Help Me With HIPAA

Follow Help Me With HIPAA
Share on
Copy link to clipboard

In today's environment of data breaches, identity theft, fraud, and increasing connectivity, HIPAA Privacy and Security rules are a responsibility to your patients and your clients. HIPAA isn't about compliance, it's about patient care.

Donna Grindle and David Sims


    • May 23, 2025 LATEST EPISODE
    • weekly NEW EPISODES
    • 46m AVG DURATION
    • 527 EPISODES

    4.9 from 60 ratings Listeners of Help Me With HIPAA that love the show mention: compliance, privacy, security, healthcare, highly recommend listening, need to know, law, training, would love, resource, date, current, learn, humor, information, understand, laugh, content, lot, entertaining.


    Ivy Insights

    The Help Me With HIPAA podcast is a highly recommended resource for anyone interested in staying up to date with HIPAA compliance and security. The hosts, Donna Grindle and David Sims, have been in the game for a long time and their experience shows in their high quality content. They have a light-touch humor that makes even the most dry subject matters entertaining. The podcast has evolved with new risks and considerations, keeping listeners informed on the latest developments.

    One of the best aspects of this podcast is Donna and David themselves. They are engaging hosts who make HIPAA fun. Their goofy personalities create an enjoyable listening experience while still delivering valuable information. They consistently provide useful knowledge and insights, ensuring that listeners learn something new each week. Additionally, their back catalog is still relevant and stands up well over time.

    One downside of this podcast is that it might not appeal to everyone. While the hosts' humor adds to the charm of the show, some listeners may prefer a more serious tone when discussing such an important topic like healthcare privacy and security. Additionally, there may be times when certain technical topics could benefit from deeper dives.

    In conclusion, The Help Me With HIPAA podcast is a must-listen for anyone interested in HIPAA compliance and security, whether they are involved in healthcare or not. Donna and David's expertise shines through their informative conversations with guests. The podcast strikes a good balance between providing valuable knowledge while entertaining listeners with light-hearted humor. It's an invaluable resource for staying up to date with current issues concerning HIPAA compliance in today's business world.



    Search for episodes from Help Me With HIPAA with a specific topic:

    Latest episodes from Help Me With HIPAA

    7 Things Healthcare Needs More Than Another Webinar - Ep 510

    Play Episode Listen Later May 23, 2025 41:28


    Let's face it — if healthcare had a dollar for every time someone said “we need another webinar,” it might actually be able to afford cybersecurity upgrades. This episode takes aim at the overload of online presentations and instead shines a light on what healthcare providers actually need. We unpack the findings of a critical report on the unique cybersecurity challenges facing small and rural healthcare providers, who are often running on shoestring budgets, outdated tech, and a whole lot of crossed fingers. More info at HelpMeWithHIPAA.com/510

    Breach, Blame, and Bad Behavior - Ep 509

    Play Episode Listen Later May 16, 2025 48:41


    When a cybersecurity CEO strolls into a hospital and decides to play malware magician with a couple of unlocked computers, you've got yourself a plot twist worthy of a Netflix docuseries. In this episode, we dive headfirst into bizarre breaches, finger-pointing fiascos, and the kind of contractual confusion that'll make you want to reread your SLAs before breakfast. It's a rollercoaster of responsibility, reputation, and really bad behavior. But at the heart of it all is the million-dollar question: who's actually responsible when it all goes sideways? More info at HelpMeWithHIPAA.com/509

    Busy Broke and Breached - Ep 508

    Play Episode Listen Later May 9, 2025 52:50


    Healthcare still has a giant “Hack Me” sign taped to its back — and the latest reports from Mandiant and Verizon are here to confirm it. These cybercrime breakdowns reveal that attackers are smarter, sneakier, and spending more time poking around your network than ever before. Waiting to secure your systems until after a breach is like installing a smoke detector after the house has already burned down — by the time you smell smoke, it's too late. From dwell times that feel more like extended Airbnb stays to small businesses learning that “we're too small to target” isn't a strategy, the findings hit hard and the lessons come wrapped in some well-placed snark. More info at HelpMeWithHIPAA.com/508

