Donna Grindle and David Sims

Help Me With HIPAA

Business EN ↓ 586 episodes

In today's environment of data breaches, identity theft, fraud, and increasing connectivity, HIPAA Privacy and Security rules are a responsibility to your patients and your clients. HIPAA isn't about compliance, it's about patient care.

Author

Donna Grindle and David Sims

Category

Business

Podcast website

helpmewithhipaa.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

OCR Phishing And More Announcements - Ep 82 13.12.2016

Recorded during our first live broadcast , this episode covers several OCR announcements.  We start with the OCR phishing alert.  Followed by that we discuss OCR's guidance that said you should consider multi-factor authentication in your risk analysis.   There have also been more resolution agreements that we haven't covered on an episode so we hit those, as well.   Since it was a live show we al...

Phishing Attacks In Healthcare - Ep 81 02.12.2016

Phishing attacks in healthcare are on the rise just like every other industry. However, unlike many other targets, phishing attacks in healthcare have a much higher return on investment if the phisherman gets anyone to take the bait. We've talked multiple times how healthcare is now a major target for hackers. Then, it only makes sense that we will see a continued rise in efforts aimed at phishing...

Ep 81 Is Being Held For Ransom 25.11.2016

We are holding episode 81 for ransom during the Thanksgiving holiday.  For our black Friday episode we hope you enjoy this replay of our most popular episode. Stay tuned! Episode 81 will be released next Friday.  We will be discussing the different types of phishing, how they work and how you can resist the bait.

HIPAA Compliant Cloud - Ep 80 18.11.2016

In early Oct the long awaited guidance on HIPAA Compliant Cloud was released by HHS / OCR. There wasn't a lot of shocking information for us since it just restated, maybe more clearly, that cloud services providers (CSPs) must sign a BAA and meet certain obligations as a BA. Hopefully, this will address all the cases where some CSPs would use "slight of hand" with phrasing to claim they didn't hav...

OCR Audits and Enforcement 2016 - Ep 79 11.11.2016

This week is basically part 2 from last week.  We left off just before reviewing the OCR audits and enforcement updates announced at the NIST / OCR Security Conference 2016.   Get more details at HelpMeWithHIPAA.com/79

HIPAA Security Conference 2016 - Ep 78 04.11.2016

Donna shares information from the 2016 NIST/OCR Annual Conference on Safeguarding Healthcare Information. Learn what she thought was interesting to share with you.   More information at https://HelpMeWithHIPAA.com/78

HIPAA Halloween Haunted House - Ep 77 28.10.2016

We tour the HIPAA haunted house in this year's Halloween episode! Cybersecurity has become a big concern over the last 18 months. Breaches in 2015 have given way to ransomware along with more daring breaches in 2016. What is really happening on your computers, networks, and the Internet every second is terrifying in several ways. There are plenty of amazing and good things happening at the speed o...

Ransomware and HIPAA - Ep 76 21.10.2016

Ransomware and HIPAA have been a topic on the podcast multiple times. They are some of our most popular episodes, in fact.  Recently, we realized we haven't discussed the OCR guidance on ransomware and HIPAA.  On July 11, 2016, HHS.gov featured a new post from Jocelyn Samuels the Director of the Office for Civil Rights (OCR).  The title is catchy:  Your Money or Your PHI: New Guidance on Ransomwar...

Disaster Recovery Planning Under HIPAA - Ep 75 14.10.2016

Everything going on today with hurricanes and such makes it is a great time to talk about this. We mention it all the time but this episode is going to be just about what DR/BC means and what you can do to be prepared in advance.  So, this episode covers disaster recovery planning under HIPAA but any business can learn from our topics! What is DR/BC Planning? Who should do it? Is this another big...

HIPAA Security Updates Recommended In New Report - Ep 74 07.10.2016

Last year Sen. Lamar Alexander and Sen. Patty Murray asked for answers to some questions concerning cybersecurity in healthcare.  They were interested in understanding what CMS and HHS were doing to protect patients from fraud.  It seems as though they were wondering if HIPAA security updates where needed.   We discussed the Senators request in episode 31 : https://helpmewithhipaa.com/episode-31-e...

Business Associate Security Issues - EP 73 30.09.2016

BAs are in the HIPAA spotlight now more than ever. TheDarkOverlord was clearly using some BA applications to infiltrate networks and exfiltrate PHI. OIG reviewed Alaska VA system after breaches and the report specifically points to the need to monitor BAs OCR audits of BAs are about to start. Previously said end of September but now saying October In this episode we discuss what all this means. Mo...

