Data Breach Today Podcast

Informações:

Sinopsis

Exclusive, insightful audio interviews by our staff with data breach/security leading practitioners and thought-leaders

Episodios

  • What's Inside Washington State's New My Health My Data Act

    15/05/2023

    Organizations of all types have important work ahead to comply with Washington state's new My Health My Data Act, which pertains to any entity - inside or outside the state - that handles health data of consumers in the state, said Cat Kozlowski, attorney at law firm Polsinelli.

  • Closing Privacy 'Loopholes' in Reproductive Healthcare Data

    12/05/2023

    A recently proposed federal rule would prohibit healthcare organizations from disclosing to law enforcement patient information related to obtaining or providing an abortion. If enacted, it will address longstanding loopholes in healthcare privacy, said attorney Kathleen McGee.

  • Checking Out Security Before Using AI Tools in Healthcare

    09/05/2023

    Most healthcare workers don't check security protocols before trying out new generative AI tools such as ChatGPT, putting patient and other sensitive data at risk, said Sean Kennedy of software vendor Salesforce, which recently conducted research on potential security gaps in healthcare settings.

  • Efficient Management of Enterprisewide Data Protection

    08/05/2023

    Over the years, most organizations acquire multiple tools for protecting data but a variety of personnel and policies make it difficult to manage enterprisewide. Skyhigh Security’s Nate Brady says it’s time to look into the latest security service edge and secure access service edge solutions.

  • Why Legacy Medical Systems Are a Growing Concern

    01/05/2023

    Healthcare sector entities' reliance on specialty and legacy equipment, including imaging systems and other gear, continues to present attractive targets for threat actors and a growing risk for medical providers, said Frank Catucci, CTO and head of research at security firm Invicti Security.

  • HHS OCR Leader: Agency Is Cracking Down on Website Trackers

    21/04/2023

    A top HIPAA-enforcement priority for regulators is cracking down on entities that disclose patient information to third parties without permission through the use of website tracking codes, says Melanie Fontes Rainer, director of the Department of Health and Human Services' Office for Civil Rights.

  • Why Health Entities Need to Implement NIST Cyber Framework

    21/04/2023

    Healthcare entities need to think more strategically about managing risk by implementing a robust cybersecurity framework such as the National Institute of Standards and Technology's CSF, said Bob Bastani, cybersecurity adviser at the Department of Health and Human Services.

  • HIPAA Considerations for AI Tool Use in Healthcare Research

    20/04/2023

    The potential use cases for generative AI technology in healthcare appear limitless, but they're weighted with an array of potential privacy, security and HIPAA regulatory issues, says privacy attorney Adam Greene of the law firm Davis Wright Tremaine.

  • Why Aren't 3rd Parties More Transparent About Breaches?

    19/04/2023

    Vendors should be more transparent and faster in communicating when they experience a breach or other security incident that affect clients' data, says Anahi Santiago, CISO at ChristianaCare. "Sometimes we find out about these incidents through our third-party monitoring systems," she said.

  • Emerging Security Concerns About Generative AI in Healthcare

    19/04/2023

    Generative AI tools such as ChatGPT will undoubtedly change the way clinicians and healthcare cybersecurity professionals work, but the use of these technologies come with security, privacy and legal concerns, says Lee Kim of the Healthcare Information Management and Systems Society.

  • Considerations for Building Successful Security Governance

    18/04/2023

    Effective security governance in a healthcare entity is a balancing act that requires sponsorship by top leadership and careful consideration of the concerns of clinicians and others in the organization, according to Eric Liederman and deputy CISO Steven Frank of Kaiser Permanente.

  • Why FDA's New Cyber Device Regs Are a 'Watershed Moment'

    18/04/2023

    The FDA's new cybersecurity policy is a "watershed moment" for the industry, says Kevin Fu of Northeastern University. The agency will soon begin rejecting manufacturers' new medical device submissions that lack detailed cybersecurity measures, which will help ensure uniformity, he says.

  • How New Federal Cyber Resources Can Help Healthcare Entities

    17/04/2023

    New resources released Monday from a high-profile federal advisory group provide insights into the state of healthcare sector preparedness and best practices for dealing with evolving cyberthreats, according to Erik Decker, CISO of Intermountain Healthcare and co-chair of the task force.

  • CISA: Why Healthcare Is No Longer Off-Limits for Attackers

    17/04/2023

    Healthcare entities of all types and sizes could be the next targets of major cybersecurity attacks, said Nitin Natarajan, deputy director of the Cybersecurity and Infrastructure Security Agency. Healthcare firms need to be vigilant against ransomware, DDoS and medical device breaches, he said.

  • Overcoming Federal Sector Compliance Regulation Challenges

    05/04/2023

    The sheer volume of federal regulations in place makes it almost impossible for agencies to monitor and comply with all of them, much less understand the impact of new ones. Nick Graham of Skyhigh Security explores the many compliance challenges - and how to overcome them.

  • How Post-Quantum Encryption Mandates Affect Healthcare

    03/04/2023

    A 3-month-old federal law meant to future-proof federal computers from quantum computer decryption will have an effect on healthcare sector entities, too, says Mac McMillan, founder and CEO emeritus of privacy and security consulting firm CynergisTek.

  • Data Protection: Data Has No Jurisdiction

    17/02/2023

    In this podcast, Rodman Ramezanian, global cloud threat lead at Skyhigh Security, discusses why the risk of data breaches is so high, how security teams can protect data wherever it resides, and why security leaders should embrace a new mindset for data protection.

  • Showing Evidence of 'Recognized Security Practices'

    11/02/2023

    Healthcare entities and their vendors should be prepared to show evidence to regulators of how they've implemented "recognized security practices," or RSPs, says Robert Booker, chief strategy officer of HITRUST. "You've got to demonstrate that you align with a framework."

  • Craig Box of ARMO on Kubernetes and Complexity

    08/02/2023

    In this episode of "Cybersecurity Unplugged," Craig Box, vice president of open source and community at ARMO, discusses the complexity of using Kubernetes in a hybrid cloud environment, the need to understand "how these moving parts work together" and potential use of Kubernetes with 5G.

  • Are We Doomed? Not If We Focus on Cyber Resilience

    30/01/2023

    In this episode of "Cybersecurity Unplugged," Patricia Muoio, a partner at SineWave Ventures, discusses the need for cyber resilience as security leaders face the inevitable stream of cybercrimes, how to achieve it through a zero trust approach, and how CISOs and the government can help.

página 6 de 139