Thursday, December 31, 2020

Cyber Attacks Will Get Worse In 2021 - Ep 285


A hospital President, after being hit by a cyber attack, said “We really did not anticipate the scope or the impact the attack had on our system and how far-reaching it was.”

This is just the beginning.  Get prepared for more to come. Especially, with the success of the major SolarWinds infiltration. We knew things were getting worse weeks ago when we recorded this one. Where do we see things going?

More at HelpMeWithHIPAA.com/285


Check out the episode!

Thursday, December 24, 2020

2020 Blooper Show


What a year it has been! Say what you will but none of us will EVER forget living through 2020. As we have all adjusted throughout the year we appreciate everyone's continued support of our efforts to educate and entertain.

As is our custom, our editor, Bojan, gets his annual 15 minutes of fame.  Enjoy his year end Blooper Show edition that gives us a week off and gives him a chance to get back at us for the whole year of crap.

More data privacy and security madness coming your way next year which is actually next week!  Happy Holidays, Happy New Year, and Happy End of 2020!


Check out the episode!

Thursday, December 17, 2020

Erik Decker - HICP and Cybersecurity Outlook - Ep 284


The value of the HICP guides is really beginning to be realized as we approach the 2nd anniversary of it's release. Erik Decker, Chief Information Security Officer and Chief Privacy Officer, University of Chicago Medical Center (and 405d Task Force industry lead and co-chair) was kind enough to join us again to discuss what's coming next for HICP and what he sees in healthcare cybersecurity management as we head into 2021.

More at HelpMeWithHIPAA.com/284


Check out the episode!

Thursday, December 10, 2020

Get off the sidewalk! - Ep 283


Amazon is rolling out a new “feature” called Sidewalk. If you have any Alexa devices or certain Ring devices on a network we say get off the Sidewalk! At least until you figure out how it can be secured.

More at HelpMeWithHIPAA.com/283


Check out the episode!

Thursday, December 3, 2020

What About Information Blocking? - Ep 282


With so much going on this year things that would have been big news are slipping by with little notice. Back in 2016 The 21st Century Cures Act was passed which included a lot of healthcare IT updates to improve patient access to their information. A specific section was all about how to prevent information blocking. What is it, why do you care and when will things happen? That’s the topic today.

More at HelpMeWithHIPAA.com/282


Check out the episode!

Thursday, November 26, 2020

Thanksgiving 2020: Replay of 2020 Predictions


Each year we take the week off on Thanksgiving and share a replay of an episode we want to share. This year it seemed appropriate to share our original predictions for 2020 that we did just before the world turned upside down with a pandemic.

In a few weeks we will evaluate how we did but for now, catch up on how naive we all were just a few months ago.


Check out the episode!

Thursday, November 19, 2020

Vendors included in lawsuits - Ep 281


Just because a story isn’t about healthcare or HIPAA doesn’t mean they don’t offer some important news for folks in healthcare to take note. Marriott and Zoom cybersecurity cases were just in the news. We all need to take note of them and pay close attention to what happened. Oh, and there is a new one in healthcare that does include a vendor.

More info at HelpMeWithHIPAA.com/281


Check out the episode!

Thursday, November 12, 2020

Enforcement, Ransomware, and More - Ep 280


Every time we think we get ahead of the current news more things happen! More enforcement news, more ransomware specific warnings, more cyber threats to worry about. Let’s get to it! 

More info at HelpMeWithHIPAA.com/280


Check out the episode!

Thursday, November 5, 2020

Effective Communication Skills Matter - Tamika Bass - Ep 279


Tamika Bass joins us today to discuss the importance of effective communication skills. We have spent a lot of time discussing that it is everyone’s responsibility to participate in cybersecurity protections. One big issue in making that happen is to have tech teams communicate effectively with non-tech teams. As Tamika says “if there is no understanding then communication didn’t happen”.

More info at HelpMeWithHIPAA.com/279


Check out the episode!

Thursday, October 29, 2020

Cyber Halloween Party - Ep 278


Hard to believe that we are rolling out our 6th Halloween episode! This year you get to help figure out the costumes at the network office party. Can you guess what all the cyber costumes are saying?

More notes at HelpMeWithHIPAA.com/278


Check out the episode!

Thursday, October 22, 2020

Right of Access Round 9 + Connected Devices - Ep 277


More HIPAA COVID examples, another OCR action announced and it is the last week of Cybersecurity Awareness Month. Time to get informed and #BeCyberSmart about connected devices.

