Help Me With Hipaa

Informações:

Sinopsis

HelpMeWithHIPAA.com is a collaboration between Kardon Compliance founder, Donna Grindle, and HIPAAforMSPs.com founder, David Sims. Our mission is to share our Privacy and Security knowledge with those who are required to understand, implement, and manage the complex Privacy and Security requirements of HIPAA compliance.Our work with CEs and BAs inspired us to launch the service to provide information about the complex requirements of HIPAA in a relaxed manner without using too much legalese or geek speak. As the podcasts programs progress we will cover topics about that include sorting through the requirements as well as real world examples of the procedures used, both good and bad.Join us as we do our best to create a show where HIPAA and humor collide!

Episodios

  • Healthcare Cyber Attacks - Ep 84

    30/12/2016 Duración: 40min

    Every day it seems we read about more healthcare cyber attacks.  As the news keeps breaking with more details on the wide variety of cases, we have plenty of work to do just to keep up.  Today, there are so many cases to talk about we couldn't even decide what to call the episode. More details at https://HelpMeWithHIPAA.com/84

  • 2016 Blooper Show - Happy Holidays!

    23/12/2016 Duración: 09min

    Listen in to outtakes from this year's episodes.  We need something lighter to celebrate the holidays!

  • HIPAA 21st Century Cures Act - Ep 83

    16/12/2016 Duración: 34min

    For a change there was a bipartisan bill passed with some big impacts on healthcare.  HIPAA 21st Century Cures Act implications are, of course, our focus.  Today, we review some thoughts on the bill that was signed into law this week. More notes at https://HelpMeWithHIPAA.com/83

  • OCR Phishing And More Announcements - Ep 82

    13/12/2016 Duración: 46min

    Recorded during our first live broadcast, this episode covers several OCR announcements.  We start with the OCR phishing alert.  Followed by that we discuss OCR's guidance that said you should consider multi-factor authentication in your risk analysis.   There have also been more resolution agreements that we haven't covered on an episode so we hit those, as well.   Since it was a live show we also take some questions! For more: https://HelpMeWithHIPAA.com/82

  • Phishing Attacks In Healthcare - Ep 81

    02/12/2016 Duración: 45min

    Phishing attacks in healthcare are on the rise just like every other industry. However, unlike many other targets, phishing attacks in healthcare have a much higher return on investment if the phisherman gets anyone to take the bait. We've talked multiple times how healthcare is now a major target for hackers. Then, it only makes sense that we will see a continued rise in efforts aimed at phishing attacks in healthcare. Types of phishing: Phishing - spray and pray - grab an email list and let it rip - big net phishing Spear phishing - Aimed directly at you. Everything makes it look like it should be in your email meant for you from someone you know Whaling - Pointed directly at upper management of a company with an urgent business matter Soft targeting - send to people with a certain job that they would expect, like HR gets a resume but financial team gets a spreadsheet Telephone phishing - Just call you up and act like they should be asking you for login information  For more info: https://HelpMeWithHIPAA

  • Ep 81 Is Being Held For Ransom

    25/11/2016 Duración: 44min

    We are holding episode 81 for ransom during the Thanksgiving holiday.  For our black Friday episode we hope you enjoy this replay of our most popular episode. Stay tuned! Episode 81 will be released next Friday.  We will be discussing the different types of phishing, how they work and how you can resist the bait.

  • HIPAA Compliant Cloud - Ep 80

    18/11/2016 Duración: 42min

    In early Oct the long awaited guidance on HIPAA Compliant Cloud was released by HHS / OCR. There wasn't a lot of shocking information for us since it just restated, maybe more clearly, that cloud services providers (CSPs) must sign a BAA and meet certain obligations as a BA. Hopefully, this will address all the cases where some CSPs would use "slight of hand" with phrasing to claim they didn't have to be a HIPAA compliance cloud provider. The amount of "all ya gotta do is" type of misinformation only makes things harder to get done. Let's look at what the guidance addressed.   For more details go to HelpMeWithHIPAA.com/80

  • OCR Audits and Enforcement 2016 - Ep 79

    11/11/2016 Duración: 43min

    This week is basically part 2 from last week.  We left off just before reviewing the OCR audits and enforcement updates announced at the NIST / OCR Security Conference 2016.   Get more details at HelpMeWithHIPAA.com/79

  • HIPAA Security Conference 2016 - Ep 78

    04/11/2016 Duración: 42min

    Donna shares information from the 2016 NIST/OCR Annual Conference on Safeguarding Healthcare Information. Learn what she thought was interesting to share with you.   More information at https://HelpMeWithHIPAA.com/78

  • HIPAA Halloween Haunted House - Ep 77

    28/10/2016 Duración: 46min

    We tour the HIPAA haunted house in this year's Halloween episode! Cybersecurity has become a big concern over the last 18 months. Breaches in 2015 have given way to ransomware along with more daring breaches in 2016. What is really happening on your computers, networks, and the Internet every second is terrifying in several ways. There are plenty of amazing and good things happening at the speed of light but so are the bad ones..... For more details go to HelpMeWithHIPAA.com/77

  • Ransomware and HIPAA - Ep 76

    21/10/2016 Duración: 38min

    Ransomware and HIPAA have been a topic on the podcast multiple times. They are some of our most popular episodes, in fact.  Recently, we realized we haven't discussed the OCR guidance on ransomware and HIPAA.  On July 11, 2016, HHS.gov featured a new post from Jocelyn Samuels the Director of the Office for Civil Rights (OCR).  The title is catchy: Your Money or Your PHI: New Guidance on Ransomware. This episode is a review of that post and the fact sheet with OCR guidance on ransomware and HIPAA that the post announced. . For more information http://HelpMeWithHIPAA.com/76

