In today's environment of data breaches, identity theft, fraud, and increasing connectivity, HIPAA Privacy and Security rules are a responsibility to your patients and your clients. HIPAA isn't about compliance, it's about patient care.
Healthcare is complicated. Joe Gellatly and Amanda Hepper are here to help, guiding us through the biggest issues and updates in healthcare security and compliance. From HIPAA Risk Assessments to the dark web, learn what factors are affecting the security of healthcare information and how to protect your data. Tune in for news, advice, and more.
HIPAA compliance is complicated, confusing and easy to get wrong. Violations, data breaches and ransomware attacks are everywhere in healthcare. HIPAA Critical brings interviews with leaders in cybersecurity, InfoSec, healthcare, and compliance straight to you. Each 30-minute episode is designed to keep you informed and entertained. A new episode is released on the first three Wednesdays of every month.
Shared workstations—especially in clinical areas—can be a blind spot in privacy and security. Whether it’s leaving PHI on the screen, shared login credentials, or lack of session timeouts, these seemingly small things can cause big issues. Learn more about Medcurity here: https://medcurity.com #Healthcare #Cybersecurity #Compliance #HIPAA #Security…
Welcome to another episode where chaos meets cybersecurity and common sense tries to crash the party. In this digital drama, we’re untangling the curious case of a former employee with way too much access, some mysterious printed medical records, and a whole lot of "Wait... WHAT?!" moments. We also dive into the thrilling (read: terrifying) reality…
What’s really driving breaches in healthcare? This episode breaks down key stats from the 2025 Verizon Data Breach Investigations Report—including ransomware trends, human error patterns, and how attackers are moving faster than ever. We’ll highlight what it means for your organization and where to focus your efforts this year. Learn more about Med…
Ever wonder what would happen if a hacker walked right into your digital living room, kicked off their shoes, and hung out for three months without anyone noticing? This week’s episode dives into a jaw-dropping CISA Red Team Assessment that reads like a cybersecurity horror flick—complete with ignored alarms, forgotten passwords, and an open-door p…
Let’s face it — if healthcare had a dollar for every time someone said “we need another webinar,” it might actually be able to afford cybersecurity upgrades. This episode takes aim at the overload of online presentations and instead shines a light on what healthcare providers actually need. We unpack the findings of a critical report on the unique …
More platforms means more places for PHI to slip through. When tools aren’t vetted, tracked, or covered by the right agreements, even routine workflows can create real risk. And without clear access controls, it’s hard to know who still has the keys. If you’re not sure where your gaps are, this is worth a closer look. Learn more about Medcurity her…
When a cybersecurity CEO strolls into a hospital and decides to play malware magician with a couple of unlocked computers, you've got yourself a plot twist worthy of a Netflix docuseries. In this episode, we dive headfirst into bizarre breaches, finger-pointing fiascos, and the kind of contractual confusion that’ll make you want to reread your SLAs…
Readiness in healthcare compliance means more than checking a box once a year. This episode looks at how healthcare organizations can move beyond annual tasks and create routines that hold up under scrutiny. It’s a practical look at what regulators are expecting and how to be ready before they come knocking. Learn more about Medcurity here: https:/…
Still relying on antivirus alone? Think HIPAA audits are too rare to matter? These six myths are leaving healthcare organizations exposed. We’re unpacking what’s false, what’s risky, and what you should be doing instead. Learn more about Medcurity here: https://medcurity.com #Healthcare #Cybersecurity #Compliance #HIPAA #SecurityRiskAnalysis #Myths…
Healthcare still has a giant “Hack Me” sign taped to its back — and the latest reports from Mandiant and Verizon are here to confirm it. These cybercrime breakdowns reveal that attackers are smarter, sneakier, and spending more time poking around your network than ever before. Waiting to secure your systems until after a breach is like installing a…