    Access Granted... and Never Revoked - Ep 507

    Play Episode Listen Later May 2, 2025 41:28


    If the Ponemon study were a horror flick, it'd be titled "The Login Came from Inside the System." This week's episode dives into the alarming trend of organizations handing out privileged access like Halloween candy — only to forget who's still got it long after the party's over. With 59% of breaches linked to insiders or third parties, and executives confidently sailing past the iceberg of reality, we explore what happens when no one's really sure who can still get into the network. Spoiler alert: it's not good. So grab your flashlight and audit logs — we're heading into the haunted house of unrevoked access. More info at HelpMeWithHIPAA.com/507

    They Got Hit. They Just Didn't Tell You. - Ep 506

    Play Episode Listen Later Apr 25, 2025 48:43


    Turns out, “they got hit, they just didn't tell you” isn't just a snarky title—it's a terrifying reality. The Black Fog report basically says, “Hey, the cybersecurity iceberg is way bigger below the surface.” From undisclosed data heists to the rapid rise of ransomware attacks, this is your reminder that you don't want to be the next plot twist in a cyber thriller. Oh, and yeah... shadow AI is watching too. Sleep tight! More info at HelpMeWithHIPAA.com/506

    HSCC Makes Bold Cyber Rx Move Before Congress - Ep 505

    Play Episode Listen Later Apr 18, 2025 53:52


    Imagine your hospital gets hacked—the MRIs are down, billing's frozen, and suddenly you're faxing patient records like it's 1999. No, that's not a “Twilight Zone” rerun—it's real life in health care. This week, we're diving into what the Health Sector Coordinating Council (HSCC) is doing about it, including their recent trip to Congress to lay it all out. From legacy devices clinging to life like old Tamagotchis to cybersecurity plans that don't sound half bad, we break it all down with just the right amount of snark. More info at HelpMeWithHIPAA.com/505

    Keeping It Boring and Patched - Ep 504

    Play Episode Listen Later Apr 11, 2025 47:22


    Forget action-packed heist movies — the real cybersecurity heroes are the ones making their auditors yawn. In this episode, we break down why "boring and patched" should be everyone's new life goal. From AI developments that won't sit still for five minutes to real-world cyber drama featuring surprise FBI visits (no popcorn needed), we're serving up a crash course in staying safe, sane, and just boring enough to avoid disaster. More info at HelpMeWithHIPAA.com/504

    AI Has A Patient Safety Problem - Ep 503

    Play Episode Listen Later Apr 4, 2025 48:52


    AI in healthcare is kind of like an overenthusiastic intern—it's full of potential, but someone probably should be watching it a little closer. In this episode, we dive into why artificial intelligence might be more “oops” than “awesome” when it comes to patient safety. A recent ECRI report flagged AI as a top safety concern and offered up smart recommendations like stronger governance and better training. From glitchy decision-making to eyebrow-raising cybersecurity breaches, we're unpacking why AI still needs some serious adult supervision in the healthcare world. More info at HelpMeWithHIPAA.com/503

    10 Security & Privacy Metrics to Keep Your SMB in the Black - Ep 502

    Play Episode Listen Later Mar 28, 2025 47:31


    Think your once-a-year vulnerability scan is enough? That's adorable. Waiting to check your security metrics until something goes wrong is like only checking your smoke alarm after the house starts smelling like burnt toast. In this episode, we peel back the layers on the top 10 security and privacy metrics every business should be tracking—whether you're the CEO, the IT person, or just someone who knows how to find the printer on the network. From patch management and MFA to phishing tests and forgotten routers older than your intern, we've got it all. Buckle up and get ready to verify like your digital life depends on it—because it kinda does. More info at HelpMeWithHIPAA.com/502

    HIPAA, Hackers, and Havoc – A Cybersecurity Reality Check - Ep 501

    Play Episode Listen Later Mar 21, 2025 56:16


    Buckle up, folks—this episode is a rollercoaster of cyber chaos! We kick things off with a quick chat about the upcoming PriSec Boot Camp (because let's be real, who doesn't love a good security boot camp?). But then, we dive headfirst into the madness: a fresh HIPAA smackdown over right-of-access failures, a rogue IT guy who locked down an entire company out of revenge, and some seriously sketchy Bluetooth vulnerabilities that could have hackers eavesdropping on your life. And if that wasn't enough, the 2025 SonicWall Cyber Threat Report drops some terrifying stats on ransomware, business email compromise, and how AI is making cyberattacks even more dangerous. Grab your tinfoil hat and let's get into it. More info at HelpMeWithHIPAA.com/501

