SecurityMetrics Podcast | 6
Business Continuity during Healthcare Crisis
In healthcare, it’s common to encounter the attitude that “HIPAA is complicated.” Naturally, this leads to people finding ways to make HIPAA seem irrelevant or useless. However, this belief couldn’t be further from the truth and leads to increased risk for patients, especially during times of crisis.
Donna Grindle of the “Help Me with HIPAA” Podcast, sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss:
- How to address the gaps in understanding and myths about HIPAA that hinder healthcare providers
- Various approaches to administrative safeguards like Business Contingency Plans and Disaster Recovery Plans
- Ways to leverage the requirements of HIPAA to better protect individuals and organizations
Resources:
Check out Donna's "Help Me with HIPAA" podcast!
Download our Guide to PCI Compliance! - https://www.securitymetrics.com/lp/pci/pci-guide
Download our Guide to HIPAA Compliance! - https://www.securitymetrics.com/lp/hipaa/hipaa-guide
[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.
Business Continuity during Healthcare Crisis Transcript
Hello, and welcome to the Security Metrics podcast. Super excited to have you here with me today, and I keep getting told that I need to actually say more about the podcast before I launch into it. I'm Jen Stone. I'm a principal security analyst, at Security Metrics.
The idea behind our podcast is to help people who are, maybe a little less technical, but even people who are technical. It's kinda runs the gamut of of security and compliance, which is the space that that we do a lot of work in. Today, though, so excited. I have with me Donna Grindle from Help Me with HIPAA podcast and Carden.
She, she and her cohost David Sims over at the Help Me with HIPAA podcast are, just second to none when it comes to understanding HIPAA, and and breaking it down in ways that people can understand and why it's important.
So I was so excited.
Donna, thank you for coming and joining me today. I know that I missed a ton of things in my very quick hello. Oh, you're great.
You're great.
Tell us about yourself, about yourself, about your podcast, about Carden. I I would love to hear a little bit about you.
Well, I was born in the mountains of North Georgia.
And Yes. You were.
Yeah.
No. They helped me with HIPAA podcast. David and I started that in twenty fifteen.
Oh, wow. Before everybody knew what a podcast was.
Right.
And, and it's his fault, and he keeps taking credit for nagging me to do it.
But Is it credit or is it blame at this point? I mean It's a little bit of both.
Okay. You know?
Because I I have to, you know, share with David a few things. We have a running gag about all of our different things. But what you hear on the podcast, that's like a normal conversation. We just start recording it.
Nice.
And nothing nothing special.
But, my background is, I always like to say, I started when, I had a pacifier in my mouth as a programmer back in the eighties because I am couldn't possibly be No. As old as I am.
But, yes, I started writing electronic claims software in the late eighties. Wow.
Yeah. So I've been around health care IT for a long time.
Nice.
Nice. Yeah. I got to see, you know, the transitions and and people that have been around health care for a long time. They'll remember the blue form, which is the, you know, at that time, it was the HIPAA fifteen hundred. I mean, I go way back.
Okay.
And, but, in, ninety nine, I went out on my own, started doing consulting and because they have a background in data. Mhmm.
When they did the code set standards in HIPAA, I got all excited, you know, because now I get to do because I was in the transition from proprietary to NSF to ANSI to Mhmm.
You know, h l seven, all that kind of stuff. I still get nerdy with it. But then I got involved in the privacy and security part, trying to get people to listen.
Right.
You know? And back then, the question was, what's gonna happen if I don't do it? And I'm like, pretty much nothing.
Yeah. Yeah. Trying to get people to do something without any consequences.
That's a Yeah.
That's a tough row.
Well and, yeah, I mean, and that that's the problem with HIPAA, and that's why it has the name. You know, everybody's like, oh, HIPAA is just a well, no. Because it's just been so confusing for so long. You know, you have to do it, but you don't have to do it. And over time, I just got to doing more and more and more of it. Mhmm. And when, the, high-tech stuff came out and the stimulus bill, I was like, I don't know because I know how bad this is.
Right.
But he's gonna have to start doing the stuff that they haven't been doing. They're gonna fight it. There's gonna be all these problems.
