• Blog
  • Services
    • PHIshMD Ongoing Training
    • HIPAA Compliance
    • Discover Vulnerabilities to Patient PHI
  • Store
    • HIPAA Secure Now Service Store
  • Contact Us
    • Sales Inquiry
    • Customer Support
  • Resources
    • Free Healthcare Security Check Up Quiz
    • HIPAA Compliance Requirements | A Guide
    • Webinars & Downloadable Content
    • Use our free Breach Cost Calculator
    • HIPAA Secured Seal
    • In-Email Training & Analysis | Catch Phish

Call us at: 877-275-4545

Client or Partner? Login here
Health Secure Now!Health Secure Now!
  • Blog
  • Services
    • PHIshMD Ongoing Training
    • HIPAA Compliance
    • Discover Vulnerabilities to Patient PHI
  • Store
    • HIPAA Secure Now Service Store
  • Contact Us
    • Sales Inquiry
    • Customer Support
  • Resources
    • Free Healthcare Security Check Up Quiz
    • HIPAA Compliance Requirements | A Guide
    • Webinars & Downloadable Content
    • Use our free Breach Cost Calculator
    • HIPAA Secured Seal
    • In-Email Training & Analysis | Catch Phish
  • All
  • Backup & Disaster Recovery
  • Business Associates
  • Client News
  • Healthcare Industry
  • HIPAA
  • HIPAA Audits
  • HIPAA Violations
  • HSN News
  • Legal
  • MACRA
  • Policies and Procedures
  • Press Release
  • Remote Workforce
  • Risk Assessment
  • Scams
  • Security
  • Security Reminders
  • Security Training
  • Telehealth
  • Website
Healthcare Business Checkup

Annual Business Checkup

December 26, 2023

It’s standard practice to remind your patients to schedule an annual checkup.  As a healthcare provider, you should do the same for your business.  Don’t worry or feel overwhelmed at the thought of it! Many of the questions will be the same: what’s working, what isn’t, and what would you do better in the new […]

Read more

The Future of Healthcare Cybersecurity: Trends to Watch

October 13, 2023

Introduction As technology booms, healthcare has become increasingly reliant for patient care, record-keeping, and communication. While this digital transformation has brought many benefits, it has also made the healthcare sector a prime target for cyberattacks. Protecting patient data and ensuring the integrity of healthcare systems is of paramount importance. To stay ahead of cyber threats, […]

Read more

How to Handle a Breach

October 8, 2023

Introduction: “You’ve been breached”: three words that no business owner ever wants to hear, but for which they should be prepared. Data breaches have become an unfortunate reality for many organizations, especially those in the healthcare industry. Protecting sensitive patient information is not just a matter of compliance; it’s a crucial component of maintaining trust […]

Read more

A Dynamic Duo: Cybersecurity and Compliance

October 2, 2023

Introduction In a world where health records are considered 50 times more valuable than credit card information on the dark web, the OCR’s basic requirements are no longer sufficient on their own. Covered entities and business associates need comprehensive solutions and cybersecurity training to avoid data breaches and safeguard their patient data. Like pediatrics and […]

Read more

Elements of a Comprehensive HIPAA Annual Training

September 22, 2023

Introduction Navigating HIPAA can be an intimidating process, from finding information to documenting completed requirements. According to the training page of the OCR’s website: “The HIPAA Rules are flexible and scalable to accommodate the enormous range in types and sizes of entities that must comply with them. This means that there is no single standardized […]

Read more

Maintaining HIPAA-Compliant Communication Amongst Colleagues

September 15, 2023

Maintaining HIPAA-Compliant Communication Amongst Colleagues Let’s Talk About Oral Privacy In such an intense and impactful field, it’s completely understandable that healthcare professionals often find themselves wanting to share experiences or seek support from colleagues. However, they must navigate a delicate balance due to the stringent regulations imposed by HIPAA. While the spotlight often shines […]

Read more
Safeguarding Patient Privacy Through Proper Record Disposal

Safeguarding Patient Privacy through Proper Record Disposal

September 11, 2023

Common Mistakes & Best Practice Recommendations In the fast-paced world of healthcare, safeguarding patient privacy remains paramount. Yet, despite the diligence exercised in patient care, one area where vulnerabilities persist is record disposal. From the cluttered file rooms to the maze of electronic data, mistakes are made that can jeopardize sensitive patient information. In this […]

Read more
Why Your SMB needs SAT

Why Your SMB Needs SAT

September 1, 2023

A Comprehensive Guide Welcome to 2023, where cybersecurity is not just an IT concern, but a vital aspect of business continuity. For small and medium healthcare organizations (SMBs), the stakes are high when it comes to data breaches and ransomware attacks. The consequences can be devastating, with costs exceeding $250,000 for recovery, investigations, customer notifications, […]

Read more
Non-Cloud Backups: A Lifeline for Healthcare

Non-Cloud Backups: A Lifeline for Healthcare

August 28, 2023

IT Experts Fall Victim to Cyberattack Last week, CloudNordic, a prominent Danish cloud provider, became the victim of a devastating ransomware attack. This malevolent intrusion sent shockwaves through the IT company as cybercriminals encrypted their servers, grinding all operations to a halt and endangering the integrity of both company and customer data. Remaining Calm and […]

Read more

The Year-Round Commitment to SRA Recommendations

August 21, 2023

The Year-Round Commitment to SRA Recommendations A Pillar of HIPAA Compliance As a covered entity or business associate, protecting sensitive patient information is not just a priority—it’s a legal and ethical obligation. HIPAA stands as the guardian of patient data, ensuring its security, privacy, and confidentiality. One of the cornerstones of HIPAA compliance is the […]

Read more
Ensuring Robust Data Security

Ensuring Robust Data Security

August 15, 2023

5 Vital Plans Every Covered Entity and Business Associate Should Have in Place With cyberattacks and data breaches on the rise in healthcare, safeguarding sensitive information has become paramount for organizations. For covered entities and business associates, proactivity is key to maintaining the integrity and confidentiality of data. Here are five essential plans that every […]

Read more
Social Engineering

The Rising Threat of Social Engineering Attacks in Healthcare

August 8, 2023

Social engineering attacks involve manipulating individuals into divulging confidential information, providing unauthorized access, or executing actions that compromise the security of systems or data. Attackers exploit psychological and emotional factors to exploit employees’ trust and manipulate them into performing actions that put the organization’s sensitive information at risk. Small healthcare businesses are under a heightened […]

Read more

NIST Guidelines for Strong Passwords

August 1, 2023

The healthcare industry relies heavily on technology to store, manage, and access patient information. And one fundamental aspect of protecting patient information is using strong passwords or passphrases in line with the National Institute of Standards and Technology (NIST) guidelines. The Significance of Strong Passwords Passwords act as the first defense against unauthorized access to […]

Read more
Online Tracking Technologies: Warning Issued for Healthcare

Online Tracking Technologies: Warning Issued for Healthcare

July 25, 2023

In response to the growing use of online tracking technologies in healthcare, the HHS Office for Civil Rights (OCR) and the Federal Trade Commission (FTC) have issued a joint warning to hospital systems and telehealth providers about the potential threats these tracking technologies pose to patient data security. The Importance of Compliance HIPAA was enacted […]

Read more
Amazon Clinic

Amazon Clinic and HIPAA

July 18, 2023

The healthcare industry has witnessed the integration of technology into many different aspects of patient care and management. The Amazon online community has stepped into this domain with the introduction of Amazon Clinic. While an innovative healthcare solution, it raises questions about its adherence to HIPAA (Health Insurance Portability and Accountability Act) compliance, a crucial […]

Read more
safe shopping

Cybersafe Tips for Finding Steals while Avoiding Scams

July 11, 2023

It’s finally here! After months of racking up your cart with all the therapy materials, prize reinforcements, and other office odds and ends, it’s time to check out. What you may not have considered is that cybercriminals have also been waiting in anticipation of Prime Day. The increased online activity and sense of urgency are […]

Read more
Healthcare Security Violation

Healthcare Security Violation

June 27, 2023

A recent investigation by the Office of Civil Rights (OCR) alleges that several security guards from Yakima Valley Memorial Hospital impermissibly accessed the medical records of 419 individuals.  This incident highlights the importance of maintaining strict protocols and vigilant oversight when it comes to safeguarding sensitive patient information.  The details involving the hospital security guards […]

Read more
security risk assessment

The Importance of a Security Risk Assessment

June 20, 2023

What is a security risk assessment (SRA) and how can it help your healthcare business? The protection of sensitive patient information and the integrity of critical systems is of paramount importance to any business. With the increase in cybersecurity threats, taking a proactive approach to security measures is far more ideal than being reactive to […]

Read more
Enhancing Ransomware Defense for Your Healthcare Businesses

Enhancing Ransomware Defense

June 13, 2023

Recent research conducted by Arete and Cyentia Institute sheds light on the ransomware landscape within the healthcare sector. The study reveals that healthcare organizations are more likely to pay ransoms than other industries. Additionally, the report highlights the low adoption of multi-factor authentication (MFA) and emphasizes the need for improved cybersecurity measures in the healthcare […]

Read more

HIPAA Secure Now: Helping Healthcare Businesses

June 7, 2023

  Simplifying HIPAA compliance for Covered Entities with HIPAA regulations can be complex and challenging for covered entities.  Failure to meet the requirements can lead to severe penalties and reputation damage. This is where we come in. Here are some of the ways that HIPAA Secure Now can help healthcare businesses: Annual Risk Assessment: We […]

Read more
Language Access

Enhancing Healthcare With Increased Language Access

May 30, 2023

HHS Releases Report to Increase Language Access for Persons with Limited English Proficiency Language barriers can pose significant challenges when it comes to delivering quality healthcare to individuals with limited English proficiency (LEP). Recognizing the importance of language access in healthcare settings, the U.S. Department of Health and Human Services (HHS) has recently released a […]

Read more
OCR 90 Day Transition

Understanding the OCR 90-Day Transition Period

May 23, 2023

The Office for Civil Rights (OCR) 90-day transition period commenced on May 12, 2023. As a HIPAA compliance company, we understand the importance of staying up-to-date with regulatory changes. Let’s delve into the transition period and its significance, and provide guidance on how your organization can ensure seamless compliance in this evolving landscape. Understanding the […]

Read more
Business Associates

Business Associates HIPAA Compliance

May 16, 2023

A recent incident involving Arkansas-based MedEvolve serves as a reminder of the consequences that arise from the mishandling of PHI and the importance of healthcare businesses ensuring that they and their business associates are HIPAA compliant. The HIPAA Violation On May 16, 2023, the HHS Office for Civil Rights announced the resolution of a HIPAA investigation […]

Read more
end of PHE

End of COVID-19 Public Health Emergency

May 9, 2023

As a healthcare provider, you are familiar with the Public Health Emergency (PHE) declaration that has been in place since the beginning of the COVID-19 pandemic. This declaration has provided a number of flexibilities and protections for healthcare providers, including increased telehealth access and relaxed HIPAA requirements. Approaching Deadline On May 11, 2023, the PHE […]

Read more
Texting dental patients in healthcare

How to Communicate with Dental Patients via Text-Messaging

May 3, 2023

As technology continues to evolve, so do the ways in which dental practices communicate with their patients. Text messaging has become a popular method of communication, providing convenience and efficiency for both patients and dental staff. However, it is crucial that any communication is done in a secure and HIPAA-compliant manner. Our team of HIPAA […]

Read more
HIPAA Privacy vs. Security

Privacy vs. Security Rule

April 25, 2023

When it comes to HIPAA compliance, it’s easy to feel as if you’re being pulled in a million different directions at once. In part, this could be due to the fact that there are 4 different rules that go into HIPAA: the Privacy Rule, the Security Rule, the Breach Notification Rule, and the Omnibus Rule. […]

Read more
Physical Safeguards for HIPAA Compliance

Physical Safeguards for HIPAA Compliance

April 18, 2023

While it’s easy to get caught up in the many, many words of policies and procedures, how your space physically looks and functions are just as important. Physical safeguards play a vital role in achieving HIPAA compliance and keeping sensitive data out of the wrong hands.  Let’s look at six physical safeguards that every healthcare […]

Read more
HIPAA Compliant Waiting Room

HIPAA Compliant Waiting Room

April 11, 2023

Let’s discuss the most bustling room in your healthcare practice- the waiting room. Whether it’s parents waiting for their children to finish their sessions, patients who arrive super early, or you’re having one of those running-behind days, having a HIPAA-compliant space is crucial to maintain patient privacy and security. So, what can you do to […]

Read more
Phishing

Be Alert: Phishing Attacks

April 4, 2023

Healthcare businesses are increasingly reliant on technology to manage patient information, conduct financial transactions, and communicate with staff and patients. While technology has many benefits, it also presents significant risks, including the threat of cyberattacks.  One of the most common types of cyberattacks is phishing when an attacker impersonates a trusted individual or entity and […]

Read more
HIPAA Legal Reminder

HIPAA Legal Reminder

March 28, 2023

As a HIPAA-covered entity, it is crucial to understand the importance of protecting the privacy and security of patient personal health information (PHI). And a recent surge in litigation serves as a reminder that healthcare organizations must take adequate measures to safeguard PHI. Recent Cases In one recent case, a healthcare provider was sued for […]

Read more
HIPAA Security Policies

HIPAA Security Policies

March 21, 2023

. In healthcare, it is crucial to ensure the security and privacy of electronic health records and all patient data with security policies.  HIPAA provides guidelines for healthcare organizations and covered entities to follow in order to maintain the confidentiality, integrity, and availability of patient health information PHI, or ePHI. What are some of the […]

Read more
restructure OCR

Restructuring the OCR

March 14, 2023

The Health and Human Services (HHS) Office for Civil Rights (OCR) is responsible for enforcing and protecting civil rights and privacy rights in the healthcare industry. With the increasing number of complaints and reviews regarding the Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health (HITECH) Act, the […]

Read more
P means Portability

HIPAA: P for Portability

March 7, 2023

Undoubtedly, and whether you’re in healthcare or not, you’ve paused when writing or typing ‘HIPAA’.  Is it HIPPAA? HIPPA?  What does it stand for?  We find that the P trips most people up more often than the rest. It’s something about ‘patient’ right? Not exactly, so let’s learn more about that P and what it […]

Read more
OCR Report

OCR Healthcare Report Released

February 28, 2023

The Office of Civil Rights (OCR) within the U.S. Department of Health and Human Services is responsible for enforcing compliance with the Health Insurance Portability and Accountability Act (HIPAA). As part of its mandate, the OCR annually releases a report on data breaches in the healthcare industry. The most recent report, which covers the year […]

Read more
HIPAA & Cybersecurity

HIPAA Compliance & Cybersecurity: How They Differ

February 21, 2023

Data privacy and cybersecurity are paramount concerns for individuals and organizations alike. The Health Insurance Portability and Accountability Act (HIPAA) and cybersecurity standards are in place for both. It’s common to confuse the two critical healthcare business components as the same thing – yet they are very different.  While both HIPAA compliance and cybersecurity address […]

Read more
heart health

A Different Kind of Heart Health

February 14, 2023

Valentine’s Day is here.  Romance and love are in the air. It’s also a good time to remind your patients to protect their hearts in a different way.  It’s the time of year when we express our love and affection for one another. That may often be with gifts, cards, and romantic gestures. However, this […]

Read more
benefits of AI in healthcare

The Benefits of Artificial Intelligence in Healthcare

February 7, 2023

Artificial intelligence (AI) is rapidly transforming many industries and healthcare is no exception. With the advent of AI, healthcare businesses may face different threats to their cybersecurity. As a result, they could find their business in possible violation of HIPAA rules and regulations. There are also important ethical and privacy concerns associated with the use of […]

Read more
end of support software and hipaa

HIPAA’s Role in Software Support

January 31, 2023

The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that was enacted in 1996 to protect the privacy and security of individuals’ health information. It established requirements for covered entities, such as healthcare providers, insurance companies, and healthcare clearinghouses, to implement reasonable and appropriate administrative, physical, and technical safeguards to protect electronic […]

Read more
Data Privacy Week

Data Privacy Week

January 24, 2023

This week is Data Privacy Week.  This international effort to encourage respect for privacy is encouraged for all industries, but in healthcare, it’s essential. Data privacy in healthcare is a critical issue that affects not only patients, but also healthcare providers, insurers, and researchers. The sensitive nature of personal health information (PHI) and the potential […]

Read more
HIPAA Chat & Text Messaging

HIPAA: Text Messaging and Chat Services

January 17, 2023

Necessary Technology As technology advances, more healthcare providers adopt digital technologies.  Therefore, HIPAA compliance in regard to text messages and chat services becomes increasingly important. The HIPAA Privacy Rule was created to protect the privacy of personal health information (PHI). And that includes PHI that is transmitted via text message or other electronic messaging services. […]

Read more
healthcare cybersecurity

Cybersecurity is Vital for Healthcare Organizations

January 10, 2023

In today’s digital world, it has become increasingly important to protect healthcare organizations from cyber threats. With the rise of medical data breaches and ransomware attacks, there has never been a more pressing need for healthcare organizations to take their cybersecurity measures seriously. Let’s take a look at why cybersecurity is so critical in the […]

Read more
Social Security Scam Warning

Social Security Scam

January 3, 2023

Social Security Scam Alert The beginning of the year provides a new opportunity to scam people. Scams that center around the annual updates and renewals of programs and policies like Social Security are one of the most reported to the government. Be sure to advise your patients that if they are in receipt of Social […]

Read more
Healthcare End of Year Checklist

Healthcare Industry End of Year Checklist

December 27, 2022

Let’s wrap up 2022 with some end-of-year tasks you’ll want to check off of your list if you’re in the business of healthcare! Training Program HIPAA compliance requires a training program.  This means ensuring that your existing staff has completed their training annually and making sure that any new hires have been trained as well. […]

Read more
AI in Healthcare

Artificial Intelligence in Healthcare

December 20, 2022

AI in Healthcare Artificial Intelligence, or AI, is increasingly used in healthcare.  This can be seen in the form of machine learning which assists in detecting patterns, diseases, learning technologies, and more options to assist with patient care. Though not a failsafe, it can offset the risk of medical errors and allow for treatment that […]

Read more
HIPAA tracking technologies

HIPAA & Tracking Technologies

December 13, 2022

HIPAA & Tracking Technologies Tracking technologies such as Google Analytics and Meta Pixel are designed to collect and analyze user data for online activity.  The Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) recently issued a notification regarding these and the obligation to HIPAA from the covered entities […]

Read more
End of Year SRA

End of Year SRA

December 6, 2022

A security risk assessment must be conducted to maintain HIPAA compliance per the Security Rule.  A security risk assessment is also referred to as an SRA.  It is a requirement for government plans such as Medicare, Obamacare, and Medicaid.  It is also required for individual health care plans and employer-sponsored plans. Where to Start Identify […]

Read more
health insurance scams

Health Insurance Scams

November 29, 2022

The annual open enrollment period for healthcare insurance provides another opportunity for scammers to take advantage of. From gathering personal information to receiving payments for non-existent plans, criminals will try nearly anything to score. The signs of a scam aren’t always easy to spot. Here are some of the tactics that consumers should be on […]

Read more
Amazon Healthcare

Amazon In Healthcare

November 22, 2022

Amazon has launched its latest venture in healthcare with Amazon Clinic. This virtual care platform will provide services and support for nonurgent health and lifestyle needs.  This was created with the goal of providing users with easy access to care that allows them to “skip the waiting room.” Treatments This virtual healthcare service will provide […]

Read more
Administrative Simplification Provisions of HIPAA

Administrative Simplification Provisions of HIPAA

November 15, 2022

The HIPAA Administrative Simplification provisions are in place to provide consistency in electronic communications within healthcare for Protected Health Information (PHI).  These mandate the usage of standard transactions, code sets, and identifiers for the United States healthcare system. Who Must Comply? The most common organizations which must comply are healthcare clearinghouses, healthcare providers, and health […]

Read more
Healthcare Asset Management Program

Asset Management Program

November 8, 2022

Having an asset management plan is essential to your healthcare business.  Similar to how you’d want a list of your household items for insurance coverage in the event of theft or loss, you need to know the details and access them quickly. Especially if an item goes missing or breaks.  It is likely that your […]

Read more
Security Incident Guidelines

Security Incident Guideline Reminder

November 1, 2022

The HIPAA Security Rule includes requirements for a security incident response plan that are important to know especially as the number of reported data breaches continues to rise. The Data Check Point Research provided a mid-year report on cyber attack trends that indicated a 69% increase in targeted healthcare data breaches between 2021 and 2022.  […]

Read more
cybersecurity physical devices

Cybersecurity: Physical Devices

October 24, 2022

As we wrap up National Cybersecurity Awareness Month, we’re going to take a look at the importance of protecting your physical devices.  The panic that sets in when you misplace your phone or laptop is overwhelming.  But that feeling is amplified if that device contains patient information or access to it. When we mention your […]

Read more
social media

Cybersecurity: Social Media

October 17, 2022

As we continue into National Cybersecurity Awareness Month, this week we focus on social media.  Why does what you do in your personal life matter in your professional world?  Aside from the possible personal implications, the risk to your cybersecurity also exists. How Hackers Work A cybercriminal knows how to gain access to your trust.  […]

Read more
Phishing

Cybersecurity: What is Phishing?

October 10, 2022

Phishing is one of the biggest threats to any business or individual. With October being National Cybersecurity Awareness Month, we thought we’d explain what it is, why it is dangerous, and how to avoid falling for it, which are all critical to staying safe. What is Phishing? Officially, phishing is defined as the practice of […]

Read more
Security Risk Assessment

Security Risk Assessment

October 4, 2022

The HIPAA Security Rule mandates that covered entities must conduct a security risk assessment or SRA.  This includes health care plans for individuals, government plans (Medicare, Medicaid, Obamacare), and employer-sponsored plans.  Providers that conduct electronic health care transactions must comply with the Security Rule.  This means conducting an SRA.  It is recommended that this occurs […]

Read more
Dental Practice HIPAA Fines

HIPAA Fines for Three Dental Offices

September 26, 2022

The HHS Office for Civil Rights (OCR) has announced resolutions regarding three HIPAA violation investigations.  These settlements result from a years-long emphasis on enforcing this regulation by the OCR.  There were three dental practices that were given fines with regard to the potential violation of the HIPAA Privacy Rule’s patient right of access. Recently appointed […]

Read more
common healthcare breaches

Common Healthcare Breaches

September 20, 2022

What Are the Most Common Healthcare Breaches? When it comes to protecting your business, the approach needs to extend beyond the locks on the doors.  Cyber threats are the highest risk to your patient and data security.  So what are the most common healthcare breaches that you should be on the lookout for regularly? Ransomware […]

Read more
HIPAA Trash Violation

Is There a HIPAA Violation in Your Trash?

September 12, 2022

Is Your Trash a HIPAA Violation? In the case of the New England Dermatology and Laser Center (NEDLC), their trash was a violation.  And a costly one with a $300,640 fee attached.  A security guard found a container with identifying information on the attached label.  As a result, an investigation by the Department of Health […]

Read more
cybersecurity insurance

HIPAA & Cybersecurity Insurance

September 6, 2022

Healthcare businesses need to be aware of the requirements that come with a cybersecurity insurance policy. In a world of online profiles, splashy websites, and great social media campaigns, businesses can misrepresent themselves in more ways than one.  A great photo of your team or a full biography may help create patient trust, but it […]

Read more
HIPAA Chat

HIPAA Compliant Chat

August 29, 2022

HIPAA Compliant Chat Being available to your patients 24/7 isn’t practical for most healthcare practices.  Chat services can provide a response option or even resolution until normal business hours resume.  Additionally, chats can offer initial patient care or registration services.  As a HIPAA-covered entity or business associate, you must consider compliance when offering this service. […]

Read more
NHS Services

NHS Cyber Attack

August 22, 2022

An Indirect Hit The NHS, or National Health Service, is the publicly funded healthcare system for the United Kingdom. They are supported by Advanced who is a managed service provider (MSP). Healthcare companies may outsource their IT departments to other companies to manage the cybersecurity and technical aspects of the business. This allows them to […]

Read more
Portability in HIPAA

Portability in HIPAA

August 15, 2022

Portability in HIPAA There are many aspects of HIPAA.  And sometimes there isn’t a clear understanding of what it covers.  We also find that it is the “P” that often trips people up.  Because of the strong emphasis on confidentiality, security, and safe handling of information, there is an assumption that the word Privacy is […]

Read more
NIST Healthcare Guidance

NIST and HIPAA

August 9, 2022

Health Care Cybersecurity Update on Guidance The National Institute of Standards and Technology (NIST) has provided updated guidance for the health care industry.  Designed to help with electronically protected health information (ePHI), they have created a new draft titled Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide (NIST Special […]

Read more
Americans with Disabilities Act

ADA: Americans with Disabilities Act

August 2, 2022

This year marks the 32nd anniversary of the signing of the Americans with Disabilities Act, known as ADA.  This Act is in place to prohibit discrimination against any qualified individual.  As outlined on the ADA National Network site, it ‘is a civil rights law that prohibits discrimination against individuals with disabilities in all areas of […]

Read more
What Is GDPR

What Is GDPR?

July 25, 2022

Are you familiar with the European Union (EU) regulation of GDPR?  There may be some confusion over this policy and those who believe it to be the counterpart to the United States’ HIPAA regulation.  While there may be some overlap, they are not the same. As a US-based business that is a covered entity or […]

Read more
Right to Access HIPAA

HIPAA Right to Access Enforcement

July 19, 2022

The Office for Civil Rights (OCR) isn’t offering leniency just because you’re a small business.  Action will be taken, despite the impact that a HIPAA fine can have on this sector of healthcare. And as eleven recent investigations prove the point, many of those were small practices.  This brings the total to 38 enforcement actions […]

Read more
Certificate of Need

Certificate of Need

July 11, 2022

What is a Certificate of Need? A certificate of need, or CON, is a legal document that is required for the construction of a new healthcare facility.  It regulates the healthcare system by requiring approval from regional governments.  However, there are variations within the 35 states and Washington D.C. that need them. What Do They […]

Read more
API Adoption Healthcare

API Adoption and Healthcare

July 5, 2022

API Adoption and Healthcare  Healthcare faces threats from cybercriminal activity at rates that continue to rise. The patient data that they access and maintain is valuable on the dark web in more ways than one. It can be an access point for a greater breach and then used to manipulate or steal identities and attack […]

Read more
Healthcare Breaches on the Rise

Healthcare Breaches on the Rise

June 27, 2022

Healthcare Breaches on the Rise Don’t shy away from this headline, healthcare businesses cannot put their head in the sand or look the other way when it comes to establishing a strong cybersecurity program.  For many, the focus has been on HIPAA compliance.  This consumes resources both in the workforce and funding.  It has also […]

Read more
Audio Only Telehealth

HIPAA and Audio-Only Telehealth

June 20, 2022

HIPAA and Audio-Only Telehealth The Department of Health and Human Services (HHS) put clarity recently on how the HIPAA Security Rule applies to telephone technologies.  In the case of telephone lines that are traditional landlines, the rule does not apply.  But it does apply to mobile technologies that utilize electronic media such as WIFI. What […]

Read more
HIPAA Breach Exceptions

Exceptions to a HIPAA Breach

June 12, 2022

Exceptions in a HIPAA Breach In 2007 the Guide to Medical Privacy Law was published.  It indicated that on multiple occasions hospitals, EMT services, schools, and other public agencies were incorrectly withholding news out of a fear of violating HIPAA policy.  Often, there isn’t a clear understanding as to what constitutes exceptions to HIPAA and […]

Read more
Healthcare Digital Front Door

What is the Digital Front Door?

June 7, 2022

The traditional way to see your healthcare practitioner was to call the office, schedule an appointment and when the time came, go to the office for your visit.  You’d get there and then open the front door to attend your appointment. Like nearly everything, time, and our increased electronic footprint have brought change to that […]

Read more
Remote Workforce

Remote Workforce and HIPAA

May 31, 2022

Whether a change in your business structure came about from the pandemic, or it just makes more sense for your team, remote work is the norm for many more professionals today than it was in years past. If you’re in healthcare, this means that you need to factor in the HIPAA component as well as […]

Read more
HSN Omnibus Rule

What’s the HIPAA Omnibus Rule?

May 23, 2022

The HIPAA Omnibus Rule was established to identify and further outline accountability within the entities of healthcare regarding patient data.  To understand the HIPAA Omnibus Rule and how it affects these entities, we need to understand who and what are the “moving parts” that make up the operation.  Once we recap these key components, we’ll […]

Read more
18 PHI

The 18 PHI (Protected Health Information) Identifiers

May 16, 2022

18 HIPAA PHI Identifiers HIPAA regulations are in place to ensure that you protect and secure the patient data that as a healthcare business, you have access to and collect.  The Department of Health and Human Services (HHS) has identified 18 patient identifier categories as it pertains to their guidance on satisfying the safe harbor […]

Read more
Client News Source

Your New HIPAA + Cybersecurity News Source

May 9, 2022

Good Intentions Your workday in your healthcare business may start out with a clear plan of what you have ahead – you have your task list and work items to get through.  But when it comes to cybersecurity, we need to be made aware of things in a timely and efficient manner.  It may be […]

Read more

HIPAA Compliance Audit: What to Expect

May 2, 2022

“We’re being audited!” Those words strike fear and uncertainty in most of us – especially if you are in healthcare. But what actually happens in a HIPAA audit?  Will a government official show up unannounced with a briefcase and ask for you to produce every bit of your business’s HIPAA documentation while sequestering your team […]

Read more
HIPAA websites

Business Websites: Do They Need to Be HIPAA Compliant?

April 25, 2022

The process of assessing your business when it comes to HIPAA Compliance will likely present you with the opportunity to review all the components that contribute to your professional structure and setup.  This will likely include a website. Does a Website Fall Under HIPAA Regulations? If a website is used to collect and process protected […]

Read more
HIVE Alert

High Alert: Healthcare Ransomware Threat!