  • Disaster Recovery Planning Under HIPAA - Ep 75

    14/10/2016 Duración: 45min

    Everything going on today with hurricanes and such makes it is a great time to talk about this. We mention it all the time but this episode is going to be just about what DR/BC means and what you can do to be prepared in advance.  So, this episode covers disaster recovery planning under HIPAA but any business can learn from our topics! What is DR/BC Planning? Who should do it? Is this another big expense? What is involved in building and maintaining DR/BC plans? General elements of a plan Get more details at http://HelpMeWithHIPAA.com/75

  • HIPAA Security Updates Recommended In New Report - Ep 74

    07/10/2016 Duración: 45min

    Last year Sen. Lamar Alexander and Sen. Patty Murray asked for answers to some questions concerning cybersecurity in healthcare.  They were interested in understanding what CMS and HHS were doing to protect patients from fraud.  It seems as though they were wondering if HIPAA security updates where needed.   We discussed the Senators request in episode 31 : https://helpmewithhipaa.com/episode-31-enforcement-efforts-ocr-increase-2016/ Their letter asked: What CMS and HHS is doing to monitor medical identity fraud What is CMS and/or OCR actually doing, if anything, to track cases of ID theft and fraud OCR uses the data collected from covered-entities to monitor potential breach victims and find out if their data have in fact been used by criminals They also want to know whether any education materials or help are offered to breach victims by the CMS and OCR The report was presented to the committee on August 6, 2016 and made public on Sept 26.

  • Business Associate Security Issues - EP 73

    30/09/2016 Duración: 44min

    BAs are in the HIPAA spotlight now more than ever. TheDarkOverlord was clearly using some BA applications to infiltrate networks and exfiltrate PHI. OIG reviewed Alaska VA system after breaches and the report specifically points to the need to monitor BAs OCR audits of BAs are about to start. Previously said end of September but now saying October In this episode we discuss what all this means. More at HelpMeWithHIPAA.com/73

  • HIPAA Penalties Increasing - Ep 72

    23/09/2016 Duración: 36min

    Did you hear that maximum penalties for HIPAA violations are being adjusted for inflation? It has quietly happened. Here is how. Check out the Federal Register entry from September 6, 2016. If you aren't in to reading yourself, don't worry, you know Donna did it. Well, at least the HIPAA parts. Learn more at: HelpMeWithHIPAA.com/72

  • OCR small breach investigations increasing - Ep 71

    16/09/2016 Duración: 35min

    OCR recently released another memo concerning compliance enforcement efforts.  They say effective August 2016, they have started an initiative to more widely investigate breaches involving under 500 patients.  That means that OCR small breach investigations will begin happening immediately.  In the past, the policy had been to investigate all breaches over 500 patients but not under.   More information at HelpMeWithHIPAA.com/71  

  • Insider Threats: Do you know who your employees are? - Ep 70

    09/09/2016 Duración: 37min

    OCR published a memo on Aug 1, 2016.  The title is "Do you know who your employees are?".  It is a great reminder about insider threats that we should all worry about regularly. Quoted directly from the memo. ============================ Although all insider threats are not malicious or intentional, the effect of these threats can be damaging to a Covered Entity and Business Associate and have a negative impact on the confidentiality, integrity, and availability of its ePHI. According to a survey recently conducted by Accenture and HfS Research, 69% of organization representatives surveyed had experienced an insider attempt or success at data theft or corruption. Further, it was reported by a Covered Entity that one of their employees had unauthorized access to 5,400 patient’s ePHI for almost 4 years. For more visit: HelpMeWithHIPAA.com/70

  • OCR 2016 settlements keep coming - Ep 69

    02/09/2016 Duración: 44min

    So far in 2016 there have been 10 resolution agreements announced. One more and this year will equal the number of agreements in all of 2015 & 2014! The latest two also include the largest one announced yet - $5.5m with Advocate Health. Before that though was The University of Mississippi Medical Center - Ole Missto those of us in the SEC world. It wasn't something to "shake a stick at" with a$2.75m resolution amount. The total amount for those 10 announcements so far in 2016 = $20,314,800 Of course the details are what we usually pay more attention to since it tells us exactly what OCR has a problem with in each case. It makes it clear what OCR wants all of us to learn from these folks mistakes. For more visit HelpMeWithHIPAA.com/69

  • OCR Desk Audit Details - Ep 68

    26/08/2016 Duración: 47min

    The OCR audits have begun.  On Wednesday, July 13, audit selected CEs where invited to a webinar. OCR staff walked through the processes they can expect for the audit and expectations for their participation.  The OCR published information from the webinar so we had to check it out and share what we learned with you guys.   For more details visit HelpMeWithHIPAA.com/68

  • Pokemon Go and HIPAA Breaches - Ep 67

    19/08/2016 Duración: 36min

    Say it ain't so! Pokemon and a HIPAA breach really? REALLY! Creatures are showing up in offices and hospitals just like everywhere else. The concept of keeping people active and engaged with their surroundings while playing a video game seems like a great idea from a healthcare standpoint. And then you actually do a risk assessment of it - this is where the wheels fall off that good idea train. Get more details as HelpMeWithHIPAA.com/67

página 20 de 24