Donna Grindle and David Sims

Help Me With HIPAA

Business EN ↓ 586 episodes

In today's environment of data breaches, identity theft, fraud, and increasing connectivity, HIPAA Privacy and Security rules are a responsibility to your patients and your clients. HIPAA isn't about compliance, it's about patient care.

Author

Donna Grindle and David Sims

Category

Business

Podcast website

helpmewithhipaa.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

3 Cyber stories we are watching - Ep 250 17.04.2020

With the national crisis still in play, cybersecurity is essential to operating businesses which are now online more than ever before. Small businesses without any apps before are going online to survive. Telehealth, remote learning, telework are all standard right now.  With so much going on we are trying to keep our eye on cyber stories to prepare ourselves and our clients for what is happening...

Crisis HIPAA Updates - Ep 249 10.04.2020

There is a lot of confusion along the way as there always will be in a crisis like this one. We are going to share some of the good information and do our best to clear up some of the misinformation. No matter what, though, it could all change in the two short weeks between when we record this and when we publish it for you guys. Our plan is to provide as much solid information that we know to be...

How do we reboot our business? - Ep 248 03.04.2020

We are all doing our best to focus on what we can do during this national crisis.  It is certain that we will bounce back at some point and be able to get back to business.  When we do this national reboot, what kinds of things will we need to do? Spend time now planning for the coming business reboot.  More at HelpMeWithHIPAA.com/248

HIC SCRiM Should Wake Up Vendors - Ep 247 27.03.2020

In Oct 2019 another document was released by the Health Sector Coordinating Council Joint Cybersecurity Working Group.  Health Industry Cybersecurity Supply Chain Risk Management Guide or HIC SCRiM for short is aimed at helping small and medium sized healthcare organizations manage their supply chain vendors. If you haven't had a chance to check it out, we are reviewing it for you today.  If you d...

No SRA First 2020 OCR Enforcement - Ep 246 20.03.2020

Opening the 2020 enforcement list for OCR is a doctor's office who reported a breach due to a business associate issue and then did nothing.  The settlement wasn't due to the BA but because the office had no SRA in place. Let's break down the settlement with Steven A. Porter, M.D ., P.C. a sole gastroenterologist practice in Ogden, UT. Time to learn from their mistakes. More at HelpMeWithHIPAA.com...

Privacy, Security, and COVID-19 - Ep 245 13.03.2020

Does your SRA include something like COVID-19?  Your business continuity plans include it? Do you need an SRA that includes virus outbreaks? Yes, you do.  If your risk analysis didn't include these kinds of things you should revisit your method for doing an SRA. What should you do about this risk and what else is missing from your SRA? Let's talk about privacy, security and COVID-19. More info at...

10 Cybersecurity Misconceptions - Ep 244 06.03.2020

Cybersecurity misconceptions are pretty common both in personal life and business.  There are definitely enough cases of misinformation coming through our offices on a regular basis to make it obvious just how confused people can be about what should be done.  We have pointed out many times that the government has been releasing information for years to assist both businesses and individuals. You...

Images Exposed - Ep 243 28.02.2020

This story has been going around since September 2019. Images exposed on the internet from PACS systems around the world available to anyone that wanted to see them.  Images exposed included x-rays, MRI scans and more. It still hasn't been locked down after all these months. That means it's time to talk about it instead of keeping it quiet. More info at HelpMeWithHIPAA.com/243

Insider Issues 2020 - Ep 242 21.02.2020

Another report comes out that says insiders are a huge problem.  You have to worry about the people, people. We have been saying this for years.  The lastest news on that front is in the 2020 Cost Of Insider Threats Global Report released by the Ponemon Institute and sponsored by ObserveIT and IBM.  It does tell us a lot of things we already knew but the details including those about how it is gro...

Wearables Plus More HIPAA Questions - Ep 241 14.02.2020

Wearables, medical devices and HIPAA are just some of the questions we have gotten recently.  Today's episode is privacy and security news plus listener questions. More at HelpMeWithHIPAA.com/241

HIPAA Ambiguous? Really? - Ep 240 07.02.2020

Is HIPAA ambiguous? That is the way many people refer to anything that has to do with HIPAA regulations. It comes from doctors, nurses, lawyers, managers, supervisors, even compliance officers. But, is it really the way we should refer to the law? Should we say it is flexible or reasonable instead? More at HelpMeWithHIPAA.com/240

Why Security Patching Matters - Ep 239 31.01.2020

There have been a lot of headlines lately about Windows 7 end of life and Windows 10 security patches.  Let's discuss why supported software and security patching matters in general. Then, we can talk about why it matters under HIPAA.   More at HelpMeWithHIPAA.com/239

