Help Me With Hipaa

  • Autor: Vários
  • Narrador: Vários
  • Editora: Podcast
  • Duração: 386:37:44
  • Mais informações

Informações:

Sinopse

HelpMeWithHIPAA.com is a collaboration between Kardon Compliance founder, Donna Grindle, and HIPAAforMSPs.com founder, David Sims. Our mission is to share our Privacy and Security knowledge with those who are required to understand, implement, and manage the complex Privacy and Security requirements of HIPAA compliance.Our work with CEs and BAs inspired us to launch the service to provide information about the complex requirements of HIPAA in a relaxed manner without using too much legalese or geek speak. As the podcasts programs progress we will cover topics about that include sorting through the requirements as well as real world examples of the procedures used, both good and bad.Join us as we do our best to create a show where HIPAA and humor collide!

Episódios

  • What is MDM and why do I want it? - Ep 110

    30/06/2017 Duração: 45min

    Mobile devices are susceptible to malware attacks, phishing, and other security vulnerabilities just the same as laptops and desktops.  The systems most of us have in place are directed at managing the security for laptops and desktops, however.  It is important to expand your security controls to address the growing threat that mobile devices introduce to your network and systems regularly.   In most cases, it is important to have a "home base" tool that can talk to and monitor the mobile devices.  That is where MDM comes into play.  For most people that brings us to the question: What is MDM and why do I want it?   For more: HelpMeWithHIPAA.com/110

  • eCW Whistleblower Made The Difference - Ep 109

    23/06/2017 Duração: 46min

    There are countless times we have covered the "my EHR vendor handles HIPAA for me" misconception. The recent $155 million whistleblower lawsuit settlement between eClinicalWorks (eCW) and the government really brings it home how wrong you can be about EHR vendors. Meaningful Use attestations relied heavily on the vendors supplying proper information. eCW set up thousands of organizations to take a major hit based on the details in this case and it's settlement. Especially, when you take into account that eCW is one of the biggest EHR vendors out there. CIA of PHI is the objective of the entire Security Rule under HIPAA. Unreliable data created by an application is clearly a data Integrity issue. If you can't trust the data can you trust the system at all? If you have knowledge of this kind of stuff going on somewhere you should review it closely. It includes civil payments by developers and project managers not just the C-Suite folks involved.   For more information: HelpMeWithHIPAA.com/109

  • 5 Stages Of Grief During A Cyber Attack - Ep 108

    16/06/2017 Duração: 51min

    The 5 stages of grief during a cyber attack really do follow the process of dealing with grief in those familiar 5 stages. Many don't realize that ransomware attacks aren't always just the result of someone clicking in an email and running a program.  As Erie County Medical Center found out recently, ransomware attacks can come from a hacker being active in your network too.  Those 5 stages of grief during a cyber attack for them and others we have seen is what we will be discussing today.   We have a special guest with us for today's discussion too.  David Benton with Altep is joining us.  David is a super IT forensics dude.  The CSI of the nerds, so to speak.  He is helping us review this topic. More information at HelpMeWithHIPAA.com/108

  • 10 Ways HIPAA Should Have Stopped Rodeo Drive Breach - Ep 107

    09/06/2017 Duração: 48min

    A major breach of PHI was announced by a Beverly Hills plastic surgeon's office on Jun 1. There are so many things about this case from the fact that it involved a malicious insider to how many different ways proper HIPAA policies and procedures would have stopped it, if not prevented it completely. Celebrity patients records breached in this case may make it hit home with a lot of folks who haven't worried too much about those protections until now. We have talked about insiders as a major vulnerability a lot lately and this one really makes it big news! 15,000 files with medical and personal information. Added to that are pictures including those of celebrity patients records breached without them even know the pictures existed! More info at HelpMeWithHIPAA.com/107

  • Disclosure of PHI in May OCR settlements - Ep 106

    02/06/2017 Duração: 43min

    OCR continued their enforcement trend for 2017 with 2 more settlements announced in May.  These stand out on their own because the focus is specific disclosure of PHI instead of major breaches.  A total of three patients were involved in these large settlements.  This week we review what transpired and what OCR found as violations of privacy for these three patients.   For more information go to HelpMeWithHIPAA.com/106  

