loader from loading.io

Episode 508: Reassurance About the Proposed HIPAA Security Rule Change-Induced Panic

Group Practice Tech

Release Date: 03/07/2025

Episode 528: Burnout, Perfectionism, and the Myth of Doing It All show art Episode 528: Burnout, Perfectionism, and the Myth of Doing It All

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we’re ... We discuss: understanding burnout as a cultural problem perfectionism, dopamine addiction, addiction to accomplishment, and sense of duty as contributing factors to burnout the roles curiousity, compassion and community play in addressing burnout  showing up imperfectly, well Listen here: For more,   PCT Resources: The below resources are not specifically oriented to addressing burnout -- but they are focused on providing wholistic...

info_outline
Episode 527: Why Therapists Shouldn’t Use Client Testimonials — Ethics, Risks, and Safer Marketing Strategies show art Episode 527: Why Therapists Shouldn’t Use Client Testimonials — Ethics, Risks, and Safer Marketing Strategies

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we’re clearing up misconceptions and sharing best practices about testimonials for your therapy practice. We discuss: Why marketing is becoming more important in our current practice context Guidance from marketing professionals who don’t understand the scope of HIPAA What the professional ethics codes for therapists specifically say about soliciting testimonials, anonymous or otherwise Suggested best practices around testimonials as a therapist Example...

info_outline
Episode 526: De-Identified or Not? The Truth about HIPAA, AI, and Client Data show art Episode 526: De-Identified or Not? The Truth about HIPAA, AI, and Client Data

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we clear up misconceptions about what it means to de-identify information under HIPAA. We discuss: What de-identifying actually means under HIPAA The two methods under which PHI can be de-identified The 18 HIPAA identifiers that indicate if information is PHI The difference between de-identified and anonymized data How to spot red flags from EHR vendors to protect PHI, and what questions to ask Opting in or out of AI note services in your EHR Listen here: ...

info_outline
Episode 525: Patrick Casale on Considerations for Diagnosing Neurodivergence in our Current Context show art Episode 525: Patrick Casale on Considerations for Diagnosing Neurodivergence in our Current Context

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, Patrick Casale joins us for a difficult but necessary conversation on the implications of diagnosing neurodivergence in our current social and political context. We discuss: The current social and political context that is causing concern for neurodivergent people and their loved ones Client self-determination in determining if diagnosis goes into their medical record The benefits of having a diagnosis on the record The risks of having a diagnosis on the...

info_outline
Episode 524: Real Talk: PCT Answers: Supervision and Session Recordings -- Secure Access Without the Stress show art Episode 524: Real Talk: PCT Answers: Supervision and Session Recordings -- Secure Access Without the Stress

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share HIPAA savvy and practical options to securely record and share sessions for supervision. We discuss: Why session recordings need to be so secure  Common non-secure recording storage methods we see at PCT The PCT-preferred solution for storing session recordings (and why we recommend doing it this way) How to securely record and share online sessions or in-person sessions Google Workspace best practices Another (less tech-friendly) option for...

info_outline
Episode 523: Quick Wins: Boost Your Practice Security With 2FA and Google Authenticator show art Episode 523: Quick Wins: Boost Your Practice Security With 2FA and Google Authenticator

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we have a realistic, high impact action for you to take today to boost your practice security: set up two-factor authentication (2FA).  We discuss: What 2FA is and why it’s so useful Where we recommend having 2FA set up How Google Authenticator works for 2FA and why we love it How to set up and use Google Authenticator Action steps to take today to boost practice security with 2FA Listen here: For more,

info_outline
Episode 522: Real Talk: PCT Answers - Can My Supervisees Practice Across State Lines Under My Compact Privileges? show art Episode 522: Real Talk: PCT Answers - Can My Supervisees Practice Across State Lines Under My Compact Privileges?

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we answer a question we’re getting a lot recently, about what’s permitted when supervising pre-licensed therapists. We discuss: How compact privileges work for therapists PSYPACT and the upcoming Counseling Compact and Social Work Licensure Compact AAMFT and the push for licensure portability  How to manage supervision for pre-licensed folks Liability and ethical implications for unauthorized practice Listen here: For more,  PCT Resources ...

info_outline
Episode 521: Practical Steps for Avoiding Shared Admin Accounts and Managing Role-Based Access show art Episode 521: Practical Steps for Avoiding Shared Admin Accounts and Managing Role-Based Access

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share a how-to guide for managing role-based access and shared accounts with HIPAA in mind.  We discuss: How to audit system access in your practice Defining roles and responsibilities to determine access Managing shared email accounts with email delegation The difference between email aliases and delegated accounts Steps to take when systems don’t allow for multiple logins Listen here: For more, Resources HHS FAQ: PCT Resources PCT...

info_outline
Episode 520: The Risk No One Talks [Enough] About: Shared Admin Accounts and Role-Based Access show art Episode 520: The Risk No One Talks [Enough] About: Shared Admin Accounts and Role-Based Access

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we explain why shared admin accounts are a security concern under HIPAA and what you can do about it.  We discuss: Why shared accounts are a no-no, and why it’s such a common practice The HIPAA standards that are impacted by this practice The internal and external risks of sharing admin accounts The why and what of role-based access control Listen here: For more, Resources HHS FAQ: PCT Resources Free CE course for group practice...

info_outline
Episode 519: Quick Wins: Simple Settings to Secure your Smartphone and Protect Client Info show art Episode 519: Quick Wins: Simple Settings to Secure your Smartphone and Protect Client Info

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share a quick update to your smartphone settings to increase device security. We discuss: Overwhelm as a barrier to HIPAA compliance and the key to success Two security settings to update on your smartphone Risk exposure + device security How to get step-by-step guidance for your specific device Listen here: For more,  PCT Resources weekly (live & recorded) direct support & consultation service, Group Practice Office Hours -- including...

info_outline
 
More Episodes

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech.

In our latest episode, we’re hoping to lower the level of distress around the proposed HIPAA Security Rule changes for therapy practice owners. 

We discuss:

  • What the some of the proposed changes to the Security Rule are, including penetration testing
  • The timeframe for these changes if they are implemented, and the likelihood they actually will be implemented
  • The rationale behind the proposed changes, and why they’re necessary in our current threat landscape
  • How following the PCT Way can minimize the changes you need to make as HIPAA regulations evolve
  • Centering client care and safeguarding client info as a motivating factor, rather than fear

Listen here: https://personcenteredtech.com/group/podcast/

For more, visit our website.

Resources

PCT Resources

  • PCT's Comprehensive HIPAA Security Compliance Program (discounted) bundles:
  • For Solo Practitioners
  • PCT's HIPAA Risk Analysis & Risk Mitigation Planning service for mental health  practices -- care for your practice using our supportive, shame-free risk analysis and mitigation planning service. You’ll have your Risk Analysis done within 2 hours, performed by a PCT consultant, using a tool built specifically for mental health group practice, and a mitigation checklist to help you reduce your risks.
  • Group Practice Care Premium
  • weekly (live & recorded) direct support & consultation service, Group Practice Office Hours -- including monthly session with therapist attorney Eric Ström, JD PhD LMHC
  • + assignable staff HIPAA Security Awareness: Bring Your Own Device training + access to Device Security Center with step-by-step device-specific tutorials & registration forms for securing and documenting all personally owned & practice-provided devices (for *all* team members at no per-person cost)
  • + assignable staff HIPAA Security Awareness: Remote Workspaces training for all team members + access to Remote Workspace Center with step-by-step tutorials & registration forms for securing and documenting Remote Workspaces (for *all* team members at no per-person cost) + more