OCR has been busy—and Security Risk Analyses are front and center. In this episode, we walk through three recent enforcement cases where missing or outdated SRAs led to fines and multi-year corrective action plans. From phishing incidents to system misconfigurations, you’ll see exactly what regulators flagged and what steps each organization is now…
If the Ponemon study were a horror flick, it’d be titled "The Login Came from Inside the System." This week’s episode dives into the alarming trend of organizations handing out privileged access like Halloween candy — only to forget who’s still got it long after the party’s over. With 59% of breaches linked to insiders or third parties, and executi…
Turns out, “they got hit, they just didn’t tell you” isn’t just a snarky title—it’s a terrifying reality. The Black Fog report basically says, “Hey, the cybersecurity iceberg is way bigger below the surface.” From undisclosed data heists to the rapid rise of ransomware attacks, this is your reminder that you don’t want to be the next plot twist in …
In five minutes, we break down what HIPAA really expects from your organization in 2025. From your Security Risk Analysis to employee training, access controls, audit logs, and business associate agreements—this is the real-world checklist regulators are looking for. We’ll explain each core requirement, how enforcement is evolving, and offer practi…
Imagine your hospital gets hacked—the MRIs are down, billing’s frozen, and suddenly you’re faxing patient records like it’s 1999. No, that’s not a “Twilight Zone” rerun—it’s real life in health care. This week, we’re diving into what the Health Sector Coordinating Council (HSCC) is doing about it, including their recent trip to Congress to lay it a…
In this episode, we’re talking about one habit that could have the biggest impact on your organization’s security posture—and it’s not a new tool or system. With phishing attacks getting more sophisticated and OCR enforcement on the rise, this one behavior can interrupt the pattern attackers rely on. We’ll unpack why it matters, how to build it int…
Forget action-packed heist movies — the real cybersecurity heroes are the ones making their auditors yawn. In this episode, we break down why "boring and patched" should be everyone's new life goal. From AI developments that won’t sit still for five minutes to real-world cyber drama featuring surprise FBI visits (no popcorn needed), we’re serving u…
What happens when you bring together proactive AI and healthcare communication? You get smarter outreach, stronger patient engagement, and fewer compliance gaps. In this special episode, we’re joined by Dan Fox, Managing Director of Healthcare at Drips. With over 12 years in AI-driven tech, Dan shares how conversational AI is transforming how healt…
The new OCR Acting Director Anthony Archeval said that Security Risk Analyses are not only required but are the first step to limit breaches—with penalties already being issued for non-compliance. In this episode, we break down why SRAs matter more than ever, what can go wrong when they’re skipped, and how to make them manageable. With recent OCR s…
AI in healthcare is kind of like an overenthusiastic intern—it’s full of potential, but someone probably should be watching it a little closer. In this episode, we dive into why artificial intelligence might be more “oops” than “awesome” when it comes to patient safety. A recent ECRI report flagged AI as a top safety concern and offered up smart re…
Think your once-a-year vulnerability scan is enough? That’s adorable. Waiting to check your security metrics until something goes wrong is like only checking your smoke alarm after the house starts smelling like burnt toast. In this episode, we peel back the layers on the top 10 security and privacy metrics every business should be tracking—whether…
Zero trust changes how healthcare protects patient data by verifying every access, every time. We’ll explain what it is, why it’s essential for your organization’s security, and how to put it in place without extra stress. It’s a straightforward way to stay secure and keep up with HIPAA requirements. Tune in to hear how Medcurity can guide you thro…
Buckle up, folks—this episode is a rollercoaster of cyber chaos! We kick things off with a quick chat about the upcoming PriSec Boot Camp (because let’s be real, who doesn’t love a good security boot camp?). But then, we dive headfirst into the madness: a fresh HIPAA smackdown over right-of-access failures, a rogue IT guy who locked down an entire …
The HIPAA Right of Access lets patients get their medical records with ease—and we’re here to help you make it happen smoothly! This episode covers the rules, from timelines to exceptions, using a recent Oregon case to show what to watch for, and shares clear steps to stay compliant. Join us to keep your processes on track and your patients happy! …
