- 49 minutes 11 secondsKeeping Humans in Charge of AI - Ep 580
Everybody wants AI to make things faster and easier. And it can. The problem starts when "AI is helping us" turns into "AI is doing it, so we stopped checking." This week, Donna and David talk about why keeping a human in the loop isn't enough if that human is just clicking "approve", how agentic AI changes the risk equation, and why organizations need real guardrails, governance, and accountability before turning AI loose. AI may be able to do a lot of the work, but that doesn't mean it should be the one making all the decisions.
More info at HelpMeWithHIPAA.com/580
2 October 2026, 4:30 am - 44 minutes 14 secondsSMB Security Makes Progress BUT - Ep 579
Small businesses are making progress on cybersecurity, and that's worth celebrating. But are they actually as prepared as they think they are? In this episode, Donna and David dig into the 2026 Small Business Cybersecurity Awareness and Practices Survey and the gap between confidence and readiness. From MFA and backups to incident response, testing, documentation, and the rapidly changing risks of AI, they discuss why putting security tools in place is only the beginning. Real security means knowing what's working, verifying it, and being able to prove it.
More info at HelpMeWithHIPAA.com/579
25 September 2026, 4:30 am - 1 hour 5 minutesThe Risk Analysis Reality Check - A Screwdriver Is Not a Hammer - Ep 578
There is no shortage of tools, scans, checklists, and reports that promise to help with cybersecurity, but calling something a risk analysis does not magically make it one. This episode takes a hard look at what OCR keeps saying about Security Risk Analysis, why incomplete SRAs continue to show up in enforcement actions, and why understanding your actual environment still matters more than simply checking the right boxes.
More info at HelpMeWithHIPAA.com/576
18 September 2026, 4:30 am - 48 minutes 1 secondDon't Make It Easy for Them - Ep 577
Every October, the National Cybersecurity Alliance uses Cybersecurity Awareness Month to remind us how to stay safer online, and this year's message is beautifully simple: don't make it easy for the criminals. They're looking for weak passwords, missing MFA, unpatched software, and people who click before they think. In other words, they're rattling digital doorknobs to see which ones open. This episode takes a look at this year's campaign and the real-world cybercriminals being used to show why basic cyber hygiene still matters. You don't have to become a cybersecurity genius. You just need to practice a few basic security habits to keep you from becoming the easiest target on the block.
More info at HelpMeWithHIPAA.com/577
11 September 2026, 4:30 am - 49 minutes 15 secondsUnmasking the Middleman - When Trust Is the Bait - Ep 576
Remember when spotting a phishing scam meant looking for terrible grammar, a suspicious link, and maybe a Nigerian prince having a bad week? Those were simpler times. Today's attackers can sound like your IT department, use tools you already trust, and even walk you through legitimate-looking security steps. The scams have gotten much better at looking trustworthy, which means the old security awareness rules need an upgrade. When urgency, anxiety, or pressure shows up, slowing down and verifying may be your best defense.
More info at HelpMeWithHIPAA.com/576
4 September 2026, 4:30 am - 54 minutes 35 secondsSpend Smarter Before the Breach - Ep 575
There are two times to spend money on cybersecurity: before something goes wrong, when you still have choices, and after something goes wrong, when your choices have packed a bag and left town. With the average U.S. data breach now costing $11.5 million, the question isn't whether security costs money. It's whether you're spending that money on the things most likely to keep a bad day from becoming a very long, very expensive year. The latest breach-cost research offers some surprisingly practical clues, including faster detection, smarter access controls, employee training, encryption, simpler systems, qualified security help, and properly managed AI. And there's an important catch: outsourcing the work doesn't outsource the accountability. This episode digs into how to spend smarter while you still have the luxury of deciding where the money goes.
More info at HelpMeWithHIPAA.com/575
28 August 2026, 4:30 am - 42 minutes 55 secondsConnecting the Dots - What the Ransomware Headlines Are Missing - Ep 574
Ransomware used to sound like a fairly straightforward nightmare: attackers get in, encrypt your files, demand money, and ruin everyone's week. Unfortunately, the business model has gotten an upgrade. Today's ransomware groups are stealing massive amounts of data, recruiting affiliates with surprisingly competitive revenue splits, disabling security tools, contacting patients directly, and even hijacking social media accounts to turn up the pressure. Meanwhile, regulators are asking harder questions about risk analysis and looking further into the past for answers. Connect those dots, and the picture gets uncomfortable fast. This episode explores what recent ransomware headlines are really telling healthcare organizations, including the small ones still hoping they're too tiny to attract attention. Spoiler alert: the bad guys appear to have misplaced their minimum-size requirement.
More info at HelpMeWithHIPAA.com/574
21 August 2026, 3:38 pm - 54 minutes 30 secondsThreats Are Evolving - Are You? - Ep 573
Cybersecurity has always been a moving target, but lately the target seems to have strapped on roller skates, grabbed an AI assistant, and headed straight for the nearest hotel Wi-Fi. Vulnerabilities are being patched at record rates, attackers are finding clever new ways to steal credentials, and AI agents can now take action with surprisingly little supervision. In this episode, we look at what happens when threats evolve faster than the plans designed to handle them, and why having security tools isn't the same as knowing they're actually protecting you. The real question isn't whether technology will keep changing. It's whether your security practices can keep up.
More info at HelpMeWithHIPAA.com/573
14 August 2026, 4:30 am - 45 minutes 37 secondsOperation Vital Signs Got Real - Ep 572
Most organizations have an incident response plan, but how well would it hold up if your normal communication channels suddenly couldn't be trusted? In this episode, we dive into a nationwide healthcare cybersecurity exercise that challenged participants to think beyond compliance and technical defenses, exposing just how critical preparation, collaboration, and secure communication become during a large-scale cyber crisis. Along the way, a surprising real-world AI development reminds us that tomorrow's threats may arrive sooner than anyone expects.
More info at HelpMeWithHIPAA.com/572
7 August 2026, 4:30 am - 34 minutes 54 secondsHIPAA Privacy Changes Soon. Maybe. - Ep 571
Regulations may move at the speed of a sleepy turtle, but patient expectations certainly don't. As healthcare organizations wait to see what the final HIPAA Privacy Rule will include, there is a surprising amount of work that can, and should, already be underway. This episode explores the practical steps you can take now, the common misconceptions that continue to create confusion, and why preparing early is far less painful than trying to outrun an approaching compliance deadline. If you start getting your ducks in a row today, it just might save you from chasing them all over the parking lot tomorrow.
More info at HelpMeWithHIPAA.com/571
31 July 2026, 4:30 am - 47 minutes 10 secondsMeasuring Financial Impacts - Ep 570
Cyberattacks are expensive—but just how expensive? This episode dives into a brand-new study that finally puts real numbers behind the financial impact of data breaches, using thousands of cyber insurance claims instead of scary headlines and wild guesses. From ransomware and business interruption to cyber insurance surprises, you'll discover why the biggest cost isn't always what you think. If you've ever wondered whether your organization is truly prepared for a breach—or just hoping insurance will magically save the day—this conversation is packed with practical insights, a few laughs, and plenty of reasons to take another look at your risk management strategy.
More info at HelpMeWithHIPAA.com/570
24 July 2026, 4:30 am - More Episodes? Get the App