    500 Episodes Later – The Threats Are Worse But So Are Our Jokes - Ep 500

    Play Episode Listen Later Mar 14, 2025 44:55


    500 episodes. A whole decade. Countless cybersecurity threats (and just as many dad jokes). Somehow, we're still talking about the same cybersecurity nightmares—only now with fancier threats and AI-powered scams. In this milestone episode of Help Me With HIPAA, we take a trip down memory lane—reminiscing about our early struggles, the evolution of security risks, and why some lessons seem to need repeating... forever. Spoiler alert: bad guys are still bad, security is still hard, and if you've been with us since episode one, you're officially a HMWH OG. If you're new here, welcome—just know that staying out of breaches is a marathon, not a sprint. More info at HelpMeWithHIPAA.com/500

    AI Tools Making AI Fools - Ep 499

    Play Episode Listen Later Mar 7, 2025 42:58


    Cybersecurity: It's like flossing—we all know we should do it, but a shocking number of people just…don't. This week, we're digging into the annual cybersecurity attitudes and behaviors report, which reveals just how careless people are with their passwords, personal info, and, well, basic online survival skills. But don't worry, AI is here to save us! Or, possibly, to make things even worse. We'll also explore how AI tools are being used (and misused), and why a scary number of people are feeding them sensitive work info like it's a buffet. Buckle up—this one's got some eye-opening stats! More info at HelpMeWithHIPAA.com/499

    Big Money Breaches & Bad Security Grades - Ep 498

    Play Episode Listen Later Feb 28, 2025 45:03


    Cybersecurity report cards are in, and let's just say—most companies would be grounded if their IT security grades were real school grades. With over 80% of Fortune 500s scoring a D or F, and healthcare companies hovering around the danger zone, it's clear that many organizations are securing data about as well as a cardboard vault. Just ask Warby Parker, which racked up multiple breaches over the years while seemingly skipping Cybersecurity 101. In this episode, we break down what these cybersecurity scores mean, how they were calculated, and what companies should be doing before they end up in the digital hall of shame. More info at HelpMeWithHIPAA.com/498

    DeepSeek, Deepfakes and AI's Big Game Moment - Ep 497

    Play Episode Listen Later Feb 21, 2025 40:21


    AI just leveled up, and we're here to talk about it! In this episode, we dive into DeepSeek—the AI model that shook up the stock market, gave OpenAI a run for its money (literally), and is both insanely cheap to run and totally open-source (which is equal parts exciting and terrifying). We also break down the rise of deepfake scams, AI's growing role in cybersecurity, and why you should probably question everything you see and hear online. If you love tech, security, and a healthy dose of paranoia, buckle up—this one's for you! More info at HelpMeWithHIPAA.com/497

    Healthcare Has A Kick Me Sign - Ep 496

    Play Episode Listen Later Feb 14, 2025 45:17


    Imagine leaving your front door wide open in a neighborhood full of burglars, then acting shocked when your TV disappears. That's basically what's happening in healthcare cybersecurity. This week, we're talking about why hackers are running rampant, how small healthcare practices are prime targets (no, you're not “too small to matter”), and what basic security steps can actually make a difference. Spoiler alert: Ignoring the problem won't make it go away.   More info at HelpMeWithHIPAA.com/496

    Bare Minimum Isn't a Security Strategy - Ep 495

    Play Episode Listen Later Feb 7, 2025 36:48


    If you've ever wondered what it's like to scream into the cybersecurity void, this episode might feel oddly relatable. We dive into why “bare minimum” isn't a security strategy—it's more like playing Russian roulette with your data. From regulatory head-scratchers to the harsh reality that a “bare minimum” security strategy is about as effective as locking your front door while leaving the windows wide open, this episode is your wake-up call, packed with sharp insights, analogies involving go-karts on the interstate, and the occasional frustrated sigh. More info at HelpMeWithHIPAA.com/495

    From $10K to $3M: The Price Tag of Neglecting Cybersecurity - Ep 494

    Play Episode Listen Later Jan 31, 2025 40:23


    If ignoring cybersecurity was a sport, some companies would be gold medalists—until they realize the prize is a hefty fine and years of regulatory headaches. It's like leaving your car unlocked in a sketchy part of town with a neon sign that says, “Free Stuff Inside.” What could possibly go wrong? Well, in this episode, we break down six real-life cases that prove skimping on security is way more expensive than just doing it right in the first place. From ransomware attacks to patient right of access failures, we're diving into what went wrong, why it happened, and—most importantly—how you can avoid becoming the next cautionary tale. More info at HelpMeWithHIPAA.com/494