Ransomware Warnings Everywhere - Ep 238 24.01.2020

We have mentioned ransomware warnings over and over on HMWH.  To the point ransomware shows up in a search on 56 different episodes before this one.  That means we've talked about ransomware warnings in 24% of our episodes. Guess what - clearly we need to talk about it again! More info at HelpMeWithHIPAA.com/238

Ambulance Company Settlement - Ep 237 17.01.2020

As we anticipated there was one more OCR settlement announcement before the end of 2019.  This one popped in at the end of December and was yet another one in our backyard. The ambulance company settlement seemed simple at first but once we read the details there is a lot to unpack in the CAP.  Let's get to it then! More info at HelpMeWithHIPAA.com/237

2020 Predictions Sortof - Ep 236 10.01.2020

We need to get on the record with our 2020 predictions even if we both agree we have no freaking idea what is going to happen in 2020.  If anyone out there says they honestly believe they have a true beat on it, check them out. We do have a few 2020 predictions that we feel sure enough about to say it outloud to you guys. More info at HelpMeWithHIPAA.com/236

Costly PHI Mistakes - EP 235 03.01.2020

Here we go with two more OCR enforcement settlements.  As we expected, the end of the year included a flurry of enforcement announcements from OCR.  Just as this was about to be recorded they announced the second patient access settlement. So we can we get both done in one episode!  Both of these cases are related to some costly PHI mistakes so let's get down to business. More info at HelpMeWithHI...

2019 Predictions Recap - Ep 234 27.12.2019

We have made it most of the way through 2019.  Now is the time to see how we did when we released our HIPAA privacy and security predictions for 2019 in episode 186 way back on Jan 11.  There were so many things that transpired this year just when thinking about the threat landscape much less all of our HIPAA discussions it feels long ago in a galaxy far, far away.  For more info HelpMeWithHIPAA.c...

2019 Holiday Blooper Show 20.12.2019

Enjoy Bojan's 2019 version of our annual blooper show.  Yes, some things really are as crazy behind the scenes as it seems. Thanks for all your support in 2019.  Enjoy whatever holiday you celebrate this time of year to the fullest!

What's in your BAA? - Ep 233 13.12.2019

A Business Associate Agreement isn't just another simple bit of paperwork.  The liability commitments in your BAA and the business relationship it defines are very serious and very important in defining clearly the responsibilities of both parties.  Lately, we have had to ask a lot of questions like what is in your BAA and today we discuss what we have been seeing out there in the wild, so to spea...

OCR Enforcement Picks Up - Ep 232 06.12.2019

OCR has been busy closing out investigations lately.  They announced 2 more enforcement actions in early November.  One was a settlement in NY, but the other was a civil money penalty with Texas HHSC. Let's review these 2 new OCR enforcement actions to see what we need to learn from the details released. More info at HelpMeWithHIPAA.com/232

Black Friday Replay 2019 - HICP Review 29.11.2019

Happy Thanksgiving from the HMWH team.  Since we just talked with Erik Decker the last two weeks about HICP it seemed fitting that our Thanksgiving replay this year is the discussion we had about our initial review of HICP earlier in 2019.  That was episode 189 . Thanks for listening and enjoy the Holiday season!

Erik Decker HICP Discussion Part 2 - Ep 231 22.11.2019

Today we share part 2 of our Erik Decker HICP discussion.  Learn about more tools for small and medium organizations. The 405(d) Task Group has more work to do so learn ways you can help spread the word about using these tools to improve healthcare cybersecurity.  We even ask how we can all help promote cybersecurity awareness and HICP to improve the healthcare cybersecurity. HelpMeWithHIPAA.com/2...

Talking HICP with Erik Decker Part 1 - Ep 230 15.11.2019

We covered the release of HICP or Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients back in Feb in the episode we called 5 Threats and 10 Protection Practices – Ep 189 .  HICP has now been out for a bit and the next phases of the project are in process.  Today we discuss all things HICP with Erik Decker who is the Health Sector Coordinating Council Co-Lead of the 40...

HIPAA Penalties Due To Disarray - Ep 229 08.11.2019

HIPAA penalties are always discussed in training and presentations about HIPAA.  Those discussions are usually more about an overview of what is in the law than actual information on how the law is applied.  HIPAA penalties are really not seen often. Civil money penalties are not part of the settlements we usually see but OCR announced a big one in October .  How do they really apply those huge nu...

HIPAA is the Floor - Ep 228 01.11.2019

The annual conference hosted by NIST and OCR Safeguarding Health Information: Building Assurance through HIPAA Security and the repeated message on day one of the conference was "HIPAA is the floor" which started with OCR Dir Severino's keynote. We always get information at some point that makes these conferences worth the time. What did we get from this one?  More info at HelpMeWithHIPAA.com/228

Listen to the Help Me With HIPAA podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.