
Sign up to save your podcasts
Or


Cyber threats are moving at lightning speed, while regulations seem to be taking the scenic route. But what happens when the rules finally catch up? Will healthcare organizations be ready, or will they find themselves scrambling to meet expectations they should have been preparing for all along? In this episode, Donna and David dig into proposed HIPAA Security Rule changes and cybersecurity legislation being discussed in Congress. From minimum security standards and leadership accountability to proving that safeguards actually work, the message is becoming pretty clear: simply saying you're secure isn't enough. And while everyone waits to see which rules become reality, the threats aren't waiting around. It's time to ask whether you're truly protecting your organization and patients, or just hoping your IT provider has everything covered.
More info at HelpMeWithHIPAA.com/581
Everybody wants AI to make things faster and easier. And it can. The problem starts when "AI is helping us" turns into "AI is doing it, so we stopped checking." This week, Donna and David talk about why keeping a human in the loop isn't enough if that human is just clicking "approve", how agentic AI changes the risk equation, and why organizations need real guardrails, governance, and accountability before turning AI loose. AI may be able to do a lot of the work, but that doesn't mean it should be the one making all the decisions.
More info at HelpMeWithHIPAA.com/580
Small businesses are making progress on cybersecurity, and that's worth celebrating. But are they actually as prepared as they think they are? In this episode, Donna and David dig into the 2026 Small Business Cybersecurity Awareness and Practices Survey and the gap between confidence and readiness. From MFA and backups to incident response, testing, documentation, and the rapidly changing risks of AI, they discuss why putting security tools in place is only the beginning. Real security means knowing what's working, verifying it, and being able to prove it.
More info at HelpMeWithHIPAA.com/579
There is no shortage of tools, scans, checklists, and reports that promise to help with cybersecurity, but calling something a risk analysis does not magically make it one. This episode takes a hard look at what OCR keeps saying about Security Risk Analysis, why incomplete SRAs continue to show up in enforcement actions, and why understanding your actual environment still matters more than simply checking the right boxes.
More info at HelpMeWithHIPAA.com/576
Every October, the National Cybersecurity Alliance uses Cybersecurity Awareness Month to remind us how to stay safer online, and this year's message is beautifully simple: don't make it easy for the criminals. They're looking for weak passwords, missing MFA, unpatched software, and people who click before they think. In other words, they're rattling digital doorknobs to see which ones open. This episode takes a look at this year's campaign and the real-world cybercriminals being used to show why basic cyber hygiene still matters. You don't have to become a cybersecurity genius. You just need to practice a few basic security habits to keep you from becoming the easiest target on the block.
More info at HelpMeWithHIPAA.com/577
Remember when spotting a phishing scam meant looking for terrible grammar, a suspicious link, and maybe a Nigerian prince having a bad week? Those were simpler times. Today's attackers can sound like your IT department, use tools you already trust, and even walk you through legitimate-looking security steps. The scams have gotten much better at looking trustworthy, which means the old security awareness rules need an upgrade. When urgency, anxiety, or pressure shows up, slowing down and verifying may be your best defense.
More info at HelpMeWithHIPAA.com/576
There are two times to spend money on cybersecurity: before something goes wrong, when you still have choices, and after something goes wrong, when your choices have packed a bag and left town. With the average U.S. data breach now costing $11.5 million, the question isn't whether security costs money. It's whether you're spending that money on the things most likely to keep a bad day from becoming a very long, very expensive year. The latest breach-cost research offers some surprisingly practical clues, including faster detection, smarter access controls, employee training, encryption, simpler systems, qualified security help, and properly managed AI. And there's an important catch: outsourcing the work doesn't outsource the accountability. This episode digs into how to spend smarter while you still have the luxury of deciding where the money goes.
More info at HelpMeWithHIPAA.com/575
Ransomware used to sound like a fairly straightforward nightmare: attackers get in, encrypt your files, demand money, and ruin everyone's week. Unfortunately, the business model has gotten an upgrade. Today's ransomware groups are stealing massive amounts of data, recruiting affiliates with surprisingly competitive revenue splits, disabling security tools, contacting patients directly, and even hijacking social media accounts to turn up the pressure. Meanwhile, regulators are asking harder questions about risk analysis and looking further into the past for answers. Connect those dots, and the picture gets uncomfortable fast. This episode explores what recent ransomware headlines are really telling healthcare organizations, including the small ones still hoping they're too tiny to attract attention. Spoiler alert: the bad guys appear to have misplaced their minimum-size requirement.
More info at HelpMeWithHIPAA.com/574
Cybersecurity has always been a moving target, but lately the target seems to have strapped on roller skates, grabbed an AI assistant, and headed straight for the nearest hotel Wi-Fi. Vulnerabilities are being patched at record rates, attackers are finding clever new ways to steal credentials, and AI agents can now take action with surprisingly little supervision. In this episode, we look at what happens when threats evolve faster than the plans designed to handle them, and why having security tools isn't the same as knowing they're actually protecting you. The real question isn't whether technology will keep changing. It's whether your security practices can keep up.
More info at HelpMeWithHIPAA.com/573
Most organizations have an incident response plan, but how well would it hold up if your normal communication channels suddenly couldn't be trusted? In this episode, we dive into a nationwide healthcare cybersecurity exercise that challenged participants to think beyond compliance and technical defenses, exposing just how critical preparation, collaboration, and secure communication become during a large-scale cyber crisis. Along the way, a surprising real-world AI development reminds us that tomorrow's threats may arrive sooner than anyone expects.
More info at HelpMeWithHIPAA.com/572
From the publisher's feed
Ranked by our users in the last 21 days

38 Listeners

199 Listeners

9 Listeners

37 Listeners