You Have Time, HIPAA’s Security Rule Hasn’t Changed Yet

NPRM Security Rule proposed

You’re fine, really. No need to panic. Yes, the NPRM is [finally] progressing. BUT – it’s not yet time to overhaul HIPAA Security Policies & Procedures, or buy new tools. Read my latest article to learn why (and DM me if you’d like a free copy of my latest webinar material relating to the NPRM). Read on to learn more.

Proposed HIPAA Rule Changes – Presentation Clip

HIPAA Changes HCCA webinar

I recently had the opportunity to present an HCCA continuing education webinar on the NPRM related to the proposed changes to the HIPAA Rule. I invite you to watch the 5-minute clip here, where I talk about proposed patching expectations and touch on the Security Risk Analysis’s emphasis. Here at Apgar and Associates, we’re scheduling … Read more

How Do You Weigh Vendor Risk Exposure?

vendor risk exposure risk management

When it comes to vendor risk exposure and its management, you need to know how to implement a proper program that aligns with HIPAA compliance. Because whether you’re talking Cloud Service Providers or others, a solid vendor risk management program is key to potentially how well your organization can avoid a serious PHI security incident. … Read more

How to Harden Laptops, Tablets & Smartphones to Protect PHI

harden devices protect phi

When your goal is to protect PHI on laptops and mobile devices, keep in mind that information security is only as strong as its weakest link. Lenient information security standards exponentially increases the risk to sensitive healthcare data. It can also place you in non-compliance with the HIPAA Security Rule. On top of that the … Read more

Privacy & Security Forum Update: OCR Activity, Audit Protocols, Ransomware & the HIPAA Security Rule

Julia and I had the pleasure of attending the 2018 Privacy & Security Forum a couple of weeks ago.  One of the sessions I attended was focused on what’s happening at OCR these days.  The speaker was Roger Severino, Director of OCR, and the moderator was Adam Greene, partner at Davis Wright Tremaine, LLP.  I … Read more

Who has access to PHI? Should they?

That was the title of an early January eblast to our subscribers where we talked about insider risk and audit controls. Then OCR sends out an email about a recent $5.5 million settlement with Memorial Healthcare Systems (MHS) about PHI being “impermissibly accessed” and “impermissibly disclosed” to doctors’ staff. The email serves as an expensive … Read more