I don't think I wanna do this. And I went to a business coach and said, I wanna I wanna figure out something new. And he asked me a bunch of questions, and he said, let me get this right.
You are uniquely qualified to handle privacy and security in health care, and there's about to be a big need for it that you are uniquely qualified to handle, and you don't wanna do it.
And I'm like Yep.
Glad I paid you a bunch of money. Yeah.
Thanks for setting me straight.
Yes. So I started by teaching IT companies how to do it because I thought that'd be a great thing because we were running an MSP at the time. And and then I realized, I don't care if you can't print, and we ditched the MSP.
Right.
And since for a while now, we focused on nothing but this since twenty twelve.
That's that's that's some pretty awesome, skill and experience to bring to this world.
Because no matter what organization I work with, they can be tiny. They can be, a big hospital complex. They can be, business associates. And honestly, most of mine are business associates, because I am super comfortable with that technology world where the the health care world I don't I don't have all the experience that you have.
I have some. I do. I have worked, for some different health care, organizations, over the years. But, not to be coding, you know, as it as it comes along.
Yeah.
That And and you need perspective.
That's for sure. Yeah.
Yeah. And and I have colleagues who are better at the working with the health care providers than I am.
You have to know, a lot about how their how their businesses run-in order to be really successful in helping them get to a security stance and privacy in in HIPAA. You know, that that kind of, brings up a question. There's a there's a strong relationship between privacy and security in HIPAA, but a lot of groups kind of they just don't get what that means. You wanna speak to that a little bit?
Well, it's one of the things that we deal with a lot with business associates.
Now granted, we have we're we do a ton of covered entities that we know. We don't focus on the big health systems. We're on the private entities. We do some small health plans, that kind of stuff. But mostly, practices of some sort Mhmm. Or some type of entity like that.
In our business associate business where we work with MSPs, we work with software companies because nerd. Yeah. And so we do some other business associates, but it is a common problem that they think all they have to worry about is a security rule.
Right.
But the issue is if you don't understand the privacy rule, then you don't understand what you're securing in the security rule. Exactly.
And one of the big problems is, you know, if something comes out on paper, it's still PHI.
Mhmm. You gotta worry about that paper just like you have to worry about what's in the computer. If somebody's saying something, you have to worry about what they're saying just like you have to worry about what's in the computer. And often, people don't necessarily get that.
So when I say, do you train your staff on minimum uses and disclosures? They're like, yeah. Okay. Well, how do they understand what that is if they don't understand what everything in PHI is.
Right. So one of the things that I try to explain to people is that security doesn't mean anything unless you're protecting something. Exactly.
Like, that there's the the privacy has to be enforced by the security. But if you don't get the privacy part, then then you're secure what are you securing?
Yeah. Everybody doesn't get the privacy rule defines what PHI is and what you can do with it. Mhmm. And the security rule kinda needs that. Yes. Otherwise order to yeah.
Yeah. Otherwise, how do you how do you apply it? Yeah. Exactly.
Yeah. Yeah. When we do an assessment of a business associate, you know, we've got our breach. No. Well, we don't have to do that.
Yeah. Yeah.
I've been around for a few years.
Agreement?
Yeah.
Here's your privacy rule assessment. Mhmm. Well, we don't have to do that. Yeah.
How do you know you're doing the right thing on your you know, step one, a complete and thorough risk analysis requires you to know, number one, what is PHI and where is it?
Well, what what they my favorite thing is if they start arguing too much, I'm like, let's open up the language of the law. And then I start reading through the HIPAA regulations with them, which is the most boring thing I do. Can't stand it. They hate it even worse.
But I'll point out things like, if you are a covered entity, you're the word covered entity are right there. If you're a business associate, the words business associate are right there, and it's all the way through all of the regulations. I mean, I'm like, you can read this. You can find this yourself.
I promise you it's there.
And so That's like when the Armageddon Final Rule came out, and I read all of it.
And I'm but I don't get bored. I get excited. I've got highlighted versions with links to things.
Donna, you really are a nerd. I am.
I'm a HIPAA nerd.