    Cavity of Lies: Westend Dental's HIPAA Coverup - Ep 493

    Play Episode Listen Later Jan 24, 2025 41:37


    Buckle up, folks, because this week's episode is a wild ride through the Cavity of Lies—where HIPAA violations, ransomware attacks, and outright absurdity collide. What happens when a dental group tries to sweep a massive breach under the rug (or, you know, hide servers in bathrooms)? Let's just say it doesn't end well. From a 3-year-long cover-up to servers stored in all the wrong places, we've got lies under oath, policies that might as well be urban legends, and enough bad decisions to make you cringe harder than hearing the dentist say “we need to talk about your flossing habits.” More info at HelpMeWithHIPAA.com/493

    HIPAA Security Changes Are Here: We Saw This Coming - Ep 492

    Play Episode Listen Later Jan 17, 2025 56:43


    Hold onto your compliance hats—big changes are brewing for HIPAA's Security Rule! The Notice of Proposed Rulemaking (NPRM) is officially out for public comment, and it's clear HHA and OCR are on a mission to modernize and tighten the safeguards for electronic protected health information (ePHI). From clarifying risk analysis expectations to making security requirements less, well, “vague,” these updates aim to bolster patient safety and data protection while keeping pace with today's tech-driven world. But with great updates come great responsibilities for covered entities and business associates alike, so now's the perfect time to weigh in and help shape the final rule before it's set in stone. More info at HelpMeWithHIPAA.com/492

    hipaa ocr coming ep hha security rule hipaa security ephi proposed rulemaking nprm
    PriSec Priorities Q1 2025 - Ep 491

    Play Episode Listen Later Jan 10, 2025 47:55


    Ready to kick off 2025 with a bang? We're diving into the must-dos for your Q1 2025 compliance and cybersecurity checklist, sprinkling in some risk management wisdom, and why Windows 10 is about as fashionable as shoulder pads in the 2020s. Plus, we sprinkle in a hearty dose of snark to keep you entertained while you get your compliance game strong. Oh and if your incident response plan is just “hope for the best,” it's time to tune in. More info at HelpMeWithHIPAA.com/491

    Supply Chain Attacks: The Risks Keep Growing - Ep 490

    Play Episode Listen Later Jan 3, 2025 50:45


    Ah, supply chain attacks—the gift that keeps on giving... headaches, fines, and catastrophic data breaches. In this episode, we unwrap three cautionary tales of organizations caught in the tangled web of digital supply chain chaos. From unpatched vulnerabilities and sneaky software backdoors to hackers casually buying network access like it's an eBay auction, each story serves up a hard truth: you don't want to be part of a supply chain attack, you don't want to have a supply chain attack, and you definitely don't want to delay dealing with a supply chain attack. So grab your metaphorical flashlight and let's go spelunking into the murky caves of cybersecurity mishaps. More info at HelpMeWithHIPAA.com/490

    Phishing Fails, SRA Woes and the OCR Hammer - Ep 489

    Play Episode Listen Later Dec 27, 2024 51:16


    It's the final countdown, folks—the last episode of the year! And OCR decided to end 2024 with a bang, handing out settlements like candy at a Christmas parade. But here's the twist: the candy comes with a price tag, and it's not cheap. This episode hones in on OCR's new enforcement initiative targeting incomplete and outdated risk analyses. So, before you pop the champagne, let's make sure your SRA isn't a ticking compliance time bomb. More info at HelpMeWithHIPAA.com/489

    2024 Holiday Blooper Show

    Play Episode Listen Later Dec 20, 2024 13:51


    Welcome to the 2024 Blooper Show, where we prove once again that even after nine years, perfection is overrated and laughter is mandatory! Big shoutout to Bojan, our long suffering audio engineer extraordinaire, who turns our chaos into coherence. And of course, we can't forget you—our amazing listeners—who tune in each week, send us your thoughts and questions, and share the chaos with your friends. Cheers to you for making this madness worth it! More info at HelpMeWithHIPAA.com/2024blooper

