Donna Grindle and David Sims

Help Me With HIPAA

Business EN ↓ 586 episodes

In today's environment of data breaches, identity theft, fraud, and increasing connectivity, HIPAA Privacy and Security rules are a responsibility to your patients and your clients. HIPAA isn't about compliance, it's about patient care.

Author

Donna Grindle and David Sims

Category

Business

Podcast website

helpmewithhipaa.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Trashy Privacy Violations - Ep 372 09.09.2022

David admits that as a kid he would dumpster dive for "treasures" people threw away. We've heard more than once of clients who have gone dumpster diving to retrieve documents containing PHI that were mistakenly thrown away in the regular trash. But, a recent OCR announcement highlights one dermatology group that had quite the trashy privacy violation. More info at HelpMeWithHIPAA.com/372

Should You Be Trusted? - Ep 371 02.09.2022

Should we be questioning other people and vendors we work with about the trust we should have in them? The answer is yes. Are they protecting and securing the patient data we entrust them with?  Trust, but verify is something we talk about a lot. So, I ask you… should you be trusted? And can you prove it? More info at HelpMeWithHIPAA.com/371

Privacy Assessments - Ep 370 26.08.2022

Privacy laws are being passed in more and more states every year. Even non-healthcare businesses are finding they must follow privacy laws in the states they do business in. Conducting a privacy assessment is a great way to understand what data you have that needs protecting, what things can go wrong and then, of those things that can go wrong, which ones we can try to prevent. More info at HelpMe...

Amazon, Facebook, and PHI oh my! - Ep 369 19.08.2022

In order to protect PHI, you have to know where it is stored and how it comes in, goes out and moves around your organization. This includes marketing analytic tools used on websites and patient portals. They could be transmitting PHI to social media platforms. Very unnerving, right? More info at HelpMeWithHIPAA.com/369

Free Training Tools 2022 - Ep 368 12.08.2022

It's that time again folks! October is Cybersecurity Awareness Month. This year's theme is "It's easy to stay safe online" with a weekly focus on key behaviors to help protect your important data. Using these free training tools and practicing basic cybersecurity behaviors, you are much more likely to stay safe online. More info at HelpMeWithHIPAA.com/368

New Security Rule Guide Coming - Ep 367 05.08.2022

An updated version of the security rule guide that we've all been waiting for! NIST has developed a cybersecurity resource guide on implementing the HIPAA Security Rule. It provides key activities, descriptions and sample questions to help covered entities and business associates comply with the HIPAA Security Rule.  This guide has tons of good information in it. So, listen in as we discuss some o...

OCR Mic Drops With 12 Cases - Ep 366 29.07.2022

OCR recently announced the resolution of 12 investigations. Eleven were for patient right of access violations and one was a big dollar settlement of a security incident at Oklahoma State University Center for Health Services. Lots to cover and learn in this episode. So, pay attention, folks. More info at HelpMeWithHIPAA.com/366

660 Providers Hit At Once - Ep 365 22.07.2022

Today's podcast episode is all about why we worry about supply chain issues, why we keep talking about the HiC SCRiM guidance, and why the first day of the PriSec Boot Camp is supply chain risk management. We'll review several supply chain breaches, one where there were 660 providers hit at once. As you probably have guessed, these breaches involved ransomware attacks. More info at HelpMeWithHIPAA...

6 Vendor Transition Tips - Ep 364 15.07.2022

It can be a stressful time when you are adding a new vendor or switching vendors for your critical services.  This is the time to create a plan and do a risk analysis to make sure everything gets transitioned and set up properly. Things can go wrong if there's no plan in place. Today, we review some tips to help you prepare for a vendor transition. More info at HelpMeWithHIPAA.com/364

Cyber Insurance Applications Are Intense - Ep 363 08.07.2022

When you're shopping for cybersecurity insurance, the applications can be intense. You'll need to provide a lot of details about your current security protections, and you may be asked to complete a security audit. This is because insurance companies want to be sure that they're not insuring businesses that aren't doing everything they can to protect themselves from cyber attacks. This episode we...

4 Ransomware Stats For Planning - Ep 362 01.07.2022

Ransomware tactics are constantly changing. Understanding the protections we use today will not be enough down the road is key. We must constantly adjust and adapt our security protections to protect against these attacks. Today, we are going to discuss ransomware stats and key points from two recent reports that can help you create a response plan for ransomware attacks. More info at HelpMeWithHI...

