Episode 508: Reassurance About the Proposed HIPAA Security Rule Change-Induced Panic
Release Date: 03/07/2025
Group Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we clarify who is impacted by the Part 2 Final Rule. We discuss: What’s included in the Part 2 Final Rule and why it’s necessary How to evaluate if you’re subject to Part 2 rules What compliance looks like under the new Part 2 rules Redisclosure under Part 2 Steps to take ahead of the February 2026 deadline for enforcement Listen here: For more, PCT Resources: Handout resource: A quick-reference tool to determine if you’re a...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we walk you through a quick win for your practice security - how to secure your Wi-Fi network. We discuss: The role of Wi-Fi in a practice's security picture The tangible risks of weak Wi-Fi security Steps to take to improve your Wi-Fi security Our free Wi-Fi security checklist, included in the show notes Listen here: For more, PCT Resources: (PDF version) (.docx version) a one-page guide with simple, high-impact steps to secure your Wi-Fi, to...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we chat about what you should know when clients use AI for therapy. We discuss: the risks and benefits of clients using AI in a therapeutic manner how clinicians can approach conversations about AI practices with clients why clients are turning to AI for therapeutic purposes, and what clinicians can do to support them safely Listen here: For more, Resources APA article: Article: Article: Article: NPR story: Article: Psychiatric Times: Stanford...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we chat with Francis Harvey from Therapist Headquarters about her new resource for therapists. We discuss: The origin of Therapist Headquarters What resource collections are available on Learning what you weren’t taught in grad school about running a business The process for vetting therapist resources Common HIPAA security and compliance misconceptions for therapists The importance of HIPAA compliance and safeguarding information in our current political...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we’re ... We discuss: understanding burnout as a cultural problem perfectionism, dopamine addiction, addiction to accomplishment, and sense of duty as contributing factors to burnout the roles curiousity, compassion and community play in addressing burnout showing up imperfectly, well Listen here: For more, PCT Resources: The below resources are not specifically oriented to addressing burnout -- but they are focused on providing wholistic...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we’re clearing up misconceptions and sharing best practices about testimonials for your therapy practice. We discuss: Why marketing is becoming more important in our current practice context Guidance from marketing professionals who don’t understand the scope of HIPAA What the professional ethics codes for therapists specifically say about soliciting testimonials, anonymous or otherwise Suggested best practices around testimonials as a therapist Example...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we clear up misconceptions about what it means to de-identify information under HIPAA. We discuss: What de-identifying actually means under HIPAA The two methods under which PHI can be de-identified The 18 HIPAA identifiers that indicate if information is PHI The difference between de-identified and anonymized data How to spot red flags from EHR vendors to protect PHI, and what questions to ask Opting in or out of AI note services in your EHR Listen here: ...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, Patrick Casale joins us for a difficult but necessary conversation on the implications of diagnosing neurodivergence in our current social and political context. We discuss: The current social and political context that is causing concern for neurodivergent people and their loved ones Client self-determination in determining if diagnosis goes into their medical record The benefits of having a diagnosis on the record The risks of having a diagnosis on the...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share HIPAA savvy and practical options to securely record and share sessions for supervision. We discuss: Why session recordings need to be so secure Common non-secure recording storage methods we see at PCT The PCT-preferred solution for storing session recordings (and why we recommend doing it this way) How to securely record and share online sessions or in-person sessions Google Workspace best practices Another (less tech-friendly) option for...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we have a realistic, high impact action for you to take today to boost your practice security: set up two-factor authentication (2FA). We discuss: What 2FA is and why it’s so useful Where we recommend having 2FA set up How Google Authenticator works for 2FA and why we love it How to set up and use Google Authenticator Action steps to take today to boost practice security with 2FA Listen here: For more,
info_outlineWelcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech.
In our latest episode, we’re hoping to lower the level of distress around the proposed HIPAA Security Rule changes for therapy practice owners.
We discuss:
- What the some of the proposed changes to the Security Rule are, including penetration testing
- The timeframe for these changes if they are implemented, and the likelihood they actually will be implemented
- The rationale behind the proposed changes, and why they’re necessary in our current threat landscape
- How following the PCT Way can minimize the changes you need to make as HIPAA regulations evolve
- Centering client care and safeguarding client info as a motivating factor, rather than fear
Listen here: https://personcenteredtech.com/group/podcast/
For more, visit our website.
Resources
- JD Supra article summarizing proposed HIPAA Security Rule Changes and context: New Year, New HIPAA Security Rule: OCR Adds to Health Care Entities’ New Year’s Resolutions
- HHS Fact Sheet on proposed changes: HIPAA Security Rule Notice of Proposed Rulemaking to Strengthen Cybersecurity for Electronic Protected Health Information
- Full text of the Notice of Proposed Rulemaking (NPRM) in the Federal Register: HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information
- Comments on the NPRM (Note, you can also search the public comments by keyword; ability make comments closed on 3/7/25)
PCT Resources
- PCT's Comprehensive HIPAA Security Compliance Program (discounted) bundles:
- For Group Practices
- For Solo Practitioners
- PCT's HIPAA Risk Analysis & Risk Mitigation Planning service for mental health practices -- care for your practice using our supportive, shame-free risk analysis and mitigation planning service. You’ll have your Risk Analysis done within 2 hours, performed by a PCT consultant, using a tool built specifically for mental health group practice, and a mitigation checklist to help you reduce your risks.
- Group Practice Care Premium
- weekly (live & recorded) direct support & consultation service, Group Practice Office Hours -- including monthly session with therapist attorney Eric Ström, JD PhD LMHC
- + assignable staff HIPAA Security Awareness: Bring Your Own Device training + access to Device Security Center with step-by-step device-specific tutorials & registration forms for securing and documenting all personally owned & practice-provided devices (for *all* team members at no per-person cost)
- + assignable staff HIPAA Security Awareness: Remote Workspaces training for all team members + access to Remote Workspace Center with step-by-step tutorials & registration forms for securing and documenting Remote Workspaces (for *all* team members at no per-person cost) + more