I try to be excited about but I I start reading that law, and I just am like, okay. We're reading this again. Alright. This is good for you.
It's like eating your broccoli. Good though. If you read the omnibus final rule, you get to read the discussions Yeah. About what people said Mhmm. And their reasoning behind the way that it's written. Yes. And that is how I'm able you know, if you understand why things are done a certain way, it's a whole lot easier to do it that way.
And security is security.
It doesn't matter whether you're health care or not.
Exactly.
The difference is PHI.
You have to know what you're protecting first, and that's what makes HIPAA different. That and, there's a lot of security standards that people try to follow that don't start with that risk assessment.
But, you know, if you don't do the risk assessment, then it it's it's a good exercise to know what are you protecting and where where is it possibly vulnerable. And and it gives people kind of a focus to start with.
Yeah. But I think some of our, the people that I work with, and I don't know if you've seen this as well, but they kind of get confused about it because, first of all, it's a lot of work. And and a lot of work is expensive, and it's time consuming, and and organizations are just like, oh, I'm not sure how to take this on. But, also, they get sometimes these, these groups that'll tell them, oh, hey. HIPAA made simple.
So so You listen to my podcast. You know how that makes my eyes poke out.
How simple is HIPAA?
Well, you know, what we always say is you don't know what you don't know. Yeah.
And if you think it's easy, go ahead. And if you want it automated, go ahead. But if you wanna do the right thing and worry about taking care of your business Mhmm. And your patients and your staff, because that's really what we're doing.
Right.
And you look at today what we're going through with coronavirus, which I haven't had a haircut since February.
And I'm in my shed.
Yeah. At least this is my normal work environment. We have been a virtual company, no brick and mortar over twenty years now. So Wow. Yeah. Back in the day, I was like, I ain't getting an office.
And then I started the company. Mhmm. And now people that work for me, they're like until they realize I wanna see you on Vidyo.
Yeah.
I had a shower.
So so yeah. But the coronavirus came along, changed a lot of things for a lot of people.
Well, the problem is it showed that we weren't ready.
Mhmm.
Because privacy and security is a huge piece of being able to deploy during a business continuity need. Exactly.
And business continuity is you know, when when you ask people, do you have a disaster recovery business continuity plan, incident response plan? Mhmm. Well, so and so knows how to do the assessment on a breach. We'll mail out the letters like they say, and our IT company takes care of the backup.
Yeah. So a lot of them are saying, hey. Maybe I should have really understood what emergency mode meant because we are all currently in emergency mode.
Maybe I should have tested my contingency plan because Mhmm.
If you I mean, this is a massive test for everyone if they haven't tested it before. Yeah. It's being tested now.
And the hard part is, how do you how do you how do you get the resources and the people and the and the interactions that have to happen to set things up when you're not allowed to go anywhere, when you're not allowed to inter interact at all.
Well, that's one of the reasons that we think folks that are the IT people are frontline people too Yeah. And part of the heroes. Because in, like, zero time, they brought the company the entire country to virtual. Right.
I mean, just overnight.
Yeah.
And no one realizes that if they haven't been doing their jobs and continue to do their jobs jobs Mhmm. Yeah. There's been security problems, but that, you know, it's because there's this you know, overall, when you think about the transition, this has been remarkable. Yes.
Yes. And particularly in health care, when you're not in the business of dealing with the virus, your dermatology, your, you know, ophthalmology, any of these other things, they're finding ways to treat patients. And, we spent the way we're competitors, you and I, but not really the we do things so differently. We do things.
Our approach is what some people call what is it? The a boutique approach.
Yeah.
But we become, like, part of the team.
Yes. And and that is very different from how we do things. We, you know, we we'll take it to a point, but then helping implement is that is a unique skill set all its own.
And we do that part. So we'll do the assessment.
We come in and then say, okay. Now you've gotta do all this stuff.
And, really, we built our programs because people cried when we left, and I felt bad.
And so then, another people, I don't look good at Orange.
And, so we would build whatever it is they needed, and then more and and then literally, we had people break down into tears over, this in the beginning.
