Help Me With Hipaa

Informações:

Sinopsis

HelpMeWithHIPAA.com is a collaboration between Kardon Compliance founder, Donna Grindle, and HIPAAforMSPs.com founder, David Sims. Our mission is to share our Privacy and Security knowledge with those who are required to understand, implement, and manage the complex Privacy and Security requirements of HIPAA compliance.Our work with CEs and BAs inspired us to launch the service to provide information about the complex requirements of HIPAA in a relaxed manner without using too much legalese or geek speak. As the podcasts programs progress we will cover topics about that include sorting through the requirements as well as real world examples of the procedures used, both good and bad.Join us as we do our best to create a show where HIPAA and humor collide!

Episodios

  • Disaster Recovery Planning Under HIPAA - Ep 75

    14/10/2016 Duración: 45min

    Everything going on today with hurricanes and such makes it is a great time to talk about this. We mention it all the time but this episode is going to be just about what DR/BC means and what you can do to be prepared in advance.  So, this episode covers disaster recovery planning under HIPAA but any business can learn from our topics! What is DR/BC Planning? Who should do it? Is this another big expense? What is involved in building and maintaining DR/BC plans? General elements of a plan Get more details at http://HelpMeWithHIPAA.com/75

  • HIPAA Security Updates Recommended In New Report - Ep 74

    07/10/2016 Duración: 45min

    Last year Sen. Lamar Alexander and Sen. Patty Murray asked for answers to some questions concerning cybersecurity in healthcare.  They were interested in understanding what CMS and HHS were doing to protect patients from fraud.  It seems as though they were wondering if HIPAA security updates where needed.   We discussed the Senators request in episode 31 : https://helpmewithhipaa.com/episode-31-enforcement-efforts-ocr-increase-2016/ Their letter asked: What CMS and HHS is doing to monitor medical identity fraud What is CMS and/or OCR actually doing, if anything, to track cases of ID theft and fraud OCR uses the data collected from covered-entities to monitor potential breach victims and find out if their data have in fact been used by criminals They also want to know whether any education materials or help are offered to breach victims by the CMS and OCR The report was presented to the committee on August 6, 2016 and made public on Sept 26.

  • Business Associate Security Issues - EP 73

    30/09/2016 Duración: 44min

    BAs are in the HIPAA spotlight now more than ever. TheDarkOverlord was clearly using some BA applications to infiltrate networks and exfiltrate PHI. OIG reviewed Alaska VA system after breaches and the report specifically points to the need to monitor BAs OCR audits of BAs are about to start. Previously said end of September but now saying October In this episode we discuss what all this means. More at HelpMeWithHIPAA.com/73

  • HIPAA Penalties Increasing - Ep 72

    23/09/2016 Duración: 36min

    Did you hear that maximum penalties for HIPAA violations are being adjusted for inflation? It has quietly happened. Here is how. Check out the Federal Register entry from September 6, 2016. If you aren't in to reading yourself, don't worry, you know Donna did it. Well, at least the HIPAA parts. Learn more at: HelpMeWithHIPAA.com/72

  • OCR small breach investigations increasing - Ep 71

    16/09/2016 Duración: 35min

    OCR recently released another memo concerning compliance enforcement efforts.  They say effective August 2016, they have started an initiative to more widely investigate breaches involving under 500 patients.  That means that OCR small breach investigations will begin happening immediately.  In the past, the policy had been to investigate all breaches over 500 patients but not under.   More information at HelpMeWithHIPAA.com/71  

  • Insider Threats: Do you know who your employees are? - Ep 70

    09/09/2016 Duración: 37min

    OCR published a memo on Aug 1, 2016.  The title is "Do you know who your employees are?".  It is a great reminder about insider threats that we should all worry about regularly. Quoted directly from the memo. ============================ Although all insider threats are not malicious or intentional, the effect of these threats can be damaging to a Covered Entity and Business Associate and have a negative impact on the confidentiality, integrity, and availability of its ePHI. According to a survey recently conducted by Accenture and HfS Research, 69% of organization representatives surveyed had experienced an insider attempt or success at data theft or corruption. Further, it was reported by a Covered Entity that one of their employees had unauthorized access to 5,400 patient’s ePHI for almost 4 years. For more visit: HelpMeWithHIPAA.com/70

  • OCR 2016 settlements keep coming - Ep 69

    02/09/2016 Duración: 44min

    So far in 2016 there have been 10 resolution agreements announced. One more and this year will equal the number of agreements in all of 2015 & 2014! The latest two also include the largest one announced yet - $5.5m with Advocate Health. Before that though was The University of Mississippi Medical Center - Ole Missto those of us in the SEC world. It wasn't something to "shake a stick at" with a$2.75m resolution amount. The total amount for those 10 announcements so far in 2016 = $20,314,800 Of course the details are what we usually pay more attention to since it tells us exactly what OCR has a problem with in each case. It makes it clear what OCR wants all of us to learn from these folks mistakes. For more visit HelpMeWithHIPAA.com/69

  • OCR Desk Audit Details - Ep 68

    26/08/2016 Duración: 47min

    The OCR audits have begun.  On Wednesday, July 13, audit selected CEs where invited to a webinar. OCR staff walked through the processes they can expect for the audit and expectations for their participation.  The OCR published information from the webinar so we had to check it out and share what we learned with you guys.   For more details visit HelpMeWithHIPAA.com/68

  • Pokemon Go and HIPAA Breaches - Ep 67

    19/08/2016 Duración: 36min

    Say it ain't so! Pokemon and a HIPAA breach really? REALLY! Creatures are showing up in offices and hospitals just like everywhere else. The concept of keeping people active and engaged with their surroundings while playing a video game seems like a great idea from a healthcare standpoint. And then you actually do a risk assessment of it - this is where the wheels fall off that good idea train. Get more details as HelpMeWithHIPAA.com/67