    Incident Panic to Plan for SMB Execs - Ep 488

    Play Episode Listen Later Dec 13, 2024 50:09


    Cybersecurity incidents can feel like a punch in the gut, but with the right plan, you can roll with the hits instead of flailing in panic. In this episode, we're diving into executive strategies for tackling the unexpected, from building response teams to keeping business operations afloat when chaos strikes. Along the way, we also cover a recent corrective action plan that serves as a cautionary tale for getting your protocols in order before trouble comes knocking. This is your go-to guide for staying cool when the heat is on! More info at HelpMeWithHIPAA.com/488

    Access Delayed, Ransom Paid, Cyber Aid Conveyed - Ep 487

    Play Episode Listen Later Dec 6, 2024 54:46


    Is your healthcare organization ready for a triple threat, or are you playing a risky game of cybersecurity roulette with delayed access, ransomware demands, and a missing incident response plan? Today, we explore three tales in healthcare that are equal parts cautionary and compelling. We kick things off with the Healthcare and Public Health Sector Coordinating Council's shiny new cyber incident response checklist—aka your cheat sheet for keeping calm in the face of chaos. Then, we give you the juicy details of a hefty civil money penalty slapped on a healthcare entity for dragging their feet on providing patient records (spoiler alert: patience isn't a virtue when it comes to HIPAA). Finally, we unravel the saga of a ransomware attack that not only encrypted data but also emptied some wallets. Whether you're here to learn, laugh, or just feel better about your own compliance game, this episode's got you covered. Buckle up, because the HIPAA ride is wild! More info at HelpMeWithHIPAA.com/487

    Thankful It Is Not Me - Ep 486

    Play Episode Listen Later Nov 29, 2024 38:55


    Feeling thankful this season? Us too—especially when it comes to dodging data disasters! In this episode, Donna and David dive headfirst into some eyebrow-raising cybersecurity tales, from job application breaches exposing sensitive information to the ever-creepy risks of unsecured IoT devices (yes, even your vacuum might be plotting against you). Whether it's researchers discovering unsecured data files or hackers turning robot vacuums into racially inappropriate terrors, we're reminded to never take our digital safety for granted. Grab your popcorn (or an encrypted snack, if that's a thing) and join us as we talk about what it means to truly be grateful for solid security practices this year. More info at HelpMeWithHIPAA.com/486

    First SRA Violation Settlement - Ep 485

    Play Episode Listen Later Nov 22, 2024 45:20


    Doing a half-baked risk analysis is like locking your front door but leaving all the windows wide open. What's the point?  Today, we dive into the first-ever Security Risk Assessment (SRA) violation settlement—a juicy topic for compliance nerds and healthcare pros alike. We're talking ransomware, compliance checklists (the kind you actually need), and why a “kinda-sorta risk analysis” isn't going to cut it with the OCR. Along the way, we'll break down the $90K fine, the three-year corrective action plan, and what this means for everyone still winging their HIPAA risk assessments. Time to up your game folks! More info at HelpMeWithHIPAA.com/485

    OCR NIST Part 2 - Ep 484

    Play Episode Listen Later Nov 15, 2024 61:37


    Buckle up for Part 2 of our breakdown on the HHS OCR NIST healthcare security conference - because, yes, 16 hours of deep dives into AI, HIPAA compliance, and cybersecurity priorities can't be tackled in just one episode! From wild projections about AI's future in healthcare to OCR's “tough love” on compliance standards, this episode peels back the curtain on the big decisions shaping healthcare data security. It's a whirlwind tour through risks, regulations, and the occasional debate on why “just doing it the old way” won't cut it anymore. Let's get into it! More info at HelpMeWithHIPAA.com/484

    OCR NIST Conference Part 1 - Ep 483

    Play Episode Listen Later Nov 8, 2024 57:43


    Buckle up, folks! Today, Donna and David are here with Part 1 of their deep dive into the recent HHS OCR NIST healthcare security virtual conference, and they're spilling all the cyber-tea. With experts from HHS, OCR, NIST, FTC, and FDA presenting, this conference covered a ton. From AI-powered hackers and QR code scams to unpatched medical devices and a spike in supply chain attacks, the discussions centered on what it takes to keep healthcare data and devices secure in a constantly evolving threat landscape. Wondering why healthcare data security feels like a game of whack-a-mole? Tune in to find out! More info at HelpMeWithHIPAA.com/483