And now we have clients that we've worked with for so long, and we have some that are in the hot spots down in Southwest Georgia. Southwest Georgia is a huge hot spot that no one's talking about.
I didn't know that.
Major problem down there.
Because just as things were there was two funerals in the Albany, Georgia area of people that were big names in the community. Mhmm.
Everybody went and so did the virus.
Oh, no.
And we're talking a lot have it it's really impacted Southwest Georgia.
It's it's very upsetting to know, you know. And even in the HIPAA world, we lost Steve Lazarus last week, and he's a big name in the HIPAA world. You know? He had a great sense of humor, and I love watching him speak, and it took him.
But when we're talking with our clients down there, you know, they started talking to us in February because we're like plan plan plan plan.
Right. Yeah.
Plan plan plan.
They're on the phone with us. They're worried about I mean, we're coordinating all kinds of things, helping them figure out how to manage, you know, when it expanded and they needed to put a tent outside to triage patients to decide what door to send them in.
Right.
You know, and those kinds of things. And they call us and they say, I need a tent. What do I need to worry about with privacy in the tent? Yeah. You know? But they're thinking about those things.
Sure. Yeah.
What walls do you put on the tent? Mhmm. How do I manage the information? What if I've got multiple people in the tent?
These are things you have to worry about. Yeah. You should worry about because you're taking the time to plan it. You know, if we're in a true crisis like the Pulse nightclub shooting, you don't have that time.
Right. Right.
But even then, people blamed HIPAA.
I can't tell you I can't tell you things because we Yeah.
But HIPAA's an easy thing to blame because people don't understand it well enough to push back on that.
Well, yeah. I've always talked about educating the public. Mhmm. But I have a hard enough time educating health care.
Yeah. And Yeah.
I I just went on a rant that's we recorded it.
I don't know when it is either coming out or we do two weeks in advance, and I can't keep up with what's been released or what I've already ranted about. And it's been Right.
But there was an article in, I believe, the Boston Herald. Mhmm. And it was HIPAA's not designed for a pandemic. And I'm like, okay.
Let me check this out. I would disagree.
Yeah. It's it's absolutely got it all built in.
Yeah.
I mean, everything they've done is built into the law. Sure.
You know, it's geared to be able to adapt. That's why it's lasted as long as it has.
And and not only that, there is a flexibility that there you know, we've we've seen come out from the the OCR over at HHS guidance on how to deal with, telehealth, for example. Yeah.
There are it it does adapt, and it does flow with the situation.
And I think that the whole idea of the contingency planning, aspect of it is is uniquely geared to something like a pandemic.
Absolutely.
I I agree.
Alright then.
We are in agreement.
But turns out the article was about it even mentioned and this is when I went, this is what they think.
The article was they mentioned that a reporter who interviewed Tom Hanks and Rita Wilson came down with coronavirus, but they disclosed. They didn't accept HIPAA. They disclosed.
I'm like, HIPAA doesn't apply to people.
Yeah.
Yes.
And and that's what that reporter was not a covered entity.
Yeah. So You know?
And that that's what the article was saying is you need to opt out, and it was telling everybody, opt out of HIPAA, but that No.
There's no opt out. It is a lie. There's no opting out.
It it doesn't even matter. The point you were making is false. Yes. The premise you and I rarely comment on anything.
Mhmm.
I had to comment on that.
Jumped in.
I had to. I had to go in and say, you got this all wrong. Yeah. You know? But it's it is a big part of educating the public.
Yeah.
And I've done some seminars and stuff, and people's eyes are like Yeah.
Really?
You have that, the training that that you and David do.
It'll come to me in a second here. The boot camp. Yeah. The HIPAA boot camp.
The HIPAA boot camp.
The oh, excuse me.
The the camp, which sounds like a great training opportunity, for people. We we had one scheduled in March, which obviously Yeah.
It's not going on. Yeah.
That's not happening. We've moved it to August with hopes that that that'll work. So we have it, and you can get information at the hip hopoot camp dot com.
Registration, all that kind of stuff.
It's August eighteenth, nineteenth, twentieth here Atlanta or Tucker, Georgia.
Alright.
We're trying to be clear. And right down the street here.
