Thursday, December 27, 2018

It's Raining Settlements - Ep 184


OCR continued to hand out settlements to close out 2018. These last few announcements came out so quickly vs normal rates it is definitely raining settlements! While these last two do pale in comparison to the huge Anthem settlement, they certainly bring home more messages. What lessons are they trying to teach us with the Florida and Colorado settlements announced in December?

More info at HelpMeWithHIPAA.com/184


Check out the episode!

Thursday, December 20, 2018

Annual Blooper Show 2018


Each year our Croatian sound editor, Bojan, compiles his favorite package of our issues to share his pain with our listeners.  Listen in to hear how much he has to work to make us sound so much better than we should.

Thanks, Bojan for all the hard work!

For all our listeners, Happy Holidays and thanks for your support this year and in the future!

 


Check out the episode!

Thursday, December 13, 2018

Should have said no comment - Ep 183


The allergy practice settlement that was recently announced will be known as the “no comment” settlement in my mind.  As always, there are lessons to be learned from this announcement and the way OCR handled it. This settlement brings up a lot of discussions about handling patient public comments.

More at HelpMeWithHIPAA.com/183


Check out the episode!

Thursday, December 6, 2018

New cybersecurity agency and office? - Ep 182


There have been several announcements about cybersecurity agencies and offices lately.  Some announcements are from the Department of Homeland Security (DHS) and some are from Health and Human Services (HHS).  What are they talking about and what does it mean to you?

 

More at HelpMeWithHIPAA.com/182


Check out the episode!

Thursday, November 29, 2018

2018 Predictions - How Did We Do? - Ep 181


It is hard to believe we are coming to the end of another year.  Seems like just yesterday we recorded 7 Educated Guesses About 2018.  Today we review our 2018 predictions, ummmm, educated guesses for 2018 and see how we did.

More info at HelpMeWithHIPAA.com/181


Check out the episode!

Thursday, November 22, 2018

Happy Thanksgiving 2019 - Compliance Officer Gift Guide Replay


This holiday we are both taking time off to celebrate with our friends and families.  In our absence, please enjoy a replay of our previous Gift Giving Guide for compliance officers.


Check out the episode!

Thursday, November 15, 2018

Listener Message Potpourri - Ep 180


Listener message potpourri means we will be hitting several different topics in this episode. We get emails and messages from listeners a lot these days. While we do our best to respond we can't say we are consistent. That is why we do these episodes periodically.  If we've missed yours, don't hesitate to point it out to us in another message.  

More info at HelpMeWithHIPAA.com/180


Check out the episode!

Thursday, November 8, 2018

Certification Is Not What You Think - Ep 179


In the recent NIST OCR security conference, a panel member said the terms “HIPAA compliant” and “HIPAA certified” made her cringe.  We agree. The Anthem settlement has a lot of people asking about certifications for cybersecurity since Anthem was technically HITRUST Certified when the hacker first broke into their network.   Let’s talk certifications and what they really mean under HIPAA, shall we?

More info at HelpMeWithHIPAA.com/179


Check out the episode!

Thursday, November 1, 2018

Anthem Settlement Lessons - Ep 178


The 2015 Anthem data breach could have been a watershed moment for HIPAA privacy and security in many ways. It remains to be seen if the settlement with OCR turns out to be another one. Either way, the historic breach and historic settlement have many lessons for us to learn. Let's discuss Anthem settlement lessons today.

More info at HelpMeWithHIPAA.com/178


Check out the episode!

Thursday, October 25, 2018

5 Horror Movie Quotes - Ep 177


Time for the annual Halloween episode!  5 horror movie quotes are this year’s theme.  We have 5 horror movie quotes that are matched up to data breach stories.

More info at HelpMeWithHIPAA.com/177


Check out the episode!

Thursday, October 18, 2018

We are #CyberAware - Ep 176


We are #CyberAware is the tag for the National Cybersecurity Awareness Month campaign.  Each year this campaign is run by the National Cybersecurity Alliance. In 2018, Kardon, Security First IT,  and HMWH are all signed up to be champions and publish information for the campaign.  Today, we will review what these campaigns are about and how you can use these and more like them to augment your education program.

More at HelpMeWithHIPAA.com/176


Check out the episode!

Friday, October 5, 2018

3 stories techs should hear - Ep 174


Often tech folks will say that they understand HIPAA. What that really means is that they understand the technical requirements of HIPAA.  The overconfidence sometimes works against them. Today we cover 3 stories tech should hear. It is important that they learn there is more than just their tech knowledge.


