - Ep 104


All of those ransomware outbreaks we have been dealing with since last year were overshadowed this past week by WannaCry.  This has been called called the most destructive attack ever.  The most concerning part is that was how bad it was but the US wasn't hit that hard.  When these kinds of things happen it is always a good idea to review what you learned from the outbreak and any necessary changes you need to make to protect you from this one happening to you.  The is the topic of the day.  What should we learn from WannaCry?

 

Learn more at HelpMeWithHIPAA.com/104


Check out the latest episode!

Friday, May 12, 2017

Managing Third Party Access - Ep 103


You may not even know about all the applications and support logins that vendors use on your applications, systems, and networks. Vendors may set up admin passwords and share them with their whole staff to support you. If they have unlimited access to the systems out there and the usernames and passwords never expire or log off automatically that is certainly not secure. How do you manage all of those?  If there are things that automatically log in and run, what about those?

More details at HelpMeWithHIPAA.com/103


Check out the latest episode!

Friday, May 5, 2017

No, No, No says OCR in three April settlements - Ep 102


April has had three more OCR resolution announcements. That's a total of 7 cases for $14.3m in 2017 so far. When we covered resolutions recently I kept waiting for another one to come out and gave up. Then, BAM, three in a row!

For more info go to HelpMeWithHIPAA.com/102


Check out the latest episode!

Friday, April 28, 2017

Are we creating a crisis of trust in healthcare? - Ep 101


Are we creating a crisis of trust in healthcare? A business partner put that question out to us recently. We have already been looking at several angles to discuss the patient part in all of this breach and ransomware news. This question seems like the perfect way to approach it. Let's look at the topic and see what we think - Are we creating a crisis of trust in healthcare?

 

For more information on this podcast and how to win $100 Amazon gift card go to HelpMeWithHIPAA.com/101


Check out the latest episode!

Friday, April 21, 2017

Top 10 HIPAA Lessons - Ep 100


For our 100th episode we wanted to do a Top 10 list.  After some thought, we landed on the Top 10 HIPAA Lessons we hope you get from our little podcast.  

It is hard to believe that we are publishing our 100th episodes of Help Me With HIPAA!  Two years ago we started out with this little idea that has become a really exciting venture for both of us.  We truly enjoy the responses and interaction from our listeners.  Well, first, we are thrilled to HAVE listeners.  But more importantly, we love hearing how much people learn and laugh at the same time.  That combination has been our show objective since the very beginning.

Another big thing we are doing with this episode is a chance to win a $100 Amazon gift card if you help share and promote us with you social networks.  Listen in or go to the website for more details on how to win! 

More info at: HelpMeWithHIPAA.com/100


Check out the latest episode!

Friday, April 14, 2017

Examples of what not to do from OCR AGAIN - Ep 99


OCR Resolutions 3 and 4 for 2017 were released in February.  Examples of what not to do from OCR were released AGAIN.  We kept waiting for another resolution to be announced and lump them together.  Once we gave up and recorded this episode to review those two you know another one was announced.  We will hit that one next time.  For now, we review what happened in these cases that resulted in OCR resolutions after a breach notification started an investigation.  They are so kind to give us examples of what not to do from OCR without us paying for it!

For more details go to HelpMeWithHIPAA.com/99

 

 


Check out the latest episode!

Friday, April 7, 2017

State privacy and breach laws and HIPAA - Ep 98


Recently, New Mexico passed a new data breach notification law in March. Once it is signed there will only be 2 states that don't have their own notification rules, Alabama and South Dakota. What do all the state laws mean when you are also required to do HIPAA notifications.

Most of them say that if you are subject to GLBA or HIPAA the notification laws do not apply to you. But, it is always best to be sure you know what your state requires.

HIPAA says that as long as it is more strict than state laws then HIPAA takes precedence but many times states are now enacting stronger legislation in some areas.

California and Texas developed some pretty extensive requirements that apply to CEs and BAs in their states. Massachusetts also added their own twist beyond HIPAA.

More info at HelpMeWithHIPAA.com/98


Check out the latest episode!

Friday, March 31, 2017

Insiders may be your biggest threat to privacy and security Ep - 98


All the news about ransomware and hackers usually gets the biggest headlines.  But, the ones that fly under the radar may be something you should pay more attention to than the big splashy news.  Insiders usually don't have to work hard to plot ways to break into your data, you have invited them in and given them access. A damaging assumption is that you don't have to worry about your insiders.

Get more info at HelpMeWithHIPAA.com/98


Check out the latest episode!

Thursday, March 23, 2017

What is included in a mobile access policy? - Ep 96


Call it teleworking, remote access, or mobile access if you have any access to PHI outside of your office, you should have a HIPAA mobile access policy. Any person that accesses you systems and data outside of your internal network should be trained and sign off on commitments to protect your PHI.

We've never specifically covered the topic of what should be included in a HIPAA mobile access policy. It is about time we did just that.

Learn more at HelpMeWithHIPAA.com/96


Check out the latest episode!

Friday, March 17, 2017

Can we build a national culture of cybersecurity? - Ep 95


Building a culture of a compliance is something we have talked about many times in this podcast.  We never looked at it as a community problem.  The things we heard about training the human element to build a cyber security culture were very exciting to us.  Well, at least to Donna.  The concepts they covered about training not just the workforce but training the community as a whole to better understand what cybersecurity really means.

We also followed that up with a session that explained some more scary darknet activity.  Your machine could be for sell on the darknet and you don't even know it.