And I think it's a great opportunity for because a lot of people learn best in person.
Well, and the way we do this, it is you're fully immersed. We call it boot camp for a reason. So we're doing it. It's three days.
Mhmm.
And we honestly say, look. We will not be able to cover everything in three days.
You will be exhausted.
But we're gonna do our best to get you educated on all of privacy and security.
Right.
At least enough to understand what you're supposed to do so that if you have to support clients that are supposed to do it, like the MSPs, we have a lot of MSPs that come to the boot camp.
Oh, okay. Great.
And you have to do it yourself if you're a business associate. If you're an MSP, you have to do it yourself, and you have to have your clients do it. Right.
And knowing where that line is and making sure that your clients understand that line. Yes. I have disaster recovery. IT takes care of the backup. You go to IT guys. But do they really?
Do you do disaster recovery? No. We only do the backup.
Also, restoring backups is, yeah, is not the same thing as disaster recovery. There's there's a huge gap between those two concepts.
Yeah. And I love what David says. Oh, crap. He's gonna hear that. I love what David said.
Don't praise him.
I know.
You can't do that often because it his head is like the big marshmallow in his Ghostbusters anyway. But the he points out you don't buy backup. You buy restore.
Yes.
And a lot of people forget that in their planning.
And we go on and on, and those are some of the things that we do in the boot camp. And that's really and truly you know, it's run. We don't have, like, this session starts here and this we're gonna do these sessions between here and here, and we just go. Yeah. And periodically, we stop because I have to go to the bathroom or something.
We we feed you while we're working. Occasionally, we'll take a break just to walk around. But even then, we're talking about what we're doing.
And I I think it would amaze people to know that that three solid days of HIPAA education is not enough to cover it all.
There is a lot to No.
We can't hit it all. And we keep trying to figure out how to add more to it without adding more to it.
But the way we finally have it is the first two days is, you know, we start with here is understanding the law and seeing the big picture.
And, you know, you always have the people that come in and we show them, like, the graph and okay. Down here is the technical part. So if you think IT is handling all of HIPAA, they're handling this. That little part of there. Yeah.
And they and also they can't handle it well if you don't define for them what it is that they're protecting.
Oh, yeah. I love it when I teach IT providers when they go into a new client that's health care.
Mhmm.
You should ask for their risk analysis and their risk management plan. They should have that. You should ask what's in their policies and procedures so that you make sure you're doing that.
And that's a rough one because a lot of IT folk do not want to read other people's documentation. They don't even wanna read their own. They don't wanna write their own. No.
I want them.
And I had a tech guy.
He was a developer, and I was explaining to him, you know, when you put these security pieces in, I need you to document them.
Yeah. And I was explaining to him, look, you make these decisions already. I just want you to write them down.
Write it down. Just write it down. It's not too fancy.
And he stopped just as, like, in the middle of grumbling, and he goes, you want me to eat my broccoli? Yes.
Yes. That is exactly. That is exactly right. You know, that that whole education peep piece and follow-up piece that you do is that's that's some difficult work, because you're you're spanning a lot of disciplines in order to get it all working together.
There's I think one of my favorite groups that I worked with so far started off as not my favorite group.
They were they were a business associate over in India.
So just imagine being a HIPAA business associate that is not located in the United States and and what it would take in order to become HIPAA compliant. And they absolutely failed the first year.
Mhmm.
And I walked away saying, well, I feel bad, but they're never coming back.
And yet, everything that I told them, they took to heart where the data has to be stored, and what the security controls had to be in place in order for them to to become compliant with with this regulation. You know, that how do we do what we wanna do and and be trusted. Right? So they knew that in order to be a trusted business associate for for covered entities, if the covered entity entity knows anything, they're gonna ask them, have you had a third party, assessment?
So I personally find a lot of value in third party assessments because it it's hard to look it's hard to look at what you're doing and find the problems because you're embedded in it. Like, you live it. You you're like, we're doing the best we can to put out this product, but then a third party comes in and sees all of the what's your experience with with organizations and and coming in as a third party? The very first time they have a third party look at at what they've got going on, what's what have you seen?