  • Answering Listener Questions - Ep 105

    26/05/2017 Duração: 50min

    A wide variety of questions have come in from listeners over the last few weeks. The list is so good we have a whole episode devoted just to answering listener questions.  At least one of these will likely apply to you if not several. For more information go to HelpMeWithHIPAA.com/105

  • What should we learn from WannaCry? - Ep 104

    19/05/2017 Duração: 48min

    All of those ransomware outbreaks we have been dealing with since last year were overshadowed this past week by WannaCry.  This has been called called the most destructive attack ever.  The most concerning part is that was how bad it was but the US wasn't hit that hard.  When these kinds of things happen it is always a good idea to review what you learned from the outbreak and any necessary changes you need to make to protect you from this one happening to you.  The is the topic of the day.  What should we learn from WannaCry?   Learn more at HelpMeWithHIPAA.com/104

  • Managing Third Party Access - Ep 103

    12/05/2017 Duração: 42min

    You may not even know about all the applications and support logins that vendors use on your applications, systems, and networks. Vendors may set up admin passwords and share them with their whole staff to support you. If they have unlimited access to the systems out there and the usernames and passwords never expire or log off automatically that is certainly not secure. How do you manage all of those?  If there are things that automatically log in and run, what about those? More details at HelpMeWithHIPAA.com/103

  • No, No, No says OCR in three April settlements - Ep 102

    05/05/2017 Duração: 43min

    April has had three more OCR resolution announcements. That's a total of 7 cases for $14.3m in 2017 so far. When we covered resolutions recently I kept waiting for another one to come out and gave up. Then, BAM, three in a row! For more info go to HelpMeWithHIPAA.com/102

  • Are we creating a crisis of trust in healthcare? - Ep 101

    28/04/2017 Duração: 47min

    Are we creating a crisis of trust in healthcare? A business partner put that question out to us recently. We have already been looking at several angles to discuss the patient part in all of this breach and ransomware news. This question seems like the perfect way to approach it. Let's look at the topic and see what we think - Are we creating a crisis of trust in healthcare?   For more information on this podcast and how to win $100 Amazon gift card go to HelpMeWithHIPAA.com/101

  • Top 10 HIPAA Lessons - Ep 100

    21/04/2017 Duração: 49min

    For our 100th episode we wanted to do a Top 10 list.  After some thought, we landed on the Top 10 HIPAA Lessons we hope you get from our little podcast.   It is hard to believe that we are publishing our 100th episodes of Help Me With HIPAA!  Two years ago we started out with this little idea that has become a really exciting venture for both of us.  We truly enjoy the responses and interaction from our listeners.  Well, first, we are thrilled to HAVE listeners.  But more importantly, we love hearing how much people learn and laugh at the same time.  That combination has been our show objective since the very beginning. Another big thing we are doing with this episode is a chance to win a $100 Amazon gift card if you help share and promote us with you social networks.  Listen in or go to the website for more details on how to win!  More info at: HelpMeWithHIPAA.com/100

  • Examples of what not to do from OCR AGAIN - Ep 99

    14/04/2017 Duração: 43min

    OCR Resolutions 3 and 4 for 2017 were released in February.  Examples of what not to do from OCR were released AGAIN.  We kept waiting for another resolution to be announced and lump them together.  Once we gave up and recorded this episode to review those two you know another one was announced.  We will hit that one next time.  For now, we review what happened in these cases that resulted in OCR resolutions after a breach notification started an investigation.  They are so kind to give us examples of what not to do from OCR without us paying for it! For more details go to HelpMeWithHIPAA.com/99    

  • State privacy and breach laws and HIPAA - Ep 98

    07/04/2017 Duração: 44min

    Recently, New Mexico passed a new data breach notification law in March. Once it is signed there will only be 2 states that don't have their own notification rules, Alabama and South Dakota. What do all the state laws mean when you are also required to do HIPAA notifications. Most of them say that if you are subject to GLBA or HIPAA the notification laws do not apply to you. But, it is always best to be sure you know what your state requires. HIPAA says that as long as it is more strict than state laws then HIPAA takes precedence but many times states are now enacting stronger legislation in some areas. California and Texas developed some pretty extensive requirements that apply to CEs and BAs in their states. Massachusetts also added their own twist beyond HIPAA. More info at HelpMeWithHIPAA.com/98