    Sell Me This Pen - Ep 482

    Play Episode Listen Later Nov 1, 2024 53:56


    Ever heard someone say you need a pen test but then start wondering if they meant a pen from a spy movie? There typically is a lot of confusion between penetration testing and vulnerability assessments—a common mix-up with big consequences for your cybersecurity game. We will walk through different types of pen tests, explain how they help you spot weaknesses before the bad guys do and tackle why continuous vulnerability management can save you from surprises. Whether you're building up your defenses or simply trying to keep up with best practices, this episode is packed with insights on staying ahead of cyber threats, one test at a time. More info at HelpMeWithHIPAA.com/482

    Gumming Up the Works: Dental Record Request Nightmare - Ep 481

    Play Episode Listen Later Oct 25, 2024 52:24


    Ever had a root canal that felt less painful than dealing with bureaucracy? Well, buckle up, because in this episode, we sink our teeth into the 50th patient right of access enforcement action under HIPAA. That's right—50 cases since 2019, and somehow, this one involving Dr. Gumb (yes, really) and a dental records dispute is the most absurd of the bunch. From a refusal to hand over records to racking up government fines like trading cards, this saga is a wild reminder of what happens when compliance takes a backseat.  More info at HelpMeWithHIPAA.com/481

    Ransomware, Recall, and Regulations - Ep 480

    Play Episode Listen Later Oct 18, 2024 51:27


    Today we tackle the trifecta of cybersecurity headaches: Microsoft's awkwardly ambitious recall feature, the looming HISAA regulations (because HIPAA wasn't enough), and a juicy enforcement action following a ransomware attack. We'll break down how Microsoft's recall reboot went from intrusive default to opt-in relief, why HISAA could mean mandatory stress tests for healthcare providers, and what lessons we can learn from a ransomware attack that left 291,000 patient records exposed—and a corrective action plan no one wants. If you've ever wondered how healthcare security, government fines, and tech mishaps collide, this one's for you. More info at HelpMeWithHIPAA.com/480

    Browsers & Breaches - Ep 479

    Play Episode Listen Later Oct 11, 2024 47:46


    Leaving your web browser open with 25 tabs is the digital version of leaving your front door unlocked? Whether it's for email, work docs, shopping, or watching cat videos, your browser is the gateway to, well, everything. But as much as we depend on them, so do hackers. From credential theft to sneaky phishing attacks, cybercriminals are finding clever ways to turn your favorite browser into a tool for their dirty work. Today, we'll break down the wild world of browsers—how we rely on them, and how hackers are exploiting them while we casually leave 25 tabs open at once. Note to self:  it's time to update your browser (and maybe close a few tabs)! More info at HelpMeWithHIPAA.com/479

    Halloween Comes Early This Year - Ep 478

    Play Episode Listen Later Oct 4, 2024 46:38


    Avoid These 5 Healthcare Marketing Mistakes - Ep 477

    Play Episode Listen Later Sep 27, 2024 52:45


    Healthcare marketing is tricky enough without tripping over the big pitfalls that could leave you tangled up in HIPAA violations or a patient privacy disaster. Today we break down five common marketing mistakes you definitely want to steer clear of. From misinterpreting HIPAA rules to guarding patient data like it's your grandma's secret cookie recipe, these blunders can get you into serious trouble. We're here to help you navigate these common missteps and protect your business from unnecessary risks. More info at HelpMeWithHIPAA.com/477

    You Have Been Warned - Ep 476

    Play Episode Listen Later Sep 20, 2024 45:13


    Do you feel like cyberattacks are the world's worst game of whack-a-mole? No matter how many you smack down, ten more pop up— and there's no sign of it slowing anytime soon and neither is the confusion over who's responsible when your data gets caught in the crossfire. If your supply chain and your own security safeguards aren't locked down, you might as well be rolling out the red carpet for hackers. Tune in as we break down the latest mess, and yes, it's as frustrating as it sounds! More info at HelpMeWithHIPAA.com/476

    Check Your Facility Access Controls - Ep 475

    Play Episode Listen Later Sep 13, 2024 52:11


    Ever left your front door unlocked, thinking it's no big deal? Well, that's what happens when you forget about facility access controls – and the consequences can be far worse than a missing TV!  Today, we dive deep into a topic that often gets overlooked but is critical to any organization's security – facility access controls. Whether it's ensuring that only authorized personnel can access sensitive areas or protecting valuable equipment from walking out the door, facility access controls are a crucial part of safeguarding not just data but also physical assets. And as much as we love talking about tech, this time it's all about locks, keys, and keeping the wrong people out.  More info at HelpMeWithHIPAA.com/475

