Security Compliance offentlig
[search 0]
Mer
Download the App!
show episodes
 
Healthcare is complicated. Joe Gellatly and Amanda Hepper are here to help, guiding us through the biggest issues and updates in healthcare security and compliance. From HIPAA Risk Assessments to the dark web, learn what factors are affecting the security of healthcare information and how to protect your data. Tune in for news, advice, and more.
  continue reading
 
Artwork
 
It’s the show, that bridges the requirements of regulations, compliance, and privacy with those of security. Your trusted source for complying with various mandates, building effective programs, and current compliance news. It’s time for Security and Compliance Weekly.
  continue reading
 
It’s the show, that bridges the requirements of regulations, compliance, and privacy with those of security. Your trusted source for complying with various mandates, building effective programs, and current compliance news. It’s time for Security and Compliance Weekly.
  continue reading
 
Loading …
show series
 
DDoS attacks are a growing threat to organizations of all sizes. What are they and what impact do they have on you? Tune in to find out. In this episode, we’er covering: Understanding DDoS Attacks: What DDoS attacks are and how they work to disrupt your services. Immediate Impact: The potential damage to business operations, financial losses, and c…
  continue reading
 
The Ascension breach has rocked the healthcare sector, and we're breaking down what happened. In this episode, we cover: - The Ascension Breach: How the Black Basta group managed to breach one of the largest healthcare associations. - Immediate Impact: Delays in patient care, administrative chaos, and over 1.2 million patient records exposed. - Key…
  continue reading
 
How are phishing attacks evolving, and what can healthcare organizations do to defend against them? In this episode, we share the latest phishing tactics targeting the healthcare sector - from spear phishing to vishing and smishing. Discover how cybercriminals are becoming more sophisticated and the devastating impacts these attacks can have on hea…
  continue reading
 
How do you decide between in-house backups and cloud-based backups for your healthcare data? In this episode, HIPAA Risk Assessment Specialist Margaret LaDuke discusses the key differences, advantages, and drawbacks of each approach. Learn how to make informed decisions that ensure HIPAA compliance and protect patient data effectively. Stay tuned f…
  continue reading
 
Artificial intelligence is revolutionizing healthcare, but what does this mean for patient privacy? In this episode, Sean explores the intersection of AI and healthcare privacy, discussing the benefits and risks of using AI in healthcare, and sharing insights on how to mitigate potential privacy concerns. Keep informed and stay ahead of the curve t…
  continue reading
 
Do you ever feel overwhelmed by HIPAA audits? In this episode, Sean breaks down the complexities of HIPAA audits and shares practical tips on how to simplify the process. From understanding HIPAA requirements to identifying potential risks and developing effective compliance strategies, we’ve got you covered. Tune in to learn how to approach HIPAA …
  continue reading
 
HIPAA has added a new rule to Substance Use Disorder (SUD) privacy. Are you up-to-date on the latest changes? In this episode, Sean dives into the recent updates and what they mean for healthcare providers. From consent forms to breach notification requirements, he covers the essential changes you need to know to ensure compliance. Tune in to stay …
  continue reading
 
In this episode, Sean covers the rest of the cybersecurity performance goals set by the U.S. Department of Health and Human Services. He shares cybersecurity tactics including TTPs, Network Segmentation, Centralized Log Collection, Centralized Incident Planning and Preparedness, and Configuration Management. Learn more about Medcurity here: https:/…
  continue reading
 
In this episode, Sean covers the first 5 enhanced cybersecurity goals set by the U.S. Department of Health and Human Services. He discusses cybersecurity tactics including asset inventory, third-party vulnerability disclosure, third-party incident reporting, cybersecurity training, and cybersecurity mitigation. Learn more about Medcurity here: http…
  continue reading
 
In this episode, Sean covers the last 6 essential cybersecurity goals set by the U.S. Department of Health and Human Services. He discusses cybersecurity tactics including strong encryption, unique and targeted credentials, incident preparedness, account access, and vendor/supplier cybersecurity requirements. Learn more about Medcurity here: https:…
  continue reading
 
Sean talks about the first several cybersecurity goals set by the U.S. Department of Health and Human Services. Learn where to start on your journey of compliance and security. He covers vulnerabilities, email security, MFA, and cybersecurity training. Learn more about Medcurity here: https://medcurity.com…
  continue reading
 
Join Sean as he breaks down the latest cybersecurity and compliance standards from the U.S. Department of Health and Human Services. He walks through the four pillars of cybersecurity to help you understand what they mean for your organization. Tune in to get straightforward insights and practical tips on staying secure in the digital age. Learn mo…
  continue reading
 