Check out the episode!

Thursday, September 27, 2018

CIS 20 and HIPAA - Ep 173


CIS 20 or SANS 20 is the name to reference a list of security controls that are intended to be used in the absence of any framework like NIST or HIPAA requirements. If you are trying to get the most bang for your buck and you know you are way behind on your security program CIS 20 may be the thing for you.

For more info go to HelpMeWithHIPAA.com/173


Check out the episode!

Thursday, September 20, 2018

How much does trust matter in healthcare? - EP 172


Have you seen the report about consumer online digital trust and what it means to all businesses? The report is The Global State of Online Digital Trust  A Frost & Sullivan White Paper which was commissioned by ca technologies and published in July 2018.  This survey study was done to compare perceptions about consumer trusts that executives and security professionals have vs the actual consumer trust findings when surveying consumers.  Would you believe there is a disconnect across the three perceptions?

For more go to HelpMeWithHIPAA.com/172


Check out the episode!

Thursday, September 13, 2018

Snooping is a serious problem - Ep 171


I can tell you from experience snooping is a serious problem that haunts all entities with health information to protect.  Even if you don’t know it is haunting you, it is. You will learn to fear it eventually. The extent of improper record access goes well beyond what most people imagine.  The image of a healthcare professional keeping patient information confidential is something we all assume is happening. In the real world, most workers know someone who has improperly accessed records if they haven’t done it themselves.

More info at HelpMeWithHIPAA.com/171


Check out the episode!

Thursday, September 6, 2018

Securing home networks - Ep 170


Securing home networks matters more now than ever before.  We are a very connected society. That creates great opportunities and new challenges every day.  Especially, for those tasked with securing all that connectivity. One opportunity that gets a lot of people talking is teleworking, telecommuting, working remotely, or working from home (WFH) - all seem to mean the same thing to most people.  Our whole company is built on the ability of our systems to be secured and also be able to connect and work from anywhere in the world. Many groups forget to worry about those home networks that are connecting to your office network and even using your office applications, and data on a regular basis.

More at HelpMeWithHIPAA.com/170


Check out the episode!

Thursday, August 30, 2018

Crisis Communications Plans - Ep 169


We live in a world of instant communications.  During a crisis, our normal standards of communications can be very limited.  How many different issues have you addressed for communications in a crisis in your plans?  We mention the business continuity and disaster recovery plans that everyone should have often in episodes. This is just one element of the plan that can make or break the business in a crisis.  If you can’t communicate effectively with each other the chance of you being able to keep things running drops significantly.

For more go to HelpMeWithHIPAA.com/169


Check out the episode!

Thursday, August 23, 2018

Are hacktivists on your SRA? - Ep 168


It may not occur to many of you that a hacktivist should be on your security risk analysis (SRA).  They must be on there in this digital age. You never know what could trigger a hacktivist to focus on your business and put you under attack.  Why you may ask - well we will discuss that now.

For more text go to KardonHQ.com/168


Check out the episode!

Thursday, August 16, 2018

BEC-EAC the latest threat to your business - Ep 167


The FBI released an alert on July 12 titled Business E-mail Compromise E-mail Account Compromise The 12 Billion Dollar Scam that should be on your radar.  BEC-EAC stands for Business Email Compromise - Email Account Compromise.  If you haven’t learned about this particular threat it is important that you review it and assess the risk it brings to your company.  That’s why we review these increasing threats and what you need to do about them in this episode.

For more go to HelpMeWithHIPAA.com/167


Check out the episode!

Thursday, August 9, 2018

3 reports from IT that you need - Ep 166


We often get questions from both the tech staff and security officers about what should be documented regularly and why it should be done.  There are 3 reports you need to get from your tech team on a regular basis IMHO. Today, we will discuss those three reports, why you need them and what to do with them.

More at HelpMeWithHIPAA.com/166


Check out the episode!

Thursday, August 2, 2018

Does size really matter? - Ep 165


One of the discussions you must always be prepared to have is that size does not matter when it comes to privacy and security issues.  Does size matter? Not as much as most people think and not in the ways that most people think either.

More at https://HelpMeWithHIPAA.com/165


Check out the episode!

Thursday, July 26, 2018

How to save money in a data breach - Ep 164


Want to know how to save money in a data breach?  You have to have a plan before you have the data breach to keep you from making costly mistakes.  Everyone knows a data breach can be expensive but there are studies that show us what makes them more expensive and what helps you save money.  The annual Ponemon cost of a data breach study has been published. IBM sponsors the study each year and it is one of the best tools for us to prepare for the cost of a data breach.  If you have any valuable data at all you should review the report to get an estimate of what the cost of a data breach would be for your organization. Let’s dig into some numbers and add a bit of perspective, shall we?

