Donna Grindle and David Sims

Help Me With HIPAA

Business EN ↓ 586 episodes

In today's environment of data breaches, identity theft, fraud, and increasing connectivity, HIPAA Privacy and Security rules are a responsibility to your patients and your clients. HIPAA isn't about compliance, it's about patient care.

Author

Donna Grindle and David Sims

Category

Business

Podcast website

helpmewithhipaa.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Black Friday Replay 8 Common HIPAA Myths 24.11.2017

We are enjoying the holiday with our families.  But, we didn't want to miss a chance to share time with our listeners.  Today we are replaying one of our favorite episodes 8 Common HIPAA Myths.

5 Things To Do Before Year's End - Ep 130 17.11.2017

Hard to believe another year is coming to an end. It is time to review 2017 and plan for 2018.  That means it is time to make your list of 5 Things To Do Before Year's End. Just in case you need some help with that list, we made one for you!   HelpMeWithHIPAA.com/130

Text messaging is not secure by default - Ep 129 10.11.2017

Text messaging is often the preferred method of communication for many people today.  It does have great advantages with its simplicity, instant delivery, and convenience.  However, I did not mention security on that list.  Text messaging is not secure by default.  Yes, you can secure it but that requires apps, platforms, and planning.  The bottom line is the communication method most people call...

Is there a cyber storm brewing? Ep 128 03.11.2017

Lately, there have been a lot of articles in the "nerd news" services about various problems and vulnerabilities looming on the horizon or happening right now.  Usually, there are one or two in a normal week or so that really get our attention.  The last few weeks though it seems a bit different.  Maybe it is just noise or paranoia created to drive traffic to sites.  But, sometimes it becomes over...

HIPAA Horror Stories V3 Ep - 127 27.10.2017

Each year we have done a special scary episode for Halloween.  Last year we took you on a tour of a haunted house.  This year for HIPAA Horror Stories V3 we get to hear a campfire horror story.  So gather around and hear how scary HIPAA mishaps can be for us all! For more info go to HelpMeWithHIPAA.com/127

Social Media, Marketing, and HIPAA - Ep 126 20.10.2017

When it comes to social media, marketing, and HIPAA things can get a little dicey. There are certainly many cases where using social media has gone awry in health care cases.  However, when handled correctly, you can actually use social media, marketing, and HIPAA in a sentence without getting chills down your spine.  Today, Janet Kennedy joins us for a discussion on the positive reasons you shoul...

On-boarding and Termination Checklists - Ep 125 13.10.2017

During the onboarding and termination process is where many mistakes are made that lead to security incidents and even reportable breaches.  Today we discuss why they are important and the kinds of things you should consider having in yours. For more information HelpMeWithHIPAA.com/125

Talk To The Boss About HIPAA - Ep 124 06.10.2017

How do you talk to the boss about HIPAA? That is a regular question we get around here.  The staff responsible for compliance gets trained and understands what needs to be done but they don't get leadership support.  Over the years we have had to have those conversations many times.  It is never easy but there are some key pointers to making ground with your argument and turning the tide for suppo...

OCR Audit Updates Phase 2 - Ep 123 29.09.2017

During the NIST OCR HIPAA Security Conference we covered in the last two episodes, there was also a session on OCR Audit Updates. OCR gave an update on the information gleaned so far from the compliance desk audits that were started in 2016. Their presentation included some interesting details. Today we cover the information they shared so you can compare and contrast those details against your ow...

NIST and OCR Security Conference Part Deux – Ep 122 22.09.2017

This is the second episode covering the things David has to share from the Safeguarding Health Information conference. There are many great points he picked up. As we review them we keep coming back to the reminder that HIPAA is about patient care now.  Join us as we discuss everything from ransomware requirements to security for a small practice on this episode. More info at HelpMeWithHIPAA.com/1...

NIST and OCR Security Conference - Ep 121 19.09.2017

The annual NIST and OCR security conference has come around again.  This year, David attended the conference via webcast and shares his notes on the first day of the conference.   Before the conference discussion, we have to touch on the announcement from Equifax about their HUGE data breach. For more information go to HelpMeWithHIPAA.com/121

Disaster Recovery Preparations Ep - 120 08.09.2017

We recorded this episode on the day that Harvey was hitting Houston and had no idea just how bad that disaster would eventually become for those on the gulf coast.  On the day we publish this episode, we are both personally involved in the evacuations and preparations in advance of Irma. She is forecast to hit Florida, Georgia, and the Carolinas in the next few days. The timing for this discussion...

