Friday, December 16, 2016

HIPAA 21st Century Cures Act - Ep 83


For a change there was a bipartisan bill passed with some big impacts on healthcare.  HIPAA 21st Century Cures Act implications are, of course, our focus.  Today, we review some thoughts on the bill that was signed into law this week.

More notes at https://HelpMeWithHIPAA.com/83


Check out the latest episode!

Tuesday, December 13, 2016

OCR Phishing And More Announcements - Ep 82


Recorded during our first live broadcast, this episode covers several OCR announcements.  We start with the OCR phishing alert.  Followed by that we discuss OCR's guidance that said you should consider multi-factor authentication in your risk analysis.  

There have also been more resolution agreements that we haven't covered on an episode so we hit those, as well.

 

Since it was a live show we also take some questions!

For more: https://HelpMeWithHIPAA.com/82


Check out the latest episode!

Friday, December 2, 2016

Phishing Attacks In Healthcare - Ep 81


Phishing attacks in healthcare are on the rise just like every other industry. However, unlike many other targets, phishing attacks in healthcare have a much higher return on investment if the phisherman gets anyone to take the bait. We've talked multiple times how healthcare is now a major target for hackers. Then, it only makes sense that we will see a continued rise in efforts aimed at phishing attacks in healthcare.


Types of phishing:

  • Phishing - spray and pray - grab an email list and let it rip - big net phishing
  • Spear phishing - Aimed directly at you. Everything makes it look like it should be in your email meant for you from someone you know
  • Whaling - Pointed directly at upper management of a company with an urgent business matter
  • Soft targeting - send to people with a certain job that they would expect, like HR gets a resume but financial team gets a spreadsheet
  • Telephone phishing - Just call you up and act like they should be asking you for login information

 For more info: https://HelpMeWithHIPAA.com/81


Check out the latest episode!

Friday, November 25, 2016

Ep 81 Is Being Held For Ransom


We are holding episode 81 for ransom during the Thanksgiving holiday.  For our black Friday episode we hope you enjoy this replay of our most popular episode.

Stay tuned! Episode 81 will be released next Friday.  We will be discussing the different types of phishing, how they work and how you can resist the bait.


Check out the latest episode!

Friday, November 18, 2016

HIPAA Compliant Cloud - Ep 80


In early Oct the long awaited guidance on HIPAA Compliant Cloud was released by HHS / OCR. There wasn't a lot of shocking information for us since it just restated, maybe more clearly, that cloud services providers (CSPs) must sign a BAA and meet certain obligations as a BA.

Hopefully, this will address all the cases where some CSPs would use "slight of hand" with phrasing to claim they didn't have to be a HIPAA compliance cloud provider. The amount of "all ya gotta do is" type of misinformation only makes things harder to get done. Let's look at what the guidance addressed.

 

For more details go to HelpMeWithHIPAA.com/80


Check out the latest episode!

Friday, November 11, 2016

OCR Audits and Enforcement 2016 - Ep 79


This week is basically part 2 from last week.  We left off just before reviewing the OCR audits and enforcement updates announced at the NIST / OCR Security Conference 2016.  

Get more details at HelpMeWithHIPAA.com/79


Check out the latest episode!

Friday, November 4, 2016

HIPAA Security Conference 2016 - Ep 78


Donna shares information from the 2016 NIST/OCR Annual Conference on Safeguarding Healthcare Information.

Learn what she thought was interesting to share with you.

 

More information at https://HelpMeWithHIPAA.com/78


Check out the latest episode!