 

Go to HelpMeWithHIPAA.com/164 for more details.

 


Check out the episode!

Thursday, July 19, 2018

Do you know where your logs are? - Ep 163


Our most downloaded episode Is from way back in May of 2016.  HIPAA Access Logs Audits was our 54th episode. It is hard to believe it was that long ago!  Today we are doing a deeper dive into how many layers exist when it comes to access logs to see if you have thought of all of them. Which of the logs really matter and what do you do with them?

For more go to HelpMeWithHIPAA.com/163


Check out the episode!

Thursday, July 12, 2018

Messaging Failures Times 3 - Ep 162


We all live in a world that revolves around communication tools today. Messaging failures are often the reason privacy breaches occur. In fact, we have 3 to share with you today. Messaging failures can occur in ways you never dreamed of until it happens to someone you know - not you, of course.  Today’s episode covers 4 different stories about messaging failures.

For more go to HelpMeWithHIPAA.com/162


Check out the episode!

Thursday, July 5, 2018

MD Anderson Loses OCR Challenge - Ep 161


OCR continues setting examples with the recent announcement of the $4,348,000 civil money penalty (CMP) that they imposed on MD Anderson.  A review of the details shows us once again that the enforcement of HIPAA obligations is not something they decide to do in a willy-nilly way.  It is specific and designed to set examples of what is expected. Most headlines are about that $4.3 million in penalties but to us, that is not what is the most interesting and important thing to note in this case. 

More at HelpMeWithHIPAA.com/161


Check out the episode!

Thursday, June 28, 2018

Managing Medical Devices - 4 steps plus a bonus - Ep 160


Medical device inventory is a challenge for most organizations.  Just as with computers and mobile devices, though, you can’t understand your risks and security requirements if you don’t know what you have out there.  A medical device treasure hunt is what it turns out to be when you make a dedicated effort to find them all in your organization. How do you find them all and how do you worry about protecting them all?

More information at HelpMeWithHIPAA.com/160


Check out the episode!

Thursday, June 21, 2018

OCR Investigations - What do they ask - Ep 159


It happens out of the blue.  You get a letter that tells you that there has been a complaint filed and an investigation has been opened by OCR.  That may not be the best day of your life. Just the thought of opening one of those letters can make some people feel queasy.  If you have ever experienced that moment you don’t have it high on your lists of things to do again. Let’s review the kinds of things you may be asked to answer when under and investigation.

For more go to HelpMeWithHIPAA.com/159


Check out the episode!

Thursday, June 14, 2018

Network Security Alerts For Everyone - Ep 158


In the past few weeks, the nerd news has been full of network security alerts and discussions about issues potentially lurking on every network, especially smaller ones.  These are not the things we normally worry about either. You usually think Windows, Office, Adobe, etc patches are the main alerts to worry about on your network. These are new alerts that could be in every network you use including home, public wifi, and work. Per usual, we are here to explain them as best we can - in English.  Tech folks you should listen up to what we expect you to be doing for our listeners who rely on you, too.

For more information go to HelpMeWithHIPAA.com/158

 

 


Check out the episode!

Thursday, June 7, 2018

Cyber Experts Agree We Are Not Alone - Ep 157


Secureworld Atlanta just finished up.  Turns out cyber experts do agree about many of the same issues we discuss here.  Two days of discussions amongst CISOs, ISOs, security techies, etc. about what to worry about and what to do for cyber protections.  Yes, there was a lot of really nerdy discussions but the good news is the central themes do not require geek speak to share with you.

Learn more at HelpMeWithHIPAA.com/157


Check out the episode!

Thursday, May 31, 2018

What data do you protect? - Ep 156


Have you considered that there are other valuable information assets to protect than just PHI?  Most healthcare privacy and security programs only focus on PHI and HIPAA requirements. If you are already doing the work why not include all of your valuable information assets.  It is time to ask yourself what data should we protect?

 

For more go to HelpMeWithHIPAA.com/156


Check out the episode!

Thursday, May 24, 2018

Digital Spring Cleaning - Ep 155


This time of year many of us think about cleaning out closets and switching seasons.  By clearing out your digital clutter you can double check the security of your devices and reduce your attack surface at the same time.  Plus, it is way easier than cleaning out the old hall closet that may have monsters lurking in the back of it.  Make the time to clean your digital clutter at least once or twice a year and you will feel better for it.  Why not do digital spring cleaning, too?