April 23, 2022

The Cybersecurity Program within the Department of Health and Human Services (HHS) came out this week with a strong warning for healthcare organizations about an “exceptionally aggressive” ransomware group that is targeting them. The Hive ransomware group is financially motivated and uses various methods to target organizations including phishing and attacking remote access/VPNs. They encrypt and steal data […]

Read more
security officer

HIPAA Security Officer

April 18, 2022

Recently we went over the role of the HIPAA Privacy Officer and what responsibilities that individual would oversee, as well as what qualifications an ideal candidate would bring to the position.  Additionally, HIPAA Regulations require that you formally identify a Security Officer in addition to a Privacy Officer, but they can be the same person. […]

Read more
HIPAA privacy officer

HIPAA Privacy Officer – Who’s in Charge Here?

April 11, 2022

Under the HIPAA Privacy Rule, there must be one individual who is identified as the Privacy Officer.  What does that mean?  Is it a paid job?  What are the requirements?  Are they the ones who will be accountable in the case of a violation or if a data breach should occur? Every covered entity and […]

Read more
business size

Regardless of Your Business Size, You’re a Target

April 4, 2022

Many people in healthcare make the incorrect assumption that their business won’t be a target for cybercriminals because they are “just a one-man show” or “aren’t part of a big network”.  Neither way of thinking is wise, because when a cybercriminal is trying to compromise data or an entire network, every organization is valuable, and […]

Read more
IoMT

IoMT: What is the Internet of Medical Things?

March 29, 2022

Are you familiar with the IoT or the Internet of Things?  This is the term that is applied to objects that are connected via the internet to collect and transfer data without any human interaction or intervention.  This includes items like your smart television or even a refrigerator that is connected to an app on […]

Read more
Tax Scams

Fraud Alert: Beware of Tax Related Scams

March 21, 2022

Healthcare professionals are gatekeepers to a variety of confidential information about their patients and the businesses that they work for, and for this reason, they are a highly coveted target by cybercriminals. Being on guard and alert all year is critical when you are overseeing the Protected Health Information (PHI) of your patients. Be aware, […]

Read more
PHI

Protected Health Information: How Long Do You Need to Keep Records?

March 15, 2022

In your home, it is likely that you have at minimum a pile of paperwork and records that you’ve held onto “just in case you need it” for a possible tax audit, warranty, to make a return, or several other random reasons you’ll need to reference it in the future.  No one ever seems to […]

Read more

What Is MFA….and Do I Need It?

March 7, 2022

What Is MFA? Multi-Factor Authentication, or as it has become commonly known, MFA, is the practice of “doubling down” on your login security.  You are using Multiple (more than one) Factors (ways or methods) to Authenticate (verify) your identity when you access an account.  When you hear the term 2FA, this means that you need […]

Read more
HIPAA Voicemails

You Can Leave a Message – But Make Sure It Is HIPAA Compliant

February 28, 2022

Even though telephone conversations and answering machines are considered outdated or passe to some people, it remains necessary to sometimes leave a message for the intended call recipient. In healthcare, voice messages are often necessary for appointment reminders, follow-up calls, and communication to patients.  Within the realm of HIPAA, what are you allowed to say? […]

Read more
Reporting Details

Reporting a HIPAA Breach – Details You’ll Want to Know

February 21, 2022

The Health Insurance Portability and Accountability Act, or as it is commonly known as HIPAA, was created to set standards nationally. These are in place to protect the personal health information and medical records of individuals as well as give them access easily. As the March 1st deadline for reporting a breach draws closer, knowing […]

Read more
Reporting Deadline Approaching

Annual Deadline for HIPAA Small Breach Reporting is Approaching

February 15, 2022

March 1st, 2022 is the deadline for breach reporting for HIPAA-covered entities and their business associates – and the date is fast approaching! The HIPAA Breach Notification Rule requirement means that HIPAA-covered entities, as well as any of their business associates, notify the appropriate parties, including the Office for Civil Rights (OCR) Secretary of Health […]

Read more
HSN Breach Stats

Healthcare Breach Statistics Continue Rising

February 8, 2022

An astronomical increase of 450% would be a wonderful thing if we are talking about revenues or productivity.  But when it comes to COVID-19 related phishing attacks, that percentage in the jump of attacks from 2019 to 2020 is staggering – and a serious issue that needs to be addressed. According to the ForgeRock 2021 […]

Read more
HIPAA & Email

How to Handle HIPAA and Email

February 1, 2022

It’s fast and easy, and you can often work more efficiently with an email exchange than if you must make phone calls or schedule appointments to discuss patient care.  But where does that exchange fall when it comes to HIPAA compliance? The HIPAA Security Rule introduced several requirements to consider before an email can be […]

Read more
HIPAA BAA

What is a Business Associate Agreement in HIPAA?

January 25, 2022

In simple summary, a Business Associate Agreement (BAA) is a legal contract that exists between a Covered Entity and a Business Associate who comes into contact with Protected Health Information (PHI). Sometimes called a Business Associate Contract, it is critical and required to maintain HIPAA compliance. With the main bulk of PHI being stored electronically, […]

Read more

Phishing Attacks on the Healthcare Industry

January 17, 2022

What is Phishing? Phishing is the practice of tricking users by imitating reputable companies in order to reveal personal or confidential information which can then be used in a more illicit manner. This is done via a deceptive email or website, and often in a combination of both.  Spear phishing takes the manipulation one step […]

Read more

Looking Ahead: Healthcare Cybersecurity Predictions for 2022

January 10, 2022

The pandemic pivot that seemed as if it would be temporary a few years ago, those behaviors that redirected how we work and live, is now a seemingly permanent modification.  Remote work, telehealth, and the increasing use of products that are part of the IoT, or the internet of things, have provided us with increased […]

Read more
HIPAA Breach Notification Rule

Your HIPAA Breach Notification Questions Answered

January 4, 2022

The HIPAA Breach Notification Rule is a requirement put in place that requires HIPAA-covered entities and their business associates to “provide notification following a breach of unsecured protected health information.” The details provide an outline for how healthcare providers, hospitals, and physicians must notify the affected individuals, the Secretary of the U.S. Department of Health […]

Read more

HIPAA Privacy Rule Update: Extreme Risk Protection Orders

December 28, 2021

Recently the Department of Health and Human Services (HHS) along with the Office for Civil Rights (OCR) issued an announcement regarding extreme risk protection order (ERPO) laws and the disclosure of protected health information (PHI).  This published model was created as a way to provide each state with a framework to consider as they implement […]

Read more

End of Year Checklist for Healthcare         

December 20, 2021

As we wrap up another calendar year, getting ready for holiday break means wrapping up more than presents.  Take a moment to go over a few items that you should review to make sure they are done for 2021 or ready to go in the new year. Security Risk Assessment A Security Risk Assessment, or […]

Read more

HIPAA Right of Access

December 13, 2021

HIPAA Right to Access Initiative is Alive & Well In 2019 we witnessed the Office for Civil Rights (OCR) make it public that they were going to up their efforts when it came to enforcing the rights of an individual to access their health records.  This is known as the HIPAA Right of Access initiative.  […]

Read more

Is That Video Rated HC?

December 6, 2021

No, there isn’t such a rating system, but it might be something to consider. There are many different communication platforms that healthcare providers can use to communicate with each other, such as email, instant messenger systems, and even through social media sites. While these platforms can be very useful for communicating quickly and easily, they […]

Read more
was that a HIPAA violation?

Oops, Was That A HIPAA Violation?!

November 29, 2021

Working in healthcare means that you are certainly aware of HIPAA’s existence, but it doesn’t necessarily mean you are the resident expert on what constitutes compliance.  You know what you can or can’t do – generally speaking.  Most likely, you follow the rules as they are explained to you, and don’t deviate much from that. […]

Read more

‘Tis the Season for Yams…and Scams

November 22, 2021

Seasonal Scams in Healthcare We’re entering the time of year that we pause and reflect on what we have to be thankful for, especially this year, as more of us are able to gather in person.  We can stop, slow down, and appreciate what we have.  But this doesn’t necessarily mean a break for those […]

Read more

Administrative Safeguards of the Security Rule: What Are They?

November 15, 2021

The HIPAA Security Rule requires healthcare providers and their business associates to implement physical, technical, and administrative safeguards to protect the electronic Protected Health Information (PHI) that they utilize. It establishes national standards to protect that information. These standards apply not just to covered entities, but any organization that handles PHI – including subcontractors and business associates.   Administrative safeguards (also called […]

Read more

Is Your Head or Your Business in the Cloud?

November 8, 2021

Cloud Hosting & HIPAA Compliance When you think of trends in healthcare, what comes to mind? Maybe it’s a particular EMR system, new machines in the office, ways in which you communicate with patients… the list goes on. One thing is for sure when we think about all the ways that healthcare has changed over […]

Read more

What’s So Important About Security Risk Assessments for HIPAA Compliance?

November 1, 2021

Before you buy a home, an inspection is completed as a way of exposing any potential issues to you as a buyer.  This can give you leverage when it comes to purchasing price negotiation since these liabilities can often present risks to you as a resident.  Those risks can come in the form of cost […]

Read more
Human Error

Human (t)Error

October 25, 2021

October. That time of year when we have pumpkin spice everything and when tricks, treats, and terrors are given front-page billing.  And for some people, it is the ideal time to binge-watch scary movies on repeat.  We stare at the screen with one eye open, begging the main characters not to go into the woods, […]

Read more

Why Celebrate Cybersecurity Awareness Month?

October 18, 2021

The History A trip into any card store or venture onto social media will alert or remind you that there is a holiday for nearly everything.  Who got to decide that April 23rd was National Talk Like Shakespeare Day? Or that Squirrel Appreciation Day would fall on January 21st? Some of them might make you […]

Read more

Health Apps & HIPAA

October 11, 2021

The Federal Trade Commission (FTC) recently released a new policy statement that requires health apps and connected device companies that collect health information to comply with the Health Breach Notification Rule.   Yes, that means those very apps that so many of us use to collect our heart rate, weight, sleep, fertility, height, or any other sensitive […]

Read more
PHI or PII

PHI or PII – What’s the Difference?

October 3, 2021

The terms protected health information (PHI) and personally identifiable information (PII) are often used interchangeably.  But while they may sound like the same thing, there are differences that set them apart, and that is especially true when it comes to HIPAA. What’s the difference? PII is any information that can be traced to a person’s […]

Read more
Cybersecurity Resources for Healthcare

Cybersecurity Resources for Healthcare

September 26, 2021

Recently The HHS Office for Civil Rights (OCR) shared a comprehensive list of resources for any HIPAA-regulated entity to assist them in the prevention, detection, and mitigation of data breaches of protected health information that occurs because of hacking or ransomware. As a covered entity or business associate under HIPAA compliance, an attack on your […]

Read more
long term effects

Long Term Effects

September 20, 2021

Accessibility is Here to Stay Health Information Technology (Health IT) is an always evolving realm, with new tools coming to market as fast as we can master the old ones. With the advancement of technology comes a need for new software and security to maintain these systems. This past year has been one example of […]

Read more

Remember When

September 13, 2021

There was a time when you would walk into any doctor’s office and the sliding walls or file cabinets of patient folders seemed endless.  Guarded like vaults, all the information safely under lock and key.  And in addition to patient data, there is employee data, which likely contained personal and banking records.  The “really” important […]

Read more

What Is a HIPAA Entity?

September 7, 2021

It’s easy to find a news story with someone misappropriating what HIPAA is, what it means, and what it does.  Most people incorrectly assume how it protects their health records and information from ‘the world at large’.  It does protect private health information, and it was created to allow for easy access to one’s health […]

Read more

Cyberattack Cost to Healthcare

August 29, 2021

Bigger business, bigger problems, right?  Not necessarily true when it comes to the cost of a cyberattack within the healthcare industry. A recently published survey brings unexpected results when it comes to comparing large and medium-sized businesses.  Surprisingly, medium-sized businesses are hit with cyberattack costs that are nearly 4x that of their larger counterparts at […]

Read more

Electronic Health Records & The Security Rule

August 22, 2021

Patient care in a digital age means that most information is stored electronically.  These records, known as electronic Protected Health Information (ePHI), are collected as electronic health records (EHR) and then stored in a variety of systems.  With the Health Insurance Portability and Accountability Act (HIPAA) in mind, how do you maintain security around the […]

Read more

Challenges in Healthcare Cybersecurity

August 16, 2021

The healthcare industry is always a top target for cybercriminals, but cybersecurity doesn’t always take the top spot when it comes to business concerns or plans in this sector.  While we hear about breaches happening on a regular basis, we don’t seem to act at the same rate.  What are the challenges that healthcare faces […]

Read more

Healthcare & Ransomware

August 10, 2021

As healthcare continues to be a prime target for cybercriminals, understanding what is happening as an employee is equally, if not more, important than just being aware of the risk.  Having insight into how the attack can play out will help you understand the threat and the outcome if a hack occurs. Ransomware is one […]

Read more

Why Do Hackers Love Healthcare?

August 2, 2021

Cybercrime.  It has become a regular part of the conversation around healthcare.   We are regularly presented with the stats, and we know that the risk is greater for our businesses when it comes to cybercriminal activity.  WHY is that the case?  While some factors may seem obvious, let’s look at some of the other issues […]

Read more

No Vacation for HIPAA

July 26, 2021

This summer many of us are taking long overdue vacations that were put on hold or delayed because of the pandemic.  As healthcare workers, you are certainly due time off – especially after the brunt of COVID-19 was dealt with by your industry. While you’re checking out and hoping that you won’t have to check […]

Read more

HIPAA & 18-Year-Old Patients

July 19, 2021

  As a parent, you might recall the first time that the doctor asked you to leave the room because your “baby is now a teenager” (ugh, cry, sigh…. joy?) and they have a few questions for them that they would like to conduct one-on-one and in private.  Suddenly your brain races, ‘what do they […]

Read more

HIPAA Turns 25

July 12, 2021

As the Health Insurance Portability and Accountability Act of 1996 (HIPAA), approaches the 25th anniversary of its enactment, we thought we’d look into the history of this game-changer in the healthcare industry. Signed into law by President Clinton on August 21, 1996, this federal statute was enacted to modernize the flow of healthcare information as […]

Read more

Common HIPAA Mistakes

July 6, 2021

As a person who works within the healthcare industry, understanding HIPAA is a necessity, even if it is knowing just the basic rules.  These rules and regulations are complex and ever-changing so that they can keep up with the fluid landscape of healthcare, so unless you are an expert, it is unlikely that you know […]

Read more

Wait, a Breach is HOW Much?

June 29, 2021

The Background Wolfe Eye Clinic is a healthcare provider located in Iowa. In business since 1919, they specialize in medical eye care and have 11 main eye care clinics across the state, and various other locations that offer treatments. According to their website, they treat approximately 700,000 patients. This seems to be a solid and […]

Read more

Executive Order

June 21, 2021

This month a memo went out from the White House and Cybersecurity and Infrastructure Agency (CISA) to industry leaders that emphasized the threat posed by ransomware within their businesses as well as emphasizing just how important it was to the current administration to prioritize the awareness.  The memo also is putting the responsibility on the […]

Read more

Vaccine Required

June 14, 2021

June 21st is fast approaching, and to most of us, that means the official start of summer.  But to a group of 178 healthcare workers in Houston, it could mean the end of their employment. We’ve been discussing the various mandates and situations concerning getting the COVID-19 vaccine.  The more public of these scenarios include […]

Read more

It Isn’t Always Obvious

June 7, 2021

Far too often, and in just about every industry, those of us who are “in it” assumes that certain aspects of what we know are obvious to the general public. For example, in healthcare, we know the basics of HIPAA and what information can and cannot be shared. This thought came to me again while […]

Read more

Vaccination Nation

June 1, 2021

Whether you choose to get a vaccine for COVID-19, it is your decision.  We aren’t here to provide personal medical guidance or tell you what is right for you.  But with regard to informing you about the healthcare landscape, well, that’s part of our program here at HIPAA Secure Now.  And we would be remiss […]

Read more

Rising Danger

May 24, 2021

Meticulous Research released a market research report “Healthcare Cybersecurity Market”, that indicated a number that anyone in healthcare would want to be aware of. They expect that by 2027 – which sounds far off but is NOT – the cybersecurity market within healthcare will reach $26.1billion with a compound annual growth rate (CAGR) of 19.8% […]

Read more

Pipeline Problems & Healthcare

May 16, 2021

The recent attack on the Colonial Pipeline has (hopefully) reawakened any slumbering notion that cybersecurity isn’t everyone’s problem.  Not sure what we mean?  To recap at a high level, a cybercrime group identified as DarkSide hacked Colonial Pipeline’s infrastructure.  As a result, the company acknowledged that they were the “victim of a cybersecurity attack” that […]

Read more

Document Storage

May 10, 2021

While the world is moving to electronic storage as a standard, there are still physical documents within healthcare that need to be protected and fall under HIPAA regulations.  Let’s take a look at how that should be handled. As paper can pile up, how long do you have to store HIPAA documents?  And what do […]

Read more

Your Prescription for Healthcare

April 26, 2021

  Your patients arrive in your office with injuries and ailments that threaten their health. You review the situation and prescribe a plan of action and perhaps medication that will remedy the situation at best and alleviate pain or risk as well. You give them a prescription for health. Because that’s what you do. When […]

Read more

Vaccination Passports

April 19, 2021

Many people are getting their vaccines for their own safety, for the general well-being of the public, for their jobs, and some are getting it so that they can safely travel again.  In fact, many people are doing this because they know that they won’t be able to leave their home base if they don’t […]

Read more

It’s Not for Everyone

April 11, 2021

Telehealth Is Not Everyone’s First Choice With regard to telehealth statistics, we saw a great rise in the number of participants during the past year with COVID-19.  It was a perfect solution for many people, especially if leaving their homes meant putting them in danger due to their high-risk factors linked to the virus. Equally […]

Read more

Oversharing

April 5, 2021

Last week we covered the different ways that social media is playing a role in deploying healthcare messages.  From patient experience to alerting the public about the pandemic, individuals and corporations are taking to the ‘digital airwaves’ of TikTok, Facebook, Instagram, and other platforms to spread awareness and messaging. This sounds like a great idea.  […]

Read more

Socially Distanced Messaging

March 29, 2021

The social media platform TikTok has become a mainstream method of learning dance moves. And some recipes.  And maybe a silly dog video here and there.  But what we didn’t expect it to become was a healthcare platform. No, surgeries aren’t being performed via the application – although we won’t be surprised if and when […]

Read more

Fake Supplements

March 21, 2021

Fake Supplements Buying a knockoff purse or jersey is one thing, and we can take you down a rabbit hole of “why you shouldn’t do that” that would occupy you for hours.  But when it comes to items you ingest and don’t simply wear, you need to pay attention. Supplementing your healthcare regime with vitamins, […]

Read more

More Time for Comments

March 15, 2021

Last week, the Office for Civil Rights (OCR) at the US Department of Health and Human Services (HHS) announced that there would be a 45-day extension of the comment period for the public with regard to the Notice of Proposed Rulemaking (NPRM) on modifying the HIPAA Privacy Rule that was originally posted in December of […]

Read more

A Different Kind of Health Hero

March 8, 2021

A Year of Heroic Feats The healthcare industry has been called to task this year in ways that make them heroic in the eyes of the world.  As a global community, words can’t accurately convey the gratitude they deserve from all of us. Today we’re going to talk about another way, one that is less […]

Read more

Dark Web Dangers

March 1, 2021

With healthcare being a top target in the world of cybercrime, it never hurts to do a review every so often of the landscape and of the players in the game. We’ll also take a look at how you might be compromised without even knowing it or suspecting it could happen. A Lay of the […]

Read more

Humans of Healthcare

February 22, 2021

With healthcare being a huge target of cybercrime, the immediate concern is likely with regard to how it will coincide with any HIPAA regulation – or revealing any failure to comply.  First thoughts usually go to the business side of a situation. How much will this cost?  Will we be fined?  Will we have to […]

Read more

HIPAA Stats & Facts

February 15, 2021

We couldn’t call them fun facts, because there’s really not a lot that one could label “fun” when it comes to HIPAA, but we thought we’d take a look at some of the statistics and facts in a summary fashion. HIPAA, often misspelled HIPPA, stands for the Health Insurance Portability & Accountability Act. This federal […]

Read more

Heart Healthy

February 8, 2021

With romance in the air for the upcoming Valentine’s Day holiday, we thought we’d shine a light on the ways that HIPAA can be affected by love in the workplace and what rules are in place to address it.  Are there ethical repercussions to dating your doctor?  Can my significant other access my medical records? […]

Read more

Remote Working & Healthcare

February 1, 2021

We have seen the healthcare industry rise to the occasion this past year.  Stepping up in more ways than can be counted and doing so under extraordinary conditions.  Telehealth does offer a viable solution for many people who cannot travel outside of their homes, and at the same time, it offers a safe solution to […]

Read more

As the Rules Apply

January 25, 2021

This week in HIPAA news we are shining a light on two rules that display the spectrum of ‘bending’ from the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR).  The first, showing flexibility, announced that penalties with regard to HIPAA, as it pertains to the COVID-19 vaccination, will not be […]

Read more

What if Employees Refuse the Vaccine

January 18, 2021

In healthcare, we want to assume that we are collectively working to advance medicine and whatever the latest developments are, well we want “in”. What if that development is the COVID-19 vaccine and as it turns out, someone on your team isn’t interested? According to a survey done by the Pew Research Center, not all […]

Read more

Learn From Others

January 11, 2021

The office for Civil Rights gathered information at the end of 2020 that is important for any covered entity or business associate that operates under HIPAA guidelines.  Summarized in the U.S. Health and Human Service (HHS) HIPAA Audits Industry Report, this data should be regarded as a useful tool for any business that deals with […]

Read more

Year-End Health Report

January 4, 2021

Ideally, we have a health physical once a year.  We assess what we are doing right, what we are doing wrong, and make modifications to our overall wellness plan as needed.  Hopefully, nothing is wrong, and we can proceed with the usual cautions and goals of maintaining a long and productive life. The same could […]

Read more

Safe Harbor Act

December 29, 2020

In our blog earlier this year that provided an overview of 2009’s Health Information Technology for Economic and Clinical Health (HITECH Act) we discussed how this was designed to promote the use of electronic health records (EHR) within the healthcare system and its providers. As is with most things, time goes on and often reveals […]

Read more

Vaccination Scams

December 21, 2020

It hasn’t even been available for a minute and we’re already being warned about scams surrounding the COVID-19 vaccination.  With healthcare being a huge target for cybercrime already, this isn’t surprising. Consumers should be aware of phone calls, text messages, social media links and posts, emails, and even in-person tactics that will be used to […]

Read more

Potential Changes Ahead

December 14, 2020

The Health and Human Services Office for Civil Rights has proposed changes to the HIPAA Privacy Rule that could be substantial. The Notice of Proposed Rulemaking (NPRM) proposal stated it was to “remove barriers to, coordinated care and individual engagement” and was issued last week. Addressing standards of the rule may limit and/or discourage care […]

Read more

Threat to Healthcare

December 7, 2020

We have had quite a year so far in 2020, and if you are in healthcare, you were hit especially hard with something that you likely didn’t adequately prepare to deal with.  However, according to a recent report from Black Book Market Research LLC, the healthcare industry has no idea what could hit them in […]

Read more

HIPAA & the Media

November 30, 2020

Can a journalist reveal an individual’s COVID-19 diagnosis or are they in violation of HIPAA laws by doing so? Healthcare and the diagnosis of a person’s well-being are private information in general, but when it comes to reporting, and doing so in a pandemic, suddenly ‘who has what and where are they?’ becomes a matter […]

Read more

HITECH Act

November 23, 2020

This week we’re taking a look at the HITECH Act and an overview of what it is and how it relates to HIPAA. Formed in 2009, the Health Information Technology for Economic and Clinical Health (HITECH) Act was introduced as part of an economic stimulus package to promote and expand the awareness and adoption of […]

Read more

HIPAA & Medical Devices

November 16, 2020

The human factor is something of huge consideration within the HIPAA and healthcare landscape. With that industry being a huge target already within the world of cybercrime, where do medical devices as well as their manufacturing companies, fall within HIPAA regulations? When the Department of Health and Human Services (HHS) created HIPAA guidelines, there were […]

Read more

No Business Is Too Small

November 9, 2020

It Happens Everywhere While the world might still be in varying states of chaos with regard to a multitude of topics, when it comes to HIPAA fines and enforcement of regulations, things are getting back on track. As the global pandemic settled into our daily lives and it became clear that the sharing of information […]

Read more

Notification Rule

November 2, 2020

Timing is Everything A data breach within your business. You think it won’t happen, you hope it doesn’t happen, but what if it does happen? What are your next steps? Like most things in healthcare, timing is essential. You need to think quickly and act swiftly during a time when your head might not be […]

Read more

Wearable Technology

October 26, 2020

The saying goes that you’re never fully dressed without a smile, but the reality for many people today is that you’re never fully dressed until you put on your smartwatch.  Or your phone in your pocket.  Or your health and fitness monitor at the gym.  These component pieces are now standard in our attire and […]

Read more

Cybersecurity Awareness Month

October 19, 2020

We’re halfway through this year’s Cybersecurity Awareness Month and never has it been more important to make sure that you are informed and making smart cyber choices in both your personal and professional life. With the pandemic providing cybercriminals ample opportunity to take advantage of our uncertainties in many aspects, and with online activity through […]

Read more

Systemic NonCompliance

October 12, 2020

The story narrative varies slightly from episode to episode, but the outcome is generally the same.  Pay a fine, make a plan, regret not doing this all in the first place.  This isn’t some soap opera or Netflix binge-worthy series; this is real life and the characters are the healthcare industry and Office for Civil […]

Read more

Second Largest Fine

October 5, 2020

Coming in second can sometimes be a good thing. But not when you’re on the receiving end of a HIPAA fine and have to pay out $6.9 million like Premera Blue Cross. The insurer is the largest health plan in the Pacific Northwest, serving more than 2 million people. This fine is the second-largest payment […]

Read more

Right to Access Enforcement Initiative

September 28, 2020

In 2019, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) announced an initiative that they would make it a priority to enforce an individual’s right to access their health records in a timely manner and at a reasonable cost. This falls under the HIPAA Privacy Rule. While […]

Read more

Hover Hover Hover

September 21, 2020

At times, it feels as if we could start every week with this sentence: “There’s a new tactic being used by cybercriminals to trick unsuspecting victims.” And the sophistication level of the new tactics is off the charts. So, what are we dealing with as of late? Well, where should we start… Hidden text is […]

Read more

Please Complete This Form

September 14, 2020

You walk into your healthcare provider’s office and are usually handed a clipboard with papers that need to be filled out, updated, and wrapped up with your signature. We mindlessly take our task to the nearest seat and complete, sign, initial, and update whatever we’ve been given. This information goes into our file and continues […]

Read more

COVID-19, Cybercrime, & HIPAA: Prepare Your Practice

September 10, 2020

Is your practice prepared to securely operate during the COVID-19 crisis? Are you facing new challenges with telehealth, your remote workforce, or with the growing cybersecurity threat to healthcare? Watch this webinar to get instant insight into how your practice can prepare and prevent losing time, money, and your good reputation because of a HIPAA […]

Read more

Statistically Speaking

September 7, 2020

Three universities recently conducted a joint study of participants that aimed to explore their likelihood of being monetarily incentivized to violate HIPAA regulations. The pilot study involved medical residents or individuals in an executive MBA program, with some of those participants already in health care executive roles.  Of the 64 medical students and 32 executive […]

Read more

Caught Off Guard

August 31, 2020

The term “new normal” is something I think we would all enjoy hearing less of at this point.  We’re at a point where this is how we are going to be operating and we need to pause, assess what happened, where we are, and how we move forward. As we reflect back, we know first […]

Read more

Physical Theft of PHI

August 24, 2020

How many unexpected and unforeseen circumstances can 2020 present us with? Each month we think that we’ve likely seen it all, considered it all, and readied ourselves for whatever comes our way. This year has provided us with plenty to panic over, and many things that we never thought we’d face. Take for example the […]

Read more

Wish You Were Here!

August 17, 2020

It’s always nice to get a postcard from friends or family who are away on vacation. But this week we learned of a new kind of postcard being sent out with not-so-well wishes. The Department of Health & Human Services’ (HHS) Office for Civil Rights (OCR) sent out a warning that fraudulent postcards are being […]

Read more

Million Dollar Laptop

August 10, 2020

Was it made of gold? Encrusted in diamonds? No. Read on to learn how one laptop ended up being worth a massive one million dollars. The U.S. Department of Health and Human Services (HHS) recently closed an investigation into Lifespan Health System Affiliated Covered Entity for a stolen laptop incident reported back in 2017. That […]

Read more

Caught off Guard: What the Pandemic Taught Healthcare Organizations About Being Prepared for a Business Interruption

August 4, 2020

COVID-19 has had a profound impact on the healthcare industry. Many day-to-day operations have changed, like how organizations provide care to patients and handle business functions behind the scenes. While these changes were required to be made quickly, some organizations found themselves far less prepared than others. – Was your organization prepared for the quick […]

Read more

COVID-19 Crime

August 3, 2020

For every moment in time, there is an opportunity to create good from it, and likewise, to create bad or negative reactions. COVID-19 has given us both. While of course, we wouldn’t wish it to happen again, we have seen people come together, new businesses arise, and an overall re-evaluation of our priorities. Then there’s […]

Read more

Smart Telehealth Practices

July 27, 2020

COVID-19 has ushered in the mass acceptance of telehealth, with so much optimism and excitement around the technology. But like many new technologies, the initial use is rushed and not well thought out with many providers trying to figure out the right technology, best practices, and optimal patient experience. We have seen temporary waivers to […]

Read more

Mask Mandate

July 20, 2020

Mask Mandate Whatever your opinion is of wearing, or not wearing a mask, there are in increasing number of mandates being put in place by governments or independent establishments in an effort to mitigate the spread of COVID-19.  This mask mandate means that most people over a certain age need to have their face covered, […]

Read more

Limitless Liability

July 13, 2020

A year of credit monitoring along with identity theft monitoring services. That’s what most of us settle for when we find out that our personal data has been compromised. We are alerted, we change our password, we read the letter that offers these services and may or may not sign up for them. Some individuals […]

Read more

Employee Errors

July 6, 2020

We all know (or should know) that human error accounts for the majority of breaches. Phishing gives hackers entry to a business’s front door by manipulating the employees who work there. Phishing is when a cyberattack is disguised and delivered using email as the carrier or weapon. Through very convincing and cleverly designed messages, the […]

Read more

Employee Coverage

June 29, 2020

As businesses like shops, restaurants, and others that were previously closed as a result of COVID-19 begin to open, precautions of various kinds are now in place.  As the state or perhaps local government encourages and sometimes requires protective gear, employers must take into consideration how it will affect their workforce. One outward-facing and immediate […]

Read more

Employee Privacy In a Pandemic

June 22, 2020

Employee Privacy in a Pandemic COVID-19 has presented businesses with a new challenge in keeping their company safe and it starts with employee health. As they re-open in the wake of the pandemic, they must keep track of individual health with regard to who is sick and how it might affect the company as a […]

Read more

Is COVID-19 Unraveling HIPAA?

