Help Me With HIPAA
Cybersecurity has always been a moving target, but lately the target seems to have strapped on roller skates, grabbed an AI assistant, and headed straight for the nearest hotel Wi-Fi. Vulnerabilities are being patched at record rates, attackers are finding clever new ways to steal credentials, and AI agents can now take action with surprisingly little supervision. In this episode, we look at what happens when threats evolve faster than the plans designed to handle them, and why having security tools isn’t the same as knowing they’re actually protecting you. The real question isn’t...
info_outlineHelp Me With HIPAA
Most organizations have an incident response plan, but how well would it hold up if your normal communication channels suddenly couldn't be trusted? In this episode, we dive into a nationwide healthcare cybersecurity exercise that challenged participants to think beyond compliance and technical defenses, exposing just how critical preparation, collaboration, and secure communication become during a large-scale cyber crisis. Along the way, a surprising real-world AI development reminds us that tomorrow's threats may arrive sooner than anyone expects. More info at
info_outlineHelp Me With HIPAA
Regulations may move at the speed of a sleepy turtle, but patient expectations certainly don't. As healthcare organizations wait to see what the final HIPAA Privacy Rule will include, there is a surprising amount of work that can, and should, already be underway. This episode explores the practical steps you can take now, the common misconceptions that continue to create confusion, and why preparing early is far less painful than trying to outrun an approaching compliance deadline. If you start getting your ducks in a row today, it just might save you from chasing them all over the parking lot...
info_outlineHelp Me With HIPAA
Cyberattacks are expensive—but just how expensive? This episode dives into a brand-new study that finally puts real numbers behind the financial impact of data breaches, using thousands of cyber insurance claims instead of scary headlines and wild guesses. From ransomware and business interruption to cyber insurance surprises, you'll discover why the biggest cost isn't always what you think. If you've ever wondered whether your organization is truly prepared for a breach—or just hoping insurance will magically save the day—this conversation is packed with practical insights, a few...
info_outlineHelp Me With HIPAA
Think cybersecurity is all about how much money you throw at the problem? Think again. In this episode, we unpack the idea of the "cybersecurity poverty line" and why being under-protected isn't always about having an empty wallet. From outdated technology to missing expertise and leadership roadblocks, you'll discover why even organizations with healthy budgets can still leave the front door wide open to cybercriminals. If you've ever wondered whether your biggest security challenge is really your budget, or something else entirely, this conversation is for you. More info at
info_outlineHelp Me With HIPAA
If you’ve ever caught yourself saying, “We’re too small to be hacked,” or “That’s why we have cyber insurance,” you might want to keep reading. This episode shines a spotlight on five cybersecurity assumptions that seem perfectly reasonable – right up until they cost you time, money, or your sanity. From misplaced confidence in vendors to the myth that restoring your systems means the crisis is over, this conversation serves up practical reality checks with just enough humor to make the hard truths a little easier to swallow. More info at
info_outlineHelp Me With HIPAA
What do lava lamps, whoopee cushions, and HIPAA have in common? More than you’d think! This week, a familiar mall retailer famous for gag gifts and lava lamps finds itself at the center of an OCR enforcement action that highlights a common misconception about employer-sponsored health plans. Along the way, you’ll learn why “we’ve never had a problem before” isn’t a cybersecurity strategy, how self-funded health plans fit into HIPAA, and why ignoring compliance can quickly become a very expensive joke. More info at
info_outlineHelp Me With HIPAA
Ever wish you could get expert HIPAA advice straight from the source – without the invoice? This episode digs into a little-known offering: the “free consulting” that the Office for Civil Rights (OCR) actually gives out, if you know where to look. We break down the seven biggest lessons buried in official OCR videos and settlement guidance, covering everything from keeping tabs on your inventory (yes, all your data – even the digital version of an old truck growing weeds) to why risk management means more than doing paperwork once a year. If you’re in healthcare and want practical...
info_outlineHelp Me With HIPAA
Healthcare is rushing to adopt AI, but most organizations haven’t figured out what it really means to keep it in check. The HSCC just released an AI governance framework aimed at helping healthcare leaders get ahead of the curve—before “shadow AI” and unapproved tools turn into a bigger problem. This episode breaks down why AI governance isn’t just IT’s job, where most organizations are getting stuck, and the surprisingly simple questions privacy and compliance teams should be asking about AI before things go sideways. More info at
info_outlineHelp Me With HIPAA
AI isn’t just a buzzword anymore—it’s showing up everywhere in healthcare, whether you realize it or not. In this episode, we get honest about what it means to live and work with AI, why so many people still feel anxious (or even a little excited) about it, and why avoiding it altogether just isn’t an option. We dig into practical ways healthcare teams can safely experiment with AI in their daily routines, what to watch out for, and how the right approach can help you solve problems instead of just creating new ones. If you’ve been wondering how AI is changing the way you work—or...
info_outlineIf you think a risk analysis is just another box to check on the HIPAA compliance to-do list, this episode might feel a bit like a reality check… with receipts. Using a real OCR settlement involving a phishing attack and nearly 2,000 patients’ data, this discussion digs into what regulators actually expect when they say “risk analysis.” Spoiler alert: it’s a lot more than running a quick scan and calling it a day.
More info at HelpMeWithHIPAA.com/551