Donna Grindle and David Sims

Help Me With HIPAA

Business EN ↓ 586 episodes

In today's environment of data breaches, identity theft, fraud, and increasing connectivity, HIPAA Privacy and Security rules are a responsibility to your patients and your clients. HIPAA isn't about compliance, it's about patient care.

Author

Donna Grindle and David Sims

Category

Business

Podcast website

helpmewithhipaa.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

From $10K to $3M: The Price Tag of Neglecting Cybersecurity - Ep 494 31.01.2025

If ignoring cybersecurity was a sport, some companies would be gold medalists—until they realize the prize is a hefty fine and years of regulatory headaches. It's like leaving your car unlocked in a sketchy part of town with a neon sign that says, "Free Stuff Inside." What could possibly go wrong? Well, in this episode, we break down six real-life cases that prove skimping on security is way more...

Cavity of Lies: Westend Dental's HIPAA Coverup - Ep 493 24.01.2025

Buckle up, folks, because this week's episode is a wild ride through the Cavity of Lies—where HIPAA violations, ransomware attacks, and outright absurdity collide. What happens when a dental group tries to sweep a massive breach under the rug (or, you know, hide servers in bathrooms)? Let's just say it doesn't end well. From a 3-year-long cover-up to servers stored in all the wrong places, we've g...

HIPAA Security Changes Are Here: We Saw This Coming - Ep 492 17.01.2025

Hold onto your compliance hats—big changes are brewing for HIPAA's Security Rule! The Notice of Proposed Rulemaking (NPRM) is officially out for public comment, and it's clear HHA and OCR are on a mission to modernize and tighten the safeguards for electronic protected health information (ePHI). From clarifying risk analysis expectations to making security requirements less, well, "vague," these u...

PriSec Priorities Q1 2025 - Ep 491 10.01.2025

Ready to kick off 2025 with a bang? We're diving into the must-dos for your Q1 2025 compliance and cybersecurity checklist, sprinkling in some risk management wisdom, and why Windows 10 is about as fashionable as shoulder pads in the 2020s. Plus, we sprinkle in a hearty dose of snark to keep you entertained while you get your compliance game strong. Oh and if your incident response plan is just "h...

Supply Chain Attacks: The Risks Keep Growing - Ep 490 03.01.2025

Ah, supply chain attacks—the gift that keeps on giving... headaches, fines, and catastrophic data breaches. In this episode, we unwrap three cautionary tales of organizations caught in the tangled web of digital supply chain chaos. From unpatched vulnerabilities and sneaky software backdoors to hackers casually buying network access like it's an eBay auction, each story serves up a hard truth: you...

Phishing Fails, SRA Woes and the OCR Hammer - Ep 489 27.12.2024

It's the final countdown, folks—the last episode of the year! And OCR decided to end 2024 with a bang, handing out settlements like candy at a Christmas parade. But here's the twist: the candy comes with a price tag, and it's not cheap. This episode hones in on OCR's new enforcement initiative targeting incomplete and outdated risk analyses. So, before you pop the champagne, let's make sure your S...

2024 Holiday Blooper Show 20.12.2024

Welcome to the 2024 Blooper Show, where we prove once again that even after nine years, perfection is overrated and laughter is mandatory! Big shoutout to Bojan, our long suffering audio engineer extraordinaire, who turns our chaos into coherence. And of course, we can't forget you—our amazing listeners—who tune in each week, send us your thoughts and questions, and share the chaos with your frien...

Incident Panic to Plan for SMB Execs - Ep 488 13.12.2024

Cybersecurity incidents can feel like a punch in the gut, but with the right plan, you can roll with the hits instead of flailing in panic. In this episode, we're diving into executive strategies for tackling the unexpected, from building response teams to keeping business operations afloat when chaos strikes. Along the way, we also cover a recent corrective action plan that serves as a cautionary...

Access Delayed, Ransom Paid, Cyber Aid Conveyed - Ep 487 06.12.2024

Is your healthcare organization ready for a triple threat, or are you playing a risky game of cybersecurity roulette with delayed access, ransomware demands, and a missing incident response plan? Today, we explore three tales in healthcare that are equal parts cautionary and compelling. We kick things off with the Healthcare and Public Health Sector Coordinating Council's shiny new cyber incident...

Thankful It Is Not Me - Ep 486 29.11.2024

Feeling thankful this season? Us too—especially when it comes to dodging data disasters! In this episode, Donna and David dive headfirst into some eyebrow-raising cybersecurity tales, from job application breaches exposing sensitive information to the ever-creepy risks of unsecured IoT devices (yes, even your vacuum might be plotting against you). Whether it's researchers discovering unsecured dat...

First SRA Violation Settlement - Ep 485 22.11.2024

Doing a half-baked risk analysis is like locking your front door but leaving all the windows wide open. What's the point?  Today, we dive into the first-ever Security Risk Assessment (SRA) violation settlement—a juicy topic for compliance nerds and healthcare pros alike. We're talking ransomware, compliance checklists (the kind you actually need), and why a "kinda-sorta risk analysis" isn't going...

OCR NIST Part 2 - Ep 484 15.11.2024

Buckle up for Part 2 of our breakdown on the HHS OCR NIST healthcare security conference - because, yes, 16 hours of deep dives into AI, HIPAA compliance, and cybersecurity priorities can't be tackled in just one episode! From wild projections about AI's future in healthcare to OCR's "tough love" on compliance standards, this episode peels back the curtain on the big decisions shaping healthcare d...