June 15, 2020

Let’s Recap The Health Insurance Portability & Accountability Act (HIPAA) was created in 1996 to protect patients and their privacy, and if you are in healthcare, you already know this and are familiar with what it means.  With a goal to ensure that people could maintain health insurance between jobs, thus the “Portability” part of […]

Read more

Delaying Treatment

June 8, 2020

The Patients Are Not Equal As COVID-19 took over in the headlines, it also took over at many hospitals around the country.  We saw a rise in the number of patients that were taken in and diagnosed with the virus, but there was an unexpected result as well.  The rate of decline in-patient activity didn’t […]

Read more

Lenient Doesn’t Mean Lazy

June 1, 2020

  In mid-March, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced that they would use “enforcement discretion” in regard to HIPAA compliance with telehealth.  And, the healthcare community gave out a collective sigh of relief.  Not because the rules and regulations were unfair, but in a time of […]

Read more

Free Download: Cyber-Attack Quick Response Resources

May 29, 2020

Cyber-attacks against healthcare organizations are on the rise, as cybercriminals target covered entities and business associates alike. The uptick in attacks on healthcare has proven the need for organizations to invest in their preventive cybersecurity efforts and ensure they are prepared to handle the aftermath of a successful attack or security incident. Download our free […]

Read more

Changes Ahead

May 26, 2020

While we have all had to adjust in obvious ways to the pandemic, the reality is that after the panic subsides, and after the immediate emergency vibe in the air passes, we will never return to the way things once were.  We are in a new reality, or as many keep saying, a new normal. […]

Read more

Healthcare Trendsetters

May 18, 2020

COVID-19 has given us a type of Fashion Week within healthcare, where new trends and rising stars emerge unexpectedly, and all at an alarmingly fast pace down the virtual runway. We are seeing work from home take on a whole new significance, which leads to new software platforms rising in popularity, existing applications modified to […]

Read more

Mental Health Assessments

May 11, 2020

We find ourselves months into the trenches of the COVID-19 crisis, and with each new day comes not only a different set of problems but new solutions as well.  As first responders, public safety officers, and the medical community continue to show the need to increase hires within their fields, the process to make those […]

Read more

COVID-19 Long Term Effects

May 4, 2020

We’ve all had to make adjustments to how we work, how we live, and how we interact overall with humanity during the COVID-19 pandemic.  This means that we’ve been stricter in some regard, and more relaxed in others (limiting screen time, who can be bothered?). The government is no exception to this.  We’ve seen some […]

Read more

Resource Guide for HIPAA Compliance & Telehealth Guidelines During COVID-19

May 1, 2020

Is your healthcare organization using telehealth to communicate with patients during this pandemic? Not sure how HIPAA comes into play with these remote communications? Our free Resource Guide for HIPAA Compliance & Telehealth Guidelines During COVID-19 will provide you with the information you need regarding telehealth and the Office for Civil Right’s enforcement discretion during […]

Read more

Redefining Identifiable Data

April 27, 2020

HIPAA provides guidelines to establish the permissible use of an individual’s personal health information (PHI).  Seems pretty straightforward for the most part.  And it was – for the most part.  Until we start to dig a little deeper and look at the resources that are now in play (which were not 20+ years ago when […]

Read more
Click to download the free resource guide for securely operating during the Covid 19 crisis

Resource Guide for Securely Operating During the COVID-19 Crisis

April 22, 2020

Is your healthcare organization operating during the global pandemic, whether in the office or working remotely? Not sure of how to handle HIPAA compliance when using technology to communicate with patients? Worried about the rise in COVID-19 scams and data breaches? We’re here to help! Our free Resource Guide for Securely Operating During the COVID-19 […]

Read more

Free Security Training: Introduction to Working Remotely

April 20, 2020

According to a survey by OpenVPN, 36% of organizations experienced a security incident caused by the actions of a remote employee. Watch this easy-to-understand video and learn how you can take steps to protect yourself, your business, and your loved ones. Watch the Free Training Video

Read more

Community-Based Testing Sites

April 20, 2020

Community-Based Testing & HIPAA Community-Based Testing Sites (CBTS) are the latest entity to be excluded from HIPAA enforcement penalties by the Office for Civil Rights (OCR) for their participation in regard to COVID-19 specimen collection and testing.  This “exercise of enforcement discretion is effective immediately (April 9, 2020), but has a retroactive effect to March […]

Read more

COVID-19 Scams Continue

April 13, 2020

Whether it involves faces masks, hand sanitizer, hospital and medical supplies, or a stimulus check, scams against healthcare organizations and individuals are booming with COVID-19 as the starting point.  Hackers and cybercriminals are looking at the pandemic as a great opportunity to take advantage of unsuspecting businesses and consumers in a variety of ways. The […]

Read more

COVID-19 & First Responders

April 6, 2020

As we continue to make our way through new territory with the COVID-19 crisis, we are having to adjust the rules and regulations that previously stood in place.  HIPAA is no exception to that. The U.S. Department of Health and Human Services Office for Civil Rights (OCR) has continued to update the guidelines under these […]

Read more

Telehealth & COVID-19

March 30, 2020

In recent years there has been an increase in the use of telehealth and remote management tools as options for maintaining patient well-being.  If you’re not familiar with these, the HHS’ Health Resource & Services Administration (HRSA) defines telehealth as “the use of electronic information and telecommunications technologies to support and promote long-distance clinical health […]

Read more

Safely Working Remotely

March 24, 2020

Effective Immediately As the Novel Coronavirus pandemic continues to greatly impact our nation, working from home is no longer an occasional benefit for many Americans, but is now a requirement for many businesses to continue operating safely and effectively. While working from home does come with its perks, there are many new cybersecurity risks created […]

Read more

Interoperability & Information Sharing

March 17, 2020

Recently, the U.S. Department of Health and Human Services put the final approval on two rules that will be transformative in the way that patients can access their health data.  This unprecedented approval will provide safe and secure access to that data via interoperability and information sharing. These rules identify the most extensive healthcare data […]

Read more

HIPAA Right of Access Myths

March 9, 2020

A patient’s right to access their healthcare data so that they can make informed decisions regarding their own health and wellbeing is the component of HIPAA known as the HIPAA Right of Access. Recently, the American Medical Association (AMA) published a new HIPAA playbook for physicians and their practices to better understand this component.  With […]

Read more

Greatest Cybersecurity Threats to Healthcare

March 2, 2020

20/20 Vision in 2020 What lies ahead for the healthcare industry in 2020?  Like patient health, we can’t predict the future accurately, but we know that preventative care can go a long way when we know the risk factors. If you’re in the business of patient care, whether that is through treatment or within a […]

Read more

One Virus, Two Ways

February 24, 2020

How Scammers Are Using the Coronavirus to Trick Their Victims As if the fear of the Coronavirus outbreak weren’t enough to have the world on edge, there’s a new way that the virus is impacting humans: through email cyber-attacks. The method of contamination takes a trusted name, the World Health Organization, and uses it to […]

Read more

Sharing Safely During an Emergency

February 18, 2020

When an emergency situation occurs, like that of the recent Novel Coronavirus (2019-nCoV) outbreak that is said to have originated in mainland China, the healthcare industry is affected worldwide.  From the individual patients all the way up to the largest facilities for patient care, it’s imperative to share knowledge and information, but it MUST be […]

Read more

Healthcare Data Breaches Affected 40 Million Americans in 2019

February 10, 2020

40 Million The US state with the highest population is California.  At the end of 2019, it was 39.56 million.  That’s A LOT of people, right? Yes.  However, according to the recent study published by Fortified Health Security, 40 MILLION Americans were affected by a healthcare data breach in 2019 alone.  That represents an increase […]

Read more

Windows 7 End of Life Creates New Opportunities for Scammers

February 3, 2020

End of Windows 7 They say when one door closes another one opens, but in this case, it’s a window.  On January 14th, 2020, Microsoft ended its support for Windows 7.  Since Microsoft is no longer offering patches or security updates for vulnerabilities identified in Windows 7, hackers have a new way of gaining access […]

Read more

2019 HIPAA Breach Reporting Deadline Approaching

January 28, 2020

2019 HIPAA Breach Reporting Deadline If in 2019 you had a HIPAA breach that affected fewer than 500 individuals, you must report that to the US Department of Health and Human Services (HHS) by Saturday, February 29, 2020. Not sure if you’ve had an incident that requires reporting?  Start by knowing that every breach must […]

Read more

Cybercriminals Now Demanding Ransoms from Patients

January 21, 2020

Imagine this: One day, out of the blue, you receive an unusual communication from an unknown individual warning YOU that they have photos and personal information about you that they are prepared to release if you don’t pay them a ransom. At first, you might chuckle thinking, there is no way this is true. But […]

Read more

Protecting Patients – More Than Meets the Eye

January 13, 2020

Don’t Overlook It When you consider a healthcare organization’s role in protecting patients, it’s easy to look at things from a high-level and miss out on some of the most critical protections an individual needs, expects and is owed. For example, when I think about protecting patients, my mind goes directly to the reason behind […]

Read more

Lost Laptop Leads to New Kind of Accident

January 6, 2020

Fender Bender In Carroll County, Georgia, there was a vehicle accident of an unusual kind recently.  It resulted in the Department of Health & Human Services’ Office for Civil Rights (OCR) slapping a $65,000 fine on West Georgia Ambulance when they were found to have multiple violations of HIPAA rules. It started in February of […]

Read more

Healthcare’s Annual Physical

December 30, 2019

Annual Physical We’ve conducted our end of year physical on the healthcare industry, and while the humans that are cared for have a variety of health issues, there is one that is plaguing the healthcare industry as a whole: cybersecurity. This was not a good year for hospitals and healthcare businesses when it came to […]

Read more

OCR Issues Guidance on Targeted Ransomware

December 23, 2019

We Are All Affected by Bad Cyber Health Pay attention, the health of your business depends on it. Wherever you fall in the food chain of the healthcare industry, cybersecurity needs to be at the forefront of your mind.  That might mean you are a small doctor’s office with a few patients, a large hospital, […]

Read more

Alexa, Increase Time with My Patients

December 17, 2019

Amazon isn’t a company that lets an opportunity go by.  With the awareness of cybersecurity rising every single day, opportunity presents itself in a variety of ways.  Not only do they have a captive consumer audience, but familiarity and reputation allow them to venture into the enterprise field with credibility as well.    With that being said, recently they announced the […]

Read more

Sentara Hospitals Agrees to $2.175 Million Settlement for HIPAA Violations

December 9, 2019

Crazy Eight If only we were talking about a card game.  Unfortunately, for Sentara Hospital, we aren’t.  Instead, we are referring to them receiving the unwanted title of being the eighth recipient of a HIPAA financial penalty in 2019.  This $2.175 million fine is given in conjunction with the requirement to create a corrective action […]

Read more

Ransomware Attack Impacts 100+ Nursing Homes

December 3, 2019

  “Doctor, How Bad Is It?” “I’m not sure, I can’t access your medical records to tell you exactly what the prognosis is.” Recently, this is what Virtual Care Provider had to tell its clients; that the technology services that they were providing were on hacker hiatus.  In other words, they were hit by a […]

Read more

Now Will You Listen?

December 2, 2019

It is likely that we can all recall a moment when we “knew about” something before anyone else.  A band, a trend, a fad.  Then it goes mainstream and you realize the word is out, and when a big name gets on board with promoting the person, place or cause, you find yourself part of […]

Read more

Conducting a Risk Analysis – What You Need to Know

November 25, 2019

You’ve likely heard of a risk analysis. Hopefully, you’ve also performed one for your organization. Whether you’ve been helping your organization work on its HIPAA compliance for years, or you’re new to the world of HIPAA, performing a risk analysis should be a high-priority item on your business’s to-do list. Let’s start with the basics. […]

Read more

Healthcare to Go

November 19, 2019

Isn’t it wonderful how technology has made medical care more accessible?  Not only can medical professionals be mobile and go TO their patients, but patients can now take ownership via apps and devices that allow them to monitor their own well-being.  Apps and devices are now available that give us so much information and access; […]

Read more

Data Breach Costs Texas Health and Human Services Commission $1.6 Million

November 12, 2019

When DADS Don’t Know Best No, we aren’t talking about Father Knows Best here.  We are referencing the Department of Aging and Disability Services (DADS).  In 2017 it was added to the Texas Health and Human Services Commission (HHSC), which is comprised of childcare and nursing facilities, operations of supported living centers, providing mental health […]

Read more

American Cancer Society’s Online Store Hit with Skimming Malware

November 5, 2019

Sick on the Inside The American Cancer Society deals with illness of the human sort, but recently they had to deal with another kind of toxic plague silently taking over.  On the outside, things looked fine.  But on the inside, there was a silent plague. Hidden as analytical code, security experts discovered malware embedded in […]

Read more

OCR Issues $2.15 Million Fine to Jackson Health System

October 29, 2019

HIPAA compliance doesn’t care if you’re a small business or a non-profit.  This isn’t said in a disrespectful manner to the laws that govern the policies, but to make you aware that your business status, or identifying structure won’t allow you to be overlooked. Hefty Fine Imposed Recently the Office for Civil Rights (OCR) at […]

Read more

Importance of a Risk Assessment

October 22, 2019

HIPAA Requirement While it is required within HIPAA rules and regulations to complete a risk assessment regularly, the question may still be in your mind regarding WHY you have to do this. The legal ramifications are obvious.  If audited, you’ll have to show a risk assessment as part of your HIPAA compliance program. And remember, […]

Read more

$85,000 Settlement in OCR’s First HIPAA Right to Access Case

October 14, 2019

HIPAA Enforcement is Happening Enforcement is in action.  That’s what Bayfront Health-St. Petersburg recently learned when they agreed to pay $85,000 in penalties to the Department of Health & Human Services (HHS) Office of Civil Rights for a potential violation of the HIPAA right to access provision. This is the first enforcement by the OCR […]

Read more

Dental Practice’s Response to Yelp Review Leads to $10,000 Fine

October 7, 2019

When it’s YOU in the Review Making dinner plans?  Check online for reviews before you spend your money dining out.  Ready to book a vacation?  You’re definitely making sure the pool is as big as they say it is. How about when it comes to personal care?  Do you check online to see if a […]

Read more

HIPAA Secure Now Joins Far-Reaching Initiative to Promote the Awareness of Online Safety and Privacy for National Cybersecurity Awareness Month

October 1, 2019

October 1, 2019 — HIPAA Secure Now! today announced its commitment to National Cybersecurity Awareness Month (NCSAM), held annually in October, by signing up as a Champion and joining a growing global effort to promote the awareness of online safety and privacy. NCSAM is a collaborative effort among businesses, government agencies, colleges and universities, associations, nonprofit […]

Read more

HIPAA Secure Now Joins Far-Reaching Initiative to Promote the Awareness of Online Safety and Privacy for National Cybersecurity Awareness Month

October 1, 2019

October 1, 2019 — HIPAA Secure Now! today announced its commitment to National Cybersecurity Awareness Month (NCSAM), held annually in October, by signing up as a Champion and joining a growing global effort to promote the awareness of online safety and privacy. NCSAM is a collaborative effort among businesses, government agencies, colleges and universities, associations, nonprofit […]

Read more

Ransomware Chaos in Campbell County

September 30, 2019

Campbell County Chaos Hopefully, you didn’t have a doctor appointment in Campbell County Wyoming recently.  And if you had an emergency situation, perhaps you were not getting the immediate care that you may have hoped for when you showed up at the ER.   It wasn’t the long wait from an overcrowded hospital waiting room, or […]

Read more

Right to Access was Implemented to Protect Patients but is Hurting Patients & Providers Alike (Part 2)

September 23, 2019

We previously published Part 1 of this article on abuses of Patient Right to Access for medical records and how these abuses can overburden healthcare providers and put patient health information at risk. This Part 2 focuses on what healthcare organization can do about the growing problem. The following blog was written for the HIPAA […]

Read more

Right to Access was Implemented to Protect Patients but is Hurting Patients & Providers Alike (Part 1)

September 17, 2019

The following blog was written for the HIPAA Secure Now community by DataFile Technologies, a leading provider of health data management including fast records release services with a 24-hour turn-around time, and an industry-leading accuracy rate over 99.9%. You may have seen an uptick in medical records requests labeled with “HITECH Request” or experienced requestors […]

Read more

Compliance & Cybersecurity Go Hand-In-Hand

September 16, 2019

Humans or HIPAA? When it comes to healthcare organizations addressing the HIPAA compliance of their business, many feel prepared and comfortable, readily checking that “compliant” box. But addressing the human part of security falls by the wayside too often.  Compliance and cybersecurity, which includes human security, both need to be a part of your overall […]

Read more

Does Your Breach Response Plan Include Notification?

September 11, 2019

Remain Calm, Remain Honest – and Remain in Business Avoiding the inevitable does not make it go away. Healthcare patients choose a provider based on the quality of care.  In addition to that, the public will generally assume that their private information is safeguarded and not something that they need to verify or investigate before […]

Read more

Ransomware Hits Hundreds of Dental Offices

September 5, 2019

A Toothache Beyond Repair Hackers have used the very software that hundreds of dentists relied on to run their business, to bring it to their knees.  A ransomware attack is responsible for shutting down computers at roughly 400 dental offices all over the U.S. The Digital Dental Record and Wisconsin-based cloud services provider, PerCSoft collaborated […]

Read more

Repeat Offender

August 27, 2019

It’s a Fact When you search for cyberattacks by vertical, always in the top categories is healthcare.  It can be filtered from there by the size of the business, whether it is enterprise or small to medium-sized establishments, but the information targeted is patient data. Why? Because who knows more personal information about you than […]

Read more

Why We Need to Go Beyond HIPAA

August 20, 2019

HIPAA – Then & Now The Health Insurance Portability and Accountability Act, better known as HIPAA, has been around since 1996, with the intent to protect patients by properly handling their protected health information (PHI). With good intentions, HIPAA set forth to provide both security provisions and data privacy. The legislation was passed in the […]

Read more

Allscripts to Pay $145 Million for Practice Fusion EHR Investigation

August 12, 2019

As many of you know, an Electronic Health Record (EHR) is a digital record of a patient’s paper charts, updated in real-time.  This is an incredible option to have in the world of medicine, where information can be exchanged between doctors as well as business associates. It also provides an incredible benefit to the patient, […]

Read more

Halfway Health Check

August 6, 2019

We’re just passed the midway point of the year and if this were our own health report, we’d be failing miserably when it comes to data breach prevention. According to a recent report from Protenus and Databreaches.net, over 31 million healthcare records were breached in the first six months of 2019.  That is double the […]

Read more

Scrolling Through the Breaches

July 30, 2019

Every day in my newsfeed I’m alerted to yet another compromise to patient information.  The headline isn’t always the attention-grabbing ones that we see when major credit companies or big-box retailers are exposed. These are just listed, one after the other, identifying locations of healthcare businesses, whether it be hospitals or private practice, that have […]

Read more

Make Time for Cybersecurity

July 26, 2019

This isn’t something you can pencil in and get to when you have time, cyber maintenance has to be something you commit to. We all have those moments when we realize that we had the best intentions to stick with something, but its priority fell by the wayside. We start off strong, then taper off […]

Read more

25,000 Patients’ Data Exposed in Email Hack

July 15, 2019

Approximately 25,000 patients are being notified by Adirondack Health that their protected health information (PHI) may have been obtained by a hacker. Vermont-based Adirondack Health is part of the Adirondacks Accountable Care Organization (ACO). Adirondacks ACO analyses health data for the entire region and is made up of all the Adirondack region’s hospitals. The Breach […]

Read more

An Analysis of Cybersecurity Practices in Healthcare

July 9, 2019

A recent report by KLAS and CHIME looked at the cybersecurity practices of healthcare providers based on recent guidance issued on the subject. The results? Although some best practices seem to be on the radars of organizations of all sizes, overall findings suggest that small practices have some work to do. In their white paper, […]

Read more

Hackers Using Social Profiles

July 3, 2019

Facebook Status: Away on Vacation Social media is great for a lot of things.  Sharing photos, reconnecting with old friends, finding like-minded people and groups to share ideas and hobbies.  But when does sharing become oversharing? Hackers gain access to your personal data via your profile and the information you share there – and you […]

Read more

Lawsuit Filed Against the University of Chicago Medical Center and Google over Data Sharing

July 1, 2019

A potential class action lawsuit has been filed against the University of Chicago Medical Center (UChicago Medicine) by a former patient, claiming his and thousands of other patients’ medical records were shared with Google without authorization and without removing identifying information. The suit was filed in the United States District Court for the Northern District […]

Read more

NEO Urology Suffers Ransomware Attack, Pays $75,000 Ransom

June 24, 2019

Cybercriminals continue to flex their muscles on the healthcare industry with ransomware hitting an Ohio medical practice earlier this month. NEO Urology in Boardman, Ohio, suffered a complex ransomware attack, with hackers encrypting the organization’s entire computer system. According to a report from local news agency WFMJ, the attack on NEO Urology occurred on June […]

Read more

Preventing Medical Identity Theft

June 18, 2019

Earlier this month, a data breach affecting Quest Diagnostics, LabCorp, and Opko was announced, stemming from an incident caused by the collections vendor, American Medical Collection Agency (AMCA). Now, the number of individuals who had their medical and personal information compromised by the incident has exceeded 20 million, bringing up major concerns of medical identity […]

Read more

10 Cybersecurity Tips for Small Businesses

June 11, 2019

In 2018, 71% of ransomware attacks targeted small businesses, according to a report by Beazley Breach Response Services. It’s clear that small businesses are a cybercriminals favorite target, yet many remain unprepared to handle a cyber-attack. Is it that small businesses don’t care about cybersecurity? It wouldn’t be fair to make that assumption; however, small […]

Read more

Quest Diagnostics Data Breach Could Impact Nearly 12 Million Patients

June 3, 2019

Quest Diagnostics, one of the country’s largest blood testing providers announced on Monday that nearly 12 million patients may have had their sensitive information compromised in a data breach. The breach occurred at one of Quest’s billing collections vendors, American Medical Collection Agency (AMCA). Quest was notified on May 14, that between August 1, 2018, […]

Read more

$100,000 Settlement Reached for 2015 HIPAA Breach

May 28, 2019

Medical Informatics Engineering, Inc. (MIE), a software and electronic medical records service provider has paid the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services $100,000 to settle a HIPAA breach from 2015. The Indiana-based company reported the data breach to OCR on July 23, 2015, following the discovery that […]

Read more

Ransomware: The Trend That Never Goes out of Style

May 21, 2019

Ransomware is not a new type of cyber-attack. In fact, it’s been around for years, but don’t let its age fool you; ransomware is not “yesterday’s news”. Ransomware is just as alive as ever before, continuing to dominate industries across the globe, and healthcare is not immune from its threat. You may be familiar with […]

Read more

HIPAA Audits 101: Your Compliance State Under Review

May 14, 2019

Hello, HIPAA The Health Insurance Portability and Accountability Act, better know as HIPAA, was passed by Congress in 1996 and called for the protection and confidential handling of protected health information (PHI). HIPAA still exists today, aiming to protect patients and their information, but it’s important to think about how far we’ve come in the […]

Read more

$3 Million Fine Issued for PHI Breach of Over 300,000 Patients

May 7, 2019

The Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) has announced a settlement with Touchstone Medical Imaging (“Touchstone”) for their potential violations of HIPAA Security and Breach Notification Rules. Touchstone has agreed to pay $3,000,000 and adopt a corrective action plan. Touchstone is a diagnostic medical imaging services company based in […]

Read more

Misconfigured Webpage Exposed Patient Data

April 30, 2019

Patient data exposed Inmediata Health Group, Corp., a provider of clearinghouse services, software, and business processing solutions to health plans, hospitals, IPAs, and independent physicians recently announced a security incident affecting some customer data. The incident was discovered in January 2019 when Inmediata found a misconfigured webpage was allowing some electronic health information to be […]

Read more

Metrocare Services Discloses Second PHI Breach in 5 Months

April 23, 2019

Metrocare Services, a mental health service provider in North Texas, has notified the Department of Health & Human Services (HHS) of a data breach affecting 5,290 patients. The Breach Discovery The breach was the result of a phishing attack and was discovered on February 6, 2019, when Metrocare found that an unauthorized third-party accessed some […]

Read more

Business Email Compromise Incidents up 133%

April 16, 2019

Business email compromises (BEC) scams made a big statement in 2018, seeing a 133% increase over 2017, according to a recent report by Beazley Breach Response Services. The Beazley Breach Briefing looked at information gathered from investigations into more than 3,300 data incidents that were reported to Beazley in 2018. The investigations revealed that nearly […]

Read more

Lost Files: The Beginning of the Problems

April 10, 2019

We previously wrote an article about the ransomware attack striking a Michigan doctor’s office, leaving their patients with no medical records and leading the practice to closure. This article is intended to provide professional insight into the liability of the practice despite its decision to close its doors. The following blog was written by Matthew […]

Read more

Ransomware Attack Shuts down Michigan Practice – Deletes All Patient Files

April 9, 2019

  A doctor’s office in Battle Creek, Michigan is closing its doors following a ransomware attack that left them with no other option – besides pay up. The Demand and the Decision Dr. William Scalf told a local news outlet, WWMT West Michigan, that hackers locked the files at Brookside ENT and Hearing Center, demanding […]

Read more

Tax Refund Scams – Know What to Look For

April 5, 2019

Tis the season!  You’re making mental plans with what is hopefully a generous tax refund and deciding what to do with the surplus of cash you’ll soon have on hand. Along the way from starting to submitting the paperwork, there are quite a few roadblocks to be aware of.  Even if you aren’t getting a […]

Read more

Ransomware Dominated Healthcare and Small Businesses in 2018

April 2, 2019

Ransomware wreaked havoc on businesses across the globe throughout 2018 with no signs of slowing down. Which sector was hit the hardest? A recent report from Beazley Breach Response Services found that the healthcare industry suffered from the most ransomware attacks last year. Why was healthcare the hardest hit? Healthcare data is valuable, and hackers […]

Read more

Study Finds Healthcare Sector Uniquely Susceptible to Phishing Attacks

March 26, 2019

Is the healthcare sector uniquely vulnerable to phishing attacks? A recent report published in the Journal of the American Medical Association says yes, with research to back that claim. A team of researchers led by William Gordon, MD of Harvard Medical School and Boston’s Brigham and Women’s Hospital set out to answer the question, “Are […]

Read more

How to Create an Incident Response Plan

March 20, 2019

Data breaches are extremely common as technology continues to advance. Of those breaches, small and medium-sized businesses (SMBs) are a favored target for cybercriminals. In fact, more than 70% of attacks target small businesses, according to the National Cyber Security Alliance, and as many as 60% of hacked SMBs go out of business following a […]

Read more

7,038 Patients of Pawnee County Memorial Hospital Notified of Phishing Attack

March 18, 2019

Pawnee County Memorial Hospital (PCMH) in Pawnee City, Nebraska has notified 7,038 patients that a hacker may have accessed some of their protected health information. The incident was discovered on November 29, 2018, when PCMH learned that their business e-mail system was compromised by a malware virus. A forensic computer investigator was hired immediately following […]

Read more

Fake Check Scam

March 13, 2019

Being scammed can happen so easily today, but when you make it about a topic that many people can let their guard down with, the scam can happen much easier.  What topic is that? We’re talking about money. Fake check scams have been around for quite some time, however, with the increase in online sales […]

Read more

Third-Party Vendor Causes Breach Impacting 45,000 Patients

March 11, 2019

Rush University Medical Center is feeling the impact of a breach they themselves did not cause. A third-party vendor is responsible for compromised personal information of 45,000 patients of Rush Medical. The breach was caused by an employee of the claims processing vendor when they inappropriately shared a patient file with an unauthorized individual. Rush […]

Read more

Nearly 974,000 UW Medicine Patients’ Medical Records Exposed

March 4, 2019

The University of Washington Medicine is notifying approximately 974,000 patients of a data breach that occurred in December, which left some of the patients’ information exposed on the Internet. The breach occurred over a 3-week period and was determined to be the result of a misconfigured server. The database was used to track the sharing […]

Read more

When a Healthcare Breach Lands You on the Wall of Shame

February 25, 2019

Healthcare breaches are incredibly difficult for organizations to deal with. Repercussions of a data breach vary greatly depending on what caused the breach to begin with. For example, there’s the struggle of getting your organization back up and running, determining the cause of the breach, notifying patients, taking corrective action, reporting the breach, potentially finding […]

Read more

Research Suggests Employees Remain the Weak Links in Security

February 22, 2019

We’ve known that employees are the weak link in security. In fact, we have been cautioning organizations for quite some time regarding the risks their employees pose when not properly trained. Despite heightened awareness of these risks, recent research from Microsoft suggests that employees remain the weak link, posing huge risks to their organizations. A […]