HIPAA Penalties Increasing - Ep 72 23.09.2016

Did you hear that maximum penalties for HIPAA violations are being adjusted for inflation? It has quietly happened. Here is how. Check out the Federal Register entry from September 6, 2016. If you aren't in to reading yourself, don't worry, you know Donna did it. Well, at least the HIPAA parts. Learn more at: HelpMeWithHIPAA.com/72

OCR small breach investigations increasing - Ep 71 16.09.2016

OCR recently released another memo concerning compliance enforcement efforts.  They say effective August 2016, they have started an initiative to more widely investigate breaches involving under 500 patients.  That means that OCR small breach investigations will begin happening immediately.  In the past, the policy had been to investigate all breaches over 500 patients but not under.   More inform...

Insider Threats: Do you know who your employees are? - Ep 70 09.09.2016

OCR published a memo on Aug 1, 2016.  The title is "Do you know who your employees are?".  It is a great reminder about insider threats that we should all worry about regularly. Quoted directly from the memo. ============================ Although all insider threats are not malicious or intentional, the effect of these threats can be damaging to a Covered Entity and Business Associate and have a n...

OCR 2016 settlements keep coming - Ep 69 02.09.2016

So far in 2016 there have been 10 resolution agreements announced. One more and this year will equal the number of agreements in all of 2015 & 2014! The latest two also include the largest one announced yet - $5.5m with Advocate Health . Before that though was The University of Mississippi Medical Center - Ole Miss to those of us in the SEC world. It wasn't something to "shake a stick at" with a $...

OCR Desk Audit Details - Ep 68 26.08.2016

The OCR audits have begun.  On Wednesday, July 13, audit selected CEs where invited to a webinar. OCR staff walked through the processes they can expect for the audit and expectations for their participation.  The OCR published information from the webinar so we had to check it out and share what we learned with you guys.   For more details visit HelpMeWithHIPAA.com/68

Pokemon Go and HIPAA Breaches - Ep 67 19.08.2016

Say it ain't so! Pokemon and a HIPAA breach really? REALLY! Creatures are showing up in offices and hospitals just like everywhere else. The concept of keeping people active and engaged with their surroundings while playing a video game seems like a great idea from a healthcare standpoint. And then you actually do a risk assessment of it - this is where the wheels fall off that good idea train. Ge...

Healthcare Hack: PHI For Sell On The DarkNet - Ep 66 12.08.2016

We first talked about this in Ep 62. Darknet sale of healthcare records. Now, more information is coming out and it gets more unfortunate for patients every time we read more. Deep Dot Web broke the news: https://www.deepdotweb.com/2016/06/26/655000-healthcare-records-patients-being-sold/ We picked it up on Data Breaches.net because they were trying to figure out who the entities actually were in...

OCR resolution agreement - OHSU - EP 65 05.08.2016

What happened? March 23, 2013 Oregon Health & Science University notified HHS of a breach due to a stolen unencrypted laptop. May 1, 2013 OCR notifies them they are investigating the incident July 28, 2013 Oregon Health & Science University notified HHS of another breach resulting from storing ePHI at an internet-based service provider without a business associate agreement November 8, 2013 OCR no...

Security Incident Response Plan - Ep 64 29.07.2016

OCR recently sent out a message on their listserv asking if your CE or BA was ready for an incident. We have been discussing security incidents a lot lately so it is nice that OCR has brought it up. Because we have seen various Incident response reports recently, so we were working on an episode anyway.  So this episode is a review of Security Incident Response Plan development. Let's first be cle...

Medical Device Security - Ep 63 22.07.2016

There has been a lot of news and industry discussions about Medical Device security.  Medical Devices are just like a computer, so they also need security to protect the information on them.   For more go to HelpMeWithHIPAA.com/63

Business Associate Breaches In The News - Ep 62 15.07.2016

A business associate is getting this OCR  resolution , $650,000 and a two-year settlement.  CHCS in Philadelphia is a BA to 6 skilled nursing clinics in the Philadelphia area. Entities like this do the business part of healthcare and the other clinics don't have to worry about it. An unencrypted iPhone that wasn't password protected had PHI on it.     Patterson Dental Supply Inc. helps manage dent...

Healthcare Data Breach Study - Ep 61 08.07.2016

Since 2010, ID Experts has sponsored this Ponemon Institute study which has been tracking data breach trends of patient data at healthcare organizations. The annual economic impact of a data breach has risen over the past six years, as has the frequency of data breaches. Criminal attacks and internal threats are the leading cause of healthcare breaches. Evolving cyber attack threats such as ransom...

HIPAA Rules In A Crisis - Ep 60 01.07.2016

As always, during times of crisis and chaos things do become confused and incorrect statements are made. It is a normal occurrence in troubling situations. But, we need to address it specifically to clear up a few points. There was no "special waiver from the White House". There was no need for one at all. People, even in a crisis, should not be invoking HIPAA over caring for the patient properly....

HIPAA, HHS, OCR, and PHI - Ep 59 24.06.2016

Today's podcast is a little different from our normal ones. We are covering a wide variety of subjects involving HIPAA, OCR, HHS, and PHI rather than one specific topic.   For more go to HelpMeWithHIPAA.com/59

Listen to the Help Me With HIPAA podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.