Thursday, July 27, 2017

Compliance Officer Personal Liability? - EP 114


There has always been a concern from many people we work with about compliance officer personal liability. Specifically, is a compliance officer personally liable for the compliance of the company?

The recent settlement agreement between the FTC and the Chief Compliance Officer of Moneygram has created interesting conversations for compliance circles. In this case, the Chief Compliance Officer of Moneygram was able to reach a settlement in the liability case against him but it included a $250,000 penalty payment and 3 years restriction on working in that industry. Yep, that is enough to make you sit up and take notice.

More details at HelpMeWithHIPAA.com/114


Check out the episode!

Thursday, July 20, 2017

OCR Mic Drop For Cloud Providers - EP 113


The monthly OCR Cyber Newsletter for June had some interesting points.  The fact that OCR mentions multiple times and in multiple ways that they do not endorse, certify, or recommend specific technology or products should serve as their "OCR mic drop moment" on this discussion.  We can dream, can't we!  Today we are going to review that newsletter and how they have pointed these things out once again.

Before we close out the episode we are also covering some questions and comments from listeners.  Hang around for those just after the 30-minute mark.

More info at HelpMeWithHIPAA.com/113


Check out the episode!

Friday, July 14, 2017

NotPetya, Windows, and Ransomware - Ep 112


This is not another episode about preventing and responding to the NotPetya ransomware. There are countless articles about those topics.  We are discussing the bigger picture today.  In this episode, NotPetya, Windows, and Ransomware, we discuss what happened in the case but also what does all of this really mean in the big picture of cyber attacks.  If you don't stay proactive in evaluating what the criminals may do next then you don't have a chance of being anything but reactive.

In light of these recent global attacks, we have many questions.  Are we experiencing a shift in the criminal's intentions or are they just bumbling around with new toys?  If is it no longer just about taking our money then what is really about?  If you haven't cared about protecting your data so far, how about protecting your data from becoming a pawn in the latest cyberwarfare battle?

For more information go to HelpMeWithHIPAA.com/112


Check out the episode!

Thursday, July 13, 2017

Breach reporting costs and decisions for 2017 - Ep 111


In June, the NY State Attorney General announced a settlement with CoPilot, a healthcare services company that illegally deferred notice of breach of more than 220,000 patient records.  Another annual report was also just released with the latest numbers : 2017 Cost of a Data Breach Study from Ponemon Institute and IBM.  Today, we are going to discuss how the two of them can help us all make better decisions where potential breaches of PHI are concerned.  Breach reporting costs and decisions in 2017 are proving to be something you should understand before a crisis, not after one hits.

For more info: HelpMeWithHIPAA.com/111


Check out the episode!

Thursday, June 29, 2017

What is MDM and why do I want it? - Ep 110


Mobile devices are susceptible to malware attacks, phishing, and other security vulnerabilities just the same as laptops and desktops.  The systems most of us have in place are directed at managing the security for laptops and desktops, however.  It is important to expand your security controls to address the growing threat that mobile devices introduce to your network and systems regularly.  

In most cases, it is important to have a "home base" tool that can talk to and monitor the mobile devices.  That is where MDM comes into play.  For most people that brings us to the question: What is MDM and why do I want it?

 

For more: HelpMeWithHIPAA.com/110


Check out the episode!

Friday, June 23, 2017

eCW Whistleblower Made The Difference - Ep 109


There are countless times we have covered the "my EHR vendor handles HIPAA for me" misconception. The recent $155 million whistleblower lawsuit settlement between eClinicalWorks (eCW) and the government really brings it home how wrong you can be about EHR vendors.

Meaningful Use attestations relied heavily on the vendors supplying proper information. eCW set up thousands of organizations to take a major hit based on the details in this case and it's settlement. Especially, when you take into account that eCW is one of the biggest EHR vendors out there.

CIA of PHI is the objective of the entire Security Rule under HIPAA. Unreliable data created by an application is clearly a data Integrity issue. If you can't trust the data can you trust the system at all?

If you have knowledge of this kind of stuff going on somewhere you should review it closely. It includes civil payments by developers and project managers not just the C-Suite folks involved.

 

For more information: HelpMeWithHIPAA.com/109


Check out the latest episode!

Friday, June 16, 2017

5 Stages Of Grief During A Cyber Attack - Ep 108


The 5 stages of grief during a cyber attack really do follow the process of dealing with grief in those familiar 5 stages. Many don't realize that ransomware attacks aren't always just the result of someone clicking in an email and running a program.  As Erie County Medical Center found out recently, ransomware attacks can come from a hacker being active in your network too.  Those 5 stages of grief during a cyber attack for them and others we have seen is what we will be discussing today.  

We have a special guest with us for today's discussion too.  David Benton with Altep is joining us.  David is a super IT forensics dude.  The CSI of the nerds, so to speak.  He is helping us review this topic.

More information at HelpMeWithHIPAA.com/108


Check out the latest episode!