Read more

Sextortion Scam

February 22, 2019

You get an email or text from what seems to be a legitimate email or phone number.  Then you read the message: “Send bitcoin right away or else I am sending compromising photos or information to your friends and family.” If you’ve received this type of email, you’ve likely been a victim to a new […]

Read more

Performing a Security Risk Assessment Offers Value Beyond Compliance

February 12, 2019

As the digital ecosystem continues to thrive and advance, so too must the regulations and practices for safely caring for sensitive data. That is especially true for the healthcare industry, which continues to be a prime target for cybercriminals. Healthcare practices need to appropriately safeguard electronic protected health information in compliance with the Health Insurance […]

Read more

Mystery Shopper Scams

February 6, 2019

Today, many people are working more than one job, and with the flexible options of contractor work, or work as needed opportunities, you can likely find something that fits your schedule and financial needs.  Maybe you are looking for a little bit of extra work to make ends meet, or a way to save up […]

Read more

Ransomware Attack on CT Optometry Office Raises Tax Fraud Concerns

February 5, 2019

Ransomware Attack on CT Optometry Office Raises Tax Fraud Concerns Cybercriminals target businesses of all industries and sizes, however, it seems as though their sights are set more on small and medium-sized businesses than large corporations. While there are many factors that may influence the shift of attention to small businesses, one explanation stands out, […]

Read more

HHS Cybersecurity Guidelines: The 6 Simple Steps That Will Mitigate The Top 5 Threats To Healthcare

February 1, 2019

Every day it seems there’s another ransomware attack in the healthcare sector. What’s worse is that these types of cyber-attacks are expected to continue to increase. Why do cybercriminals target this industry so heavily? – Their victims pay the ransom because healthcare practices can’t afford a business interruption – Large numbers of outdated systems make […]

Read more

Email Hack Leads to Valley Hope Association Breach of Patient Data

January 28, 2019

Valley Hope Association (VHA), a Kansas-based addiction treatment organization with 16 facilities in seven Midwest states has started notifying patients that their information may have been compromised in a data breach. After officials found suspicious activity on an employee’s email account in October, an investigation was launched. VHA hired a forensics team to uncover details […]

Read more

Ransomware Is Alive and Well – Here Are 10 Tips to Help Protect Your Organization

January 22, 2019

  Remember ransomware, the malicious software that blocks computer access until a ransom demand is paid? The threat was huge and dominated headlines in the past but seems to have slowed down in recent months. Could the decline in publications citing ransomware as the cause of a data breach or loss of data indicate that […]

Read more

5 Tips for Protecting Your Electronic Health Records

January 15, 2019

As the value of healthcare data remains high, there is no denying that healthcare organizations make prime targets for cybercriminals. To wreak havoc and make a profit from compromised patient data, cybercriminals exploit weak spots in healthcare organizations, whether that be a loophole in the security of the server, poorly trained employees, or a variety […]

Read more

VUMC Uses Multi-Factor Authentication to Combat Phishing Attacks

November 26, 2018

Educating employees on security awareness and the dangers posed by cybercriminals is critical to any organization. While you can train employees on what to look for and how to best protect your practice, cybercriminals will continue to find unique and more sophisticated ways to trick individuals and gain access to the sensitive data they’re trying […]

Read more

Why Physicians Need Improved Cybersecurity Education

November 6, 2018

A recent survey conducted by the American Medical Association (AMA) and the consulting firm Accenture surveyed 1,300 U.S. physicians to find out about their experiences and attitudes towards cybersecurity. Unsettling findings in the survey revealed a lack of cybersecurity education among physicians. The five key findings of the survey as reported by the AMA and […]

Read more

Avoiding Android Malware

November 1, 2018

[tvideo type=”vimeo” clip_id=”299922099″]

Read more

Why Your Employees Break the Rules

October 30, 2018

It’s no secret that employees violate security policies. Whether we’d like to admit it or not, there’s a good chance we have all violated a security policy once upon a time. Sometimes, employees violate policies to save time or make their job easier, and sometimes, they don’t even know they’re doing it. How do you […]

Read more

Phishing Attack Leaves 37K Gold Coast Health Plan Members’ PHI at Risk

October 22, 2018

On October 5, California-based Gold Coast Health Plan (GCHP) informed the Office for Civil Rights (OCR) that a phishing attack may have exposed the protected health information of 37,005 plan members. The attack occurred when hackers successfully tricked a GCHP employee with a phishing email, which allowed the hackers access to that employee’s email account […]

Read more

Why Hackers Target Healthcare

October 16, 2018

Cybercriminals have been targeting the healthcare industry for years.  As healthcare has become the second largest sector of the U.S. economy, it should come as no surprise that the industry receives special attention from hackers. Aside from its size, what else accounts for the indisputable interest cybercriminals have in exploiting healthcare? Hackers Set Sights on […]

Read more

Business Email Compromise Scams – Here to Stay

October 2, 2018

Business email compromise (BEC) scams remain one of the most widely used attack vectors among cybercriminals to date. In fact, cybercriminals are finding so much success in exploiting human vulnerabilities through BEC scams that their frequencies have been dramatically increasing. What is a BEC scam? In a BEC scam, the attacker gains access to an […]

Read more

Backup Your Data

October 1, 2018

[tvideo type=”vimeo” clip_id=”292763261″]

Read more

HIPAA Violations During ‘Boston Med’ Filming Leave Three Boston Hospitals with $999,000 in Fines

September 24, 2018

On September 20, the Department of Health and Human Services’ Office for Civil Rights announced a fine of $999,000 for three Boston hospitals, all of which violated HIPAA while allowing ABC’s TV series “Boston Med” to film the show in their facilities. Boston Medical Center (BMC), Brigham and Women’s Hospital (BWH), and Massachusetts General Hospital […]

Read more

Breached Records to Skyrocket with SMBs as the Biggest Targets

September 17, 2018

A lot can happen in 5 years, and unfortunately, not always for the better. According to a recent report by Juniper Research, Cybercrime & the Internet of Threats 2018, data breaches are expected to reach 146 billion records over the next five years. For cybercriminals to successfully compromise such an extreme number of records, significant […]

Read more

51% of SMB Leaders Think Their Business Isn’t a Target for Cybercriminals

September 7, 2018

Small businesses are often thought to be a forgotten entity when it comes to cybercrime. On the surface, it seems like a fair assumption that hackers wouldn’t target small businesses when there are large enterprises with much greater assets. Unfortunately, many small business leaders fall for this “I’m not a target” mentality, when in fact, […]

Read more

HIPAA and MACRA/MIPS 2018 – What You Need to Know

September 4, 2018

As we move into the second half of the year, many practices and physicians are starting to consider the data they will need to submit under the MACRA/MIPS program.  The MACRA/MIPS rules change slightly every year, and this year is no exception.  Even though the rules have been adjusted, a basic requirement remains in place:  […]

Read more

Appropriate Electronic Disposal

September 1, 2018

[tvideo type=”vimeo” clip_id=”288217944″]

Read more

Missouri-Based Practice Suffers Breach of Nearly 45,000 Patient Records

August 27, 2018

Despite reports that the healthcare sector is seeing fewer ransomware attacks this year than years prior, that doesn’t mean they don’t still exist. Unfortunately, for Missouri-based Blue Springs Family Care, that lesson was learned the hard way after suffering a breach of 44,979 patient records resulting from a ransomware attack. Cass-Regional Medical Center, also based […]

Read more

Healthcare Data Breaches Rise Along with Consumer Concerns of Privacy and Data Security

August 20, 2018

A recent survey conducted by the health insurance company Aetna revealed some significant results as to what consumers consider to be their most important concern in terms of healthcare. According to the survey of 1,000 consumers, concerns of patient privacy and data security are more important than the cost of care. 80% of survey respondents […]

Read more

The Psychology of Falling for a Phishing Email

August 9, 2018

Phishing is a cybercrime that has been around for many years, where targets are sent malicious emails claiming to be from a legitimate individual or organization to trick them into disclosing their sensitive information. Phishing emails remain a major threat today, however despite increased awareness of the cybercrime, cybercriminals continue to fool their targets into […]

Read more

Healthcare Data Security: Less of a Concern for U.S. Adults than Threats to Financial Information

August 6, 2018

Our healthcare data holds a multitude of sensitive information regarding our personal lives. That information could include our full name, date of birth, home address, health history, diagnoses, and test results to name a few pieces of information. While we know the data contained in our healthcare records is quite extensive, less than half of […]

Read more

Use Caution with USB Drives

August 1, 2018

[tvideo type=”vimeo” clip_id=”282716076″]

Read more

$150K Proposed Settlement for Victims of 2014 Flowers Hospital Data Breach

July 31, 2018

The end may now be in sight for a four-year-long legal battle for individuals affected by a 2014 healthcare data breach. While the settlement has not yet received final court approval, the tentative settlement of the class-action lawsuit could provide more than 1,200 affected individuals of the 2014 Flowers Hospital data breach up to $150,000 […]

Read more

Exactis Database Leaks 340 Million Records of Personal Data

July 16, 2018

There is a good chance you’ve never heard of the major marketing and data aggregation company Exactis, but that doesn’t mean they don’t know you. In fact, Exactis may know a great deal of your personal information, including your email address, your home address, your habits and hobbies, your children’s ages and genders if you […]

Read more

7 Password Tips

June 28, 2018

[tvideo type=”vimeo” clip_id=”277471559″]

Read more

Password Reuse: A Common Practice for 25% of Employees

June 25, 2018

  Risky cyber behavior among employees is nothing new, in fact, despite organizations becoming more aware of the state of cybersecurity, employees continue to cause data breaches in unacceptable numbers. TechRepublic looks at a recent OpenVPN survey, which dissects poor cyber hygiene among employees. Despite an increased focus on security training, 25% of the 500 […]

Read more

HIPAA Security Tips and Reminders – Phishing Sites

June 25, 2018

Security Tips: Phishing Sites Click on  above to view in fullscreen mode!

Read more

Security Awareness Training – Time to Jump on the Bandwagon

June 10, 2018

Human-error; we talk about it all the time, but what exactly do we mean? Human-error occurs when an individual performs a task or does something with an unintended outcome. It’s easy to point the finger at employee’s as being an organization’s weakest link, but without appropriate security awareness training provided by the employer, how can […]

Read more

SMS Phishing Scam for Email Accounts

June 8, 2018

[tvideo type=”youtube” clip_id=”_dj_90TnVbo” rel=”false” showinfo=”false”]

Read more

HHS’ OCR proposes HIPAA change to share settlements of data breaches with victims

May 29, 2018

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) is planning to issue an advance notice of proposed rulemaking this November that could be a major game changer for HIPAA breach settlements. According to the Data Protection Report, the OCR plans to get the public’s input on a policy change […]

Read more

Insiders to Blame for Poor Cybersecurity in Healthcare

May 21, 2018

It comes as no surprise that the healthcare industry is a prime target for cybercriminals. Since it’s easy to recognize the potential profit in stealing Protected Health Information (PHI), it is crucial to know and understand the potential security threats that exist, including threats from the inside. Verizon found in their 2018 Protected Health Information […]

Read more

FTC: Five Ways to Help Protect Your Identity

May 16, 2018

[tvideo type=”youtube” clip_id=”lp_8cvNm_vE”]

Read more

Two San Francisco Hospitals Suffer Breach of Patient Data

May 14, 2018

According to the San Francisco Public Health Department, nearly 900 patients at two San Francisco hospitals had their personal information breached. On Friday, the Department stated that the breach occurred at San Francisco General and Laguna Honda hospitals when a former employee of one of the hospitals’ vendors gained unauthorized accessed the patient data. An […]

Read more

Learn more about the impact of ransomware

May 1, 2018

[tvideo type=”youtube” clip_id=”X08wgodFgXw” width=”600″ rel=”false”]

Read more

HIPAA Security Tips and Reminders – Public WiFi Networks

May 1, 2018

Security Tips: Public WiFi Networks The FTC has some good tips on securing confidential information, including patient information, when using Public WiFi Networks.

Read more

OCR Cyber Security Newsletter: Risk Analyses vs. Gap Analyses – What is the difference?

April 30, 2018

April 2018 OCR Cyber Security Newsletter Risk Analyses vs. Gap Analyses – What is the difference? The Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security and Breach Notification Rules require covered entities and their business associates to safeguard electronic protected health information (ePHI) through reasonable and appropriate security measures. One of these measures required […]

Read more

Mitigating Insider Threats in Healthcare

April 30, 2018

It is no secret that healthcare data breaches are on the rise. While we often hear about hackers targeting the healthcare industry, you may be surprised to learn that more healthcare data breaches are caused by insiders than hackers! In their recent Protected Health Information Data Breach Report, Verizon has found that 58% of all […]

Read more

Why SMEs and SMBs Fail After A Cyberattack

April 23, 2018

Malicious cyberattacks are increasing every day around the globe. In fact, cyber-incidents nearly doubled from 82,000 incidents in 2016, to 159,700 in 2017. While the media often depicts large corporations as the primary target for cyberattacks, small business are just as likely – if not more likely to be targeted. An article on CSO looks […]

Read more

Effective Security Training Requires Change in Employee Behavior

April 16, 2018

  Many organizations spend countless hours and resources on training their employees, only to find that their business has suffered a data breach caused by human error. Despite the quality and frequency of a security awareness training program, if employees are not engaged in training or feeling a sense of motivation to protect their organization, […]

Read more

You Received a Letter from OCR, Now What?

March 30, 2018

This article was written by Matt Fisher and originally appeared on the Mirick O’Connell Health Law Blog.  It is published here with permission. At some point in time most group practices, hospitals or other provider organizations will receive a letter from the Office for Civil Rights (“OCR”). The letter will state that OCR received a […]

Read more

Federal Trade Commission Warns of Fake Invoice Phishing Scams

March 26, 2018

Phishing has become a common threat faced by organizations in today’s digital era.  While cybercriminals are enhancing their tactics to make their attempts seem more legitimate, they continue to recycle old scams, making only minor changes to trick their victims. An old phishing attempt has recently started resurfacing where scammers pose as a well-known tech […]

Read more

FBI Warns Small Businesses to Beware of Cybercriminals

March 19, 2018

It is no secret that the Internet has become a key component of our daily lives for personal and business use alike. Unfortunately, the dependency of the Internet in today’s culture has become quite clear to cybercriminals, making security an incredibly important concern, especially for small businesses. An article on Homeland Security Today explores the […]

Read more

What can PHI be used for?

March 6, 2018

Read more

OCR February 2018 Cybersecurity Newsletter: Phishing

March 1, 2018

In the February OCR Cybersecurity Newsletter, they give very good information on Phishing and how to avoid being a victim.  The newsletter is reprinted below:   February 2018 Cybersecurity Newsletter Phishing Phishing is a type of cyber-attack used to trick individuals into divulging sensitive information via electronic communication by impersonating a trustworthy source. For example, […]

Read more

How Does the Dark Web Impact Small Businesses?

February 28, 2018

Identity theft is an unfortunate occurrence that is all too familiar with most business owners, but do those individuals know where the compromised data will end up? Often, these business owners are unaware of the virtual marketplace where stolen data is purchased and sold by cybercriminals; a place known as the “Dark Web”.  An article […]

Read more

The Human Factor – The Weakest Link In Data Protection

February 26, 2018

Click for full image

Read more

How Will Your Employees Get You Hacked?

February 15, 2018

Breaches are becoming increasingly common as cybercriminals continue to advance their skills and tactics to trick their victims into falling for their scams. While cybercriminals are remaining diligent in their efforts to carry out their attacks, small business owners continue to underspend on cybersecurity. An article on Entrepreneur looks at 5 things your employees are […]

Read more

Affiliated Covered Entities

February 13, 2018

Matthew Fisher, ESQ and Jonathan Krasner Healthcare represents a very large segment of our economy – approaching 20% by some estimates.  As such, healthcare organizations come in many sizes and flavors.  We are all, hopefully, familiar with the basics that HIPAA compliance requirements apply Covered Entities, Business Associates and subcontractors.  A CE and a BA […]

Read more

What is Your Personal Information Worth on the Dark Web?

February 8, 2018

The dark web is often known for the illegal activities conducted there, and while not everything on the dark web is illegal, it’s most appealing factor is its anonymity. The dark web is often a place where stolen data and personal information is bought and sold following a data breach or hacking incident. An article […]

Read more

Mapping Base-EHR to MIPS ACI-Base-Score: 5 Things You Need to Know

February 4, 2018

This is a guest post by Pawan Jindal of MyMIPSScore and originally appeared at the MyMIPSScore Blog Under MACRA, Advancing Care Information(ACI) category of MIPS replaced Meaningful Use. As we discussed briefly in the 10 step overview of MIPS, ACI scoring under MIPS is determined based on the provider’s performance for a set of base […]

Read more

Ransomware Wreaks Havoc in 2017

January 29, 2018

Ransomware dominated the healthcare industry in 2017, with six of the top ten breaches reported to the U.S. Department of Health and Human Services a direct result of the malicious software. An article on Security Current looks at some ransomware attacks from 2017 as well as steps you can take to help avoid becoming a […]

Read more

Allscripts Suffers Ransomware Attack: Recovery Underway

January 22, 2018

  Billion-dollar electronic health record (EHR) company Allscripts has fallen victim to a ransomware attack, which began on Thursday, January 18 around 2:00 a.m. EST. By 6:00 a.m. EST, the ransomware attack was full-blown requiring Microsoft and Cisco’s incident response teams to be called upon for assistance. An article on CSO explores the attack which […]

Read more

Analysis of 2017 Health Data Breaches

January 8, 2018

While you might expect that the number of mega-breaches in 2017 would surpass all previous years, the numbers may take you by surprise. In fact, 2017 saw a drop in the number of individuals affected by healthcare breaches. An article on Bank Info Security provides an analysis on 2017’s health data breaches and the outlook […]

Read more

Employee training crucial this holiday season

December 13, 2017

Employee training crucial this holiday season American small businesses know the holiday shopping season is a vital time to make one final push to meet sales goals for the year. With an increase in retail sales, it is crucial that businesses, especially startups, have a robust cybersecurity plan in place to protect themselves and their […]

Read more

Make sure to make available patient records on a timely basis

December 11, 2017

HIPAA is often described as dealing with CIA – the Confidentiality, Integrity and Access to patient records. In the past, access to patient records often required a written request, accompanied by a response in the mail that could take several weeks. However, in today’s world where electronic systems can provide almost instant action to data, […]

Read more

HIPAA Secure Now! Chosen as Preferred Vendor for 2,700 YMCAs Across the United States

December 4, 2017

MORRISTOWN, N.J. (PRWEB) DECEMBER 04, 2017 YMCA of the USA (Y-USA), the national resource office for 2,700 YMCAs (“Ys”), has selected HIPAA Secure Now! (HSN) as a preferred provider of HIPAA compliance and cyber security services to local Ys nationwide. HSN will help ensure that protected health information (PHI) for thousands of participants in the […]

Read more

HIPAA Secure Now! Joins Forces with MyMipsScore to Aid Physicians in Raising MIPS Scores and Medicare Reimbursements

December 1, 2017

MORRISTOWN, NJ (PRWEB) NOVEMBER 27, 2017 HIPAA Secure Now! (HSN) and MyMipsScore™ (MMS) are joining forces in a new partnership designed to give healthcare providers a competitive advantage as they adapt to the requirements of MIPS – the Merit-based Incentive Payment System – which determines Medicare reimbursements using value-based care criteria rather than the traditional fee-for-service […]

Read more

Tips for securing ePHI on mobile devices

November 13, 2017

While mobile devices play a major role in how we stay connected to the world in our personal lives, they are also becoming increasingly popular in our work environments. Not only are mobile devices such as smartphones, tablets and laptops convenient in the workplace, but they can also help increase productivity. In its October cybersecurity […]

Read more

Avoiding MIPS Penalty: There’s an App for That!

October 31, 2017

This is a guest post by Pawan Jindal of MyMIPSScore and originally appeared at the MyMIPSScore Blog In our last blog we discussed an overview of MIPS submission process. As promised, we are very excited today to announce the availability of a new feature of MyMipsScore that will allow you to avoid the MIPS penalty for free. […]

Read more

The weakest link in cybersecurity

October 30, 2017

By now I’m sure you’ve heard that when it comes to information security, employees are the weakest link. Organizations often emphasize that despite any security measures they put in place to protect their infrastructure, all it takes is one employee who is not following the rules to undo all of that. An article on TechRepubic […]

Read more

MIPS Submissions: It’s NOT Complicated

October 26, 2017

This is a guest post by Pawan Jindal of MyMIPSScore and originally appeared at the MyMIPSScore Blog It is hard to believe that we are already in the last quarter of 2017. Even as the first year of MIPS winds down, complaints about how complicated MIPS is, continue to dominate the news. Over the past nine […]

Read more

Security risks can be a MIPS score killer

October 23, 2017

Prolonging the process of figuring out quality measures under the Medicare Access and CHIP Reauthorization Act of 2015 (MACRA) and increasing scores for the Merit-Based Incentive Payment System (MIPS) could put medical practices at a competitive disadvantage. Healthcare providers will earn a MIPS score each year, starting in 2019 (based on 2017 performance).  According to Jim Tate, president […]

Read more

Fall prevention strategies apply to anti-phishing efforts

October 16, 2017

Patient falls have been a serious problem in hospitals and other healthcare facilities for years. In fact, in January 2013 the Agency for Healthcare Research and Quality set out to help reduce the number of falls in healthcare facilities by commissioning a RAND Corporation/ Boston University School of Public Health Report. The report, titled “Preventing […]

Read more

Study finds cybercriminals favor small businesses

October 2, 2017

As ransomware continues to grow, so do the millions of dollars businesses are dishing out to cybercriminals in hopes of regaining control of their sensitive data.  An article on Fox Business looks at a study released by data security solutions firm Datto to see how ransomware is affecting small-to-mid-sized businesses. According to the study, in […]

Read more

5 ways a hacker may target your small business

September 25, 2017

Cyberattacks only happen to large corporations because they hold the most personal and sensitive data, right? Wrong. While the media often leads us to believe cyberattacks are only occurring on high-profile organizations holding a lot of data, the statistics show us otherwise. An article on Information Security Buzz takes a look at 5 ways hackers […]

Read more

Engage Users in Cybersecurity Training

September 11, 2017

As you may know, successful cyberattacks often come as a result of human error, but did you know those errors are often made by employees who have already been through training? An article on Healthcare IT News takes a look at what methods help cybersecurity training stick. Cybercriminals direct their attacks on untrained employees or […]

Read more

“Human Factor” to Blame for Increase in Ransomware Attacks

August 27, 2017

Cybersecurity company Malwarebytes recently released findings from their Second Annual State of Ransomware Report, which provides us with some important insight on today’s state of digital security. An article on CNET highlights findings from the report. According to the report, one-third of SMBs (small-to-medium-sized businesses) were hit by ransomware in the last year. For the […]

Read more

Study finds that 30% of SMEs lack an incident response plan

August 24, 2017

Cybersecurity issues have become very prevalent in the modern era, making headlines with their disasters and fines associated with them. While it may seem obvious that businesses should take precautions to protect themselves against these potential attacks, they have been slow to move forward with improving their security measures – especially small and medium-sized enterprises […]

Read more

OCR deputy discusses common mistakes that often lead to compliance reviews

August 21, 2017

  Have you ever wondered what exactly triggers a breach case investigated by Health and Human Services? While a number of things may attribute to an investigation, according to Deven McGraw, deputy director for health information privacy at the HHS Office for Civil Rights, nearly every breach case investigated by the department stems from a […]

Read more

Article: What Happens When Your Small Business Is Hacked

August 13, 2017

As cyber-attacks continue to sweep across the globe, the pressure is also increasing for IT providers and security professionals to keep security measures a top priority. An article on Entrepreneur explores the consequences of falling victim to a data breach and ways to prepare for one in the event it were to occur.  While you […]

Read more

56% of healthcare organizations see employees as their greatest threat to IT security

August 4, 2017

A recent survey conducted by Netwrix found that although healthcare organizations understand the importance of protecting patient information, they often fall short on improving their security measures. An article on PR Newswire explores the findings of the Netwrix survey. The survey included responses from IT professionals across various industries, including healthcare. Where are healthcare organizations […]

Read more

Cyberattack Costs New York Hospital Nearly $10 million

July 30, 2017

Erie County Medical Center in New York fell victim to a ransomware attack in April, leaving the hospital with the decision to pay the ransom and potentially recover their data or lose their encrypted files to a cybercriminal. The cyberattack, which took down over 6,000 computers had a ransom demand of $30,000 dollars (24 bitcoins […]

Read more

New Strain of Ransomware Hits Michigan Hospital

July 19, 2017

A hospital in Michigan is feeling the pressure after suffering a ransomware attack earlier this month. On July 5th, Caro Community Hospital, Caro Medical Clinic and Caro Quick Care lost access to their phones, email services and patient records as a result of the ransomware attack. According to CEO Marc Augsburger, the ransom note accompanying […]

Read more

Data breaches happen to both small and large businesses

July 17, 2017

It is no secret that despite increased awareness of data breaches around the globe, businesses continue to fall victim to cybercriminals exploiting their weak security measures. An article on Small Business Computing explores data breaches and how the size of the business doesn’t matter to criminals seeking confidential information. Large corporations are often thought to […]

Read more

Cyberattack Forces West Virginia Hospital to Scrap Its Computer Systems

July 11, 2017

  As another detrimental cyberattack, coined NotPetya, wreaks havoc across the globe, organizations are hoping their security measures are enough to keep them from falling victim. Unfortunately for Princeton Community Hospital in West Virginia, their security measures were not enough, resulting in NotPetya destroying their entire computer network. An article on Fox Business explains the […]

Read more

Should healthcare organizations be incentivized to adopt cybersecurity?

June 29, 2017

It is no secret that healthcare organizations underfund their defense efforts when it comes to protecting patient data. Even though personal health information is very valuable to cybercriminals and can even generate more revenue on the black market than financial information, healthcare organizations continue to take a lax approach in their cybersecurity practices. Last week […]

Read more

Article: Former Durango Family Medicine patients warned of security breach

June 26, 2017

While convenient, portable devices come with a great deal of risk. No organization wants to imagine their portable devices getting lost or stolen, however it happens.  If appropriate safeguards are not in place to protect those devices, a serious breach could occur. Unfortunately for Durango Family Medicine, this nightmare came true when a portable external […]

Read more

Google to remove ePHI from its Search Results

June 25, 2017

  HIPAA data breaches can occur if ePHI (electronic protected health information) is posted on an open web site.  In that situation, not only is the ePHI available for viewing, it also can be indexed by an Internet search engine such as Google.  Many data breaches have been uncovered by finding the unauthorized ePHI via […]

Read more

Healthcare Seen Highly Vulnerable to Cyberattack

June 9, 2017

In a recent report conducted by the American International Group (AIG), experts were asked a broad, but valid question; “is cyber risk systematic?” Looking at recent events, AIG indicated that cyber risk is in fact systemic, predicting an event much like the global ransomware attack, “WannaCry” that took the world by storm earlier this month. […]

Read more

Global Ransomware Attacks Target Healthcare Organizations

May 16, 2017

As you may be aware, a global ransomware attack, called WannaCry, started on Friday May 12, 2017 and is continuing as of today. The attack has affected 200,000 Microsoft Windows based machines in over 150 countries. The cybercriminals have focused on healthcare and financial services but have affected many other industries and individuals as well. […]

Read more

75% of health organizations fall below cybersecurity poverty line

May 12, 2017

George DeCesare, Chief Technology Risk Officer for Kaiser Permanente, met with the Health and Human Services Department as well as other security experts and came away with some shocking truth. An article on Healthcare IT News provides some great insight on why falling below the cybersecurity poverty line could be detrimental to health organizations. Seventy-five […]

Read more

$31,000 fine for not having a Business Associate Agreement

May 8, 2017

The Center for Children’s Digestive Health (CCDH) a small, for-profit practice has agreed to implement a corrective action plan for their potential violations of the Health Insurance Portability Accountability Act of 1996 (HIPAA) Privacy Rule. According to the U.S. Department of Health and Human Services (HHS), the settlement includes a hefty payment of $31,000 for […]

Read more

Article: 68 percent of healthcare organizations have compromised email credentials

May 1, 2017

A study from the cloud services provider, Evolve IP suggests that over two-thirds of all healthcare organizations have employees using compromised email credentials. An article over on Healthcare IT News explains how Evolve IP determined these findings. The study found that 55 to 80 percent of organizations have email accounts that have been compromised. Looking […]

Read more

Article: How healthcare organizations should prepare for a HIPAA audit

April 27, 2017

Preparing for a HIPAA audit is vital for healthcare organizations. Sure, these organizations understand that they may face a HIPAA audit, but often let preparation for such an event fall to the bottom of their priority list. It is important to ensure your organization is prepared prior to receiving notification of a forthcoming audit.  An […]

Read more

Even Non-Profits can get HIPAA Fines

April 19, 2017

Federally Qualified Health Centers (FQHCs), Community Health Centers (CHCs) and related entities are non-profit organizations that run on shoestring budgets.  These organizations are constantly in search of revenue, grants and donations to keep their operations running.  Therefore, any type of adverse financial event will be devastating.  However, these organizations also must comply with relevant regulations, […]

Read more

Ransomware Attack Hits Pediatric Practice

April 18, 2017

ABCD Pediatrics, a Texas based pediatric practice has recently reported a major data breach, which came as the result of a ransomware attack occurring in early February.  An article on Gov Info Security explores the attack, looking closely at what made it a reportable incident. According to the practice, an employee discovered a virus had […]

Read more

Large data breaches happening at U.S. Hospitals

April 13, 2017

When you think of being a patient in the hospital, the last thing you may think about is the safety of your personal data. According to research findings by Michigan State University, the security of your personal information in U.S. hospitals is something to be concerned over. An article on UPI explores the study, showing […]

Read more

Ransomware ‘Philadelphia’ Discovered Targeting Healthcare Industry

April 12, 2017

According to researchers, a new variant of ransomware has stepped onto the scene, choosing the healthcare industry as its target. Researchers from the security firm Forcepoint have discovered the ransomware, which has been name Philadelphia. An article over on Healthcare IT News explores how the newly discovered virus works. Philadelphia can be purchased by amateur […]

Read more

Americans receive mixed results in cybersecurity IQ

April 10, 2017

While it is true that Americans are becoming more aware of the need to protect their information online through methods such as utilizing strong passwords or being conscious of how they’re using public Wi-Fi, many still lack in key areas which could cause significant data breaches. Things like recognizing “phishing” emails or determining if a […]

Read more

TV Show – Chicago Med a Ransomware Victim

April 6, 2017

You know ransomware is a real threat when it starts showing up on TV shows. Chicago Med is a victim of a ransomware attack on the hospital. It is time to be concerned in real life!         [tvideo type=”youtube” clip_id=”LOQfWaKOSnU”]  

Read more

5 Tips for Staying #HIPAA Compliant on Social Media

April 5, 2017

Social media has become an incredibly valuable tool, whether for personal or business use, the need and desire to use social media has increased dramatically since it first stepped on the scene. Historically, medical professionals have steered clear from social media in fear that they may violate HIPAA guidelines. Today, medical professionals cannot deny the […]

Read more

Article: Computer Virus Potentially Exposes PHI of 2.5K at Oregon Clinic

March 30, 2017

  Lane Community College (LLC) health clinic located in Oregon may be dealing with a serious breach. An article over on Health IT Security discusses the computer virus a technician at the hospital discovered, which may have led to exposure of some patients PHI. The Oregon college health clinic stated the virus may have been […]

Read more

Ransomware Attack on Urology Austin

March 30, 2017

A total of 279,663 patients are being notified by Urology Austin that their protected health information (PHI) may have been compromised in a ransomware attack. Information that may have been compromised in the attack includes patient names, addresses, dates of birth, medical records and social security numbers. An article over on HIPAA Journal provides insight […]

Read more

Article – FBI: Attackers Targeting Anonymous FTP Servers in Healthcare

March 29, 2017

A warning issued by the FBI cautions healthcare providers to beware of threat actors, who are now targeting anonymous File Transfer Protocol Servers (FTP), associated with both medical and dental organizations. An article on Dark Reading goes into great detail about the trouble with anonymous FTP servers and why it is important to turn yours […]

Read more

The Latest Details on HIPAA Compliance Audits

March 23, 2017

Deven McGraw, deputy director of the Department of Health and Human Services’ Office for Civil Rights has announced that the department’s plans for initiating onsite audits is currently on hold and will remain so until more than 200 desk audits have been completed.  An article over on Data Breach Today gives us great detail on […]

Read more

Office for Civil Rights Issues Second Largest HIPAA Fine to Date – $5.5 Million

March 22, 2017

According to an article over on tripwire, a covered entity is facing serious penalties after the Office for Civil Rights issued them a hefty fine for their failure to comply with audit procedures including review, modification and termination of users’ access. In the scope of the investigation, it was discovered that more than 100,000 individuals […]

Read more

Article: Snooping St. Charles Health System Employee Accessed Almost 2,500 Patient Records

March 20, 2017

According to an article on HIPAA Journal, over a 27 month period an employee of St. Charles Health System in Oregon accessed nearly 2,500 patient records without authorization. All it took to discover the unnamed employee had been inappropriately accessing patient records was one incident that sparked further review, occurring on January 16, 2017. The […]

Read more

Healthcare firms to increase security spending

March 15, 2017

With the dramatic number of security breaches over the last few years, it should come as no surprise that the healthcare industry has plans to increase spending on IT security. An article over at CIO talks about just how necessary the increase in IT security spending really is. According to a survey released this Tuesday, […]

Read more

Ransomware: could smaller practices be the next victims?

