Donna Grindle and David Sims

Help Me With HIPAA

Business EN ↓ 586 episodes

In today's environment of data breaches, identity theft, fraud, and increasing connectivity, HIPAA Privacy and Security rules are a responsibility to your patients and your clients. HIPAA isn't about compliance, it's about patient care.

Author

Donna Grindle and David Sims

Category

Business

Podcast website

helpmewithhipaa.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Disclosure of PHI in May OCR settlements - Ep 106 02.06.2017

OCR continued their enforcement trend for 2017 with 2 more settlements announced in May.  These stand out on their own because the focus is specific disclosure of PHI instead of major breaches.  A total of three patients were involved in these large settlements.  This week we review what transpired and what OCR found as violations of privacy for these three patients.   For more information go to H...

Answering Listener Questions - Ep 105 26.05.2017

A wide variety of questions have come in from listeners over the last few weeks. The list is so good we have a whole episode devoted just to answering listener questions.  At least one of these will likely apply to you if not several. For more information go to HelpMeWithHIPAA.com/105

What should we learn from WannaCry? - Ep 104 19.05.2017

All of those ransomware outbreaks we have been dealing with since last year were overshadowed this past week by WannaCry.  This has been called called the most destructive attack ever.  The most concerning part is that was how bad it was but the US wasn't hit that hard.  When these kinds of things happen it is always a good idea to review what you learned from the outbreak and any necessary change...

Managing Third Party Access - Ep 103 12.05.2017

You may not even know about all the applications and support logins that vendors use on your applications, systems, and networks. Vendors may set up admin passwords and share them with their whole staff to support you. If they have unlimited access to the systems out there and the usernames and passwords never expire or log off automatically that is certainly not secure. How do you manage all of t...

No, No, No says OCR in three April settlements - Ep 102 05.05.2017

April has had three more OCR resolution announcements. That's a total of 7 cases for $14.3m in 2017 so far. When we covered resolutions recently I kept waiting for another one to come out and gave up. Then, BAM, three in a row! For more info go to HelpMeWithHIPAA.com/102

Are we creating a crisis of trust in healthcare? - Ep 101 28.04.2017

Are we creating a crisis of trust in healthcare? A business partner put that question out to us recently. We have already been looking at several angles to discuss the patient part in all of this breach and ransomware news. This question seems like the perfect way to approach it. Let's look at the topic and see what we think - Are we creating a crisis of trust in healthcare?   For more information...

Top 10 HIPAA Lessons - Ep 100 21.04.2017

For our 100th episode we wanted to do a Top 10 list.  After some thought, we landed on the Top 10 HIPAA Lessons we hope you get from our little podcast.   It is hard to believe that we are publishing our 100th episodes of Help Me With HIPAA!  Two years ago we started out with this little idea that has become a really exciting venture for both of us.  We truly enjoy the responses and interaction fr...

Examples of what not to do from OCR AGAIN - Ep 99 14.04.2017

OCR Resolutions 3 and 4 for 2017 were released in February.  Examples of what not to do from OCR were released AGAIN.  We kept waiting for another resolution to be announced and lump them together.  Once we gave up and recorded this episode to review those two you know another one was announced.  We will hit that one next time.  For now, we review what happened in these cases that resulted in OCR...

State privacy and breach laws and HIPAA - Ep 98 07.04.2017

Recently, New Mexico passed a new data breach notification law in March. Once it is signed there will only be 2 states that don't have their own notification rules, Alabama and South Dakota. What do all the state laws mean when you are also required to do HIPAA notifications. Most of them say that if you are subject to GLBA or HIPAA the notification laws do not apply to you. But, it is always best...

Insiders may be your biggest threat to privacy and security Ep - 97 31.03.2017

All the news about ransomware and hackers usually gets the biggest headlines.  But, the ones that fly under the radar may be something you should pay more attention to than the big splashy news.  Insiders usually don't have to work hard to plot ways to break into your data, you have invited them in and given them access. A damaging assumption is that you don't have to worry about your insiders. Ge...

What is included in a mobile access policy - Ep 96 24.03.2017

Call it teleworking, remote access, or mobile access if you have any access to PHI outside of your office, you should have a HIPAA mobile access policy. Any person that accesses you systems and data outside of your internal network should be trained and sign off on commitments to protect your PHI. We've never specifically covered the topic of what should be included in a HIPAA mobile access policy...

Can we build a national culture of cybersecurity? - Ep 95 17.03.2017

Building a culture of a compliance is something we have talked about many times in this podcast.  We never looked at it as a community problem.  The things we heard about training the human element to build a cyber security culture were very exciting to us.  Well, at least to Donna.  The concepts they covered about training not just the workforce but training the community as a whole to better und...