    Using Free CSAM Toolkit - Ep 474

    Play Episode Listen Later Sep 6, 2024 42:40


    It's that time of year again: Cybersecurity Awareness Month! We're diving into the world of cybersecurity like a hacker in a candy store—except we're here to keep the candy (your data) safe! We're breaking down how you can use the free CE Awareness Month toolkit to boost your cybersecurity game both in your business and at home. Whether you're an IT pro or someone who just learned how to turn on two-factor authentication, we've got tips, tricks, and a few laughs to help you navigate the digital wild west. So buckle up and let's secure our world, one strong password at a time! More info at HelpMeWithHIPAA.com/474

    Yes You Are A Victim - Ep 473

    Play Episode Listen Later Aug 30, 2024 52:29


    Navigating the world of cybersecurity these days feels like walking through a minefield with clown shoes—are you stepping safely or just a step away from disaster? In this episode, we dive into the jaw-dropping National Public Data breach that's got everyone asking, "Am I a victim too?" Spoiler alert: the odds aren't in your favor. Then, we sift through the chaos of the recent CrowdStrike outage because what's a week in cybersecurity without a little mayhem? And just when you thought it couldn't get worse, we've got a few more terrifying tales ripped straight from the headlines to keep you on your toes. Grab your stress ball, and let's brace ourselves for a journey into the digital dark side! More info at HelpMeWithHIPAA.com/473

    Show me your SBOM - Ep 472

    Play Episode Listen Later Aug 23, 2024 37:51


    In this episode, we're diving deep into the world of Software Bill of Materials (SBOM)—basically, the recipe for your software, minus the secret sauce. If you've ever wondered what's really under the hood of your favorite apps (or been caught off guard by a sneaky ingredient), this one's for you. We're breaking down why you should care about SBOMs, how they're becoming a must-have in your vendor vetting process, and what it all means for the future of tech. Think of it as your crash course in making sure your software isn't serving up any nasty surprises. More info at HelpMeWithHIPAA.com/472

    A Bloody Mess - Ep 471

    Play Episode Listen Later Aug 16, 2024 51:47


    Navigating healthcare cybersecurity is like walking through a minefield—you never know which step could trigger the next explosion. In this episode, we're diving headfirst into the bloody mess of ransomware attacks that have turned hospitals and blood banks into a logistical nightmare. Amidst the chaos, Health-ISAC and the American Hospital Association are urging special consideration for critical supply chain entities. It's a wild ride through the chaos that one click can unleash on healthcare, and how the ripple effects can leave everyone scrambling to pick up the pieces. More info at HelpMeWithHIPAA.com/471

    How Well Do You Know Remote Workers? - Ep 470

    Play Episode Listen Later Aug 9, 2024 42:10


    How well do you really know your remote workers? With remote work increasingly becoming the norm, the complexities of securing devices and monitoring access have skyrocketed. The challenges of providing robust security measures for an increasingly dispersed workforce are immense. Real-world examples like the KnowBe4 incident, where a remote worker used a stolen identity to infiltrate company systems, highlight the necessity of layered security and proactive monitoring. Our discussion today, highlights the crucial need to grasp the subtle threats from cyber attackers, especially when dealing with sensitive patient data and HIPAA compliance. More info at HelpMeWithHIPAA.com/470

    CrowdStrike's Major Tech Outage - Ep 469

    Play Episode Listen Later Aug 2, 2024 40:33


    Ever had one of those days where everything just seems to crash and burn? Well, in this episode, we dive into a tech catastrophe that sent ripples across the digital landscape. Donna and David will unravel the chaos caused by CrowdStrike's major tech outage—a meltdown that wasn't just an ordinary hiccup, but a vendor-of-a-vendor fiasco. From blue screens of death to grounded flights, this incident highlights the domino effect a single update can have on the entire supply chain. More info at HelpMeWithHIPAA.com/469