March 14, 2017

As you may know, ransomware has become a top concern for organizations across the globe as cybercriminals continue to flex their muscles and show just how easily they can take down an organization through a simple e-mail. An article over at SC Magazine takes a look at the threat of ransomware to smaller practices. What is […]

Read more

Want to Score with MACRA? Perform a HIPAA Risk Assessment.

February 23, 2017

Congress may be poised to roll back the Affordable Care Act, but HIPAA and MACRA, the Center for Medicare & Medicaid’s (CMS) new model for reimbursements, are as certain to remain as death and taxes. Moreover, MACRA and HIPAA go hand in hand. Physicians cannot participate in MACRA, which went into effect on January 1, […]

Read more

Want to Score with MACRA? Perform a HIPAA Risk Assessment.

February 23, 2017

Congress may be poised to roll back the Affordable Care Act, but HIPAA and MACRA, the Center for Medicare & Medicaid’s (CMS) new model for reimbursements, are as certain to remain as death and taxes. Moreover, MACRA and HIPAA go hand in hand. Physicians cannot participate in MACRA, which went into effect on January 1, […]

Read more

CMS extends Meaningful Use deadline to March 13, 2017

February 8, 2017

The Centers for Medicare & Medicaid Services extended the deadline for Meaningful Use requirements for providers participating in the Medicare EHR Incentive program. The new deadline is March 13, 2017, a two-week extension from the previous Feb. 28 deadline, according to a CMS spokesperson. Eligible providers, hospitals, and critical access hospitals must attest to the […]

Read more

Updated 2017 HIPAA Training

February 7, 2017

We are excited to announce that the HIPAA training classes have been updated for 2017. The update includes the HIPAA Security and Privacy classes for both HIPAA Covered Entities and Business Associates. [tvideo type=”youtube” clip_id=”6Ogt7YBqh6k” autoplay=”true” controls=”false” loop=”false” rel=”false” showinfo=”false” modestbranding=”false”] More engaging The training now utilizes more multimedia, video and engaging content. In fact, […]

Read more

OCR’s guidance to audit controls

January 18, 2017

In the January, 2017 edition of the OCR Cyber Newsletter (PDF), OCR gives guidance to what is required from Covered Entities and Business Associate regarding auditing / monitoring of access to PHI. Covered Entities and Business Associates should make sure that they appropriately review and secure audit trails, and they use the proper tools to […]

Read more

Still time to do a SRA for Meaningful Use

January 6, 2017

We frequently get asked about the timing of when a Security Risk Assessment (SRA) needs to be performed for Meaningful Use. So here is some guidance: SRA for Meaningful Use A SRA needs to be performed before a provider attests for Meaningful Use. According to CMS – https://www.cms.gov/Regulations-and-Guidance/Legislation/EHRIncentivePrograms/Downloads/2016_SecurityRiskAnalysis.pdf Conducting a security risk analysis is required […]

Read more

Data breaches at smaller companies can be devastating

December 23, 2016

According to a Verizon study, data breaches at Small and Midsize Businesses (SMBs) occur more frequently than at larger companies. Another study found that the impact of a SMB breach could be devastating to the business. Find out more about the leading cause of SMB data breaches and what you can do to prevent a […]

Read more

MACRA regulation commences January 1, 2017

December 19, 2016

MACRA regulation (Medicare Access and CHIP Reauthorization Act) commences January 1, 2017. MACRA significantly changes the way physicians are paid and overall Medicare reimbursements. Learn more in our 80 second video [tvideo type=”youtube” clip_id=”3Qe2bVJK05s” rel=”false”]

Read more

Peachtree Orthopedics breach hits 531,000 patients

December 15, 2016

Peachtree Orthopedics has experienced a huge data breach that affects over 500,000 patients. It seems that Peachtree was a victim of a hacker who stole the information and went a step further by issuing a press release: It all began many months ago when we acquired 543k patient records which contain both PII and PHI […]

Read more

MACRA Requires a HIPAA Security Risk Assessment

December 13, 2016

MACRA starts in January, 2017 and requires a HIPAA Security Risk Assessment [tvideo type=”youtube” clip_id=”Bo-ZdAd1sFk” width=”500″]

Read more

New CMS MACRA Rule Kicks In, Factors HIPAA Compliance into New Payment Structure

November 30, 2016

MORRISTOWN, NJ (PRWEB) NOVEMBER 21, 2016 HIPAA Secure Now! is set to handle security risk assessments that will be required of medical practices, under the new MACRA regulation (Medicare Access and CHIP Reauthorization Act), which commences January 1, 2017. HIPAA Secure Now! helps medical practices comply with HIPAA, and protect their most valuable asset – […]

Read more

New CMS MACRA Rule Kicks In, Factors HIPAA Compliance into New Payment Structure

November 30, 2016

MORRISTOWN, NJ (PRWEB) NOVEMBER 21, 2016 HIPAA Secure Now! is set to handle security risk assessments that will be required of medical practices, under the new MACRA regulation (Medicare Access and CHIP Reauthorization Act), which commences January 1, 2017. HIPAA Secure Now! helps medical practices comply with HIPAA, and protect their most valuable asset – […]

Read more

WARNING: BE ON THE LOOKOUT FOR OCR PHISHING EMAIL

November 29, 2016

  In a cruel twist of fate, health care entities are being phished using an OCR (HHS Office of Civil Rights) email as the bait.  Here is the context:  HHS/OCR is the governmental entity in charge of enforcing the HIPAA statutes.  Back in May, we reported that OCR had started sending emails to Covered Entities […]

Read more

OCR ‘Laser Focused’ on HIPAA Violation Complaints, Enforcement

October 27, 2016

HealthIT Security has a very good article on OCR HIPAA activities. A key message is that not all OCR complaints result in HIPAA violations OCR will continue to focus “its enforcement efforts and its resources” in areas of alleged non-compliance and “where corrective action under HIPAA may be the only remedy.” In terms of OCR […]

Read more

OCR’s Guidance to HIPAA & Cloud Computing

October 12, 2016

We have previously posted about HHS/OCR’s Guidance on HIPAA & Cloud Computing. The guidance is presented in question and answer form. To see the full guidance, you can go to the OCR page.   Below are the 11 questions with partial answers to keep this brief but provide a good overview: Questions 1. May a […]

Read more

HIPAA Gets a Little Cloudy

October 11, 2016

Pun intended.  We all use cloud computing resources every day.  All you have to do is go on the Internet, and chances are the website you are accessing uses cloud services.  Our website, www.healthsecurenow.com, uses the Amazon cloud.  There are many definitions of cloud services, but at a high level it is the use of […]

Read more

Hospital fined $400,000 for obsolete Business Associate Agreements

September 27, 2016

In a clear message to healthcare organizations, The U.S. Department of Health and Human Services Office of Civil Rights (OCR), fined Women & Infants Hospital of Rhode Island (WIH) for not having updated HIPAA Business Associate Agreements. WIH provided OCR with a business associate agreement with Care New England Health System effective March 15, 2005, […]

Read more

Dropbox Data Breach and Phishing Scams

September 1, 2016

Dropbox, the popular file sharing service, has experienced a data breach that could affect up to 60 million users. Dropbox is urging their users to change their passwords immediately. In addition, we are seeing an increase in Dropbox related phishing emails. In this security tip video, we show you real examples of Dropbox related phishing […]

Read more

Athens Orthopedic won’t pay for credit monitoring in data breach

August 16, 2016

Data breaches are happening on a frequent basis. You can’t read the news or watch TV without hearing about another data breach. While a company may give out some details of a data breach, the financial details of what the data breach will cost a company usually are not disclosed. This is especially true with […]

Read more

Healthcare software bugs have big consequences

August 11, 2016

Almost all software programs have bugs in their code. The bugs may be security holes, problems displaying pages on mobile devices or inaccurately displaying results in reports to name a few. So it should be no shock that electronic health record (EHR) systems would have bugs as well. EHRs are complex software programs and are […]

Read more

IRS Imposter Scams

August 8, 2016

[tvideo type=”youtube” clip_id=”i4nCy6Xs6R8″ rel=”false” showinfo=”false”]

Read more

HHS Office for Civil Rights releases ransomware guidance

July 13, 2016

There has been a lot of articles written lately about the threat of ransomware to healthcare organizations. Hollywood Presbyterian Medical Center paid a $17,000 ransom to regain access to their systems after they were infected with ransomware. Several other hospitals have been ransomware victims and countless other medical practices have fallen victim as well. There […]

Read more

Phase 2 HIPAA Audits – You Can Get Selected

July 12, 2016

Back in March, we reported that OCR had announced its Phase 2 Audit Program. When we last heard from OCR about Phase 2 HIPAA Audits, we saw that emails were being sent to Covered Entities and Business Associates. The purpose of the emails was to verify and expand the OCR HIPAA audit pool. We wrote […]

Read more

Don’t Let HIPAA Audits, Ransomware Sink Your Practice

July 11, 2016

HIPAA Secure Now! President and CEO writes an article for Physicians Practice called: Don’t Let HIPAA Audits, Ransomware Sink Your Practice At the same time medical practices are faced with the increased likelihood of a HIPAA audit, hackers hover around waiting to steal patients’ personal data and/or hold it hostage through ransomware scams. These practices […]

Read more

Becker’s: 8 HIPAA compliance best practices

June 27, 2016

A recent article over at Becker’s Spine Review, discusses some of the “low hanging fruit of HIPAA compliance”. They give 8 best practices for being HIPAA compliant. For the article they interviewed David Holtzman, JD, CIPP, vice president of compliance strategies, Cynergistek and Aaron Tantleff, partner and intellectual property lawyer with Foley & Lardner LLP. Encrypt health information.  The […]

Read more

Secure Now! Discusses Data Security on Worldwide Business with kathy ireland®

June 20, 2016

  Tune in to Fox Business Network as sponsored programming and Bloomberg International on Sunday, June 26, 2016. See market-by-market listings below. Los Angeles, CA – June 23, 2016 — Secure Now! President/CEO Art Gross will soon appear on the award-winning, global TV show, Worldwide Business with kathy ireland®. Gross will share his expertise in the small and mid-sized business […]

Read more

Secure Now! Discusses Data Security on Worldwide Business with kathy ireland®

June 20, 2016

  Tune in to Fox Business Network as sponsored programming and Bloomberg International on Sunday, June 26, 2016. See market-by-market listings below. Los Angeles, CA – June 23, 2016 — Secure Now! President/CEO Art Gross will soon appear on the award-winning, global TV show, Worldwide Business with kathy ireland®. Gross will share his expertise in the small and mid-sized business […]

Read more

Lack of HIPAA Education causes problems in Orlando

June 15, 2016

By now we are all aware of the horrible event that took place in Orlando over the weekend.  Mass casualties caused local hospitals and ERs to respond heroically.  One of the tasks required during these operations was the necessity to communicate patient status with family and loved ones.  Unfortunately, this was not handled very well. […]

Read more

MedSafe and HIPAA Secure Now! Announce Partnership to Offer Enhanced Healthcare Compliance Solutions

May 27, 2016

We are excited to partner with Medsafe to add OSHA services to our suite of HIPAA services. We are also looking forward to helping their clients with HIPAA Security Risk Assessments. WELLESLEY, MA–(Marketwired – May 24, 2016) – MedSafe, the leader in total healthcare compliance solutions, is pleased to announce its partnership with HIPAA Secure […]

Read more

Physicians: Don’t skip your security risk assessment

May 25, 2016

Publication: Medical Economics Until you’ve opened a letter from the U.S. Department of Health and Human Services’ Office of Civil Rights (OCR) notifying you that your practice is being audited for Health Insurance Portability and Accountability Act (HIPAA) compliance, you won’t realize the gravity of the situation.

Read more

Phase 2 HIPAA Audits – The OCR Emails Have Begun

May 23, 2016

Back in March, we reported that OCR had announced its Phase 2 Audit Program.   OCR stated that they would compile a database of both Covered Entities and Business Associates to form the basis of the pool of organizations potentially targeted for audit.  They have followed up on their intentions and in the last week organizations […]

Read more

Holy MACRA! – Being HIPAA Compliant is Part of How Physicians get Paid

May 4, 2016

On April 27, CMS came out with a proposed rule on how physicians will get paid under MACRA (the Medicare Access and CHIP Reauthorization Act). If you want to read the whole 962 page snoozefest, you can find it here (PDF). But sleep or not, this regulation changes the fundamental Fee-For-Service (FFS) system that CMS […]

Read more

New ransomware is bad news for healthcare organizations

May 1, 2016

Well that didn’t take long. In a recent article I made the case that newer variations of ransomware could result in a reportable HIPAA breach. I argued that if ransomware not only encrypted the victim’s files but also copied the files off of a computer or allowed access to the files, then the result could […]

Read more

Updated HIPAA Training

April 4, 2016

If you go back in time, to 2004, and look at Facebook it looks a lot different than it does today. The same can be said for applications like Microsoft Word or Excel. As these services or products mature they evolve – offering improved functionality, performance, stability and features. New HSN HIPAA Training Like Facebook […]

Read more

Is Ransomware Considered A HIPAA Breach?

March 30, 2016

The topic of ransomware, especially ransomware hitting healthcare organizations, is making headlines daily. Dan Munro has a very good article over at Forbes that asks an important question: Is Ransomware Considered A Health Data Breach Under HIPAA? David Harlow, Principal – The Harlow Group, LLC, whose insight into HIPAA law I respect greatly, states: Ransomware […]

Read more

HSN CEO on NJTV discussing the next phase of the HIPAA audits

March 28, 2016

Watch HSN CEO discuss the next round of HIPAA Audits

Read more

OCR HIPAA Audits – It’s real this time

March 24, 2016

Background Although HIPAA is an important set of laws passed to protect the sensitive medical information handled by millions of covered entities and business associates, Health and Human Services Office for Civil Rights (OCR) has never established a permanent compliance audit program.   Auditing activity to date by OCR has consisted of a pilot program of […]

Read more

NBC NY Reports on Medical Records Found in Trash

March 14, 2016

NBC news in New York is reporting that medical records from Mount Sinai Beth Israel Senior Health Center were found un-shredded in a public trash container. The documents were apparently discarded from the Mount Sinai Beth Israel Senior Health Center in Chelsea. NBC 4 New York viewer Chris Caeser contacted the I-Team when he discovered […]

Read more

Six Ways to Improve Data Security at Your Practice

March 10, 2016

A married couple — both doctors who shared a medical practice — almost divorced over a HIPAA breach that blindsided them when a patient called to say that her medical records appeared in a Google search and she was filing a lawsuit. The orthopedist of a small practice didn’t want to fund the cost of […]

Read more

Another healthcare ransomware attack

February 29, 2016

First it was Hollywood Presbyterian Medical Center that made headlines when ransomware disabled the hospital’s computer network. Now another California healthcare organization has become a victim. Los Angeles County Department of Health Services is the latest large healthcare organization to experience the pain of ransomware. According to the Los Angeles Times: Los Angeles County Department […]

Read more

Free Wi-Fi is hard to resist for most people

February 28, 2016

In this “always connected” society being without Wi-Fi and Internet access makes a lot of people uncomfortable. Many people have heard about the dangers of free Wi-Fi but still that doesn’t stop a majority of people from connecting when it is available. According to an article over at ZDNet, the security company Avast setup open […]

Read more

Texas Print Shop Hit by Ransomware

February 25, 2016

Ransomware that crippled Hollywood Presbyterian Hospital made national headlines but ransomware continues to be a major menace for small to midsize businesses. A print shop in Lubbock, Texas was shut down last week due to ransomware. An employee opened an infected file and ransomware took control of the network. Click below to watch the video […]

Read more

HSN President and CEO contributes to NJTV story on ransomware

February 23, 2016

Art Gross, the President and CEO of HIPAA Secure Now!, contributes to the NJTV News story on the dangers or ransomware. Watch the full story below (Click on image to start video)

Read more

How to avoid ransomware called “Locky”

February 23, 2016

[embedyt]https://www.youtube.com/watch?v=zPTOcjWtJ5E&width=600[/embedyt]

Read more

Paper-based PHI and Business Associate Cause HIPAA Breach

February 23, 2016

  A story over at Gov Info Security details a recent HIPAA breach involving paper-based records that were dumped on a city street on the way to be disposed. “During transport, a small quantity of records were released on Fowler Street in Fort Myers, Florida,” the statement says. “This incident resulted from the condition of […]

Read more

The Aftermath of a HIPAA Data Breach

February 19, 2016

Quite often we hear about data breaches, but we don’t always hear about the consequences.  On February 17,  Memphis, TN media sources ran articles about a man who was indicted on felony fraud charges.  According to a Commercial Appeal newspaper article: “Jeremy Jones is charged in a scheme to steal the identities of more than […]

Read more

Hollywood hospital becomes ransomware victim

February 15, 2016

A hospital in Hollywood, CA has been a victim of a ransomware attack that has left computers unusable for over a week. According to a ZDNet article: the Southern California hospital has been left unable to practice its usual day-to-day operations. The hospital’s president and CEO Allen Stefanek said “significant IT issues” were discovered last […]

Read more

NBC Special Report: 1 in 3 American’s Info Compromised in 2015

February 12, 2016

NBC News had a special report on medical record theft. Medical record fraud is up over 11,000% last year and 1 in 3 Americans have been a victim. When your clients see this, be prepared to answer the question: What are you doing to protect my medical records? Watch the report below:

Read more

CMS Administrator Announces the End of Meaningful Use – NOT

January 19, 2016

Last week, Andy Slavitt, Acting Administrator, Centers for Medicare & Medicaid Services (CMS), spoke at a health care conference.  The text of his speech can be found here.   His remarks touched on many subjects including Meaningful Use.  The MU program is controversial because many providers feel,  and with good reason, that portions of MU are […]

Read more

HHS offers guidance regarding HIPAA and individual access

January 11, 2016

The Department of Health and Human Services (HHS) has issued guidance regarding an Individual’s Right under HIPAA to Access their Health Information. The link should be bookmarked by all organizations as a reference for future guidance, questions and answers: http://www.hhs.gov/hipaa/for-professionals/privacy/guidance/access/index.html Here is the introduction text from the guidance: Providing individuals with easy access to their […]

Read more

HHS modifies HIPAA to strengthen the firearm background check system

January 4, 2016

CMS announced in a blog post that HHS has modified HIPAA to strengthen the firearm background check system. Today the Department of Health and Human Services (HHS) moved forward on commitments made by President Obama to curb gun violence across the nation. Specifically, we have modified the Health Insurance Portability and Accountability Act (HIPAA) Privacy […]

Read more

IBM Says that 2015 is the “Year of the Healthcare Breach”

December 22, 2015

At the end of the year all kinds of publications and organizations publish yearly summaries to review the events of the past 12 months.  Much of the time this can be positive publicity for a celebrity, firm, organization or industry.  In this case, for healthcare, it is decidedly negative.  Why has IBM made this proclamation?  […]

Read more

Why is HIPAA compliance and security so weak?

December 3, 2015

Computerworld has an excellent article called Healthcare security and HIPAA: Why compliance and security are still lacking. The author does a very good job of trying to figure out why there are so many healthcare related data breaches. Here are some highlights: The author takes a look at a previous article and cites some reasons: […]

Read more

Healthcare Data Breaches Cost $6 Billion A Year (Infographic)

November 24, 2015

Royal Jay has developed an interesting infographic on healthcare breaches Highlights: 19 out of 20 organizations had at least one breach in the last 2 years The cost of a healthcare related breach is $398 per record In 2014, around 1.6 million patients had their medical information stolen from healthcare providers Medical identity theft victims […]

Read more

What You Should Know About the HIPAA Privacy Rule

November 21, 2015

Publication: AAOS Headlines about data breaches draw attention to the Health Insurance Portability and Accountability Act’s (HIPAA) Security Rule. However, its companion—the HIPAA Privacy Rule—is just as important. Although the two rules work hand-in-hand, they are based on different concepts. The Security Rule oversees the mechanisms used to protect the privacy of electronic patient health […]

Read more

Don’t skimp on your HIPAA risk assessment

November 20, 2015

Publication: Medical Economics Until you’ve opened a letter from the U.S. Department of Health and Human Services’ Office of Civil Rights (OCR) notifying you that your practice is being audited for Health Insurance Portability and Accountability Act (HIPAA) compliance, you won’t realize the gravity of the situation.

Read more

Dropbox Business will now sign a HIPAA BAA

November 6, 2015

Dropbox announced at the Dropbox Open event that their business product is now HIPAA compliant. Dropbox Business is a business version of the consumer file sync product. Dropbox announced that they will sign a HIPAA Business Associate Agreement (BAA) for the Dropbox Business product. Dropbox now supports HIPAA-regulated businesses Big news for companies that handle […]

Read more

Computer Fraud and Abuse Act may help companies against employee cyber theft

November 5, 2015

The Computer Fraud and Abuse Act CFAA is not a very widely known piece of federal legislation but could help companies that have been victims of employee or ex-employee theft of digital information. According to an article over at Fox Rothschild LLP the CFAA can be used to help companies that have had employees or […]

Read more

Average cost per lost health care record is $363

November 3, 2015

A recent study by the Ponemon Institute calculated the cost of a healthcare related data breach to be $363 per record. This was the highest amount across all industries. A financial data breach cost $215 per record and a retail data breach cost $165 per record Targeting Protected Health Information According to an article by […]

Read more

HIPAA compliance is a business risk

October 19, 2015

Medicine is Risky The practice of medicine is a risky business. There is always the risk that a certain treatment will fail to help a patient. There is a risk of being accused of malpractice. There is a risk of being accused of incorrectly billing a patient, insurance company or government agency. There is a […]

Read more

Revised Meaningful Use: SRA #1 Objective

October 8, 2015

There is a lot of confusion about the requirements for Meaningful Use. The program has been around for 5 years and has seen many changes. We talk to potential clients and have recently heard the following quote many times: I heard the Security Risk Analysis is no longer a requirement for Meaningful Use I heard […]

Read more

OCR squeezed between OIG and funding restraints

October 2, 2015

The Department of Health and Human Services Office of Inspector General (“OIG”) has issued a report that is critical of the Office for Civil Rights (“OCR”).  OIG concluded that OCR is not fulfilling its responsibility to enforce HIPAA regulations that safeguard protected health information (PHI) and to ensure that organizations protect patient’s privacy. Here are some […]

Read more

Excellus Blue Cross Blue Shield Breach Yet Another Sign To Step Up Health-Care Security Investment

September 15, 2015

Publication: CRN The challenge, Gross said, is that many health-care organizations are still taking the “it can’t happen to me” attitude toward security. On a smaller scale relative to many of the health-care breaches so far this year, Gross said that he hopes the Excellus incident will alert smaller insurance and medical companies that hackers […]

Read more

$750,000 HIPAA fine offers valuable lessons

September 3, 2015

On September 2, 2015 The HHS Office of Civil Rights (OCR) issued a press release announcing a $750,000 HIPAA settlement with Cancer Care Group, P.C. This large fine offers some very important lessons. Let’s take a closer look: Cancer Care Group is a mid-size practice. They have 18 physicians.  It is important to note the […]

Read more

It’s Not Just Large Data Breaches That Matter

August 13, 2015

We are all well aware of the epidemic of large data breaches that have been occurring recently.  Anthem, Blue Cross, UCLA, the list goes on and on.  Over 143 million records breached to date – an astounding figure!  Since 2009, when the Office of Civil Rights “Wall of Shame” came into existence, there have been […]

Read more

Wall of Shame now at 143 million breached individuals

August 7, 2015

Hacking and breaches of healthcare data continue to happen. The scale of the breaches are increasing as well. According to an article over at Data Breach Today, 143 million individuals have had their healthcare related information breached. 70% of the 143 million breached records have occurred just in 2015. Healthcare organizations are not making security […]

Read more

Six Potential HIPAA Threats for PHOs and Super Groups

June 27, 2015

Publication: Physicans Practice But just like a negative restaurant review on Yelp can hurt customer patronage and the restaurant’s reputation, one practice that commits a HIPAA violation can affect the entire group, and result in an expensive fine, cause distrust among patients, and in extreme cases, the data breach can lead to medical identity theft.

Read more

Recorded Webinar: How to Avoid HIPAA-Related Breaches

June 25, 2015

Art Gross, President and CEO of HIPAA Secure Now!, participated in an American Osteopathic Association (AOA) webinar on 2015 HIPAA Audits and How to Avoid HIPAA Related Breaches. The recorded webinar is below.

Read more

AOA Webinar: Protect Your Practice: How to Avoid HIPAA-Related Breaches

June 25, 2015

Publication: American Osteopathic Association Join Art Gross, president and CEO at HIPAA Secure Now!, to learn how to prepare for the recent Office of Civil Rights (OCR) HIPAA audits. Understand the need for a Security Risk Assessment, HIPAA Security and Privacy Policies, and Employee Training.

Read more

Patients Demand the Best Care … for Their Data

June 25, 2015

Publication: EMR & HIPAA Prep for natural disasters, teach staff to spot threats, and review activity in your electronic medical record system, DOs and security experts say.

Read more

The Security Risks of Medical Devices

June 13, 2015

There are a large number of potential attack vectors on any network.  Medical devices on a healthcare network is certainly one of them.  While medical devices represent a potential threat, it is important to keep in mind that the threat level posed by any given medical device should be determined by a Security Risk Assessment […]

Read more

Audits are only one way of coming under the HIPAA microscope

June 8, 2015

Now that the 2015 HIPAA Audits have begun, organizations are reevaluating their HIPAA compliance posture. This is a good thing being that an organization will have very little time to respond to pre-audit and audit inquiries from the Office of Civil Rights (OCR). On the other hand, some organizations are evaluating the risk of being […]

Read more

Ounce of prevention: 5 steps to boosting your practice’s data security

June 8, 2015

Publication: The DO Prep for natural disasters, teach staff to spot threats, and review activity in your electronic medical record system, DOs and security experts say.