More info at HelpMeWithHIPAA.com/277


Check out the episode!

Thursday, October 15, 2020

OCR Drops More + NCSAM Week 3 Healthcare - Ep 276


We get to week 3 of #BeCyberSmart NCSAM. We had no idea when we made this plan that OCR would start dropping settlements at the same time. After a pretty quiet year they announced more settlements in September than they ever had in a single month before. Again, we have a lot to review! Reminds me of one of my favorite movie quotes:

“Life moves pretty fast. If you don't stop and look around once in a while, you could miss it.”  Ferris Bueller

More info at HelpMeWithHIPAA.com/276


Check out the episode!

Thursday, October 8, 2020

Athens Ortho Settlement + NCSAM Week 2 - Ep 275


Our commitment to include #BeCyberSmart each week this month did not anticipate that OCR would set a record for resolution announcements in September. This week we give you info to plan for next week’s activities for NCSAM plus a review of the Athens Orthopedic resolution agreement. A lot to cover!

More at HelpMeWithHIPAA.com/275


Check out the episode!

Thursday, October 1, 2020

If You Connect It. Protect It. - Ep 274


The first week of National Cybersecurity Awareness Month (NCSAM) 2020 is next week. The theme: If You Connect It, Protect It. How can you use it in your organization? We cover that plus OCR’s 5 resolutions in one announcement reiterating their commitment to patient access rights.

For more info: HelpMeWithHIPAA.com/274


Check out the episode!

Thursday, September 24, 2020

NCSAM Kick-Off starts next week - Ep 273


We missed the boat on National Insider Threat Awareness month in Sept: Insider Threat Mitigation but we are not going to miss NCSAM this year. Do Your Part. #BeCyberSmart and If You Connect It, Protect It. are going to be all over the place here in October.

More at HelpMeWithHIPAA.com/273


Check out the episode!

Thursday, September 17, 2020

HIPAA changes coming in 2020? - Ep 272


There is so much going on right now it is hard to keep up. I know there is a lot of activity when we can’t keep an eye on everything! There are several stories that I think we should all be aware of but the big headline one is about HIPAA changes coming in 2020. However, it isn’t the only one about changes that you should be aware of also.

More info at HelpMeWithHIPAA.com/272


Check out the episode!

Thursday, September 10, 2020

Cybersecurity Tales with Gary Salman Part 2 - Ep 271


This episode is the continuation of our Cybersecurity Tales Part 1 last week. We get into more discussions about real world cases involving cyber attacks the team at Black Talon have been called for data breach response. This part is where David really started getting scared!

More info at HelpMeWithHIPAA.com/271


Check out the episode!

Thursday, September 3, 2020

Cybersecurity Tales with Gary Salman Part 1 - Ep 270


Recently we talked with Gary Salman, CEO of Black Talon Security. Our discussion was lively and full of great stories and tips. There was so much there we decided to break this into two episodes. This is part 1 and next week we will share part 2. Let’s get started on cybersecurity tales!

More at HelpMeWithHIPAA.com/270


Check out the episode!

Thursday, August 27, 2020

Ten Cyber Myths Reviewed - Ep 269


After teaching our 3-day HIPAA Boot Camp we were pretty exhausted. In this episode we are discussing the interesting things David found when reading articles about cybersecurity myths. 

More info at HelpMeWithHIPAA.com/269


Check out the episode!

Thursday, August 20, 2020

Here Comes Trouble - Ep 268


Today we are going to cover what we expected to see start happening after the rush to convert us all to work from home. The discussions about our concern that no one was paying attention except the criminals is starting to come to fruition. 

More info at HelpMeWithHIPAA.com/268


Check out the episode!

Thursday, August 13, 2020

Data Breach Costs Continue Rising - Ep 267


Everywhere we turn this year we are dealing with chaos and stress. Can we all just sing Kumbaya and make it go away? If it was only that easy.   Just because craziness has happened doesn't mean HIPAA goes out the window. As we all try to navigate the unknown we can not forget that the criminals thrive on chaos like this. If you aren’t protecting your information a data breach becomes almost inevitable. It is important to understand the data breach costs you are looking at when one occurs.

More info at HelpMeWithHIPAA.com/267


Check out the episode!

Thursday, August 6, 2020

No More Guessing What OCR Expects - Ep 266


These new settlements from OCR should be new required reading. There is very little guessing about their expectations in these CAPs. Specifically mentioning encryption requirements and mobile device management is not ambiguous at all. Things are getting real folks!