    OCR Ransomware Settlement - Ep 468

    Play Episode Listen Later Jul 26, 2024 37:48


    Ever wondered how neglecting a cybersecurity risk analysis is like leaving your front door wide open in a sketchy neighborhood? Well, buckle up because today we dig into the latest OCR ransomware settlement involving Heritage Valley Health Systems and a laundry list of potential violations. From failing to conduct a thorough risk analysis to lacking a proper contingency plan for ransomware attacks to neglecting to train their workforce on policies and procedures, this is a cautionary tale of what happens when cybersecurity isn't taken seriously. More info at HelpMeWithHIPAA.com/468

    Just Because You Can Does NOT Mean You Should - Ep 467

    Play Episode Listen Later Jul 19, 2024 46:01


    In the HIPAA world, just because you can, doesn't mean you should – unless you're keen on trading your business casual for prison orange. No one expects that a HIPAA violation will send them to jail, but there can be serious criminal penalties associated with HIPAA breaches, ranging from fines to imprisonment. Today, we will share real-life examples of how some people misinterpret their rights to access patient records. More info at HelpMeWithHIPAA.com/467

    How Can SMBs Do SSO? - Ep 466

    Play Episode Listen Later Jul 12, 2024 50:41


    How can small and medium businesses (SMBs) tackle the complexities of single sign-on (SSO) and boost their password security? A recent study from CISA highlighted the lag in SSO adoption among SMBs and why basic security measures like SSO and multi-factor authentication (MFA) should be standard. Join us as we navigate through the maze of managing multiple passwords, the pitfalls of manual methods, and the critical need for vendors to prioritize security from the get-go.  More info at HelpMeWithHIPAA.com/466

    Always BOLO - Ep 465

    Play Episode Listen Later Jul 5, 2024 52:45


    Ever wonder why staying vigilant in cybersecurity is like playing whack-a-mole? Let's dive into some wild stories that highlight the need to always be on the lookout! From hackers using legitimate websites to spread malware, to the humorous and slightly terrifying saga of employees using mouse jigglers to fake work, to cyberattacks from space, there are a lot of reasons why we should always keep our guard up in the wild world of cybersecurity! More info at HelpMeWithHIPAA.com/465

    Crawl Out Through The Fallout - Ep 464

    Play Episode Listen Later Jun 28, 2024 51:00


    What happens when healthcare giants falter in the face of cyber threats? Today, we dive into the critical need for better cybersecurity investments, continuous training and education and robust cybersecurity standards. We will explore the fallout from UHG's cyber incident and break down three fiery letters from Congress demanding accountability and stricter regulations for cybersecurity practices in healthcare. More info at HelpMeWithHIPAA.com/464

    Will Your Response Plan Work Without Internet? - Ep 463

    Play Episode Listen Later Jun 21, 2024 48:15


    Today, we're diving into a topic that might keep you up at night and might make you reconsider your relationship with your Wi-Fi router. Picture this: your internet goes down, and it's not just a blip—it's a full-blown blackout. We're talking no Netflix, no Zoom meetings, and definitely no online shopping. We'll unravel the chaos that ensues and discuss how you can keep your cool and your business running smoothly when the digital world decides to take a nap. More info at HelpMeWithHIPAA.com/463

    7 Crucial Steps to a Comprehensive SRA - Ep 462

    Play Episode Listen Later Jun 14, 2024 61:29


    Join us as we debunked some common myths about what Security Risk Analysis isn't and then cruise through the seven essential steps to conduct a complete and thorough SRA for any organization. It's not just a one-off IT review or a checkbox on compliance forms—it's an ongoing, dynamic process. From identifying what you need to protect to managing how you protect it, each step builds on the last to fortify your defense against the digital wild west.  More info at HelpMeWithHIPAA.com/462

    comprehensive sra crucial steps security risk analysis
    Can Clickers Change? - Ep 461

    Play Episode Listen Later Jun 7, 2024 48:57


    Today we dive into the world of compulsive clickers—the folks who just can't help but tap on every tantalizing link that winks at them from their inbox. It's not just a harmless habit; these clicks can lead to some pretty sketchy places. Imagine a world where every click could be a potential minefield, threatening your digital safety with every tap. But here's the kicker: can we change these click-happy habits? Let's explore whether it's possible to turn a reckless clicker into a prudent, pause-and-think-before-you-click kind of user.  More info at HelpMeWithHIPAA.com/461

    Claim Help Me With HIPAA

    In order to claim this podcast we'll send an email to with a verification link. Simply click the link and you will be able to edit tags, request a refresh, and other features to take control of your podcast page!

    Claim Cancel