  • Insiders may be your biggest threat to privacy and security Ep - 97

    31/03/2017 Duração: 44min

    All the news about ransomware and hackers usually gets the biggest headlines.  But, the ones that fly under the radar may be something you should pay more attention to than the big splashy news.  Insiders usually don't have to work hard to plot ways to break into your data, you have invited them in and given them access. A damaging assumption is that you don't have to worry about your insiders. Get more info at HelpMeWithHIPAA.com/97

  • What is included in a mobile access policy - Ep 96

    24/03/2017 Duração: 44min

    Call it teleworking, remote access, or mobile access if you have any access to PHI outside of your office, you should have a HIPAA mobile access policy. Any person that accesses you systems and data outside of your internal network should be trained and sign off on commitments to protect your PHI. We've never specifically covered the topic of what should be included in a HIPAA mobile access policy. It is about time we did just that. Learn more at HelpMeWithHIPAA.com/96

  • Can we build a national culture of cybersecurity? - Ep 95

    17/03/2017 Duração: 46min

    Building a culture of a compliance is something we have talked about many times in this podcast.  We never looked at it as a community problem.  The things we heard about training the human element to build a cyber security culture were very exciting to us.  Well, at least to Donna.  The concepts they covered about training not just the workforce but training the community as a whole to better understand what cybersecurity really means. We also followed that up with a session that explained some more scary darknet activity.  Your machine could be for sell on the darknet and you don't even know it. More information at HelpMeWithHIPAA.com/95

  • Frank Abagnale Can Even Scare Us About ID Theft - Ep 94

    10/03/2017 Duração: 44min

    If you saw the movie Catch Me If You Can then you know some of Frank Abagnale's story.  Maybe you even read his book Catch Me If You Can: The True Story of a Real Fake.   Tom Hanks said "Abagnale’s lecture may be the best one-man show you will ever see."   He WAS NOT KIDDING!   The famous con man in his youth eventually became a white hat working for the FBI and others to combat fraud and ID theft for over 40 years. Now, he works as a consultant, writer, and speaker on the subject as he continues working with the United States Government   The information he shared with us during his #HIMSS17 session blew us away.  That means we have to tell you guys about it! Learn more at https://HelpMeWithHIPAA.com/94

  • HIMSS17: Deven McGraw Talks HIPAA Enforcement - Ep 93

    03/03/2017 Duração: 48min

    The first full day of HIMSS17 HIPAA had a big session. It featured Deven McGraw, Deputy Director for Health Information Privacy at the HHS Office for Civil Rights (OCR).  She is also Acting Chief Privacy Officer for the Office of the National Coordinator for Health IT (ONC).  Clearly, it was one of the sessions at the top of the list for us to attend.  We got there early enough to be perched on the front row.  In this episode, we review what McGraw covered in her session and our thoughts on it. For more details and timestamps go to HelpMeWithHIPAA.com/93

  • HIPAA Hodge Podge - RDP FAXing Dumpsters - Ep 92

    24/02/2017 Duração: 45min

    HIPAA news stories are sometimes so short we need to bundle them together. Some listeners questions are also addressed today. So, we have a little bit of everything in this episode. So stick with us as we go through our HIPAA hodge podge. For more details go to HelpMeWithHIPAA.com/92

  • What is HIPAA privacy anyway - Ep 91

    17/02/2017 Duração: 37min

    What is HIPAA privacy anyway? The annual reporting deadline for little breaches is up at the end of Feb. That means all those little privacy violations in 2016 must be reported on the HHS website soon if you haven't already done it. Since those little ones often mean so much more than the big ones it made me think it would be a good time to talk about privacy. A recent bizarre case in an Atlanta suburb made me realize just how much we value our privacy but may not realize it until it has been taken from us. More at HelpMeWithHIPAA.com/91

página 20 de 25