Read more

HIPAA Secure Now! Appoints Jonathan Krasner to Head Business Development, Grow MSP Partner Base, Help Partners Succeed

June 4, 2015

Krasner brings 25 years of IT and seven years of Healthcare IT, HIPAA and Meaningful Use experience to HIPAA Secure Now! Morristown, NJ (PRWEB) June 04, 2015  

Read more

HIPAA Secure Now! Appoints Jonathan Krasner to Head Business Development, Grow MSP Partner Base, Help Partners Succeed

June 4, 2015

Krasner brings 25 years of IT and seven years of Healthcare IT, HIPAA and Meaningful Use experience to HIPAA Secure Now! Morristown, NJ (PRWEB) June 04, 2015 HIPAA Secure Now!, a HIPAA compliance service provider, has named Jonathan Krasner to the position of Director of Business Development. Krasner was hired to expand the company’s MSP […]

Read more

Horizon-scanning around HIPAA, HITECH

June 1, 2015

Publication: Health Management Technology How far will they protect healthcare data from insiders, outsiders?

Read more

Safety first: How to perform a security risk assessment

May 29, 2015

Publication: The DO The patient information in your practice is one of your most valuable assets, so protecting it is a smart business move.

Read more

Top Day 1 Quotes From ASCII Chicago

May 28, 2015

Publication: Business Solutions Magazine A crowd of nearly 100 channel executives enjoyed Day 1 of Wednesday’s ASCII Success Summit at the Hyatt Regency O’Hare in Chicago. I wanted to share with you some the best quips and quotes from the day.

Read more

Health care in the time of data breaches: 3 things to know

May 19, 2015

Publication: Business Solutions Magazine A HIPAA expert outlines what physicians need to understand about preparation, fines and retaining patients.

Read more

2015 HIPAA Audits – A Step Closer

May 14, 2015

There has been a lot of talk about the next round of HIPAA Audits. While the rollout of the audits have been delayed a few times, it now looks like they are about to start. The clear sign is that a the pre-audit survey has been approved by the Office of Management and Budget (OMB). […]

Read more

Starbucks data breach shows the real damage of a breach

May 14, 2015

Starbucks has a big problem. Don’t worry, they will still sell you their $5 cup of coffee. The problem they are dealing with is the repercussions of a data breach. The breach is connected with Starbucks’ mobile app. The Starbucks’ mobile app makes it incredible easy to buy a cup of coffee. Customers love the […]

Read more

The Hidden Epidemic of Medical Identity Theft Now Claiming Millions of Victims

May 12, 2015

Publication: Business Solutions Magazine NEW YORK (MainStreet) — Credit card related data breaches get all the headlines – but there is a bigger, more worrisome threat to your safety and privacy, multiple experts insisted to Mainstreet, and they pointed to medical identity theft.

Read more

HIPAA lacks guidance on BYOD policies

May 7, 2015

If you look around you will see the overwhelming amount of mobile devices that are in use today including laptops, smartphones and tablets. Many organizations allow employees to use their own smartphones or laptops to access the organization’s email, network and data. Clients are starting to understand the risk of these devices and many have asked […]

Read more

How to Teach Your Employees to Recognize Hacker Scams

May 4, 2015

Publication: American Express OPEN forum Cyber criminals are on the prowl for business data. Every company, no matter the size, has valuable data that’s as enticing as cracking a safe–but with far less risk, because cyber attackers are virtually untraceable. Here’s how your employees can learn to recognize hacker scams.

Read more

HIPAA Security Tips and Reminders – How to Create a Strong Password

April 23, 2015

Security firm Sophos has a good video on how to create a strong password.

Read more

ONC releases guide to Privacy and Security of Electronic Health Information

April 13, 2015

The Office of the National Coordinator for Health Information Technology has just released a valuable resource called: Guide to Privacy and Security of Electronic Health Information Here is a look at the information included in the guide:   [framed_box bgColor=”#ffd390″] Understand a HIPAA / Meaningful Use Risk Assessment Organizations need to perform a Risk Assessment […]

Read more

OIG increases the pressure of Meaningful Use audits

April 12, 2015

The U.S. Health and Human Services Department’s Office of Inspector General (OIG) will begin auditing individual providers to determine if they met Meaningful Use requirements. Currently the Centers for Medicare & Medicaid Service (CMS) is auditing providers through contractor Figliozzi & Co. The CMS audits look to see if providers met the Meaningful Use measures […]

Read more

HIPAA Secure Now! Helps Covered Entities Comply with HIPAA Privacy Rule

April 8, 2015

HIPAA Secure Now’s New Privacy Tools Augment the Company’s HIPAA Security Compliance Services Morristown, NJ (PRWEB) April 08, 2015  

Read more

I Won I Won the Audit!

April 4, 2015

Today started like every other day until I opened an email from a client. Below is a excerpt of the email: I Won I Won I Won I won the audit. Many thanks to you. I have been giving out your website and phone # to everyone I know. I cannot thank you enough. We […]

Read more

Infographic: HIPAA, We Have a Problem

April 3, 2015

Interesting Infographic on healthcare professionals’ knowledge of HIPAA regulations from NueMD   [framed_box bgColor=”#ffd390″] Free HIPAA Security Training! All Covered Entities and Business Associates need to train their employees on HIPAA security. We now offer free online HIPAA security training for Covered Entities and Business Associates. Find out more about our free training and send […]

Read more

CIO: Health records are the new credit cards

March 26, 2015

An article over at CIO compares health records to credit cards and unfortunately they come to a gloomy conclusion: Health records are worth more and easier to get The value of health records “Cyber criminals are now going after health care records because they hold up to ten times more value on the black market […]

Read more

HIPAA Security Tips and Reminders – Protecting Portable Devices

March 20, 2015

Security Tips: Protecting Portable Devices Click on  above to view in fullscreen mode!

Read more

Top 10 ridiculous overheard HIPAA statements

March 19, 2015

After performing over 1,000 HIPAA Security Risk Assessments, you can imagine that we have heard some ridiculous statements concerning HIPAA. There is a LOT of misinformation about HIPAA. Here are the Top 10 ridiculous overheard HIPAA statements: 10) My IT company won’t sign the Business Associate Agreement because they said it is not valid unless […]

Read more

Even Dear Abby knows about HIPAA

February 20, 2015

The column Dear Abby gives advice to a wife who illegally accessed her husband’s medical records. Read the whole article here. DEAR CONCERNED: Unless you claim to be clairvoyant, I don’t see how you can discuss this without admitting you accessed his medical records, which is against the law. Be prepared for him to be […]

Read more

Health Informatics and HIPAA

February 19, 2015

The following is a guest post by James Hinton In 1854 John Snow had a moment. At the time it hadn’t seemed like that significant an event, but Dr. Snow’s use of collected data and maps to pinpoint the source of a cholera outbreak in London started something. Though it started small, Big Data and Geographic […]

Read more

The problem with patient portals

February 18, 2015

Publication: Medical Practice Insider Patient portals seem like the logical next step for a healthcare system that’s becoming increasingly more reliant on electronic health records and other various digital constructs.

Read more

Are you a sitting duck for data breaches?

February 14, 2015

The below infographic gives some frightening facts about healthcare related breaches. Click on the image to see the whole infographic Source: Datamotion   [framed_box bgColor=”#ffd390″] Free HIPAA Security Training! All Covered Entities and Business Associates need to train their employees on HIPAA security. We now offer free online HIPAA security training for Covered Entities and […]

Read more

OCR 2016 budget includes increase for HIPAA audits

February 13, 2015

The total budget request (PDF) for the Department of Health & Human Services (HHS) is $83 billion. This includes $43 million for the Office for Civil Rights (OCR) which is a $4 million increase over the 2015 budget. The increase will help support the permanent HIPAA audit process. OCR conducted a pilot program to ensure […]

Read more

MSP Differentiates His Business With HIPAA, SMB Security, Expands Partner Program

February 12, 2015

Publication: Business Solutions Magazine “Security is the place to focus on now and in the future,” advises Art Gross, president and CEO of HIPAA Secure Now! “It’s not going away.”

Read more

Why is healthcare data so valuable?

February 10, 2015

Security experts have been predicting that large healthcare related data breaches will continue into 2015. With the Anthem Inc., breach of 80 million records this prediction is now a reality. An article over at Forbes explores why healthcare data is so valuable. Here are some of the reasons: Quantity of information—Think of the 15 pages […]

Read more

CMS to shorten the MU EHR reporting period in 2015 to 90 days

January 29, 2015

On a blog post over at the CMS website, it has been announced that CMS will shorten the Meaningful Use 2015 reporting period to 90 day. Currently the 2015 reporting period is 365 days. Today, we at the Centers for Medicare & Medicaid Services (CMS) are pleased to announce our intent to engage in rulemaking […]

Read more

Tips for avoiding HIPAA fines in 2015

January 27, 2015

An article over at Physicians Practice gives some useful tips to avoid HIPAA fines. 1) Conduct or update your security risk assessment required by the security rules – A security risk assessment is the core of the HIPAA security rule 2) Implement the administrative, technical, and physical safeguards required by the HIPAA security rule – […]

Read more

HIPAA Security Tips and Reminders – Privacy Screens

January 20, 2015

Security Tips: Privacy Screens Click on  above to view in fullscreen mode!

Read more

The business of selling patient records

January 19, 2015

Publication: Dermatology Times Criminals are after your patients’ medical records, plain and simple. The number of criminal cyberattacks reported by healthcare organizations jumped to 40% in 2013 from 20% in 2009, according to an annual survey by the Ponemon Institute. Whether it’s an ex-employee with a grudge, a crime ring defrauding the government, or a […]

Read more

HIPAA Security Infographic

January 17, 2015

Read more

10 quotes that defined the medical practice realm in 2014

January 7, 2015

Publication: Medical Practice Insider Small and midsize physician practices confronted challenges seemingly from every direction during 2014. Doctors and industry observers voiced their views on the realities of contemporary practice in these memorable quotes from Medical Practice Insider’s coverage of the year just concluded.

Read more

2015 HIPAA Audits

January 7, 2015

With the start of a new year, many organizations take a second look at their business and make necessary changes. 2015 is looking like a challenging year in terms of data security. The New Year brings back the Office of Civil Rights (OCR) HIPAA audits. Both HIPAA Covered Entities (CEs) and Business Associates (BAs) will […]

Read more

MSP Turned HIPAA Compliance Expert

January 1, 2015

Publication: Channel Pro  

Read more

Nurse steals patients’ credit cards for personal use

December 21, 2014

According to the Herald-Tribune, a registered nurse working in the Lakewood Ranch Medical Center’s emergency room was fired and arrest for using patients’ credit card information. While investigating separate fraudulent credit card cases, detectives determined the victims’ information had been stolen while receiving treatment at the Lakewood Ranch Medical Center’s emergency room, according to the […]

Read more

HIPAA Secure Now! is the ASCII 2014 Esteemed Noble Partner #10

December 20, 2014

HIPAA Secure Now! is the ASCII 2014 Esteemed Noble Partner #10. We are honored to be included with industry heavyweights Datto, HP, AVG, StorageCraft, Lenovo, and GFI Max/Maxfocus! Click to watch the video on Vimeo

Read more

What happens if your business associate has a patient data breach?

December 6, 2014

This article written by HIPAA Secure Now! President and CEO, Art Gross, was published over at Dermatology Times. What happens if your business associate has a patient data breach? Here’s a cautionary tale: A medical practice comes to us in a panic. It turns out the physician had received a letter from the Office of […]

Read more

What happens if your business associate has a patient data breach?

December 4, 2014

Publication: Dermatology Times Here’s a cautionary tale: A medical practice comes to us in a panic. It turns out the physician had received a letter from the Office of Civil Rights (OCR) ordering an investigation related to a patient data breach – not his own.

Read more

Promoting Data Security in the Workplace (Infographic)

November 27, 2014

Source: University of Alabama at Birmingham’s Online Business Program

Read more

Hey Small Business: You ARE a cyber-target!

November 22, 2014

The security firm, FireEye, has a very eye opening report titled “Big Threats for Small Businesses Five Reasons Your Small or Midsize Business is a Prime Target for Cybercriminals” The report addresses a common misconception that small businesses have: I’m too small to be a target “The ‘I’m too small to be a target’ argument […]

Read more

How to avoid a HIPAA related breach

November 19, 2014

HIPAA Secure Now! President and CEO, Art Gross, offers some tips to avoid HIPAA related breaches in an article over at Dermatology Times Back in 2013 Adult & Pediatric Dermatology of Concord, Massachusetts, was hit with a $150,000 HIPAA fine for an unencrypted thumb drive that stored more than 2,200 patient records and was stolen […]

Read more

The ASCII Group Names HIPAA Secure Now! Esteemed Noble Partner at ASCII Success Summit 2014

November 18, 2014

Members of ASCII Group, longstanding IT channel organization voted HIPAA Secure Now! for award, signifying company’s commitment to peers and helping them grow their businesses. Morristown, NJ (PRWEB) November 17, 2014 HIPAA Secure Now! was voted one of the top 10 Esteemed Noble Partners by members of the ASCII Group, a membership-based community of independent […]

Read more

The ASCII Group Names HIPAA Secure Now! Esteemed Noble Partner at ASCII Success Summit 2014

November 17, 2014

Members of ASCII Group, longstanding IT channel organization, voted HIPAA Secure Now! for award, signifying company’s commitment to peers and helping them grow their businesses. Morristown, NJ (PRWEB) November 17, 2014  

Read more

Hackers love small businesses – Infographic

November 14, 2014

A infographic by the National Cyber Security Alliance (NCSA) reported that 71 percent of security breaches target small businesses, and nearly half of all small businesses have been victims of cyberattacks.

Read more

How to avoid the HHS ‘Wall of Shame’

November 12, 2014

Publication: Dermatology Times Back in 2013 Adult & Pediatric Dermatology of Concord, Massachusetts, was hit with a $150,000 HIPAA fine for an unencrypted thumb drive that stored more than 2,200 patient records and was stolen from a staff member’s car. Not only did the dermatology group owe the hefty sum, it joined the ranks of […]

Read more

Cost to a HIPAA breach victim is $19,000

November 12, 2014

We talk about the cost of HIPAA related breaches for organizations but have you ever wondered how much it costs a victim of a HIPAA related breach? According to Becker’s Hospital Review, the average cost of a HIPAA related breach to an individual is about $19,000. According to a report by the Ponemon Institute, the […]

Read more

Not encrypting PHI is negligent

November 9, 2014

With over 30 million patient records breached since 2009 (and that only includes the breaches that have been reported. The actual number is probably much higher) there is a real crisis with protecting patient information. We keep hearing about healthcare organizations having breaches due to lost or stolen laptops and portable media (USB drives, CD/DVDs, […]

Read more

Weak 2014 Meaningful Use Attestation Numbers

November 4, 2014

According to FireceEMR, as of Nov 1, 2014 only 43,898 eligible professionals (EPs) have attested from Meaningful Use (MU). There are over 500,000 active registrants signed up to participate in the MU program. Furthermore, only 11,478 EPs have attested for MU Stage 2 as of Nov 1, 2014. The number of providers attesting to Meaningful […]

Read more

How Hackers Attack: Inside a Business Data Breach

November 2, 2014

Good video on how hackers gain access to valuable data. Steps on how to protect your organization are discussed as well. Share with employees and colleagues [divider] [framed_box bgColor=”#ffd390″] Free HIPAA Security Training! All Covered Entities and Business Associates need to train their employees on HIPAA security. We now offer free online HIPAA security training […]

Read more

CMS changes timing for Meaningful Use Security Risk Assessment

October 24, 2014

The Centers for Medicare & Medicaid Services (CMS) has made a change to the timing of a Meaningful Use (MU) Security Risk Assessment. Previously, providers were required to perform a Security Risk Assessment either before or during the MU reporting period. The change gives more flexibility to providers on when they can perform the Security […]

Read more

There’s a blind spot in every meaningful use attestation

October 22, 2014

Publication: Dermatology Times The Centers for Medicare and Medicaid Services (CMS) pulls no punches when it warns healthcare providers that meaningful use audits are happening, at random, and consequences for failing the audit are costly. If a provider cannot produce documentation that fully supports its electronic health record (EHR) attestation, the CMS could recoup incentive […]

Read more

HIPAA Secure Now! Signs Agreement with the American Osteopathic Association (AOA), Provides Full Array of HIPAA Compliance Services to 100,000-Plus Members

October 21, 2014

HIPAA Secure Now! Signs Agreement with the American Osteopathic Association, Provides Full Array of HIPAA Compliance Services to 100,000-Plus Members (PRWEB) October 21, 2014 HIPAA Secure Now! has forged a partnership with the American Osteopathic Association (AOA) to help members become fully compliant with HIPAA rules for protecting electronic protected health information (ePHI). Members will […]

Read more

HIPAA Secure Now! Signs Agreement with the American Osteopathic Association, Provides Full Array of HIPAA Compliance Services to 100,000-Plus Members

October 14, 2014

HIPAA Secure Now! Offers HIPAA risk assessment and other compliance services to American Osteopathic Association. (PRWEB) October 21, 2014  

Read more

Prevent business associates from putting your practice at risk

October 13, 2014

Publication: Medical Practice Insider So you’ve taken all the steps to align your practice with HIPAA mandates — you’ve conducted a risk assessment, you keep regular tabs on your encryption functionality and you’ve memorized your breach disaster plan by heart.You’re ready; the problem is, your business associates may not be.

Read more

InformationWeek: Inside A HIPAA Breach

October 9, 2014

The following article, written by Alison Diana, appeared over at InformationWeek on 10/7/2014. The article interviews one of HIPAA Secure Now’s clients that utilized our service after one of their Business Associates had a HIPAA related breach. The client asked to remain anonymous but wanted to share the information so other HIPAA Covered Entities and […]

Read more

Inside A HIPAA Breach

October 7, 2014

Publication: InformationWeek A Saturday night phone call gave no indication it heralded months of bureaucracy, finger pointing, expense — and the dismal realization that even the smallest healthcare provider is liable and harmed when a business associate suffers a HIPAA breach.

Read more

HIPAA Security Tips and Reminders – Securing Your iPhone

September 22, 2014

Security Tips: Securing Your iPhone

Read more

OCR Fines Are the Least of Your Worries in a HIPAA Related Breach

August 27, 2014

Publication: EMR & HIPAA Ask any medical professional about their biggest concern for protecting patient information and they will probably tell you about the threat of a random audit conducted by the Office of Civil Rights (OCR). OCR is tasked with enforcing HIPAA regulations and has the ability to hand out fines up to $1.5 […]

Read more

eWEEK: CHS Breach a Sign of Health Care’s Security Illness

August 26, 2014

An article over at eWEEK takes a look at the Community Health Systems’ (CHS) 4.5 million patient record breach. The message of the article is that the healthcare industry spends the least on protecting data and is the most susceptible to data breaches. Some highlights of the article include: The health care industry has given […]

Read more

This actual OCR audit letter should terrify everyone!

August 25, 2014

A prospective client asked for our help after receiving a HIPAA audit letter from the Office of Civil Rights (OCR). OCR sent the client the letter after one of the client’s business associates experienced a HIPAA related breach. I won’t give any additional information on the client, the business associate or details of the security […]

Read more

HIPAA Secure Now! Ramps up EHR Partner Program, Helps Healthcare Providers Achieve Meaningful Use under Revised CMS Deadlines

August 21, 2014

HIPAA Secure Now! Ramps up EHR Partner Program, Helps Healthcare Providers Achieve Meaningful Use under Revised CMS Deadlines Medical practices applying for Meaningful Use can now get a HIPAA security risk assessment through their EHR provider. The risk assessment is a key requirement for Meaningful Use, Stages 1 and 2. Morristown, NJ (PRWEB) August 21, […]

Read more

HIPAA Secure Now! Ramps up EHR Partner Program, Helps Healthcare Providers Achieve Meaningful Use under Revised CMS Deadlines

August 21, 2014

Morristown, NJw (PRWEB) August 21, 2014 HIPAA Secure Now! rolled out its EHR (electronic health records) partnership program, making it possible for EHR vendors to now offer their customers a HIPAA security risk assessment, a vital requirement for achieving meaningful use. HIPAA Secure Now! provides risk analysis services, policies, procedures and training to medical practices […]

Read more

Hacker’s advice: How to create stronger passwords

August 18, 2014

There is an insightful article over at WonderHowTo written by an IT security professional and forensic investigator. The article looks at ways to prevent hackers from accessing important information online. Specifically the article focuses on how to create strong passwords that will reduce the likeliness that your account will be hacked. All passwords can be […]

Read more

HIPAA and the Cloud: How to Securely Store and Share Patient Files with Dropbox

August 14, 2014

The following is a guest post by Asaf Cidon, CEO and co-founder of Sookasa Healthcare providers across the country are quickly learning how useful cloud-based file-sharing services like Dropbox, Box, and Google Drive can be. These services allow practitioners to store documents in the cloud, share them with other users, and automatically synchronize the latest […]

Read more

Legal Pitfalls of Electronic Patient Communication

August 10, 2014

This article originally appeared in the July/August 2014 issue of Physicians Practice. July 28, 2014 | Law & Malpractice, Mobile, Patient Relations, Risk Management By Shelly K. Schwartz Patients prefer it. Medicare’s meaningful use program requires it. And within a few years, health information technology analysts predict that electronic communication will be par for the […]

Read more

How to approach your next risk assessment

August 7, 2014

Publication: Medical Practice Insider Try as they may, small practices are having a hard time running HIPAA’s gamut between compliance and security.Of course, when the source material is so dense and with technical support hard to come by, who could blame them? Certainly not Art Gross.

Read more

OCR: shred, burn or pulverize PHI before disposing!

August 7, 2014

The Department of Health and Human Service (HHS) Office of Civil Rights (OCR) has a frequently asked questions document (PDF) on the disposal of protected health information (PHI). Below are some of the highlights of the guidance: What do the HIPAA Privacy and Security Rules require of covered entities when they dispose of protected health […]

Read more

Legal Pitfalls of Electronic Patient Communication

July 28, 2014

Publication: Physicians Practice Patients prefer it. Medicare’s meaningful use program requires it. And within a few years, health information technology analysts predict that electronic communication will be par for the course in delivering patient care. Indeed, mobile devices and Web-based technology have provided new platforms to market your practice, transmit medical records, consult with other […]

Read more

AMA advises members to perform a security risk assessment

July 25, 2014

Hot off the American Medical Association (AMA) Wire, a service that provides news and information to AMA members, is a reminder that the HIPAA audits will resume this year. The AMA Wire reminds members that the HIPAA audits will start as early as this summer If you haven’t conducted a privacy and security risk assessment […]

Read more

Good infographic on the need to implement secure communications to protect patient information

July 23, 2014

Good infographic on the need to implement secure communications to protect patient information   Original infographic can be found at TheConnectedClinician.com [divider_line] [divider_line]

Read more

Beware of racketeers making big money on patient records

July 22, 2014

Publication: Cardiovascular Business Armed robbery and drug trafficking are no longer the only crimes of choice for gangs. Instead of a gun, their newest weapon of choice is a mobile phone with Internet access. Now more sophisticated gang members are targeting medical practices and using their smart phones to steal patient records.

Read more

Case study: Breach of PHI by a Business Associate

July 12, 2014

One of our medical practice clients contacted us regarding a breach of Protected Health Information (PHI) by their billing company. The client received a letter from the billing company’s attorney stating that 60 of the client’s patients had their information breached when the billing company’s file server was compromised. The PHI included treatment reports, name, […]

Read more

HIPAA Complaints Vex Healthcare Organizations

July 8, 2014

Publication: InformationWeek Since 2013, complaints to the Department of Health and Human Services have risen regarding Health Insurance Portability and Accountability Act violations.

Read more

Criminals Have Their Eyes on Your Patients’ Records

July 2, 2014

The post appeared on June 26, 2014 in EMR & HIPAA It’s one thing to have a laptop stolen with 8,000 patient records or for a disgruntled doctor to grab his patients’ records and start his own practice. It’s another when the Cosa Nostra steals that information, siphons money from the patient’s bank account and […]

Read more

Criminals Have Their Eyes on Your Patients’ Records

June 26, 2014

Publication: EMR & HIPAA It’s one thing to have a laptop stolen with 8,000 patient records or for a disgruntled doctor to grab his patients’ records and start his own practice. It’s another when the Cosa Nostra steals that information, siphons money from the patient’s bank account and turns it into a patient trafficking crime […]

Read more

Don’t comply with HIPAA!

June 26, 2014

Here is a quote from one of our IT partners: My client got physically upset at me when I brought up the topic of HIPAA. They didn’t want to discuss it and said it was just another government regulation and they just want to practice medicine. While I was shocked to hear someone actually say […]

Read more

Text messages are part of a patient’s medical record

June 24, 2014

Medical Economics has a very interesting and thought provoking article on sending patients text messages. The article is definitely worth reading in its entirety. Here are a few highlights: Any text message that involves the transmission of information that would be considered PHI, including information relating to the treatment of your patients, should be considered […]

Read more

HIPAA Secure Now! Offers Annual HIPAA Security Training Subscriptions for Employees of Covered Entities and Business Associates

June 23, 2014

HIPAA Secure Now!’s Training Program Ensures Employees Understand and Maintain HIPAA Compliance and Security Morristown, NJ (PRWEB) June 23, 2014  

Read more

Deadline approaching for 2Q14 Meaningful Use Risk Assessment

June 19, 2014

Read more

Another HIPAA breach caused by unencrypted flash drive

June 12, 2014

Another day, another HIPAA breach of 34,000 patient records on an unencrypted USB drive. The drive was stolen from an employee’s locker at Redwood Regional Medical Group imaging center. According to a report: The drive was stolen June 2 from an unlocked employee locker at the former Redwood Regional Medical Group imaging center at 121 […]

Read more

Interesting look at paper referrals and HIPAA violations

June 11, 2014

referralMD has a very interesting article and infographic on paper based referrals. They take a look at HIPAA violations as well. Courtesy of: referralMD           

Read more

Dropbox links spreading malware

June 10, 2014

A phishing scam that uses Dropbox links to spread malware is being sent to unsuspecting users. The malware makes it seem like the user has received an electronic fax and provides a link to access the file. The file contains a screen saver that encrypts the user’s hard drive and all of its contents. The […]

Read more

Healthcare Organizations Prep For Increased Audits

June 6, 2014

Publication: InformationWeek As office manager of the Fertility Institute of Virginia, Pattie Carson needed to ensure the practice was compliant with laws related to mobile usage, emails, and security. But keeping up with changing laws while running the busy reproductive endocrinology practice was impractical, if not impossible.

Read more

A HIPAA violation that every organization should read about

May 24, 2014

Our job at HIPAA Secure Now! is to help our clients comply with HIPAA regulations. As part of that process we try to educate our clients and their employees on the importance of protecting patient privacy. We use examples of HIPAA violations to help clients understand some of the concepts of HIPAA such as; what […]

Read more

CMS 2014 MU Changes – Risk Assessment Impact

May 20, 2014

Centers for Medicare & Medicaid Services (CMS) has proposed extending the use of 2011 certified EHR technology (CEHRT) into 2014. Previously all eligible providers (EPs) were required to use 2014 CEHRT to attest for Meaningful Use in 2014. The table below explains what version and what Meaningful Use objectives EPs can use in 2014   […]

Read more

HIPAA – Looking Forward

May 16, 2014

We are at an inflection point regarding HIPAA enforcement. For years we have talked about HIPAA regulations including the HIPAA Security Rule, HITECH Act, small scale HIPAA audits and the HIPAA Omnibus Rule but true HIPAA enforcement has eluded us. Are we at a fork in the road where HIPAA enforcement and compliance with HIPAA […]

Read more

Is Meaningful Use Helping or Hurting EHR Adoption? [INFOGRAPHIC]

May 7, 2014

Very interesting Infographic from NueMD [divider_line] [divider_line]

Read more

6 things organizations are doing that are not HIPAA compliant

May 2, 2014

Here is a list of common HIPAA violations that we find while performing a HIPAA Risk Assessment: Using Dropbox to store PHI Everyone loves Dropbox! Dropbox is simple, easy to use and convenient. It makes backing up and sharing data very easy. Unfortunately Dropbox is NOT HIPAA compliant. So use Dropbox for personal use but […]

Read more

Electronic Health Records Infographic

May 1, 2014

[divider]

Read more

Physicians Find Security In The Cloud

April 24, 2014

Publication: InformationWeek Healthcare practices are increasingly partnering with trusted cloud service providers to provide enhanced data security along with improved efficiency of IT operations.

Read more

Fine of $1,689 per lost unencrypted record!

April 24, 2014

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) levied $1,975,220 in fines on two entities for HIPAA violations. Both entities had breaches related to lost laptops that were not encrypted to protect the patient information. Concentra Health Services (Concentra) was handed down a $1,725,220 for a stolen laptop that […]

Read more

Infographic – How to create the perfect password

April 22, 2014

Click on the image to see the full infographic

Read more

Good insight into new HHS Security Risk Assessment Tool

April 15, 2014

There is an article over at HealthIT Security that discusses the new Department of Health and Human Services – HHS security risk assessment tool. The article interviews Alisa Chestler a shareholder in the Washington, D.C. office of Baker Donelson. Alisa shares many of the same thoughts I had when I reviewed the tool for the […]

Read more

Colleagues In Cuffs: When Employees Steal Patient Records

April 7, 2014

Publication: InformationWeek The Queens County DA recently arrested two Jamaica Hospital employees for stealing patient data, a lucrative crime occurring at hospitals across the nation.

Read more

One Guy’s Opinion: MSPs and HIPAA Compliance

April 3, 2014

Publication: Recovery Zone It’s important for MSPs to understand what HIPAA compliance is, what they can do to be HIPAA compliant, and what might happen if they try to service clients in the medical field without being HIPAA compliant. Luckily, our friend Guy Baroan, expert MSP and owner of IT solutions provider Baroan Technologies, knows […]

Read more

Fear OCR like you do the IRS

April 1, 2014

Have you ever received a letter from the Internal Revenue Service (IRS)? The letter might be due to a discrepancy on your tax return, a notice of interest due or that your tax return is being audited. Remember the fear that overwhelms you just seeing the letter from the IRS. Even if you have done […]

Read more

ONC provides insight on protecting mobile devices

March 29, 2014

The Office of the National Coordinator for Health Information Technology (ONC) has updated their website with with very useful information on protecting patient information on mobile devices. Click on image below to access the ONC Mobile Device Security Page ONC has also published a Mobile Device Fact Sheet

Read more

Your clients aren’t worried about HIPAA

March 28, 2014

Publication: MAX IQ The hard reality is that a lot of organizations including HIPAA Covered Entities (physicians, dentists, chiropractors) and their Business Associates (IT, medical billing, transcriptionists, and lawyers) aren’t overly worried about complying with HIPAA.