Should I use a local, data center, or cloud server? - Ep 119 01.09.2017

Every time we discuss server security issues it opens a debate about where is the best place to keep your servers.  There are three options and we are going to discuss them today.  Local hosting vs data center hosting vs cloud servers under HIPAA. For more details HelpMeWithHIPAA.com/119 email us: contact@helpmewithhipaa.com

What is reasonable and appropriate? Ep 118 25.08.2017

What is reasonable and appropriate? The HIPAA legal reference and guidance mentions reasonable and appropriate all over the place. Many times that concept creates confusion. How do you determine what is reasonable or appropriate for any environment? More at HelpMeWithHIPAA.com/118

Alexa Plus HIPAA Plus Other Questions - Ep 117 18.08.2017

Can a doctor have Alexa in OR to play music?   Is it a HIPAA violation for staff to look at their own records or is it an internal policy violation? I am a small company BA do I really have to do all of HIPAA compliance requirements? If I know my upstream BA or CE isn't following their HIPAA compliance obligations what am I legally obligated to do? Why would you make daily copies of your visitor l...

Security Incident Investigations Find More Than Expected - Ep 116 11.08.2017

Sometimes following the news lets you find things like security incident investigations with interesting details.  But, these cases were different than most.  Even better than that, we learned how can a fish tank help hackers!  There were just too many parts of these stories that got my attention to pass them up.  When something occurs and the investigation uncovers way more to the story than you...

Incident Response Plans V2 - Ep 115 04.08.2017

Incident response plans have been a topic of our show several times. But, these days we just can't get enough of a good thing! Actually, there is a reason we are covering it in this episode.  I was reviewing a Business Associate Due Diligence from a software provider. In the questionnaire, we always ask if you have a written incident response plan and trained incident response team. They responded...

Compliance Officer Personal Liability? - EP 114 28.07.2017

There has always been a concern from many people we work with about compliance officer personal liability. Specifically, is a compliance officer personally liable for the compliance of the company? The recent settlement agreement between the FTC and the Chief Compliance Officer of Moneygram has created interesting conversations for compliance circles. In this case, the Chief Compliance Officer of...

OCR Mic Drop For Cloud Providers - EP 113 21.07.2017

The monthly OCR Cyber Newsletter for June had some interesting points.  The fact that OCR mentions multiple times and in multiple ways that they do not endorse, certify, or recommend specific technology or products should serve as their "OCR mic drop moment" on this discussion.  We can dream, can't we!  Today we are going to review that newsletter and how they have pointed these things out once ag...

NotPetya, Windows, and Ransomware - Ep 112 14.07.2017

This is not another episode about preventing and responding to the NotPetya ransomware. There are countless articles about those topics.  We are discussing the bigger picture today.  In this episode, NotPetya, Windows, and Ransomware, we discuss what happened in the case but also what does all of this really mean in the big picture of cyber attacks.  If you don't stay proactive in evaluating what...

Breach reporting costs and decisions for 2017 - Ep 111 14.07.2017

In June, the NY State Attorney General announced a settlement with CoPilot , a healthcare services company that illegally deferred notice of breach of more than 220,000 patient records .  Another annual report was also just released with the latest numbers : 2017 Cost of a Data Breach Study from Ponemon Institute and IBM .  Today, we are going to discuss how the two of them can help us all make be...

What is MDM and why do I want it? - Ep 110 30.06.2017

Mobile devices are susceptible to malware attacks, phishing, and other security vulnerabilities just the same as laptops and desktops.  The systems most of us have in place are directed at managing the security for laptops and desktops, however.  It is important to expand your security controls to address the growing threat that mobile devices introduce to your network and systems regularly.   In...

eCW Whistleblower Made The Difference - Ep 109 23.06.2017

There are countless times we have covered the "my EHR vendor handles HIPAA for me" misconception. The recent $155 million whistleblower lawsuit settlement between eClinicalWorks (eCW) and the government really brings it home how wrong you can be about EHR vendors. Meaningful Use attestations relied heavily on the vendors supplying proper information. eCW set up thousands of organizations to take a...

5 Stages Of Grief During A Cyber Attack - Ep 108 16.06.2017

The 5 stages of grief during a cyber attack really do follow the process of dealing with grief in those familiar 5 stages. Many don't realize that ransomware attacks aren't always just the result of someone clicking in an email and running a program.  As Erie County Medical Center found out recently, ransomware attacks can come from a hacker being active in your network too.  Those 5 stages of gri...

10 Ways HIPAA Should Have Stopped Rodeo Drive Breach - Ep 107 09.06.2017

A major breach of PHI was announced by a Beverly Hills plastic surgeon's office on Jun 1. There are so many things about this case from the fact that it involved a malicious insider to how many different ways proper HIPAA policies and procedures would have stopped it, if not prevented it completely. Celebrity patients records breached in this case may make it hit home with a lot of folks who haven...

Listen to the Help Me With HIPAA podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.