Frank Abagnale Can Even Scare Us About ID Theft - Ep 94 10.03.2017

If you saw the movie Catch Me If You Can  then you know some of Frank Abagnale's story.  Maybe you even read his book Catch Me If You Can: The True Story of a Real Fake .   Tom Hanks said "Abagnale's lecture may be the best one-man show you will ever see."   He WAS NOT KIDDING!   The famous con man in his youth eventually became a white hat working for the FBI and others to combat fraud and ID the...

HIMSS17: Deven McGraw Talks HIPAA Enforcement - Ep 93 03.03.2017

The first full day of HIMSS17 HIPAA had a big session. It featured Deven McGraw, Deputy Director for Health Information Privacy at the HHS Office for Civil Rights (OCR).  She is also Acting Chief Privacy Office r for the Office of the National Coordinator for Health IT (ONC).  Clearly, it was one of the sessions at the top of the list for us to attend.  We got there early enough to be perched on t...

HIPAA Hodge Podge - RDP FAXing Dumpsters - Ep 92 24.02.2017

HIPAA news stories are sometimes so short we need to bundle them together. Some listeners questions are also addressed today. So, we have a little bit of everything in this episode. So stick with us as we go through our HIPAA hodge podge. For more details go to HelpMeWithHIPAA.com/92

What is HIPAA privacy anyway - Ep 91 17.02.2017

What is HIPAA privacy anyway? The annual reporting deadline for little breaches is up at the end of Feb. That means all those little privacy violations in 2016 must be reported on the HHS website soon if you haven't already done it. Since those little ones often mean so much more than the big ones it made me think it would be a good time to talk about privacy. A recent bizarre case in an Atlanta s...

First HIPAA Settlements of 2017 - Ep 90 10.02.2017

OCR continues releasing new settlement agreements on their new pace. There have been two announced in January 2017. We have no idea what will happen now but since these two brought in over $2.6m there may not be a reason we will see them stop their pace. As always, we believe in learning from other's mistakes (not schadenfreude, though). Time to learn what these two can teach us.... HelpMeWithHIPA...

Understanding Cybersecurity Insurance With John Miller of Sterling Risk Advisors - Ep 89 03.02.2017

More reasons to have this coverage pop up every day. Whether it is your own business risk management or those required by a business partner in a contract, all businesses should at least evaluate getting cybersecurity coverage. To help us share information on that we have a guest on this episode. Interview with John Miller II , Founding Principal, Sterling Risk Advisors 

8 Common HIPAA Myths - Ep 88 27.01.2017

We reviewed the OCR/HHS list of common HIPAA compliance myths when we first started the podcast. Their list is so long that it spread across 3 episodes. Those episodes are still fairly popular today. For today, though, we are covering our own list of common HIPAA compliance myths that we hear. Common HIPAA Compliance Myths Our list may be very similar to all the other lists out there but it is imp...

Healthcare Breaches Continue in 2017 - Ep 87 20.01.2017

At the beginning of 2016, we did some speculation about what the year would be like in the cybersecurity and HIPAA worlds.  Today we plan to review how we did for 2016 and explain expect healthcare breaches continue in 2017. More at https://HelpMeWithHIPAA.com/87

MACRA and HIPAA - Ep 86 13.01.2017

We've talked before about HIPAA showing up in lots of other places. That trend has continue. Now, you will see HIPAA questions on cyber security insurance applications, certification programs from other entities, and now in payment model reforms. Today we are going to talk a little bit about MACRA and HIPAA requirements. If you don't know what MACRA, APMs, and MIPS is all about we may not cover en...

2017 Compliance Management Plans - Ep 85 06.01.2017

Last January, we did an episode with a 2016 Compliance Management Plan.  We even created a reminder poster for it you could download.  The episode was about providing a compliance management plan guideline for compliance officers who are trying to find a way to fit this in your with all your other job duties. That episode was very popular and the poster was downloaded by new folks even in December...

Healthcare Cyber Attacks - Ep 84 30.12.2016

Every day it seems we read about more healthcare cyber attacks.  As the news keeps breaking with more details on the wide variety of cases, we have plenty of work to do just to keep up.  Today, there are so many cases to talk about we couldn't even decide what to call the episode. More details at https://HelpMeWith HIPAA.com/84

2016 Blooper Show - Happy Holidays! 23.12.2016

Listen in to outtakes from this year's episodes.  We need something lighter to celebrate the holidays!

HIPAA 21st Century Cures Act - Ep 83 16.12.2016

For a change there was a bipartisan bill passed with some big impacts on healthcare.  HIPAA 21st Century Cures Act implications are, of course, our focus.  Today, we review some thoughts on the bill that was signed into law this week. More notes at https://HelpMeWithHIPAA.com/83

Listen to the Help Me With HIPAA podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.