More information at HelpMeWithHIPAA.com/95


Check out the latest episode!

Friday, March 10, 2017

Frank Abagnale Can Even Scare Us About ID Theft - Ep 94


If you saw the movie Catch Me If You Can then you know some of Frank Abagnale's story.  Maybe you even read his book Catch Me If You Can: The True Story of a Real Fake.  

Tom Hanks said "Abagnale’s lecture may be the best one-man show you will ever see."   He WAS NOT KIDDING!  

The famous con man in his youth eventually became a white hat working for the FBI and others to combat fraud and ID theft for over 40 years. Now, he works as a consultant, writer, and speaker on the subject as he continues working with the United States Government  

The information he shared with us during his #HIMSS17 session blew us away.  That means we have to tell you guys about it!

Learn more at https://HelpMeWithHIPAA.com/94


Check out the latest episode!

Friday, March 3, 2017

HIMSS17: Deven McGraw Talks HIPAA Enforcement - Ep 93


The first full day of HIMSS17 HIPAA had a big session. It featured Deven McGraw, Deputy Director for Health Information Privacy at the HHS Office for Civil Rights (OCR).  She is also Acting Chief Privacy Officer for the Office of the National Coordinator for Health IT (ONC).  Clearly, it was one of the sessions at the top of the list for us to attend.  We got there early enough to be perched on the front row.  In this episode, we review what McGraw covered in her session and our thoughts on it.

For more details and timestamps go to HelpMeWithHIPAA.com/93


Check out the latest episode!

Friday, February 24, 2017

HIPAA Hodge Podge - RDP FAXing Dumpsters - Ep 92


HIPAA news stories are sometimes so short we need to bundle them together. Some listeners questions are also addressed today. So, we have a little bit of everything in this episode. So stick with us as we go through our HIPAA hodge podge.

For more details go to HelpMeWithHIPAA.com/92


Check out the latest episode!

Friday, February 17, 2017

What is HIPAA privacy anyway - Ep 91


What is HIPAA privacy anyway? The annual reporting deadline for little breaches is up at the end of Feb. That means all those little privacy violations in 2016 must be reported on the HHS website soon if you haven't already done it. Since those little ones often mean so much more than the big ones it made me think it would be a good time to talk about privacy.

A recent bizarre case in an Atlanta suburb made me realize just how much we value our privacy but may not realize it until it has been taken from us.

More at HelpMeWithHIPAA.com/91


Check out the latest episode!

Sunday, February 12, 2017

First HIPAA Settlements of 2017 - Ep 90


OCR continues releasing new settlement agreements on their new pace. There have been two announced in January 2017. We have no idea what will happen now but since these two brought in over $2.6m there may not be a reason we will see them stop their pace.

As always, we believe in learning from other's mistakes (not schadenfreude, though). Time to learn what these two can teach us....

HelpMeWithHIPAA.com/90


Check out the latest episode!

Friday, February 3, 2017

Understanding Cybersecurity Insurance With John Miller of Sterling Risk Advisors - Ep 89


More reasons to have this coverage pop up every day. Whether it is your own business risk management or those required by a business partner in a contract, all businesses should at least evaluate getting cybersecurity coverage. To help us share information on that we have a guest on this episode.

Interview with John Miller II, Founding Principal, Sterling Risk Advisors 


Check out the latest episode!

Friday, January 27, 2017

8 Common HIPAA Myths - Ep 88


We reviewed the OCR/HHS list of common HIPAA compliance myths when we first started the podcast. Their list is so long that it spread across 3 episodes. Those episodes are still fairly popular today. For today, though, we are covering our own list of common HIPAA compliance myths that we hear.

Common HIPAA Compliance Myths

Our list may be very similar to all the other lists out there but it is important to cover those because they are clearly STILL being passed along. Why do we keep hearing the same things over and over?

 

More at HelpMeWithHIPAA.com/88


Check out the latest episode!

Friday, January 20, 2017

Healthcare Breaches Continue in 2017 - Ep 87


At the beginning of 2016, we did some speculation about what the year would be like in the cybersecurity and HIPAA worlds.  Today we plan to review how we did for 2016 and explain expect healthcare breaches continue in 2017.

More at https://HelpMeWithHIPAA.com/87


Check out the latest episode!

Friday, January 13, 2017

MACRA and HIPAA - Ep 86


We've talked before about HIPAA showing up in lots of other places. That trend has continue. Now, you will see HIPAA questions on cyber security insurance applications, certification programs from other entities, and now in payment model reforms. Today we are going to talk a little bit about MACRA and HIPAA requirements. If you don't know what MACRA, APMs, and MIPS is all about we may not cover enough to explain it all be we will certainly touch on MACRA and HIPAA crossing paths starting in 2017.

More information at HelpMeWithHIPAA.com/86


Check out the latest episode!

Friday, January 6, 2017

2017 Compliance Management Plans - Ep 85


Last January, we did an episode with a 2016 Compliance Management Plan.  We even created a reminder poster for it you could download.  The episode was about providing a compliance management plan guideline for compliance officers who are trying to find a way to fit this in your with all your other job duties.

That episode was very popular and the poster was downloaded by new folks even in December.  

This episode reviews that compliance management plan and adds a bit more to it for "extra credit".   We also added a second poster and compliance management plan for a more aggressive approach than just the bare minimum.

Get the downloads and more information at HelpMeWithHIPAA.com/85


Check out the latest episode!