Read more

HIPAA Secure Now Voted Best Vendor at ASCII IT SMB Success Summit in Austin, TX

March 26, 2014

Austin, TX — (SBWIRE) — 03/25/2014 — HIPAA Secure Now! (HSN) was voted best vendor at the ASCII IT SMB Success Summit held in Austin, TX. The ASCII event was well attended by Managed Service Providers (MSPs). HSN was represented by Art Gross HSN President and CEO and Patrick Felicetta HSN National Partner Relations. Gross […]

Read more

Step by step approach to HIPAA security

March 9, 2014

When it comes to complying with the HIPAA Security and Omnibus Rules, there is a lot of confusion as to what needs to be done. And if you look at the amount of work it can be overwhelming; security risk assessment, employee training, policies and procedures, business associates, breach notification, encryption, disaster recovery to name […]

Read more

The reality of Meaningful Use audits

March 6, 2014

If anyone doubts that Meaningful Use (MU) audits are occurring, I would like a chance to change their mind. Yesterday 2 potential new clients contacted us with similar stories. Both had received letters from the Centers for Medicare & Medicaid Services (CMS) letting them know that they have been audited for Meaningful Use. One client […]

Read more

HIPAA audits: 800 covered entities and 400 business associates

February 24, 2014

Susan McAndrew, OCR deputy director for health information privacy, said in an interview with Information Security Media Group that the Office of Civil Rights (OCR) will resume its HIPAA compliance audit program. The audit program should resume in the coming months. Hopefully in coming months you’ll see actual activity that will start up on the […]

Read more

OCR HIPAA audit program to start with pre-audit survey

February 24, 2014

We have been writing about the permanent HIPAA audit program that will be put in place in 2014. Details of the program are starting to be released. The full text can be access by going to: Agency Information Collection Activities; Proposed Collection; Public Comment Request Here are some of the highlights: Number of Organizations A […]

Read more

Photocopiers are a danger to patient information – must watch video!

February 3, 2014

Almost every business uses a multi-function copy machine that copies, scans, prints and possibly faxes information. What most people don’t realize is that many of these machines have hard drives that store all information that the machine has access to. Think of these machines as computers that store a digital record of every copy it […]

Read more

Admit it, you don’t know where to start with HIPAA security

February 2, 2014

Like many other people, you keep hearing about increased HIPAA enforcement and the increase in patient data breaches. And naturally you are starting to worry. But here is the problem, you are not sure what to do about HIPAA security or where to start. Privacy is much easier HIPAA privacy is much more intuitive. Only […]

Read more

Basic rule to determine cloud provider’s HIPAA compliance

January 28, 2014

The HIPAA Omnibus Rule made major changes to how Business Associates are regulated under HIPAA. How can I tell if my cloud vendor is HIPAA compliant? One of the most frequent questions that we get asked by clients: How can I tell if my cloud vendor is HIPAA compliant? A lot goes into being HIPAA […]

Read more

HIPAA Security Tips and Reminders – Social Networks

January 27, 2014

Security Tips: Social Networks Click on  above to view in fullscreen mode!

Read more

More employees fired over posting a patient picture on Facebook

January 21, 2014

WZZM13 is reporting that several employees of Spectrum Health in Grand Rapids, MI have been fired over a picture of a patient posted on Facebook. A source tells WZZM 13 News that an off-duty employee was in the emergency room when he saw an attractive female. He took a picture of her back side and […]

Read more

Meaningful Use Risk Assessment for 2014

January 5, 2014

As we previously mentioned, we were busy in December, 2013 with practices rushing to get their Meaningful Use (MU) Risk Assessments completed by 12/31/2013. So here we are in 2014 and organizations need to be concerned about attesting for MU again. We are hoping to shed some more light onto MU Risk Assessments, ongoing MU […]

Read more

OCR gives more insight into 2014 plans

December 30, 2013

HealthITSecurity.com has a very good article called What the HIPAA Omnibus Rule meant for healthcare in 2013 They give a good overview of the HIPAA Omnibus Rule and its impact. What I found even more interesting is some of the comments by OCR regarding their plans for 2014. It gives clear insight into the permanent […]

Read more

Dermatology practice agrees to pay $150,000 HIPAA fine

December 27, 2013

This post is updated with an official company statement below Adult & Pediatric Dermatology of Concord, MA has agreed to pay a $150,000 HIPAA fine as a result of a HHS Office of Civil Rights (OCR) investigation. The 12 physician practice was investigated by OCR after they reported a loss of an unencrypted thumb drive […]

Read more

Tis the season of meaningful use risk assessments!

December 21, 2013

Usually you think of the last 2 weeks in December as a slow period in terms of work. Many people schedule vacations during these 2 weeks. But if you are performing Meaningful Use Risk Assessments it is anything but slow. As organizations rush to ensure their 2013 Meaningful Use Risk Assessment is completed, our HIPAA […]

Read more

Microsoft’s site helps with preventing weak passwords

December 12, 2013

Microsoft recently released a research website that will help prevent the use of weak passwords. Weak passwords can be easily guessed and can put sensitive information including patient information at risk. The new site is called Telepathwords According to Microsoft: How does Telepathwords work: Telepathwords tries to predict the next character of your passwords by […]

Read more

HIPAA Secure Now! Announces a Low Cost $399 HIPAA Security Service Aimed at Small Organizations

December 10, 2013

Morristown, NJ — (SBWIRE) — 12/10/2013 — HIPAA Secure Now! (HSN) announced today a low cost HIPAA security service aimed at organizations with 10 or fewer employees. The new service called the HIPAA Basic Service includes a thorough HIPAA / Meaningful Use risk assessment, HIPAA security training / compliance testing for all employees and 1 […]

Read more

OCR’s Clear Message: Protect Patient Information

November 20, 2013

U.S. Department of Health & Human Services’ (HHS) Office of Civil Rights (OCR) has produced a series of videos. The videos are targeted at both providers and patients. The message is clear, providers have the responsibility to protect patient information. Patients are educated on their rights and told to file a complaint if they feel […]

Read more

ONC’s 10 Myths of Security Risk Analysis

November 5, 2013

The Office of the National Coordinator for Health Information Technology (ONC) has published a list of the top 10 Myths of Security Risk Analysis. The complete list can be found here: http://www.healthit.gov/providers-professionals/top-10-myths-security-risk-analysis The first myth is one we get asked about all the time. 1.) The security risk analysis is optional for small providers. False. […]

Read more

HIPAA Security Tips and Reminders – Protecting Mobile Devices

October 24, 2013

ONC has launched a mobile device guidance page to help protect mobile devices. The page offers some good advice and tips to protect mobile devices including (go to the ONC page for more details on each): Use a password or other user authentication Install and enable encryption Install and activate remote wiping and/or remote disabling […]

Read more

3 things you can do for HIPAA compliance

October 17, 2013

Nobody thinks complying with the HIPAA Security and Omnibus Rules are easy. Both HIPAA regulations are hundreds of pages long, require a lot of understanding, planning, policies and technology to be in full compliance. It should be noted that there is a huge difference between not complying, trying to comply and being in full compliance […]

Read more

Google will sign a BAA but it will cost you

October 12, 2013

Microsoft used to be one of the only large cloud providers that was willing to sign a HIPAA Business Associate Agreement (BAA). That has changed now that Google has announced that they will sign a BAA for customers that use their Google Apps platform. Google Apps includes: Gmail, Google Calendar, Google Drive, and Google Apps […]

Read more

HIPAA Security Tips and Reminders – Protecting Your Laptop

October 2, 2013

Security Tips: Protecting your laptop Click on  above to view in fullscreen mode!

Read more

OCR gives more insight into increased HIPAA enforcement

September 26, 2013

Leon Rodriguez, director of the U.S. Department of Health & Human Services’ (HHS) Office for Civil Rights (OCR), spoke this week at the HIMSS Privacy and Security Forum in Boston. Rodriquez gave some interesting insight into where HIPAA enforcement is going. The permanent audit program is scheduled to be in place the beginning of 2014. […]

Read more

Won’t make the Omnibus deadline? It is never too late to be compliant

September 19, 2013

September 23, 2013, the official date that HIPAA Omnibus regulations are enforced. One of the results of the new HIPAA Omnibus Rule is that it has raised awareness of HIPAA regulations. Existing covered entities (hospitals, physicians, dentists, chiropractors) and business associates (IT companies, medical billing, law firms, etc.) are scurrying around in efforts to be […]

Read more

The AMA releases toolkit to help organizations comply with HIPAA Omnibus Rule

September 9, 2013

The American Medical Association (AMA) released a toolkit that helps organizations understand and comply with the HIPAA Omnibus Rule changes. Below is the table of contents from the toolkit (click on image to access the PDF toolkit). The toolkit gives a very good overview of the HIPAA Omnibus Rule changes.  In addition to the overview […]

Read more

HIPAA Compliance: Will you have a good story?

August 29, 2013

Here is a secret that compliance experts have known for a long time: It is very difficult to be 100% compliant with HIPAA regulations Of course, you have probably seen claims like these: Buy our product and we will make you HIPAA compliant Compliance in a box! Be HIPAA compliant in 30 days! Snake oil […]

Read more

960,000,000 Reasons to Encrypt Patient Information

August 27, 2013

Chicago based Advocate Medical Group announced that a burglary at their administrative office has resulted in a breach of 4 million patient records. Immediately after discovering that four computers were stolen, that same day, the Park Ridge Police Department was notified. AMG then launched an investigation and discovered that while the computers did not contain […]

Read more

Trendjacking the latest threat to patient information

August 10, 2013

Steve Thom wrote an interesting article called Trendjacking threats are a growing concern. Trendjacking is a refined phishing scam. Thom defines the term Trendjacking as: The term is “Trendjacking”, and it refers to spammers and malware authors using current trends to trick you into opening malicious email messages. Trendjacking scams are emails that come from […]

Read more

Your employees will cause your next HIPAA breach

August 6, 2013

When people think of HIPAA breaches a lot of times they think of hackers breaking into a network and stealing patient information. While that is a real concern, another cause of breaches should not be ignored. What is the other cause of breaches you should be concern with? Your employees. Employees cause HIPAA breaches. In […]

Read more

HIPAA Omnibus Rule Enforcement Countdown

August 1, 2013

HIPAA Omnibus Rule Enforcement Countdown [framed_box bgColor=”#d5d5d5″ textColor=”#BC1310″ rounded=”true”] HIPAA Omnibus Final Rule enforcement begins on September 23, 2013 [fergcorp_cdt_single date=”09/23/2013″] Eastern Standard Time [/framed_box] Are you ready? (Click on the links below for more information) Covered Entities Business Associates Now is the time to get ready for the HIPAA Omnibus Final Rule enforcement!

Read more

The threat of thumb drives to patient data

July 26, 2013

In the past you would need a truck to steal 10,000 patient’s charts. Now you can download a report out of an EHR and copy it to a thumb drive and stick it in your pocket. In an interesting article over at Business Insider called: The Biggest Threat To National Security Is The Thumb Drive, […]

Read more

We are a small practice do I need to worry about HIPAA security?

July 24, 2013

We had a discussion with a potential client today. We were explaining the requirements of the HIPAA Security Rule. The client stopped us and said: I am a small provider practice. I never heard of HIPAA security. Are you sure I need to do this? No one ever mentioned this to me. Not my lawyer, […]

Read more

HIPAA Secure Now! includes $100,000 financial protection from HIPAA breach and violation expenses

July 23, 2013

Morristown, NJ (SBWIRE) – July 23, 2013 –HIPAA Secure Now! announced today that the HIPAA Secure Now! annual HIPAA compliance subscription will include $100,000 of financial protection from HIPAA breach and violation expenses.  The financial protection will be included in the HIPAA Secure Now! annual compliance subscription for 50 employees or less. The financial protection […]

Read more

ONC Privacy & Security Training Games

July 15, 2013

The Office of the National Coordinator for Health Information Technology (ONC) has some great resources to help healthcare organizations ensure privacy and security of health information. Privacy & Security Training Games ONC has a very good privacy and security training game. The game gives real life scenarios and has the player make privacy and security […]

Read more

Don’t think We are too small a fish to worry about the HIPAA net

July 13, 2013

Big HIPAA penalties and fines make great news headlines. Recently the managed care company WellPoint Inc. agreed to pay a $1.7 million fine to settle potential HIPAA violations. False sense of security Large fines make headlines and show that violating HIPAA regulations can be very expensive. Unfortunately it can have an opposite effect as well. […]

Read more

Another business associate breach affects 277,000 patients

July 12, 2013

We have previously written about the risk of business associates (BAs) to patient information here and here. Now we have another large data breach caused by a hospital’s business associate. An article over at the Star Telegram goes into the details. A contractor for Texas Health Harris Methodist Hospital Fort Worth failed to destroy hundreds […]

Read more

HIPAA dangers of mobile devices

July 10, 2013

Mobile devices including laptops, tablets and smartphones are a growing threat to patient information. We wrote about how many organizations fail to realize how much protected health information (PHI) is on mobile devices. Ponemon Study In a very insightful study called The Risk of Regulated Data on Mobile Devices & in the Cloud, the risks […]

Read more

HHS video explains the HIPAA Security Rule

July 7, 2013

HHS released a short video (under 2 minutes) in 2012 that briefly explains the HIPAA Security Rule. With the upcoming HIPAA Omnibus Rule enforcement and the expanded regulation to Business Associates, we thought we would post the video again. Note the push to implement encryption to protect patient records! HHS OCR – HIPAA Security Rule […]

Read more

Evidence mounts that illegally selling PHI is big business

July 5, 2013

Recently we wrote about gang members stealing patient information and filing false tax returns and we wrote about meth dealers stealing patient information to obtain the materials to manufacture methamphetamine. Once again a there is a case where a hospital employee is accused of stealing patient information and selling it in exchange for crack cocaine. […]

Read more

Stanford HIPAA breach shows value of destroying PHI

July 2, 2013

The one thing you can say is that there are no 3 strikes and you are out when it comes to HIPAA breaches. Stanford Hospital in Palo Alto, Calif. recently suffered its 5th HIPAA breach since 2009. The most recent breach involved a stolen unencrypted laptop that contained 13,000 patient records. What makes this even […]

Read more

HIPAA breach exposes woman’s secret adoption

June 29, 2013

We have written about various HIPAA breaches but this breach is much easier to identify with. An article over at The Tampa Bay Times explains how a patient’s secret was exposed by a relative that was snooping in an EHR. Not only did the relative access her family member’s records inappropriately but she breached her […]

Read more

Employees quit practice and steal EHR data

June 24, 2013

The news on patient information breaches gets stranger every day. In an article over at Pensacola News Journal (pnj.com), 2 ex-employees are being sued for stealing patient information. Sight and Sun Eyeworks Gulf Breeze are suing a former physician and office manager for stealing patient information and trying to switch patients to the new practice […]

Read more

First gang members, now meth dealers want your health records

June 22, 2013

Back in April we wrote about gang members who are getting their girlfriends hired at medical practices.  The gang member’s girlfriends are stealing medical records and giving it to their boyfriends to file false tax returns. Detective Craig Catlin of the North Miami Beach Police Department Gang Unit goes so far as to call it an […]

Read more

Keeping Data Safe & HIPAA/HITECH Compliant (Infographic)

June 18, 2013

Read more

Ensure your Business Associates know how to protect patient information

June 15, 2013

We wrote about the risks of Business Associates (BAs) to patient information. The reality is many Business Associates have no idea of the requirements of HIPAA or the real risks to patient information. And even though all Business Associates will be responsible for complying with the HIPAA Security and Omnibus rules come September that may […]

Read more

Free HIPAA Security Training!

June 14, 2013

Click below to watch a short video on our free HIPAA security training! Clients love our HIPAA security training! We keep hearing that their employees find the training to be valuable and some even say it is fun (or as fun as HIPAA security training can be). We keep working to make the training engaging […]

Read more

Your smartphone will cause your next data breach

June 7, 2013

You may have read the headline and said to yourself “How can my smartphone cause a data breach if I don’t have any patient information on it?” While it may be true that you do not access your EMR on your phone, you should still be concerned. Smartphones are amazing devices. They have the power […]

Read more

Do you know what is going on in your EHR?

June 5, 2013

One of the requirements of the HIPAA Security Rule is to audit access to Protected Health Information (PHI). Auditing is the recording of access to PHI. It usually includes: who accessed PHI, when was PHI accessed and what PHI was accessed? Many EHRs and all certified EHRs for Meaningful Use have the ability to audit […]

Read more

Guilty until proven innocent regarding HIPAA breaches

May 30, 2013

The HIPAA Omnibus Final Rule brings a significant change to the HIPAA/HITECH Breach Notification Rule. Prior to the HIPAA Omnibus Rule, organizations were required to perform a risk assessment to determine if there was likely harm to a patient resulting from a privacy breach. Determining if the breach resulted in harm was referred to as […]

Read more

The calm before the HIPAA enforcement storm

May 28, 2013

Pilot Program Last year the Department of Health and Human Services’ Office for Civil Rights (OCR), which enforces HIPAA, conducted 115 HIPAA compliance audits. The program is being looked at as a pilot project that will eventually be used to put in place a permanent audit program. According to a HealthcareInfoSecurity interview with OCR’s Susan […]

Read more

What sets us apart?

May 26, 2013

A potential client asked us on a conference call: What sets HIPAA Secure Now! apart from your competition? A lot of companies offer similar services. I thought about the question for a second before responding. The client was right. There are a lot of companies that offer similar services. I responded: What sets HIPAA Secure […]

Read more

A closer look at the $400,000 Idaho State University HIPAA fine

May 23, 2013

The HHS Office for Civil Rights (OCR) announced that it has fined Idaho State University (ISU) $400,000 for failing to protect patient information. The HHS Office for Civil Rights (OCR) opened an investigation after ISU notified HHS of the breach in which the ePHI of approximately 17,500 patients was unsecured for at least 10 months, […]

Read more

HIPAA Secure Now! and BUMI Partner to Provide a HIPAA Compliant Data Backup Service

May 21, 2013

Introduces New HIPAA Compliant Data Backup Service, HIPAA Secure Backup Powered by BUMI Morristown, NJ (PRWEB) May 21, 2013 HIPAA Secure Now! and BUMI (Backup My Info!) announced today a new HIPAA compliant data backup service called HIPAA Secure Backup Powered by BUMI. BUMI is the premium provider of managed online backup and recovery solutions […]

Read more

The risk of having patient information is similar to the risk of owning a car

May 15, 2013

Risk of owning a car If you take a step back and think of the risks of owning a car I think you would be shocked. Cars have associated risks that could significantly impact you and your family. Some of the risks include: The risk of being hurt or killed in a car accident The […]

Read more

5 Common Myths About HIPAA Compliance – Infographic

May 7, 2013

The below infographic provides good insight into common myths of HIPAA compliance for medical practices. Embedded from HIPPOmsg.com Thanks goes out to HIPPOmsg for putting the infographic together! [framed_box bgColor=”#ffd390″] We put together a free guide to help your compliance effort called: 5 simple and inexpensive tips to protect patient information [/framed_box]

Read more

Microsoft updates BAA to address HIPAA Omnibus Rule

May 4, 2013

Microsoft has announced that they have updated their Business Associate Agreement (BAA) for  Microsoft Office 365. The new BAA addresses the requirements in the HIPAA Omnibus Rule that went into effect on March 26, 2013. Addressing HIPAA is embedded in the DNA of Microsoft’s cloud solutions, and Microsoft updated its BAA to help healthcare organizations […]

Read more

HIPAA Book of Evidence when OCR Audits Your Organization

May 2, 2013

There is a very good article over at HealthData Management called Want to Impress OCR During a HIPAA Audit? Write a Book The author discusses the benefits of creating a “Book of Evidence” that your organization is in HIPAA compliance if you were to get audited by the HHS Office of Civil Rights (OCR). Creating […]

Read more

Emergency operations plans under HIPAA – Boston metro lockdown scenario

April 23, 2013

The Harvard Business Review has an excellent article on how some Boston companies handled the Boston metro lockdown situation. The article points out that proper planning for emergencies is the best way to prepare in the event of a real emergency. The Cambridge-based company, HubSpot, had an emergency operations plan in place and executed the […]

Read more

Here is why you haven’t addressed HIPAA security yet

April 22, 2013

We know you know about HIPAA security. HIPAA breaches are in the news on a weekly basis. The new HIPAA Omnibus Rule has been finalized and there is a lot of buzz about it. So the question is why haven’t you gotten serious about HIPAA security? We think we know some of the reasons.   […]

Read more

Farzad Mostashari, MD gives good insight into healthcare IT

April 18, 2013

Dr. Farzad Mostashari, the National Coordinator for Health Information Technology at the U.S. Department of Health and Human Services, participated in an excellent interview. He gave insight into: EHR technologies Where the Meaningful Use program is headed EHR interoperability The future of Regional Extension Centers It was a very good interview and I urge everyone to read […]

Read more

Additional insight into: Why Gang Members Want Your Identity

April 9, 2013

In a very interesting article titled Why Gang Members Want Your Identity Fox Business News reporter Kate Rogers examines a disturbing trend of stealing electronic patient records and using them to commit crimes. Gang members are stealing patient records and using them to file false tax returns. Detective Craig Catlin of the North Miami Beach […]

Read more

A valuable look into cybercrime and cyber / HIPAA insurance

April 4, 2013

Two recent articles shed some needed light on the risk of Cybercrime to small businesses including medical practices. Most Small Businesses Don’t Recover From Cybercrime The first article from the Wall Street Journal titled Most Small Businesses Don’t Recover From Cybercrime examines how many small businesses suffer from cyberattacks and the consequences of those attacks. […]

Read more

Information security director talks of increased HIPAA enforcement

March 28, 2013

An article over at Healthcare IT News titled Get set: New HIPAA has teeth gives insight into the increased HIPAA enforcement that is looming. Diana Manos interviewed Jorge Rey, an associate principal and the director of information security and compliance for Kaufman, Rossin for the article. Rey provides some insight into some of the changes […]

Read more

Microsoft Office 365 for Healthcare

March 26, 2013

We have put together some useful information on Microsoft’s HIPAA compliant cloud based Office 365 service. The Office 365 suite of products enables communication and collaboration while providing the required HIPAA security to protect patient information. Microsoft is the only leading cloud provider that will sign a HIPAA Business Associate Agreement. Our Microsoft Office 365 […]

Read more

Entegration’s move to Microsoft Office 365

March 25, 2013

This is a guest post from C. Patrick Felicetta. Patrick is the Entegration, Inc. Chief Operating Officer (COO). He gives some good insight into some of the advantages of Microsoft’s cloud based Office 365 service. For the past 13 years Entegration, Inc., a computer networking company, has specialized in meeting the IT needs of healthcare […]

Read more

Incredibly detailed analysis of a HIPAA security breach

March 21, 2013

I came across an article on HIStalk Practice that describes exactly what happens when a laptop containing patient information is stolen from an employee’s car.  The stolen laptop cost the company around $300,000.  An analysis and breakdown of the costs are provided in the article. A few things to note about the article: The article […]

Read more

A closer look at a real-life HIPAA breach notification

March 20, 2013

The Gloucester, MA Fire Department Ambulance Service experienced a HIPAA security breach when one of its billing company’s employees improperly accessed and disclosed patient account information. The employee was involved in a scheme to file false federal tax return. The Gloucester Fire Department Ambulance Service posted a substitute data breach notice on the Gloucester government […]

Read more

ONC video explains Health IT to patients

March 18, 2013

The Office of the National Coordinator for Health Information Technology (ONC) has released a very good video that explains the push towards Electronic Health Records (EHR). The video is aimed at patients so they understand Health IT and the push to upgrade technology. From the ONC website: Health Information Technology, or Health IT for short, […]

Read more

Most common BA question regarding HIPAA Omnibus

March 15, 2013

We have received a lot of questions from our clients regarding the changes to HIPAA from the HIPAA Omnibus Rule. The most common question to date has been around Business Associate Agreements (BAAs). The questions come from covered entities as well as business associates. The question is basically the same for a different perspective. We […]

Read more

More Phishing Scams – LinkedIn

March 14, 2013

My inbox had a lot of emails from LinkedIn today. I sent several requests to connect last night and I received notifications that these people accepted the invitation. But a few of the notifications were about people I didn’t even know. My first reaction was to click on the link to go to LinkedIn and […]

Read more

Make HIPAA easy

March 13, 2013

Make HIPAA easy When we started to build the HIPAA Secure Now! service, we had 2 goals. Those goals were to help clients with protecting patient information and to “make HIPAA easy”. We realize most organizations hate HIPAA. We thought if we could build a service with the following characteristics, clients may not love HIPAA […]

Read more

OCR Director talks about breaches and encryption

March 6, 2013

Office for Civil Rights Director Leon Rodriguez presented at the HIMSS13 conference Monday morning. His message was very clear. Organizations that make an effort to protect patient information by the use of encryption and organizations that respond and learn from breaches will be much better off. Organization’s “willful neglect” of the HIPAA regulations and failure […]

Read more

Make no mistake, HIPAA enforcement to increase!

February 28, 2013

The Federal government is not being shy or covert about the increase in HIPAA enforcement that is about to occur. Covered Entities (Physician Practices and Hospitals) as well as Business Associates (Contractors and Subcontractors of Covered Entities) should have no doubt that compliance with HIPAA is no longer an optional activity. There is no way […]

Read more

HIPAA Omnibus and Microsoft Office 365

February 16, 2013

As we mentioned here and here, the HIPAA Omnibus Rule has a significant impact on HIPAA Business Associates. There is some debate over exactly who is a Business Associate regarding Cloud Providers. One thing that seems clear is, if you are storing protected health information (PHI) unencrypted at a Cloud Provider, the Cloud Provider most […]

Read more

CEs responsibilities for BAs under the HIPAA Omnibus Rule

February 13, 2013

In a previous blog we discussed the new HIPAA Omnibus regulations as they related to Business Associates (BA). Let’s take a look at the HIPAA Omnibus regulations for Business Associates as they relate to Covered Entities (CE). Business Associates Agreements CEs have been required to have Business Associate Agreements (BAAs) with BAs for quite a […]

Read more

Business Associates under the HIPAA Omnibus

February 12, 2013

There is lots of buzz about the changes to Business Associates under the new HIPAA Omnibus Rule. Let’s take a look at some of the items that both Covered Entities (CE) and Business Associates (BA) should know about the new HIPAA changes. Who are Business Associates? The definition of Business Associates for the most part […]

Read more

Not encrypting laptops is negligent

January 24, 2013

If you work in a healthcare organization and you have a laptop it should be encrypted. We have heard many discussions about why a laptop does not need to be encrypted. Some of the reasons include; it doesn’t contain patient information or it never leaves the office or it never leaves our employee’s possession. Laptops […]

Read more

DHS advises disabling Java in Browsers

January 12, 2013

The Department of Homeland Security (DHS) is advising people to disable Java in their browsers (Internet Explorer, Chrome, Safari, etc.). According to a CBS News report: The recommendation came in an advisory issued late Thursday, following up on concerns raised by computer security experts. Experts believe hackers have found a flaw in Java’s coding that […]

Read more

2012 strangest data breaches

January 9, 2013

Gienna Shaw over at FierceHealthIT has an entertaining article on some to the strangest security breaches in 2012. Here are her “highlights” of 2012. 1.) EMR held ransom (We also discussed another EMR ransom case here) In the Lake County case, an unauthorized remote user posted a message on the practice’s server stating that its […]

Read more

HIPAA fine for breach under 500 patients

January 3, 2013

The HHS Office for Civil Rights (OCR) has fined the Hospice of North Idaho (HONI) $50,000 for a breach resulting from a stolen laptop. What makes this unique is it represents the first time an organization has been fined for a breach of less than 500 patients. We will take a look at the details […]

Read more

Lawyer warns against ignoring HIPAA

January 2, 2013

In an article over at Healthcare IT News, Philadelphia attorney Christopher Ezold gives some very good insight that organizations should not ignore HIPAA requirements. Ezold hits on many good points to drive this home: Ezold warns that while enforcement of PHI rules have been lax in the past, the Department of Health and Human Services […]

Read more

The most dangerous HIPAA action of the year

December 31, 2012

The most dangerous HIPAA action you can do is very simple: DO NOTHING You may be under a false sense of security because none of these events have happened to your organizations: You haven’t had a HIPAA breach You haven’t received a HIPAA fine You didn’t need to use a Security Incident Response Plan You […]

Read more

Washington Post slams healthcare security

December 27, 2012

The Washington Post published a report that is highly critical of the security of patient information in the healthcare industry. A year-long examination of cybersecurity by The Washington Post has found that health care is among the most vulnerable industries in the country, in part because it lags behind in addressing known problem Avi Rubin […]

Read more

Protecting those shiny new smartphones

December 22, 2012

This year more and more employees are going to get smartphones this holiday season. And more and more employees will be asking for access to email and data via those new smartphones. You may take the stance and say “no” to access via smartphones. But these employees might have access to email and data already […]

Read more

ONC’s mobile device privacy and security website

December 20, 2012

ONC has launched a mobile device guidance page to help protect mobile devices. The page offers some good advice and tips to protect mobile devices including (go to the ONC page for more details on each): Use a password or other user authentication Install and enable encryption Install and activate remote wiping and/or remote disabling […]

Read more

Having a Security Incident Response Plan can lower your HIPAA fine

December 19, 2012

Having a Security Incident Response Plan (SIRP) will allow an organization to respond to a security incident.  We define the steps of a SIRP here. An article over at Government Health IT has a question and answers segment that Leon Rodriguez, director of the Office of Civil Rights (OCR) at the Department of Health and Human Services […]