OCR NIST Conference Part 1 - Ep 483 08.11.2024

Buckle up, folks! Today, Donna and David are here with Part 1 of their deep dive into the recent HHS OCR NIST healthcare security virtual conference, and they're spilling all the cyber-tea. With experts from HHS, OCR, NIST, FTC, and FDA presenting, this conference covered a ton. From AI-powered hackers and QR code scams to unpatched medical devices and a spike in supply chain attacks, the discussi...

Sell Me This Pen - Ep 482 01.11.2024

Ever heard someone say you need a pen test but then start wondering if they meant a pen from a spy movie? There typically is a lot of confusion between penetration testing and vulnerability assessments—a common mix-up with big consequences for your cybersecurity game. We will walk through different types of pen tests, explain how they help you spot weaknesses before the bad guys do and tackle why...

Gumming Up the Works: Dental Record Request Nightmare - Ep 481 25.10.2024

Ever had a root canal that felt less painful than dealing with bureaucracy? Well, buckle up, because in this episode, we sink our teeth into the 50th patient right of access enforcement action under HIPAA. That's right—50 cases since 2019, and somehow, this one involving Dr. Gumb (yes, really) and a dental records dispute is the most absurd of the bunch. From a refusal to hand over records to rack...

Ransomware, Recall, and Regulations - Ep 480 18.10.2024

Today we tackle the trifecta of cybersecurity headaches: Microsoft's awkwardly ambitious recall feature, the looming HISAA regulations (because HIPAA wasn't enough), and a juicy enforcement action following a ransomware attack. We'll break down how Microsoft's recall reboot went from intrusive default to opt-in relief, why HISAA could mean mandatory stress tests for healthcare providers, and what...

Browsers & Breaches - Ep 479 11.10.2024

Leaving your web browser open with 25 tabs is the digital version of leaving your front door unlocked? Whether it's for email, work docs, shopping, or watching cat videos, your browser is the gateway to, well, everything. But as much as we depend on them, so do hackers. From credential theft to sneaky phishing attacks, cybercriminals are finding clever ways to turn your favorite browser into a too...

Halloween Comes Early This Year - Ep 478 04.10.2024

Boo! 🎃 Halloween may not be here yet, but we're kicking off the spooky vibes early! Donna and David dive into the eerie world of cybersecurity, where the tricks are plentiful, and the treats are hard to find. From scary ransomware attacks to the horrifying reality of business email compromises, the internet is scarier than a haunted house with no exit. Grab your digital pumpkin spice latte, becau...

Avoid These 5 Healthcare Marketing Mistakes - Ep 477 27.09.2024

Healthcare marketing is tricky enough without tripping over the big pitfalls that could leave you tangled up in HIPAA violations or a patient privacy disaster. Today we break down five common marketing mistakes you definitely want to steer clear of. From misinterpreting HIPAA rules to guarding patient data like it's your grandma's secret cookie recipe, these blunders can get you into serious troub...

You Have Been Warned - Ep 476 20.09.2024

Do you feel like cyberattacks are the world's worst game of whack-a-mole? No matter how many you smack down, ten more pop up— and there's no sign of it slowing anytime soon and neither is the confusion over who's responsible when your data gets caught in the crossfire. If your supply chain and your own security safeguards aren't locked down, you might as well be rolling out the red carpet for hack...

Check Your Facility Access Controls - Ep 475 13.09.2024

Ever left your front door unlocked, thinking it's no big deal? Well, that's what happens when you forget about facility access controls – and the consequences can be far worse than a missing TV!  Today, we dive deep into a topic that often gets overlooked but is critical to any organization's security – facility access controls. Whether it's ensuring that only authorized personnel can access sensi...

Using Free CSAM Toolkit - Ep 474 06.09.2024

It's that time of year again: Cybersecurity Awareness Month! We're diving into the world of cybersecurity like a hacker in a candy store—except we're here to keep the candy (your data) safe! We're breaking down how you can use the free CE Awareness Month toolkit to boost your cybersecurity game both in your business and at home. Whether you're an IT pro or someone who just learned how to turn on t...

Yes You Are A Victim - Ep 473 30.08.2024

Navigating the world of cybersecurity these days feels like walking through a minefield with clown shoes—are you stepping safely or just a step away from disaster? In this episode, we dive into the jaw-dropping National Public Data breach that's got everyone asking, "Am I a victim too?" Spoiler alert: the odds aren't in your favor. Then, we sift through the chaos of the recent CrowdStrike outage b...

Show me your SBOM - Ep 472 23.08.2024

In this episode, we're diving deep into the world of Software Bill of Materials (SBOM)—basically, the recipe for your software, minus the secret sauce. If you've ever wondered what's really under the hood of your favorite apps (or been caught off guard by a sneaky ingredient), this one's for you. We're breaking down why you should care about SBOMs, how they're becoming a must-have in your vendor v...

A Bloody Mess - Ep 471 16.08.2024

Navigating healthcare cybersecurity is like walking through a minefield—you never know which step could trigger the next explosion. In this episode, we're diving headfirst into the bloody mess of ransomware attacks that have turned hospitals and blood banks into a logistical nightmare. Amidst the chaos, Health-ISAC and the American Hospital Association are urging special consideration for critical...

Listen to the Help Me With HIPAA podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.