For more go to HelpMeWithHIPAA.com/155


Check out the episode!

Thursday, May 17, 2018

Risk OR Gap Analysis THAT Is The Question - Ep 154


There is a frequent issue with people understanding what a Security Risk Analysis includes. In fact, there is so much confusion we often see documents presented as a risk analysis that is actually a gap analysis. It happens so often that OCR is trying to address it in their April newsletter. We are going to take a stab at explaining what gap analysis reports look like vs what a security risk analysis report really includes when done properly.

For more information: HelpMeWithHIPAA.com/154


Check out the episode!

Thursday, May 10, 2018

5 HIPAA Cybersecurity Laws - Ep 153


Back in January, I read an article in Forbes titled: The Five Laws Of Cybersecurity.  When reading it I realized that it was a great message to our listeners but it needed a HIPAA flavor added it to it.  This episode we add our thoughts to his article and turn it into 5 Laws of HIPAA Cybersecurity.

For more details HelpMeWithHIPAA.com/153


Check out the episode!

Thursday, May 3, 2018

Don't accept candy from strangers - Ep 152


More news on the insider front makes it necessary to point out, again, how susceptible healthcare is to insider failures.

HelpMeWithHIPAA.com/152


Check out the episode!

Thursday, April 26, 2018

Physicians and Security Officers - Ep 151


The American Medical Association (AMA) did a survey of physicians and their thoughts about privacy and security practices. It was interesting to hear their responses. Also, when a group of Security Officers gets together for a chat some people glaze over.  For nerds like us, it is an exciting discussion. Today we are going to discuss the Security Officer panel topics and the AMA report presentation from the National HIPAA Summit.

HelpMeWithHIPAA.com/151


Check out the episode!

Thursday, April 19, 2018

Ready for extreme vendor vetting? - Ep 150


Are you ready for extreme vendor vetting? Many vendors have been pushing back against any covered entity or business associate that asked them to answer questions about their privacy and security programs. They believe signing a business associate agreement (BAA) meets the legal requirements and that is all they must do. Well, the times they are a changing - again.  There are many different factors making it necessary to ask these type questions and not just accept a BAA as reasonable assurances. What are those factors and how things are changing are the topics we discuss in this episode.

 

For more go to HelpMeWithHIPAA.com/150


Check out the episode!

Thursday, April 12, 2018

National HIPAA Summit News - Ep 149


The National HIPAA Summit always features some interesting news from OCR concerning guidance, enforcement, and audits.  This year was no different. In this episode, we discuss the highlights as we interpreted them anyway.

More at HelpMeWithHIPAA.com/149


Check out the episode!

Thursday, April 5, 2018

Cyberscary Trends - Ep 148


Cybersecurity trends sound scary when you hear us talk about some of this stuff.  Cyberscary is actually what we decided to call it.  The good news is we do talk about other things sometimes. There are two reports that came out in recent weeks have gotten my attention and just have to be discussed with you guys.

More info at HelpMeWithHIPAA.com/148


Check out the episode!

Thursday, March 29, 2018

Cybersecurity And The Law - Ep 147


Cybersecurity legal requirements keep changing at the state, federal, and international level.  Most of the changes are just trying to keep up with the constantly changing landscape of threats in cyberspace. Today we call in an expert, Mitzi Hill, to talk to us about those cybersecurity legal requirements.  How those changes may impact your business and your privacy and security program is certainly something we don’t want to lose track of in the mix.

More information at HelpMeWithHIPAA.com/147


Check out the episode!

Thursday, March 22, 2018

6 Listener Questions - Ep 146


We get questions from listeners on a pretty regular basis.  When they come in from an email we do our best to reply with an answer.  Sometimes they get backed up for us to get them on the show, however. Today we are covering some of those, in fact, we are covering 6 listener questions.

HelpMeWithHIPAA.com/146


Check out the episode!

Thursday, March 15, 2018

Uber Health HIPAA - Ep 145


News abounds about Uber and other ride-sharing services taking people to their doctor appointments.  They say they have it covered and Uber Health HIPAA compliance is solid. Today we look at what they are saying about HIPAA here and what that means to us.

More info at HelpMeWithHIPAA.com/145


Check out the episode!

Thursday, March 1, 2018

Cyber issues around every corner - Ep 143


If it seems like cyber issues are around every corner these days, you aren’t imagining things. In episode 128 way back in November 2017, we discussed the fact that we thought there were signs of a coming cyber storm. Today we look at what is going on and see if we may actually be in the midst of that storm or is it still building.