500 episodes. A whole decade. Countless cybersecurity threats (and just as many dad jokes). Somehow, we’re still talking about the same cybersecurity nightmares—only now with fancier threats and AI-powered scams. In this milestone episode of Help Me With HIPAA, we take a trip down memory lane—reminiscing about our early struggles, the evolution of …
Facing an audit can feel overwhelming, but knowing the 11 key things the government might ask for can keep your healthcare organization prepared. This episode breaks down what those requests—covering security risks and compliance—mean and how to have the right documentation ready. Tune in to get the insights you need to stay ahead of HIPAA requirem…
Cybersecurity: It’s like flossing—we all know we should do it, but a shocking number of people just…don’t. This week, we’re digging into the annual cybersecurity attitudes and behaviors report, which reveals just how careless people are with their passwords, personal info, and, well, basic online survival skills. But don’t worry, AI is here to save…
Credential stuffing could be the silent killer of your healthcare security—imagine hackers slipping in with just one reused password, exposing patient data and triggering massive fines. We break down how these sneaky attacks exploit password habits on the dark web, why they’re a goldmine for cybercriminals targeting medical records, and the simple …
Cybersecurity report cards are in, and let’s just say—most companies would be grounded if their IT security grades were real school grades. With over 80% of Fortune 500s scoring a D or F, and healthcare companies hovering around the danger zone, it's clear that many organizations are securing data about as well as a cardboard vault. Just ask Warby …
Outdated systems are a major security risk—but modern solutions can bridge the gap. In this episode, we explore how legacy tech leaves healthcare organizations vulnerable and what steps you can take to strengthen security without a complete overhaul. Learn more about Medcurity here: https://medcurity.com #Healthcare #Cybersecurity #Compliance #HIPA…
AI just leveled up, and we’re here to talk about it! In this episode, we dive into DeepSeek—the AI model that shook up the stock market, gave OpenAI a run for its money (literally), and is both insanely cheap to run and totally open-source (which is equal parts exciting and terrifying). We also break down the rise of deepfake scams, AI’s growing ro…
How does HIPAA work when every second counts? Learn how emergency provisions let healthcare providers quickly share the essential patient info they need—using treatment exceptions and the “minimum necessary” rule—while still keeping privacy in check. Learn more about Medcurity here: https://medcurity.com #Healthcare #Cybersecurity #Compliance #HIPA…
Imagine leaving your front door wide open in a neighborhood full of burglars, then acting shocked when your TV disappears. That’s basically what’s happening in healthcare cybersecurity. This week, we’re talking about why hackers are running rampant, how small healthcare practices are prime targets (no, you’re not “too small to matter”), and what ba…
Insider threats are a big risk to healthcare security, whether caused by simple mistakes or intentional misuse of access. Patient data can be exposed in ways many organizations don’t even realize. Learn how HIPAA addresses these risks and the best strategies to keep sensitive information secure. Learn more about Medcurity here: https://medcurity.co…
AI is here, and with it come big responsibilities. Learn the benefits and risks of this emerging technology and why it’s important for the healthcare industry to stay informed. Technology is powerful, but it’s how we use it that matters the most. Learn more about Medcurity here: https://medcurity.com #Healthcare #Cybersecurity #Compliance #HIPAA…
If you’ve ever wondered what it’s like to scream into the cybersecurity void, this episode might feel oddly relatable. We dive into why “bare minimum” isn’t a security strategy—it’s more like playing Russian roulette with your data. From regulatory head-scratchers to the harsh reality that a “bare minimum” security strategy is about as effective as…
If ignoring cybersecurity was a sport, some companies would be gold medalists—until they realize the prize is a hefty fine and years of regulatory headaches. It’s like leaving your car unlocked in a sketchy part of town with a neon sign that says, “Free Stuff Inside.” What could possibly go wrong? Well, in this episode, we break down six real-life …