More info at HelpMeWithHIPAA.com/266


Check out the episode!

Thursday, July 30, 2020

Enforcement and More News - Ep 265


There are plenty of things happening that you should be aware of including a new settlement announcement from OCR. This and more things happening out there you should know about!

More info at HelpMeWithHIPAA.com/265


Check out the episode!

Thursday, July 23, 2020

Free Security Awareness Training - Ep 264


So happy that we are finally doing this show in time to remind you to use the free security awareness training resources available for October which is National Cybersecurity Awareness Month (NCSAM). There are a lot of free resources available to promote security awareness under that program released each year. Today we are discussing how to use these resources to  work out a plan for your training through out October!  

More at HelpMeWithHIPAA.com/264

 


Check out the episode!

Thursday, July 16, 2020

Ransomware - MSPs and Insurance - Ep 263


The threat of ransomware continues to be a major issue for all businesses. MSPs were a gateway for mass cyber attacks in 2019. Make sure your IT provider is using the new guide specifically for them produced by NIST and NCCoE: PROTECTING DATA FROM RANSOMWARE AND OTHER DATA LOSS EVENTS. While we are at it there are a couple of articles relating to ransomware’s impact on insurance coverage that we need to bring to your attention.

More at HelpMeWithHIPAA.com/263


Check out the episode!

Thursday, July 9, 2020

2020 Data breach stats good news and not - Ep 262


The annual Verizon data breach report was recently released for 2020. Learning from other’s mistakes is always the best way to learn vs the alternatives. These reports always offer very specific details that we find very enlightening and helpful in making business decisions relating to security in all businesses.

More at HelpMeWithHIPAA.com/262


Check out the episode!

Thursday, July 2, 2020

COVID-19 Testing vs HIPAA - Ep 261


COVID-19 Testing vs HIPAA is starting to play out all over the country as businesses reopen and the virus continues to spread. Today we will discuss some of the confusion about all the COVID-19 testing and HIPAA.

More at HelpMeWithHIPAA.com/261


Check out the episode!

Thursday, June 25, 2020

No one is watching the hen house - Ep 260


So far 2020 has the whole world turned upside down. A true global pandemic, global economic fallout still happening from a shutdown caused by the pandemic and a level of global social unrest that hasn’t been seen in 40-50 years. Yes, it is overwhelming. But, it is also very clear that the criminal factors and nation-state attackers are well aware no one is watching the hen house too.

More info at HelpMeWithHIPAA.com/260


Check out the episode!

Thursday, June 18, 2020

It Is Everyone's Responsibility - Ep 259


Too often our human selves will happily put off some responsibilities on others if we can find any small reason for doing so. It may not be our best quality but it is certainly one that bonds most of us together. I personally can’t name anyone that would say sorry I would like to take responsibility for something I think is your responsibility. In our world today we all need to take responsibility for helping protect the group as a whole. The NICE team from NIST published something about just that when it comes to cybersecurity. Time to get ready to discuss it is everyone’s responsibility, not just a select few.

More at HelpMeWithHIPAA.com/259


Check out the episode!

Thursday, June 11, 2020

Cyberattacks coming from inside the network - Ep 258


If you are a fan of horror flicks you know the story. Even if you are not a fan you probably know the line from When A Stranger Calls:  “the calls are coming from a phone inside the house”.  That stuff happens in the opening. Personally, I have never made it through that part much less through the whole thing.  Today we have a whole new horror flick to discuss: cyberattacks coming from inside the network.  Maybe we should hold this until Halloween but who knows what will happen then, we need to cover this because it is happening now.


Check out the episode!

Thursday, June 4, 2020

New Tactical Crisis Response Guide- Ep 257


Perfect timing rarely happens these days but we have been discussing updating incident response plans based on what we have learned in the last two months. In fact, we ended our last episode saying the response plan update is one of the most important things you should do. Like magic Erik Decker posts on LinkedIn this week that the HIC group has finished a new guide specifically about crisis response.

More info at HelpMeWithHIPAA.com/257


Check out the episode!

Thursday, May 28, 2020

HIPAA Privacy Rights Still Exist - Ep 256


We always know when serious stuff has happened behind the scenes and OCR got involved. Some major violations of privacy rights must have happened when we see the OCR notice reminding everyone that you can not share patient information with the media without authorization.

More info at HelpMeWithHIPAA.com/256


Check out the episode!