For more: HelpMeWithHIPAA.com/143


Check out the episode!

Thursday, February 22, 2018

Do I Need A Lawyer? - Ep 142


Information privacy and security requirements in various laws are coming up in legal cases more often these days.  Part of that is because we have more of those type laws. Although HIPAA has been in effect for over a decade, I don’t recall seeing it used in lawsuits and legal cases as frequently as I do now.  Maybe I am just paying more attention but there are certainly plenty of cases in the courts today.  Most are civil cases but some are even criminal cases.  After hearing these you will probably know the answer to the question “Do I need a lawyer”.   Probably, maybe, that is a fact-specific determination.  Honestly, though, the answer is you probably will if you are not taking information privacy and security seriously today.

More at HelpMeWithHIPAA.com/142


Check out the episode!

Thursday, February 15, 2018

5 Breaches Equals 1 Big Settlement - Ep 141


As expected, OCR has continued to announce enforcement actions in 2018.  This one is a bit different than any previous resolution in that there are 5 different cases across multiple locations in a single organization. It is also important to note that all 5 of these issues data back to 2012.  Almost 6 years since the first one occurred, we have the resolution agreement.

 

HelpMeWithHIPAA.com/141


Check out the episode!

Thursday, February 8, 2018

HIPAA Made Easy? - Ep 140


HIPAA made easy is a topic we have discussed many times before but today we are going to cover it specifically.  So often we get requests for the “easiest way” to do HIPAA. This isn’t something to check off a list and have it done. It is something that you do every day as part of your business. The idea that you can make HIPAA easy is similar to saying that doing all of your accounting and taxes for your business is easy.  Maybe if there is one person to pay and that is you but handling your finances correctly isn’t something many people find easy. Yes, the data can be gathered and entered into systems.  But, do you know all the forms to complete, documents to save, follow up to do, classifications to determine, etc.  It isn’t easy but it is doable.  So is HIPAA.  

 

For more HelpMeWithHIPAA.com/140


Check out the episode!

Thursday, February 1, 2018

6 Cybersecurity Lessons In The News - Ep 139


Cybersecurity is in the news a lot lately. Particularly a lot of news just since the beginning of the year. As usual, we review all the news looking for important things to share with our clients and listeners.  There are just so many different stories to choose from this week, we decided to cover several of them in one episode.  So, here are 6 cybersecurity lessons in the news. Some of them may be things you saw before but all of them were worth discussing what we should be aware of and learn from all the information coming in for 2018.

For more go to HelpMeWithHIPAA.com/139


Check out the episode!

Thursday, January 25, 2018

Cybersecurity Outside The Office - Ep 138


In December, the OCR newsletter was titled Cybersecurity While on Holiday.  First, how very British of them!  Second, is it just when on holiday?  The same rules apply anytime you are on the road with technology and access to the internet.  We see this as something you should review no matter when you plan to access information outside the office.  While some think the corner coffee shop is a great work space others work in hotels and conference rooms all over town without being on holiday at all.  In this episode, we review the suggestions in the newsletter but drill down a bit more into how much of this applies when you are working mobile from home or just down the street as well.  

More at HelpMeWithHIPAA.com/138


Check out the episode!

Thursday, January 18, 2018

OCR Ends 2017 With A Bang - Ep 137


At the beginning of 2017 OCR announced several settlements.  Then, the settlement announcements stopped in May as their were leadership changes that continue to happen.  In fact, the only reason this announcement seemed to come out was because it was included in a bankruptcy court filing earlier this month.  

For more go to HelpMeWithHIPAA.com/137


Check out the episode!

Thursday, January 11, 2018

Meltdown - Patch Baby Patch - Ep 136


Unless you never listen to nerd-speak you have to have heard the discussion about Meltdown and Spectre over the last few weeks. It is a perfect time to talk about what patch management really means in your cybersecurity protections.  We try our best to discuss it with less geek speak and more English.  

For more info HelpMeWithHIPAA.com/136


Check out the episode!

Thursday, January 4, 2018

7 Educated Guesses About 2018 - Ep 135


Here we go for another year!  It is amazing that this is the third new year we have covered on HMWH.  There are so many things that have happened over that time and as we head into 2018, so many things to look into our crystal ball and make 7 educated guesses about 2018.  We may not be predicting the future but we both have some opinions about what we see happening out there in the world of HIPAA, privacy, and cybersecurity in the coming months.

Get more at HelpMeWithHIPAA.com/135


Check out the episode!