Thursday, August 31, 2017

Should I use a local, data center, or cloud server? - Ep 119


Every time we discuss server security issues it opens a debate about where is the best place to keep your servers.  There are three options and we are going to discuss them today.  Local hosting vs data center hosting vs cloud servers under HIPAA.

For more details HelpMeWithHIPAA.com/119

email us: contact@helpmewithhipaa.com


Check out the episode!

Thursday, August 24, 2017

What is reasonable and appropriate? Ep 118


What is reasonable and appropriate?

The HIPAA legal reference and guidance mentions reasonable and appropriate all over the place. Many times that concept creates confusion. How do you determine what is reasonable or appropriate for any environment?

More at HelpMeWithHIPAA.com/118


Check out the episode!

Wednesday, August 16, 2017

Alexa and HIPAA Plus Other Questions - Ep 117


Can a doctor have Alexa in OR to play music?  

Is it a HIPAA violation for staff to look at their own records or is it an internal policy violation?

I am a small company BA do I really have to do all of HIPAA compliance requirements?

If I know my upstream BA or CE isn't following their HIPAA compliance obligations what am I legally obligated to do?

Why would you make daily copies of your visitor logs?

More info at HelpMeWithHIPAA.com/117


Check out the episode!

Thursday, August 10, 2017

Security Incident Investigations Find More Than Expected - Ep 116


Sometimes following the news lets you find things like security incident investigations with interesting details.  But, these cases were different than most.  Even better than that, we learned how can a fish tank help hackers!  There were just too many parts of these stories that got my attention to pass them up.  When something occurs and the investigation uncovers way more to the story than you normally see we should all learn from them.

More details at HelpMeWithHIPAA.com/116


Check out the episode!

Thursday, August 3, 2017

Incident Response Plans V2 - Ep 115


Incident response plans have been a topic of our show several times. But, these days we just can't get enough of a good thing!

Actually, there is a reason we are covering it in this episode.  I was reviewing a Business Associate Due Diligence from a software provider. In the questionnaire, we always ask if you have a written incident response plan and trained incident response team. They responded Yes, with a comment of "we have an engineering department".

More info at HelpMeWithHIPAA.com/115


Check out the episode!

Thursday, July 27, 2017

Compliance Officer Personal Liability? - EP 114


There has always been a concern from many people we work with about compliance officer personal liability. Specifically, is a compliance officer personally liable for the compliance of the company?

The recent settlement agreement between the FTC and the Chief Compliance Officer of Moneygram has created interesting conversations for compliance circles. In this case, the Chief Compliance Officer of Moneygram was able to reach a settlement in the liability case against him but it included a $250,000 penalty payment and 3 years restriction on working in that industry. Yep, that is enough to make you sit up and take notice.

More details at HelpMeWithHIPAA.com/114


Check out the episode!

Thursday, July 20, 2017

OCR Mic Drop For Cloud Providers - EP 113


The monthly OCR Cyber Newsletter for June had some interesting points.  The fact that OCR mentions multiple times and in multiple ways that they do not endorse, certify, or recommend specific technology or products should serve as their "OCR mic drop moment" on this discussion.  We can dream, can't we!  Today we are going to review that newsletter and how they have pointed these things out once again.

Before we close out the episode we are also covering some questions and comments from listeners.  Hang around for those just after the 30-minute mark.

More info at HelpMeWithHIPAA.com/113


Check out the episode!