My favorite quote ever is we got a call, and we're about halfway through because, I mean, it we literally try to turn over every rock just like you're talking about.
Yeah.
And, you know, being in health care, you totally get this. But, they said, you're I've been through so many assessments, and going through your assessment is like a colonoscopy without anesthesia.
Accurate.
I said, yeah. We're doing our job.
Yeah. You're welcome.
She jokes and said, you broke me, but I'm better now. I'm a better person because, you know and and the the level that you have to get to to truly understand the things that you you constantly need to worry about this stuff.
Right. So from from your standpoint, just to kinda wrap up these concepts, if if an organization knows HIPAA applies to them and thinks they're doing all the right things Mhmm. What's the best thing that they can do to get a gut check on that?
I always say the first thing you have to do is say you don't know what you don't know.
Because we've had groups that call us in and say, we've got this covered, but, you know, we take approach.
It's fun at an expo when you're talking with people and we say, look. When it comes to HIPAA, most people fall into one of three categories.
Is they think they have it covered, and if you do, we'll come in, just do we we model the OCR audit protocol.
Mhmm. Yes.
That's why we do it as well.
Mhmm.
And we'll do the audit, and we literally, it's like you sign up, and then you just will randomly get the notification. I mean, we give you the upload place. We do it exactly the way OCR does it.
Right.
We just, you know, we randomly choose the questions out of the protocol. So we we'll do that. And if you think you've got it covered, we'll start there.
Right.
Then there's the people that are terrified, and we're designed to build that program and help you build and manage the program. That that's our wheelhouse. And then you have the people that say, HIPAA, I don't care. I can't really help you there.
Can't help them.
Mm-mm. I can't help you at that point until you're ready to reconsider.
Right.
And then I'll help move you to I'm terrified. I need help.
Right.
Because that's the next step. It's not like you go from here to here. Yeah. There's three.
So the most important thing that you can do is step back. And even if you do it yourself, you can go and download that audit protocol.
Mhmm.
It's a big long spreadsheet. There's hundreds of questions in there.
Yes.
And they're you know, and one question is really, like, ten questions.
It because it infers a lot of connections and a lot of things that have to be in place in order to answer that question.
Yeah. Inquire if they have done this. Yes. But this should include this, this, this, this, and this. Mhmm.
And if you truly think you've got it covered and you don't want that third party input Mhmm.
At least go do that.
Yeah. Yeah.
You know? And and Find out. Do the security rule first.
Yeah.
You know? Just start there. And then make your decisions.
Good advice.
Or you could just listen to podcasts like yours and ours and go, crap. I don't know what's going on.
I and I'm not kidding you. I have listened to every podcast you put out. Oh, wow. Since you I went back to the beginning, and I listened to all of them.
Because, I think that you have a a unique way of a a couple things you talk about, you know, current event. What's going on, and how is it how is it apply to things that I already know? But, also, how do you talk to people? And I I love the way you talk to organizations, both, on the IT side and the nontechnical side, about tough concepts.
You You know, you have the language to do that. So I really value what you've put out. And I'm so grateful to you for joining me today. I I'm this has been, something that I've really looked forward to.
Oh, thank you very much. We appreciate that. You know, we just record that and slap it out there and hope people learn from it. That's our big thing is we were all about educating people when we started. Definitely. And that's really what we're still about.
And we love to get feedback that says it's working.
And especially, you know, when people are enthusiastic about HIPAA because, you know, we've had people tell us, I didn't even think my job mattered until I started listening to you guys.
And and then it and it does.
It And you really start to understand how much what privacy and security means in the world of health care.
Exactly.
Well, I'm gonna keep listening to you.
I'm gonna keep listening to you. I really appreciate what you've done. Thank you so much for joining me today, and I hope we get to talk again.
Oh, thank you for having me, and good luck with your podcast.
Thank you. Alright. You take care. Thank you for joining us again here at the Security Metrics podcast, and I'll see you on the slopes.
Thanks for watching. To watch more episodes of Security Metrics podcast, click on the box on the right. If you prefer to listen to this podcast, it's available on all your favorite podcast platforms. See you on the slopes.