No More Passwords FIDO - Ep 361 24.06.2022

We use passwords for everything. Creating a unique, secure password for every website and application is hard to remember, right? So, why hasn't someone figured out how to get rid of passwords? Well, today we are going to talk about the FIDO password killer solution. More info at HelpMeWithHIPAA.com/361

What Would You Do? - Ep 360 17.06.2022

How many of us know what we don't know, or at least, willing to admit we don't know what we don't know? Today, we are going to find out as we cover a few potential data breach scenarios and ask "what would you do - report it or not?"  More info at HelpMeWithHIPAA.com/360

6 Takeaways 2022 Verizon DBIR - Ep 359 10.06.2022

Today, we are going to give you our six takeaways from the 15th annual Verizon Data Breach Investigation Report. We like these reports because they give us an indication of what's going on in the cyber world, what we need to be looking for and looking out for. More info at HelpMeWithHIPAA.com/359

How Do They Get In? - Ep 358 03.06.2022

We get this question all of the time:  How do they get in?  How do the bad guys get in and attack my network? Seems like a simple question, right?  Well there's not always a clear cut answer.  The first thing you need to understand is that cybersecurity isn't a problem you solve. It's a chronic condition that you have to manage.  More info at HelpMeWithHIPAA.com/358

MSP Customer Alert - Ep 357 27.05.2022

Recently, a Cybersecurity Advisory was released worldwide to MSPs and their customers. We will take a look into what this guidance is, how it applies, and what needs to be done about it.  This is BIG and we all better be paying attention. More info at HelpMeWithHIPAA.com/357

Everybody get on board! - Ep 356 20.05.2022

Everybody get on board because data security laws keep getting signed in states each year. The new Maryland and Kentucky data security laws are designed to help protect insurance companies from cyber attacks by implementing cybersecurity standards, developing, implementing, and maintaining a written information security program. Their service providers are also required to implement such programs...

10 Roles of Operational Continuity - Ep 355 13.05.2022

Incident response planning is important to every business. You don't want to figure out how to manage the business and respond to an incident on the fly.  These plans should be reviewed and updated regularly. Today we review a brand new guide from the Healthcare & Public Health Sector Coordinating Council on Operational Continuity - Cyber Incident. More info at HelpMeWithHIPAA.com/355

PriSec Teams Require Everyone - Ep 354 06.05.2022

Over the last couple years, we've had some high-profile cybersecurity compromises and data breaches. And this trend is not slowing down. Today, we review a recent study of the top cyber threats to healthcare organizations. The results reinforce that PriSec teams require everyone to participate. More info at HelpMeWithHIPAA.com/354

3 Tricky Places HIPAA Applied - Ep 353 29.04.2022

Recently, we've had a couple things come up which involved tricky places that HIPAA has applied that most people might not think of. So, we thought we'd throw them out there and have a little bit of fun discussing them. More info at HelpMeWithHIPAA.com/353

6 Ways To Make Money Online - Ep 352 22.04.2022

Cybercrime is a booming business. In 2021, the US experienced an unprecedented increase in cyber attacks with criminals making $6.9 billion online. In today's podcast, we review the FBI's Internet Crime Report for 2021. More info at HelpMeWithHIPAA.com/352

4 Takeaways from Okta Breach? - Ep 351 15.04.2022

It is crucial for every business to understand the security practices of their vendors. And also to make sure that those vendors are vetting their vendors.  A cyber attack at a link in your supply chain can drastically affect your business. Evidence: the Okta breach. More info at HelpMeWithHIPAA.com/351

4 OCR Cases For Us - Ep 350 08.04.2022

Have you heard the one about three dentists and a psychiatrist walk into... an OCR investigation? OCR has announced their first set of enforcement actions of 2022, and just in time for our 350th episode.  These involve patient right of access and improper disclosure violations. More info at HelpMeWithHIPAA.com/350

6 Points from HIPAA Summit - Ep 349 01.04.2022

Donna made many notes from the HIPAA Summit. Today, she and David will share six of her top picks, including the difference between an incident and a breach, how a "check the box compliance program" is not a privacy and security program, importance of understanding what your vendor's incident response plans are and more. More info at HelpMeWithHIPAA.com/349

3 HIPAA Enforcement Arms - Ep 348 25.03.2022

If you are a regular listener of the podcast, you know how Donna loves to "HIPAA-geek out" over the National HIPAA Summit each year. This year's National HIPAA Summit did not disappoint. Today, we discuss a few points made concerning enforcement of HIPAA related cases by three arms of the federal government. More info at HelpMeWithHIPAA.com/348

Listen to the Help Me With HIPAA podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.