Medcurity and iatricSystems have teamed up to explore internal and external privacy and security threats facing healthcare right now. Joe Gellatly with Medcurity and Demi Borden with iatricSystems are bringing their firsthand experiences in the field to demonstrate the best practices they are seeing work right now. They will be discussing: -Lessons…
  continue reading
 
Listen to Medcurity's Director of Business Development, Ari Van Peursem share what healthcare organizations need to keep top of mind as we move into 2023. She will be covering: 1. Themes from 2022 2. The most recent breaches and what we can learn as the environment continues to evolve 3. Regulatory updates 4. The future of technology & HIPAA…
  continue reading
 
Author of "Why CISOs Fail" is joining us today to tell us about the success of his first book as well as introduce us to his forthcoming book, "Security Hippie. Barak is best known for pioneering the concept of the virtual (or fractional) CISO model nearly two decades ago. Over the twenty years since then he has applied that model and strategy to b…
  continue reading
 
Author of "Why CISOs Fail" is joining us today to tell us about the success of his first book as well as introduce us to his forthcoming book, "Security Hippie. Barak is best known for pioneering the concept of the virtual (or fractional) CISO model nearly two decades ago. Over the twenty years since then he has applied that model and strategy to b…
  continue reading
 
Author of "Why CISOs Fail" is joining us today to tell us about the success of his first book as well as introduce us to his forthcoming book, "Security Hippie. Barak is best known for pioneering the concept of the virtual (or fractional) CISO model nearly two decades ago. Over the twenty years since then he has applied that model and strategy to b…
  continue reading
 
Ben Carr will lead us in a discussion about the origins of the role of CISO, roles/responsibilities, and what it's like to be a CISO. We'll touch on qualifications, organizational structure, its place in security and compliance, what it's like to be hero or scapegoat. All this and more! Show Notes: https://securityweekly.com/scw98 Visit https://www…
  continue reading
 
Ben Carr will lead us in a discussion about the origins of the role of CISO, roles/responsibilities, and what it's like to be a CISO. We'll touch on qualifications, organizational structure, its place in security and compliance, what it's like to be hero or scapegoat. All this and more! Visit https://www.securityweekly.com/scw for all the latest ep…
  continue reading
 
Ben Carr will lead us in a discussion about the origins of the role of CISO, roles/responsibilities, and what it's like to be a CISO. We'll touch on qualifications, organizational structure, its place in security and compliance, what it's like to be hero or scapegoat. All this and more! Visit https://www.securityweekly.com/scw for all the latest ep…
  continue reading
 
There’s something happening here – and what it is ain’t exactly clear to O.G hackers like John Threat or our own Mr. Jeff Man. We’re going to devote an episode talking about how things used to be back in the day from a hacker/penetration perspective and discuss how things are today. Are things better? Worse? Depends on your attack vector, perhaps? …
  continue reading
 
There’s something happening here – and what it is ain’t exactly clear to O.G hackers like John Threat or our own Mr. Jeff Man. We’re going to devote an episode talking about how things used to be back in the day from a hacker/penetration perspective and discuss how things are today. Are things better? Worse? Depends on your attack vector, perhaps? …
  continue reading
 
There’s something happening here – and what it is ain’t exactly clear to O.G hackers like John Threat or our own Mr. Jeff Man. We’re going to devote an episode talking about how things used to be back in the day from a hacker/penetration perspective and discuss how things are today. Are things better? Worse? Depends on your attack vector, perhaps? …
  continue reading
 
In the early days of PCI there was an online column called StorefrontBacktalk which focused on retail and technology issues. The column provided valuable insights from various specialists on the interpretation and application of many of the more challenging security requirements found in PCI DSS which was reflected in its tag line, “Techniques, Too…
  continue reading
 
In the early days of PCI there was an online column called StorefrontBacktalk which focused on retail and technology issues. The column provided valuable insights from various specialists on the interpretation and application of many of the more challenging security requirements found in PCI DSS which was reflected in its tag line, “Techniques, Too…
  continue reading
 
In the early days of PCI there was an online column called StorefrontBacktalk which focused on retail and technology issues. The column provided valuable insights from various specialists on the interpretation and application of many of the more challenging security requirements found in PCI DSS which was reflected in its tag line, “Techniques, Too…
  continue reading
 