Thursday, May 21, 2020

Reboot Checklist - Ep 255


We mentioned in the last episode that we would put together a checklist of sorts for what to do as everyone switches back to the old way of doing business or sets up under new remote models. While this isn’t exactly a copy and paste checklist it does give you food for thought as to what to consider for your own reboot checklist.

More at HelpMeWithHIPAA.com/255


Check out the episode!

Thursday, May 14, 2020

New Ransomware Concerns - Ep 254


When can we stop talking about ransomware? Apparently, never. One of the things we can list as part of our “new normal” is new ways ransomware is going to be impacting us differently. Things are worse today than when we discussed ransomware just a couple of months ago. The pandemic has opened up so many ways for the criminals to attack they are having a field day.

More at HelpMeWithHIPAA.com/254


Check out the episode!

Thursday, May 7, 2020

Rethink Threat Lists Post COVID-19 - Ep 253


Like it or not we have to face new realities on our threat lists as we figure out our new normal in the post COVID-19 landscape. The privacy and security risks have changed just like everything else during the crisis. Threat lists used for your SRA must be updated and addressed. You do not want to be hit with data breaches and privacy breaches just as you get things back up and running, do you?

More at HelpMeWithHIPAA.com/253


Check out the episode!

Thursday, April 30, 2020

Evaluating MSPs - Ep 252


Before things went all COVID on us this episode was planned out. It may be even more worthy of an episode now. Have you been evaluating your MSPs response to your current state of business? We knew there were some MSP issues in 2019 but now, in 2020, you must have a reliable trusted MSP partner more than ever. What kinds of things do you need to know about your tech needs, your MSP and where you both plan for the future?

More at HelpMeWithHIPAA.com/252


Check out the episode!

Thursday, April 23, 2020

Coronavirus Scams Galore - Ep 251


So many scams and so little time to keep up with them.  Yes, that is what it feels like these days.  There are so many coronavirus scams we have to take some time to update you guys.  There have been cybercrime alerts and stupid people stories galore.  Here are the coronavirus scams and crimes we have on our radar this week.  

More at HelpMeWithHIPAA.com/251


Check out the episode!

Thursday, April 16, 2020

3 Cyber stories we are watching - Ep 250


With the national crisis still in play, cybersecurity is essential to operating businesses which are now online more than ever before. Small businesses without any apps before are going online to survive. Telehealth, remote learning, telework are all standard right now.  With so much going on we are trying to keep our eye on cyber stories to prepare ourselves and our clients for what is happening out there. Today let’s discuss 3 cyber stories we are watching right now.

More at HelpMeWithHIPAA.com/250


Check out the episode!

Thursday, April 9, 2020

Crisis HIPAA Updates - Ep 249


There is a lot of confusion along the way as there always will be in a crisis like this one. We are going to share some of the good information and do our best to clear up some of the misinformation. No matter what, though, it could all change in the two short weeks between when we record this and when we publish it for you guys. Our plan is to provide as much solid information that we know to be true and accurate today.

More at HelpMeWithHIPAA.com/249


Check out the episode!

Thursday, April 2, 2020

How do we reboot our business? - Ep 248


We are all doing our best to focus on what we can do during this national crisis.  It is certain that we will bounce back at some point and be able to get back to business.  When we do this national reboot, what kinds of things will we need to do? Spend time now planning for the coming business reboot. 

More at HelpMeWithHIPAA.com/248


Check out the episode!

Thursday, March 26, 2020

HIC SCRiM Should Wake Up Vendors - Ep 247


In Oct 2019 another document was released by the Health Sector Coordinating Council Joint Cybersecurity Working Group.  Health Industry Cybersecurity Supply Chain Risk Management Guide or HIC SCRiM for short is aimed at helping small and medium sized healthcare organizations manage their supply chain vendors. If you haven’t had a chance to check it out, we are reviewing it for you today.  If you do review it you will see why we think that HIC SCRiM should wake up vendors.

More info at HelpMeWithHIPAA.com/247


Check out the episode!

Thursday, March 19, 2020

No SRA First 2020 OCR Enforcement - Ep 246


Opening the 2020 enforcement list for OCR is a doctor’s office who reported a breach due to a business associate issue and then did nothing.  The settlement wasn’t due to the BA but because the office had no SRA in place. Let’s break down the settlement with Steven A. Porter, M.D., P.C. a sole gastroenterologist practice in Ogden, UT. Time to learn from their mistakes.

More at HelpMeWithHIPAA.com/246


Check out the episode!