What does it take to protect patient data, handle ever-changing regulations, and keep your organization audit-ready? In this episode, we break down the day-to-day reality of healthcare compliance. Learn more about Medcurity here: https://medcurity.com #Healthcare #Cybersecurity #Compliance #HIPAA
Artificial intelligence is reshaping healthcare, and the new HHS AI Strategic Plan hopes to pave the way for safer, smarter innovation. This framework focuses on fostering trust, promoting equity, and empowering healthcare teams to responsibly integrate AI into their work. Curious about how AI is set to transform patient care and public health? Tun…
Buckle up, folks, because this week’s episode is a wild ride through the Cavity of Lies—where HIPAA violations, ransomware attacks, and outright absurdity collide. What happens when a dental group tries to sweep a massive breach under the rug (or, you know, hide servers in bathrooms)? Let’s just say it doesn’t end well. From a 3-year-long cover-up …
Hold onto your compliance hats—big changes are brewing for HIPAA’s Security Rule! The Notice of Proposed Rulemaking (NPRM) is officially out for public comment, and it’s clear HHA and OCR are on a mission to modernize and tighten the safeguards for electronic protected health information (ePHI). From clarifying risk analysis expectations to making …
Proposed HIPAA updates could redefine how healthcare handles cybersecurity. From mandatory encryption to multi-factor authentication, these changes aim to tackle modern threats head-on. In this episode, we’re breaking down what’s changing and what it means for compliance in 2025. Learn more about Medcurity here: https://medcurity.com #Healthcare #C…
Ready to kick off 2025 with a bang? We’re diving into the must-dos for your Q1 2025 compliance and cybersecurity checklist, sprinkling in some risk management wisdom, and why Windows 10 is about as fashionable as shoulder pads in the 2020s. Plus, we sprinkle in a hearty dose of snark to keep you entertained while you get your compliance game strong…
Ah, supply chain attacks—the gift that keeps on giving... headaches, fines, and catastrophic data breaches. In this episode, we unwrap three cautionary tales of organizations caught in the tangled web of digital supply chain chaos. From unpatched vulnerabilities and sneaky software backdoors to hackers casually buying network access like it’s an eB…
The new year is here, but cybersecurity threats and compliance challenges never take a holiday. This week, we’re talking about the risks of leaving your systems unprotected during downtime and the steps you can take to ensure everything is up to date and secure. Learn more about Medcurity here: https://medcurity.com #Healthcare #Cybersecurity #Comp…
It’s the final countdown, folks—the last episode of the year! And OCR decided to end 2024 with a bang, handing out settlements like candy at a Christmas parade. But here’s the twist: the candy comes with a price tag, and it’s not cheap. This episode hones in on OCR’s new enforcement initiative targeting incomplete and outdated risk analyses. So, be…
There’s a new HIPAA Rule that went into effect on Monday, and it’s something every healthcare professional needs to know. In this episode, we’re talking about new restrictions on sharing patient data, the introduction of an attestation requirement, and what these changes mean for healthcare organizations. Learn more about Medcurity here: https://me…
Welcome to the 2024 Blooper Show, where we prove once again that even after nine years, perfection is overrated and laughter is mandatory! Big shoutout to Bojan, our long suffering audio engineer extraordinaire, who turns our chaos into coherence. And of course, we can’t forget you—our amazing listeners—who tune in each week, send us your thoughts …
HIPAA compliance isn’t always where you expect it. Online forms, patient reviews, and digital apps can all create potential risks for HIPAA incidents. In this episode, we’re uncovering hidden compliance pitfalls and giving you practical tips to safeguard patient data in these overlooked areas. Learn more about Medcurity here: https://medcurity.com …
Cybersecurity incidents can feel like a punch in the gut, but with the right plan, you can roll with the hits instead of flailing in panic. In this episode, we’re diving into executive strategies for tackling the unexpected, from building response teams to keeping business operations afloat when chaos strikes. Along the way, we also cover a recent …