Episode 506: One Year After the Change Healthcare Breach: What Group Practices Must Learn
Release Date: 02/21/2025
Group Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we clarify who is impacted by the Part 2 Final Rule. We discuss: What’s included in the Part 2 Final Rule and why it’s necessary How to evaluate if you’re subject to Part 2 rules What compliance looks like under the new Part 2 rules Redisclosure under Part 2 Steps to take ahead of the February 2026 deadline for enforcement Listen here: For more, PCT Resources: Handout resource: A quick-reference tool to determine if you’re a...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we walk you through a quick win for your practice security - how to secure your Wi-Fi network. We discuss: The role of Wi-Fi in a practice's security picture The tangible risks of weak Wi-Fi security Steps to take to improve your Wi-Fi security Our free Wi-Fi security checklist, included in the show notes Listen here: For more, PCT Resources: (PDF version) (.docx version) a one-page guide with simple, high-impact steps to secure your Wi-Fi, to...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we chat about what you should know when clients use AI for therapy. We discuss: the risks and benefits of clients using AI in a therapeutic manner how clinicians can approach conversations about AI practices with clients why clients are turning to AI for therapeutic purposes, and what clinicians can do to support them safely Listen here: For more, Resources APA article: Article: Article: Article: NPR story: Article: Psychiatric Times: Stanford...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we chat with Francis Harvey from Therapist Headquarters about her new resource for therapists. We discuss: The origin of Therapist Headquarters What resource collections are available on Learning what you weren’t taught in grad school about running a business The process for vetting therapist resources Common HIPAA security and compliance misconceptions for therapists The importance of HIPAA compliance and safeguarding information in our current political...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we’re ... We discuss: understanding burnout as a cultural problem perfectionism, dopamine addiction, addiction to accomplishment, and sense of duty as contributing factors to burnout the roles curiousity, compassion and community play in addressing burnout showing up imperfectly, well Listen here: For more, PCT Resources: The below resources are not specifically oriented to addressing burnout -- but they are focused on providing wholistic...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we’re clearing up misconceptions and sharing best practices about testimonials for your therapy practice. We discuss: Why marketing is becoming more important in our current practice context Guidance from marketing professionals who don’t understand the scope of HIPAA What the professional ethics codes for therapists specifically say about soliciting testimonials, anonymous or otherwise Suggested best practices around testimonials as a therapist Example...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we clear up misconceptions about what it means to de-identify information under HIPAA. We discuss: What de-identifying actually means under HIPAA The two methods under which PHI can be de-identified The 18 HIPAA identifiers that indicate if information is PHI The difference between de-identified and anonymized data How to spot red flags from EHR vendors to protect PHI, and what questions to ask Opting in or out of AI note services in your EHR Listen here: ...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, Patrick Casale joins us for a difficult but necessary conversation on the implications of diagnosing neurodivergence in our current social and political context. We discuss: The current social and political context that is causing concern for neurodivergent people and their loved ones Client self-determination in determining if diagnosis goes into their medical record The benefits of having a diagnosis on the record The risks of having a diagnosis on the...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share HIPAA savvy and practical options to securely record and share sessions for supervision. We discuss: Why session recordings need to be so secure Common non-secure recording storage methods we see at PCT The PCT-preferred solution for storing session recordings (and why we recommend doing it this way) How to securely record and share online sessions or in-person sessions Google Workspace best practices Another (less tech-friendly) option for...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we have a realistic, high impact action for you to take today to boost your practice security: set up two-factor authentication (2FA). We discuss: What 2FA is and why it’s so useful Where we recommend having 2FA set up How Google Authenticator works for 2FA and why we love it How to set up and use Google Authenticator Action steps to take today to boost practice security with 2FA Listen here: For more,
info_outlineWelcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech.
In our latest episode, we break down some important action items for group practice owners as a result of last year’s Change Healthcare breach.
We discuss:
- What happened with Change Healthcare
- What a ransomware attack is and how the hackers gained access
- Foundational security awareness training, and creating an overall security culture in your practice
- How to improve training for your workforce
- Having the right security configurations in place in your systems
- The importance of risk analysis and risk mitigation planning
- Codifying everything into comprehensive security policies and procedures
Listen here: https://personcenteredtech.com/group/podcast/
For more, visit our website.