Thursday, March 12, 2020

Privacy, Security, and COVID-19 - Ep 245


Does your SRA include something like COVID-19?  Your business continuity plans include it? Do you need an SRA that includes virus outbreaks? Yes, you do.  If your risk analysis didn’t include these kinds of things you should revisit your method for doing an SRA. What should you do about this risk and what else is missing from your SRA? Let’s talk about privacy, security and COVID-19.

More info at HelpMeWithHIPAA.com/245


Check out the episode!

Thursday, March 5, 2020

HMWH EPISODE 244 10 CYBERSECURITY MISCONCEPTIONS V4


Cybersecurity misconceptions are pretty common both in personal life and business.  There are definitely enough cases of misinformation coming through our offices on a regular basis to make it obvious just how confused people can be about what should be done.  We have pointed out many times that the government has been releasing information for years to assist both businesses and individuals. You can find a lot of information that is very helpful at StaySafeOnline.org.  Today we are going to discuss one directed at SMBs explaining several cybersecurity misconceptions.

More at HelpMeWithHIPAA.com/244


Check out the episode!

Thursday, February 27, 2020

Images Exposed - Ep 243


This story has been going around since September 2019. Images exposed on the internet from PACS systems around the world available to anyone that wanted to see them.  Images exposed included x-rays, MRI scans and more. It still hasn’t been locked down after all these months. That means it’s time to talk about it instead of keeping it quiet.

More info at HelpMeWithHIPAA.com/243


Check out the episode!

Thursday, February 20, 2020

Insider Issues 2020 - Ep 242


Another report comes out that says insiders are a huge problem.  You have to worry about the people, people. We have been saying this for years.  The lastest news on that front is in the 2020 Cost Of Insider Threats Global Report released by the Ponemon Institute and sponsored by ObserveIT and IBM.  It does tell us a lot of things we already knew but the details including those about how it is growing are important to note.

More info at HelpMeWithHIPAA.com/242


Check out the episode!

Thursday, February 13, 2020

Wearables Plus More HIPAA Questions - Ep 241


Wearables, medical devices and HIPAA are just some of the questions we have gotten recently.  Today’s episode is privacy and security news plus listener questions.

More at HelpMeWithHIPAA.com/241


Check out the episode!

Thursday, February 6, 2020

HIPAA Ambiguous? Really? - Ep 240


Is HIPAA ambiguous? That is the way many people refer to anything that has to do with HIPAA regulations. It comes from doctors, nurses, lawyers, managers, supervisors, even compliance officers. But, is it really the way we should refer to the law? Should we say it is flexible or reasonable instead?

More at HelpMeWithHIPAA.com/240


Check out the episode!

Thursday, January 30, 2020

Why Security Patching Matters - Ep 239


There have been a lot of headlines lately about Windows 7 end of life and Windows 10 security patches.  Let’s discuss why supported software and security patching matters in general. Then, we can talk about why it matters under HIPAA.  

More at HelpMeWithHIPAA.com/239


Check out the episode!

Thursday, January 23, 2020

Ransomware Warnings Everywhere - Ep 238


We have mentioned ransomware warnings over and over on HMWH.  To the point ransomware shows up in a search on 56 different episodes before this one.  That means we’ve talked about ransomware warnings in 24% of our episodes. Guess what - clearly we need to talk about it again!

More info at HelpMeWithHIPAA.com/238


Check out the episode!

Thursday, January 16, 2020

Ambulance Company Settlement - Ep 237


As we anticipated there was one more OCR settlement announcement before the end of 2019.  This one popped in at the end of December and was yet another one in our backyard. The ambulance company settlement seemed simple at first but once we read the details there is a lot to unpack in the CAP.  Let’s get to it then!

More info at HelpMeWithHIPAA.com/237


Check out the episode!

Thursday, January 9, 2020

2020 Predictions Sortof - Ep 236


We need to get on the record with our 2020 predictions even if we both agree we have no freaking idea what is going to happen in 2020.  If anyone out there says they honestly believe they have a true beat on it, check them out. We do have a few 2020 predictions that we feel sure enough about to say it outloud to you guys.

More info at HelpMeWithHIPAA.com/236


Check out the episode!

Thursday, January 2, 2020

Costly PHI Mistakes - EP 235


Here we go with two more OCR enforcement settlements.  As we expected, the end of the year included a flurry of enforcement announcements from OCR.  Just as this was about to be recorded they announced the second patient access settlement. So we can we get both done in one episode!  Both of these cases are related to some costly PHI mistakes so let’s get down to business.

More info at HelpMeWithHIPAA.com/235


Check out the episode!