  • Healthcare Hack: PHI For Sell On The DarkNet - Ep 66

    12/08/2016 Duración: 39min

    We first talked about this in Ep 62. Darknet sale of healthcare records. Now, more information is coming out and it gets more unfortunate for patients every time we read more. Deep Dot Web broke the news: https://www.deepdotweb.com/2016/06/26/655000-healthcare-records-patients-being-sold/ We picked it up on Data Breaches.net because they were trying to figure out who the entities actually were in each case: https://www.databreaches.net/damn-anyone-know-what-facilities-these-are/ Get more info at https://HelpMeWithHIPAA.com/66

  • OCR resolution agreement - OHSU - EP 65

    05/08/2016 Duración: 44min

    What happened? March 23, 2013 Oregon Health & Science University notified HHS of a breach due to a stolen unencrypted laptop. May 1, 2013 OCR notifies them they are investigating the incident July 28, 2013 Oregon Health & Science University notified HHS of another breach resulting from storing ePHI at an internet-based service provider without a business associate agreement November 8, 2013 OCR notifies them they are investigating the new incident July 18, 2016 settlement announced for $2.7 million and a 3 year CAP   What can we learn from this?  Go to Help Me WithHIPAA.com/65

  • Security Incident Response Plan - Ep 64

    29/07/2016 Duración: 37min

    OCR recently sent out a message on their listserv asking if your CE or BA was ready for an incident. We have been discussing security incidents a lot lately so it is nice that OCR has brought it up. Because we have seen various Incident response reports recently, so we were working on an episode anyway.  So this episode is a review of Security Incident Response Plan development. Let's first be clear, this isn't just about HIPAA. We also have been reviewing the Economist Intelligence Unit 2013 (EIU) report: Cyber incident response: Are business leaders ready?, which is asking the very same question. For more information go to HelpMeWithHIPAA.com/64

  • Medical Device Security - Ep 63

    22/07/2016 Duración: 41min

    There has been a lot of news and industry discussions about Medical Device security. Medical Devices are just like a computer, so they also need security to protect the information on them.   For more go to HelpMeWithHIPAA.com/63

  • Business Associate Breaches In The News - Ep 62

    15/07/2016 Duración: 40min

    A business associate is getting this OCR resolution, $650,000 and a two-year settlement.  CHCS in Philadelphia is a BA to 6 skilled nursing clinics in the Philadelphia area. Entities like this do the business part of healthcare and the other clinics don’t have to worry about it. An unencrypted iPhone that wasn’t password protected had PHI on it.     Patterson Dental Supply Inc. helps manage dental practice information for various providers. One of the clinics they help service is Massachusetts General Hospital, and 4,300 patients had their PHI hacked and compromised.   For more info: HelpMeWithHIPAA.com/62

  • Healthcare Data Breach Study - Ep 61

    08/07/2016 Duración: 33min

    Since 2010, ID Experts has sponsored this Ponemon Institute study which has been tracking data breach trends of patient data at healthcare organizations. The annual economic impact of a data breach has risen over the past six years, as has the frequency of data breaches. Criminal attacks and internal threats are the leading cause of healthcare breaches. Evolving cyber attack threats such as ransomware and malware are of primary concern for 2016. At the same time, internal issues such as employee negligence, third-party snafus, and stolen computing devices continue to put patient data at risk. For more info on this episode go to helpmewithhipaa.com/61 28w47ezq

  • HIPAA Rules In A Crisis - Ep 60

    01/07/2016 Duración: 30min

    As always, during times of crisis and chaos things do become confused and incorrect statements are made. It is a normal occurrence in troubling situations. But, we need to address it specifically to clear up a few points. There was no "special waiver from the White House". There was no need for one at all. People, even in a crisis, should not be invoking HIPAA over caring for the patient properly. The hospitals talked about implementing their crisis plan - why wasn't HIPAA addressed in the plan. It should be! For more details go to HelpMeWithHIPAA.com/60

  • HIPAA, HHS, OCR, and PHI - Ep 59

    24/06/2016 Duración: 42min

    Today’s podcast is a little different from our normal ones. We are covering a wide variety of subjects involving HIPAA, OCR, HHS, and PHI rather than one specific topic.   For more go to HelpMeWithHIPAA.com/59

  • Preventing Ransomware - Ep 58

    17/06/2016 Duración: 35min

    Preventing ransomware is a major concern for every business today.  If not, it should be.  This episode covers understanding ransomware and methods for preventing it. Is ransomware a phi breach? April record number of cases and not slowing down 8 hospitals (more by the time we record) already hit. Training and vigilance is best defense Ransomware attacks continue to evolve to be "smarter"   For more see HelpMeWithHIPAA.com/58

  • HIPAA Policy and Procedure Templates - Ep 57

    10/06/2016 Duración: 32min

    HIPAA policy and procedure templates seem to be a panacea to many people who are just trying to meet the standards and move on. However, these are not the droids you seek! Templates can be the basis for what you need to do but they shouldn't be the solution to the written policy and procedure requirements under HIPAA.   See HelpMeWithHIPAA.com/57

  • Malware Protection under HIPAA - Ep 56

    03/06/2016 Duración: 47min

    Two reasons for today's topic: A question we received from a listener about understanding antivirus software and a news report about a malware scan that interrupted a medical procedure. Between those two cases it felt like it was time to discuss malware protection under HIPAA. Suzie from Savannah: I would like to have a podcast or a quick answer to the different between anti-virus software releases and anti-virus definitions being up-to-date. I understand the AV definitions up to date but a little fuzzy on AV software releases and examples please.... Report came out about malware scan stopping a medical procedure   

página 21 de 24