CISA recently published guidance for how managed service providers (MSPs) should approach security for their operations based on the premise that cyber threat actors are known to target MSPs to reach their customers. MSPs provide remote management of customer IT and end-user systems and generally have direct access to their customers’ networks and …
  continue reading
 
CISA recently published guidance for how managed service providers (MSPs) should approach security for their operations based on the premise that cyber threat actors are known to target MSPs to reach their customers. MSPs provide remote management of customer IT and end-user systems and generally have direct access to their customers’ networks and …
  continue reading
 
CISA recently published guidance for how managed service providers (MSPs) should approach security for their operations based on the premise that cyber threat actors are known to target MSPs to reach their customers. MSPs provide remote management of customer IT and end-user systems and generally have direct access to their customers’ networks and …
  continue reading
 
Join us on this episode of SCW for a general discussion about how to do this whole security/compliance thing better; how compliance really needs to come first; how it's all risk-based or should be RGC not GRC; legal and privacy issues/focus - and how they help or hinder the cause; other factors like burnout/gatekeeping/etc. that all contribute to o…
  continue reading
 
Join us on this episode of SCW for a general discussion about how to do this whole security/compliance thing better; how compliance really needs to come first; how it's all risk-based or should be RGC not GRC; legal and privacy issues/focus - and how they help or hinder the cause; other factors like burnout/gatekeeping/etc. that all contribute to o…
  continue reading
 
Join us on this episode of SCW for a general discussion about how to do this whole security/compliance thing better; how compliance really needs to come first; how it's all risk-based or should be RGC not GRC; legal and privacy issues/focus - and how they help or hinder the cause; other factors like burnout/gatekeeping/etc. that all contribute to o…
  continue reading
 
With cybersecurity skills already in short supply, the prospect of losing what little workforce there is to pull from to resignations (especially in the context of the ‘Great Resignation’), is a disturbing one. Rick McElroy will speak to the causes of security burnout and the steps organizations need to take to prevent the loss of the precious reso…
  continue reading
 
With cybersecurity skills already in short supply, the prospect of losing what little workforce there is to pull from to resignations (especially in the context of the ‘Great Resignation’), is a disturbing one. Rick McElroy will speak to the causes of security burnout and the steps organizations need to take to prevent the loss of the precious reso…
  continue reading
 
With cybersecurity skills already in short supply, the prospect of losing what little workforce there is to pull from to resignations (especially in the context of the ‘Great Resignation’), is a disturbing one. Rick McElroy will speak to the causes of security burnout and the steps organizations need to take to prevent the loss of the precious reso…
  continue reading
 
Tony and Thomas will discuss the importance, value, and challenge of cross-mapping security frameworks, and the rationale and process used by CIS to create end support mapping, and some real-world examples and some real-life problems. Show Notes: https://securityweekly.com/scw92 Visit https://www.securityweekly.com/scw for all the latest episodes! …
  continue reading
 
Tony and Thomas will discuss the importance, value, and challenge of cross-mapping security frameworks, and the rationale and process used by CIS to create end support mapping, some real-world examples, and some real-life problems. Visit https://www.securityweekly.com/scw for all the latest episodes! Show Notes: https://securityweekly.com/scw92…
  continue reading
 
Tony and Thomas will discuss the importance, value, and challenge of cross-mapping security frameworks, and the rationale and process used by CIS to create end support mapping, some real-world examples, and some real-life problems. Visit https://www.securityweekly.com/scw for all the latest episodes! Show Notes: https://securityweekly.com/scw92…
  continue reading
 
We’re getting closer to the Q1 2022 release of PCI DSS 4.0, which is expected to differ from the current PCI DSS 3.2.1 version in a few key ways. This includes giving organizations more options in how they become compliant, along with customized implementation. In this podcast, Chris Pin, VP of Privacy and Compliance at PKWARE, will discuss what cu…
  continue reading
 
We’re getting closer to the Q1 2022 release of PCI DSS 4.0, which is expected to differ from the current PCI DSS 3.2.1 version in a few key ways. This includes giving organizations more options in how they become compliant, along with customized implementation. In this podcast, Chris Pin, VP of Privacy and Compliance at PKWARE, will discuss what cu…
  continue reading
 
We’re getting closer to the Q1 2022 release of PCI DSS 4.0, which is expected to differ from the current PCI DSS 3.2.1 version in a few key ways. This includes giving organizations more options in how they become compliant, along with customized implementation. In this podcast, Chris Pin, VP of Privacy and Compliance at PKWARE, will discuss what cu…
  continue reading
 
Loading …

Snabbguide