Read more

Get ready for OCR to hand out larger HIPAA fines in 2013

December 17, 2012

Leon Rodriguez, director of the Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) recently conducted an interview with HealthcareInfoSecurity. Click on the link to listen to the full interview. Rodriguez gave some valuable insight into OCR’s plans for 2013 and beyond as well as guidance that organizations should follow to protect […]

Read more

Deeper look at preventing EMR hijacking

December 15, 2012

In our post New reality: EMRs held hostage we discuss the Australian medical center that had their EMR encrypted. The hackers then demanded $4,000 ransom to decrypt the EMR. Let’s take a look at how something like this can happen. The more you know about how hackers can get into your network the better you […]

Read more

HIPAA audits to continue into 2013

December 12, 2012

Dom Nicastro over at HCPro gives insight into the status of the OCR audit program for 2013. Top OCR officials have made it clear the audit ­program will continue next year, says Mac McMillan, FHIMSS, CISM, cofounder and CEO of CynergisTek, Inc., in Austin, Texas. There will be more audits going forward; HITECH requires them, […]

Read more

New reality: EMRs held hostage

December 11, 2012

Data security and protecting valuable information is the new Wild West. There is a constant battle between trying to protect data and criminals intent on stealing or hacking data. In a story that broke yesterday, Russian cyber criminals have hacked into a medical organization and held their patient information ransom. The Australian medical center, Miami […]

Read more

Beyond the HHS Wall of Shame

December 10, 2012

By now many people have heard of the HHS Wall of Shame. The Wall of Shame refers to the list of organizations that have had a breach affecting 500 or more individuals. The list includes the name of the organization, the date of the breach, the approximate number of individuals affected, the type of breach […]

Read more

Practices with 1-100 employees account for 60% of all data breaches

December 6, 2012

According to a report produced by the Health Information Trust Alliance (HITRUST), there has been little progress in reducing the amount of healthcare related data breaches. A close look at the HHS data reveals that since 2009 the industry has experienced 495 breaches involving 21 million records at an estimated cost of $4 billion. With […]

Read more

OIG wants proof before making meaningful use payments

November 29, 2012

The Office of Inspector General (OIG) is criticizing CMS’ oversight of the Meaningful Use incentive program. They worry that CMS might be paying organizations who do not qualify for Meaningful Use incentives. This study is an early assessment of CMS’s oversight of the Medicare electronic health record (EHR) incentive program, for which CMS estimates it […]

Read more

Hurricane Sandy tests organization’s HIPAA availability requirements

November 15, 2012

When people think of the HIPAA Security Rule many think about protecting the privacy / confidentiality of patient information. Privacy is a major part of HIPAA security but also ensuring the availability of patient information is equally important. Let’s take a look at the HIPAA Security General Rules: § 164.306 Security standards: General rules. (a) […]

Read more

Terrifying reasons to protect patient information

October 4, 2012

We write a lot about protecting patient information and HIPAA security. It is widely known that over 20 million patient records have been breached in the past few years. Have you ever thought about some of the consequences of breach medical information? We came across a very interesting blog article over at 403 Blogs. 403 […]

Read more

MLEMA Testimonial

September 24, 2012

Below is an awesome testimonial from David Grossman, M.D. at Main Line Emergency Medicine Associates (MLEMA)   I am the Compliance officer, for Main Line Emergency Medicine Associates (MLEMA), We are an emergency medicine practice, conducting provider services for Main Line Health hospitals, in southeasternPennsylvania.  In February, 2012, our practice decided to get Breach insurance and […]

Read more

Healthcare Providers Insurance Exchange (HPIX) and HIPAA Secure Now! Announce Partnership

July 27, 2012

We are very excited to announce that Healthcare Providers Insurance Exchange (HPIX) and HIPAA Secure Now! have created a partnership to provide HIPAA risk assessments to all of HPIX clients. HPIX will pay for the risk assessment and provide the service free to their clients. HPIX will utilize our HIPAA Secure Now! service to perform […]

Read more

A closer look at the Alaska HIPAA fine

July 5, 2012

The Alaska Department of Health and Social Services (DHSS) was handed a $1.7 million fine by the Office of Civil Rights (OCR). The fine is one of the largest imposed on an organization. A closer look reveals why the fine was so large. Healthcare Info Security gives an in-depth look at the fine. The Alaska […]

Read more

A look at the OCR Audit Protocol

June 26, 2012

OCR released the details of the HIPAA audit protocol. There aren’t a lot of surprises in their list of items they look for during an audit. The protocol looks like a summary of the HIPAA Privacy and Security Rules with the addition of the Breach Notification Rule. There are 77 items for HIPAA Security and […]

Read more

Medical practices stand little chance against cyber-criminals

June 12, 2012

We wrote about LinkedIn having 6 million passwords stolen. eHarmony has also been a victim of 1.5 million passwords being stolen. The clear message here is that if these large websites can be victims of cyber-criminals, much smaller organizations stand little chance in defending its information. Both LinkedIn and eHarmony are well funded companies that […]

Read more

LinkedIn passwords hacked

June 11, 2012

By now you may have heard about the 6 million passwords that were stolen from LinkedIn. The passwords were posted on a Russian online forum. The passwords were encrypted but through the use of password cracking programs many of the passwords have been cracked. An article over at IT security company Qualys goes into details […]

Read more

The danger of HIPAA self risk assessments

May 30, 2012

There are many tools available to organizations that help them perform the required HIPAA and Meaningful Use Risk Assessment. The problem with an organization doing their own Risk Assessment revolves around the saying What you put in is what you get out In order to get an accurate analysis of risks to patient information it […]

Read more

The HIPAA speed trap

May 23, 2012

You have been driving 45 mph on the same 25 mph road for years. There are never any police on the road and there is really no reason to drive 25 mph. Then after years of ignoring the posted speed limit, one day a police officer is waiting behind a tree and pulls you over […]

Read more

HIPAA “Need to know basis”

May 16, 2012

There is a good article over at the Vormetric Security Blog that looks at restricting employee access to patient information. They argue that not all employees need full access and unless an employee can demonstrate that access is needed to perform their job function, no access to patient data should be given. The below paragraph […]

Read more

ONC’s Risk Assessment Myths and Facts

May 15, 2012

The office of National Coordinator for Health Information Technology (ONC) has published a useful guide to Privacy and Security of Health Information (PDF). One of the sections looks at common myths and facts about a security risk analysis / assessment.  Let’s take a look at it in more detail. Below are ONC’s myths and facts: Let’s look […]

Read more

A closer look at phishing scams

May 13, 2012

There are many threats to patient information and financial resources and one that seems to be popping up a lot lately is phishing scams. A phishing scam is basically an email that looks like a legitimate email from a bank, credit card company, retail stores, social networks (Facebook, Twitter, LinkedIn, etc.). The email usually has […]

Read more

More on Phoenix Cardiac Surgery’s $100,000 HIPAA Fine

May 9, 2012

We have written about the $100,000 HIPAA fine that was handed down to Phoenix Cardiac Surgery. There is a very good article at AISHealth that details the case and provides some good insight by industry professionals. One quote by well respected HIPAA attorney Jeff Drummond really sheds light on what happens when you ignore compliance […]

Read more

Make sure you encrypt your backup tapes

May 7, 2012

Many organizations are still using tapes to backup data. Those organizations that are still using backup tapes need to ensure that the tapes utilize encryption. Without encryption, a lost or stolen backup tape could result in a very large data breach. Best network practices call for performing a backup on all systems at least daily. […]

Read more

Changing landscape of healthcare IT

May 6, 2012

There should be no doubt that we are witnessing a changing landscape for healthcare IT. As the government gives billions of dollars in incentives to hospitals and medical practices to implement electronic health records the repercussions are being heard around the country. Medical practices are going from low-tech businesses that focused on paper charts and very little […]

Read more

Introducing our Small Business Package

May 2, 2012

We are excited to announce our new Small Business Package. The Small Business Package is for organizations with 10 or fewer employees. We have reduced the price of the complete HIPAA Secure Now! service from $1,750.00 to $999.00. The Small Business Package is exactly the same as our regular service and includes custom policies and […]

Read more

We are not another company selling HIPAA products

May 1, 2012

You’ve seen hundreds of companies selling HIPAA products. There are HIPAA training videos, policy templates, consultants, HIPAA books, HIPAA coffee mugs and the list goes on and on.  And yet “become HIPAA compliant” is still on your long list of things to do. Have you asked yourself why you never seem to get to “become […]

Read more

How HIPAA Secure Now! would’ve helped Phoenix Cardiac Surgery

April 23, 2012

We have written about the HIPAA fine and reputation damage to Phoenix Cardiac Surgery. Phoenix Cardiac Surgery is a small 5 physician specialist in Phoenix, AZ. Let’s quickly review why the Office of Civil Rights fined Phoenix Cardiac Surgery $100,000. Lack of HIPAA Policies and Procedures Lack of HIPAA training for all workforce members Lack […]

Read more

OCR HIPAA fine and resolution agreement

April 20, 2012

The Phoenix Cardiac Surgery medical practice was handed a $100,000 fine for failing to protect patient information. The resulting resolution agreement from the Office of Civil Rights (OCR) is very interesting. Let’s take a look at is. The full resolution agreement can be found here (PDF). Lack of training for employees (a) From April 14, […]

Read more

Phoenix Cardiac Surgery – HIPAA violation

April 19, 2012

There has been a lot written recently about organizations that have received high profile HIPAA fines from the Office of Civil Rights (OCR). The Tennessee Blue Cross Blue Shield was handed a $1.5 million fine, Cignet Health was given a $4.3 million fine and Massachusetts General Hospital was awarded a $1 million fine. The only […]

Read more

The risk of business associates to patient data

March 31, 2012

In the Ponemon 2011 Cost of Data Breach Study, 41% of breaches were due to third party mistakes. Take a step back and think about the impact of that number. The use of third party organizations are more and more common. According to the HHS.gov website, some examples of third party / business associates include: […]

Read more

A look at the cost of healthcare data breaches

March 30, 2012

The annual Ponemon 2011 Cost of Data Breach Study has been released and it gives very good insight. The study looks at various costs of data breaches across industries such as media, retail, financial, healthcare and pharmaceutical. Let’s focus in on the costs of data breaches in the healthcare industry. Overall the average cost of […]

Read more

Encryption for data at rest

March 28, 2012

Part of the proposed requirements for Meaningful Use Stage 2 addresses encrypting data at rest. Let’s take a look at the exact wording conduct or review a security risk analysis in according with the requirements under 45 CFR 164.308(a)(1), including addressing the encryption/security of data at rest in accordance with requirements under 45 CFR 164.312(a)(2)(iv) […]

Read more

A practical look at a HIPAA Incident Response Plan

March 14, 2012

Many people ask us what is needed for an Incident Response Plan (IRP).  It seems to be one of the HIPAA requirements that people have a hard time putting their arms around. So let’s take a practical look at what is needed. Incidents will happen The first thing that must be accepted and understood is […]

Read more

OCR video explaining the HIPAA Security Rule

February 28, 2012

The Office of Civil Rights (OCR) has released a series of videos to help practices and medical professionals understand the HIPAA regulations. Unfortunately as of today it is not a very well-known resource, each of the 4 videos has less than 75 views. Hopefully with more awareness of this resource, more people will watch the […]

Read more

OCR to offset budget cuts with fines it collects

February 27, 2012

In an interview with Howard Anderson over at healthcareinfosecurity.com, OCR’s Leon Rodriguez gives some interesting insight into OCR’s audit program. Some are some highlights of the interview: Due to funding cuts and capacity of KPMG, the firm hired to conduct the audits, the agency may come up short of the 150 planned audits OCR funding […]

Read more

Meaningful Use Stage 2 – IT impact

February 24, 2012

The proposed meaningful use stage 2 requirements were posted yesterday. The requirements are over 450 pages so we are still going through them and trying to digest them. As of now, two major IT related items jump out at us. The first IT related objective is focused on protecting and securing patient information. In stage […]

Read more

Meaningful Use Stage 2 and Encryption

February 19, 2012

As John Lynn and Neil Versel have both reported, it looks like the Meaningful Use (MU) Stage 2 proposal will be out in the next few weeks. One area of interest will be the wording around the use of encryption to protect patient information. Currently the HIPAA and HITECH regulations do not make the use […]

Read more

6 things you must know about HIPAA Security

February 14, 2012

There is a lot to know about HIPAA but let’s take a look at 6 things that you must know. HIPAA is not optional A lot of practices feel they are exempt from the HIPAA regulations. This may stem from the fact that “small practices” were granted a 1 year extension to comply with the […]

Read more

HIPAA audits have begun

January 6, 2012

Over at Healthcareinfosecurity.com there is an insightful article on the first HIPAA audits. Some highlights of the article include: In the pilot phase, OCR is auditing eight health plans, two claims clearinghouses plus 10 provider organizations, including three hospitals, three physicians’ offices, and a laboratory, a dental office, a nursing/custodial facility and a pharmacy.   […]

Read more

The importance of HIPAA training and social networks

January 4, 2012

  A recent incident shows just how important it is to train all workforce members on the HIPAA regulations. Notice how I used the words workforce members and not just employees. A temporary staff member of Providence Holy Cross Medical Center recently posted patient information on Facebook. The temporary staff member also made fun of […]

Read more

A look back and a glance forward

December 26, 2011

2011 has been a great year for us and we couldn’t be more excited for 2012. We had the opportunity to work with some really great people at a lot of different medical practices throughout the United States. We got to show that the HIPAA Secure Now! process really works and can help practices with […]

Read more

Taking a look at NIST HIPAA Security Rule Toolkit

November 28, 2011

The National Institute of Standards and Technology (NIST) has recently released a HIPAA Security Rule Toolkit to help organizations comply with the HIPAA Security Rule. From their website: The NIST HIPAA Security Toolkit Application is intended to help organizations better understand the requirements of the HIPAA Security Rule, implement those requirements, and assess those implementations […]

Read more

Guest blog | SPAM filiters

October 7, 2011

Kim Falkner from SPAMfighter is our guest blogger and gives her insight into hosted vs. in-house SPAM filters. It is a good topic because with SPAM comes risks to electronic protected health information (ePHI). Hosted spam filter? Better than in-house software? We do not have to delve on the fact that spam is an annoyance […]

Read more

You received a HIPAA audit notification, now what?

October 5, 2011

The Department of Health and Human Service (HHS) has announced that they will perform 150 HIPAA audits by the end of 2012. The chance of you getting audited is very small but what if you open up your mail one day and found a notice that your medical practice has been select to be audited? […]

Read more

150 HIPAA audits a preview of more to come

October 4, 2011

Leon Rodriquez the head of OCR, in an interview, stated that the 150 HIPAA audits is just a pilot program. OCR recently hired the consulting firm KPMG to launch a HIPAA compliance audit program, with 150 audits anticipated by the end of 2012. Because this is the first time the office is conducting audits, the […]

Read more

OCR’s Leon Rodriguez gives insight in HIPAA Audits

October 3, 2011

Howard Anderson, Executive Editor over at HealthcareInfoSecurity.com had an insightful interview with Leon Rodriguez, the new director of the Department of Health and Human Services’ Office for Civil Rights. Rodriquez a former prosecutor and defense lawyer talks about his priorities as the head of OCR. He states: Making enforcement a priority (because) enforcement promotes compliance […]

Read more

Practice Administrators are the key to HIPAA security

September 30, 2011

Every day we work with Practice Administrators (PAs) to help them with HIPAA compliance. It is amazing how much responsibility is placed on a PA’s plate. They are involved with hiring and firing of employees, billing, scheduling, personnel issues, insurance issues, patient issues, equipment issues, technology issues, provider issues and compliance issues. It is amazing […]

Read more

Don’t skip the meaningful use risk assessment

September 16, 2011

FierceEMR posted a story on how some providers are attesting to meaningful use measures but are actually not addressing all of the required measures. Specifically some providers are stating that they have performed a meaningful use risk assessment on how patient data is being protected but have not actually performed the risk assessment. The article […]

Read more

No doubt HIPAA enforcement is coming

September 15, 2011

It seems that every day it becomes more and more clear that the government is planning on enforcing HIPAA regulations. Patient data privacy and security is becoming their priority. This could have to do with the fact that almost 8 million patients have had their data breached over the past 2 years. And considering that […]

Read more

A look at the upcoming 150 HIPAA audits

September 13, 2011

The Department of Health and Human Services (HHS) announced that they have awarded a $9.2 million contract to the consulting firm KPMG. KPMG will develop the process and perform HIPAA audits. There will be an estimated 150 onsite audits by the end of 2012. The audits are a requirement under the HITECH act and have […]

Read more

7.9 million records breached and counting

September 10, 2011

According to a report to Congress from The Department of Health and Human Services (HHS), there have been almost 8 million records breached since 2009. That is a staggering number. What is worse it that the number of data breaches continues to increase. Another way of looking at it is that we are only in […]

Read more

HIPAA Security Tips and Reminders – Disasters

August 30, 2011

Security Tips: Disasters: Are You Prepared? Click on  above to view in fullscreen mode!

Read more

How risk assessments lower the risk to patient data

August 11, 2011

One of the most important aspects of complying with the HIPAA Security Rule is to perform a risk assessment to evaluate how an organization is protecting patient data.  The results of the risk assessment provide a playbook for how additional protections can lower the risk to patient information. Let’s take a closer look at the […]

Read more

Lesson from the KPMG data breach

August 10, 2011

In a very embarrassing and ironic turn of events, KPMG announced that they had a data breach that involved 4,500 patient records. KPMG has been selected by The Office of Civil Rights (OCR) to perform HIPAA compliance audits. So it appears that the company that will do HIPAA audits has experienced a HIPAA related data […]

Read more

Details of the HIPAA audits

August 4, 2011

Health Info Security has published the transcript from an interview with Susan McAndrew of the Department of Health and Human Services’ Office for Civil Rights. The article is very good and should be read in its entirety. Below are some of the key points. When asked if business associates as well as covered entities will […]

Read more

OCR’s McAndrew discusses upcoming HIPAA Audits

July 15, 2011

Susan McAndrew, deputy director of The HHS Office of Civil Rights (OCR) gives a very insightful interview to Howard Anderson, Executive Editor, HealthcareInfoSecurity.com. There are a lot of good points and I suggest reading the whole interview. I will point out a few of the highlights. When asked about who will be audited, McAndrew was […]

Read more

HHS to perform 150 HIPAA Audits by end of 2012

July 12, 2011

Last week the Department of Health and Human Services (HHS) announced that they have awarded a $9.2 million contract to the consulting firm KPMG. KPMG will develop the process and perform the HIPAA audits. There will be an estimated 150 onsite audits by the end of 2012. “Site visits conducted as part of every audit […]

Read more

Microsoft’s Office 365 Cloud Service to offer Business Associate Agreements

June 29, 2011

Microsoft’s latest cloud based service called Office 365 was recently released. More than 200,000 organizations participated in the beta testing period. Office 365 provides the following: Microsoft Office, Microsoft SharePoint Online, Microsoft Exchange Online and Microsoft Lync Online in an always-up-to-date cloud service, at a predictable monthly subscription. In addition, Microsoft is trying to target […]

Read more

Why people hate HIPAA

June 4, 2011

Working with clients over the years, we have come to the conclusion that most people hate HIPAA. There we said it! Fortunately we don’t take it personally because we actually understand why people hate HIPAA. Here are a few valid reasons. HIPAA is confusing HIPAA is boring HIPAA is expensive HIPAA gets in the way […]

Read more

HIPAA Secure Now! available to MedTech GPO

June 4, 2011

Entegration, Inc. Joins MedTech For Solutions Group Purchasing Organization as a New Vendor Morristown, NJ, June 04, 2011 –(PR.com)– Entegration, Inc. (Entegration) is pleased to announce that they have joined MedTech For Solutions Group Purchasing Organization (GPO) (MedTech) as a new vendor. This partnership will enable Entegration to provide Information Technology (IT) services to the […]

Read more

A closer look at a HIPAA Risk Assessment

May 27, 2011

In a previous post I discussed the risk of having patient information on smartphones. I ended the post with stating that a HIPAA Risk Assessment can help reveal where security measures are needed. Let’s look at that a little more in depth. Many people are confused as to what a HIPAA Risk Assessment is. Here […]

Read more

Choosing security products is difficult

May 26, 2011

The problem with HIPAA compliance and security in general is that there are so many products and services on the market, how does one decide which are the right ones? Let’s not discuss a HIPAA security service (although we hope you choose HIPAA Secure Now!) but let’s look at after you have taken the first […]

Read more

Beware of patient information on smartphones

May 25, 2011

I had a conversation with a group of physicians a couple weeks ago that shed some interesting light on where patient information resides and how to protect it. Each of the 5 physicians had a smartphone of various manufacturers. Two had iPhones, two had Android phones and one had a Blackberry phone. I asked the […]

Read more

When real life disasters happen

May 24, 2011

Joplin, MO was hit by a massive tornado on Sunday evening that did extensive damage to the St. John’s Regional Medical Center hospital. There are reports that x-rays from the hospital have been found in driveways 70 miles east of the hospital. On Twitter Steven Waldren sheds some very interesting and insightful perspectives: Steven’s quotes gets to […]

Read more

Why are HIPAA regulations ignored but IRS regulations aren’t?

May 23, 2011

The IRS audits about 1.5% of all tax returns that are filed. Looked at another way, there is a 98.5% chance that the IRS will not audit your return. Yet even with this very low percentage of people that get audited, most people are very frightened that they will be one of the unlucky individuals. […]

Read more

Why you need to invest in HIPAA Security

May 22, 2011

To be successfully in any business you need a few basic elements.  Two of the elements include; customers that value your service and are willing to purchase your services. Secondly, you also need to eliminate or reduce liabilities that can damage or hurt your business. Implementing HIPAA security can help your business The first element […]

Read more

Insightful letter from OCR following a data breach

May 18, 2011

There is a great post over at Infosec Island regarding a letter that was received from the Office of Civil Rights (OCR) after a data breach that occurred at a small medical practice. The breach was the result of a burglary. No details were given on what was stolen or what kind of patient information […]

Read more

Encryption is too easy and cheap to not use it

May 6, 2011

It seems that at least twice a month we are hearing about a health care organization that has had a data breach because of a lost of stolen laptop. Every time I read about a new breach I shake my head and ask myself why aren’t these organizations using encryption to protect the contents on […]

Read more

5 easy steps to protecting patient data

May 1, 2011

Medical practices are not only tasked with protecting their patient’s health but now are responsible for protecting their patient’s electronic information as well. Protecting data is probably something that most practice employees have not been trained to do nor are they familiar with best security practices. Data security is usually left to IT consultants who […]

Read more

Dropbox is not HIPAA compliant

April 29, 2011

An article over at KevinMD.com on using Dropbox to store transcriptions has set off a lot of conversation on Twitter asking if Dropbox is HIPAA compliant. Let’s look at what the article references: www.dropbox.com Download the Dropbox software (free) and save files to your Dropbox in the cloud. Access Dropbox files from any computer with a web […]

Read more

Fear and destroy USB drives!

April 8, 2011

In what appears to be a reoccurring story, another hospital is notifying over 90,000 patients that their personal information has been breached. MidState Medical Center in Meriden, Conn., has notified around 93,000 patients that their information was stored on a USB drive and the drive is now lost. Information on the drive included names, addresses, […]

Read more

What does it take to be compliant with the HIPAA Security Rule?

March 31, 2011

One of the questions that I get asked a lot is;  What does it take to be compliant with the HIPAA Security Rule? And when I start to answer the question, inevitably the person’s eyes glaze over.  So to prevent your eyes from glazing over I will give the simple answer: A lot. OK, that […]

Read more

Looking for guest bloggers and partners!

March 30, 2011

Let’s work together! At HIPAA Secure Now! our main focus is on helping healthcare organizations become compliant with the HIPAA Security Rule and HITECH act. We realize that we are only a piece of the puzzle. We can help with policies and procedures, a risk assessment and training but there is a lot more to […]

Read more

HHS should embrace social media for HIPAA education

March 28, 2011

As we work with more and more clients to help them comply with the HIPAA Security Rule, it is becoming clear that many people don’t fully understand HIPAA. The good news is that we can help them understand HIPAA and all the things that need to be done to comply with HIPAA and to protect […]

Read more

Recruit employees to protect patient data

March 18, 2011

The Health and Human Services’ Office of Civil Rights (OCR) has handed out over $5 million in HIPAA fines in the past 2 weeks.  OCR has also stated that more HIPAA enforcement is coming.  So now is a very good time to think about how you can avoid regulatory penalties and even more importantly, how […]

Read more

Analysis of OCR’s message on HIPAA

March 16, 2011

OCR is serious about enforcement! That is a message that 3 officials from the U.S. Department of Health and Human Services’ Office for Civil Rights made clear as they presented at the 19th National HIPAA Summit. The 3 officials who presented (links below take you to their presentations [PDF] ) were: Susan McAndrew – Deputy Director for […]

Read more

OCR shows its serious about HIPAA enforcement

March 11, 2011

The Office for Civil Rights (OCR) showed once again that is serious about enforcing the HIPAA security and privacy regulations. OCR invited the 50 state attorneys general (AG) to 2 day in-person meetings to prepare them to better enforce the HIPAA regulations. The HITECH Act gave state attorneys general the authority to bring civil actions […]

Read more

Using patient record security as a competitive advantage

March 7, 2011

The following blog was written a year ago but the content is still relevant today. What if organizations looked at HIPAA security as a competitive advantage and not just something that is mandatory and required by the government? In two recent surveys a clear message is being sent. The message is that patients want doctors […]

Read more

Deeper look at the $4.3 million HIPAA fine

February 23, 2011

The Health and Human Services’ (HHS) Office of Civil Rights (OCR) issued a $4.3 million fine to Cignet Health of Prince George’s County, MD (Cignet) for violating the Privacy Rule of HIPAA. Cignet refused to provide 41 patients with access to their medical records. Under HIPAA, patients are entitled to have access to their medical […]

Read more

Huge security breach fines coming in 2011

February 21, 2011

According the Health Data Management magazine, The HHS Office for Civil Rights plans big changes to privacy and security regulations. Below are some sections from their article. Adam Greene, senior health IT and privacy advisor in the OCR, outlined a slew of changes to existing regulations. The final HITECH privacy, security and breach notification rules […]

Read more

Employee training might produce the best security ROI

February 21, 2011

There are countless security products on the market today. You can buy products from hardware firewalls, to anti-virus / anti-malware, to web content management, to email encryption, to log management platforms, the list goes on and on. All of these products have a place and help in protecting data and electronic protected health information (ePHI). […]

Read more

Free HIPAA Security Tips and Reminders

February 20, 2011

One of the administrative requirements of the HIPAA Security Rule is to implement a security awareness and training program. And one of the implementation specifics is to implement security reminders. (5)(i) Standard: Security awareness and training. Implement a security awareness and training program for all members of its workforce (including management). (ii) Implementation specifications. Implement: […]

Read more

Why perform a Risk Assessment?

February 15, 2011

A Risk Assessment is required in order to comply with the HIPAA Security Rule. The Security Management Process standard in the Security Rule requires organizations to “[i]mplement policies and procedures to prevent, detect, contain, and correct security violations.” (45 C.F.R. § 164.308(a)(1).) Risk analysis is one of four required implementation specifications that provide instructions to […]

Read more

Introducing HIPAA Secure Now!

February 13, 2011

We are proud to announce the launch of the HIPAA Secure Now! service. HIPAA Secure Now! is the first comprehensive and affordable HIPAA Security Rule service. The service includes: 18 Policy and Procedures covering the administrative, physical and technical safeguards as required by the HIPAA Security Rule. A thorough Risk Assessment that looks at all […]

Read more
Load more

Recent Posts

  • Annual Business Checkup
  • The Future of Healthcare Cybersecurity: Trends to Watch
  • How to Handle a Breach
  • A Dynamic Duo: Cybersecurity and Compliance
  • Elements of a Comprehensive HIPAA Annual Training

Recent Comments

  • Art on Maintaining HIPAA-Compliant Communication Amongst Colleagues
  • Michell Holmes on Maintaining HIPAA-Compliant Communication Amongst Colleagues
  • campusmedicine important source on You Can Leave a Message – But Make Sure It Is HIPAA Compliant
  • Milan on PHI or PII – What’s the Difference?
  • Automatic Backlinks on Free HIPAA Security Training!

Archives

  • December 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • September 2017
  • August 2017
  • July 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • January 2016
  • December 2015
  • November 2015
  • October 2015
  • September 2015
  • August 2015
  • June 2015
  • May 2015
  • April 2015
  • March 2015
  • February 2015
  • January 2015
  • December 2014
  • November 2014
  • October 2014
  • September 2014
  • August 2014
  • July 2014
  • June 2014
  • May 2014
  • April 2014
  • March 2014
  • February 2014
  • January 2014
  • December 2013
  • November 2013
  • October 2013
  • September 2013
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • December 2012
  • November 2012
  • October 2012
  • September 2012
  • July 2012
  • June 2012
  • May 2012
  • April 2012
  • March 2012
  • February 2012
  • January 2012
  • December 2011
  • November 2011
  • October 2011
  • September 2011
  • August 2011
  • July 2011
  • June 2011
  • May 2011
  • April 2011
  • March 2011
  • February 2011

Categories

  • Backup & Disaster Recovery
  • Business Associates
  • Client News
  • Download
  • Healthcare Industry
  • HIPAA
  • HIPAA Audits
  • HIPAA Violations
  • HSN News
  • Legal
  • MACRA
  • Policies and Procedures
  • Press Release
  • Remote Workforce
  • Risk Assessment
  • Scams
  • Security
  • Security Reminders
  • Security Training
  • Telehealth
  • Uncategorized
  • Webinar
  • Website

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Contact Us

  • HIPAA Secure Now
  • 55 Madison Ave, Suite 400 Morristown, NJ 07960
  • (877) 275 - 4545
  • info@hipaasecurenow.com

Find us on Social Media

LEGAL

Privacy Policy

Terms of Service

Subscribe to our Newsletter

  • Hidden

© 2026 · HIPAA Secure Now!