Health IT Security and Compliance

A New Era, Few Guardrails: Strategies for Healthcare Leaders to Mitigate AI Risks Today

By Andrew Mahler – Imagine a large health system implementing an advanced AI-powered imaging tool designed to assist radiologists in identifying abnormalities in chest CT scans. The AI vendor’s marketing materials include data demonstrating faster turnaround times and reduced error rates, promising enhanced efficiency and accuracy.

Read More


The Cost of Catching Up

By Erik Eisen – Why Healthcare Practices Can’t Afford to Treat Cybersecurity Like a To-Do List. I’ve heard the fear and anxiety in the wake of a cybersecurity incident, “I wasn’t scared when it happened. I was scared when I realized how long we’d ignored it.” That’s the problem. “Cybersecurity” has become white noise.


Do Your Risk Analysis

By Matt Fisher – The drumbeat of settlement agreements for alleged HIPAA violations by the Office for Civil Rights is continuing along with the consistent finding that the required risk analysis did not occur. The consistent announcement of settlements offers regular reminders to the healthcare industry that OCR is watching and expecting compliance to improve.



Be Truthful to Get Patients

By Matt Fisher – Imagine this scenario: an individual is suffering from substance use disorder and decides to seek help. A big reason for not getting treatment is reportedly not knowing how or where to get treatment, not being able to afford the treatment, and/or not finding a program or clinician where they wanted to be able to go.



Insider Risks

By Matt Fisher – The risk to privacy and security of healthcare information, despite all of the headlines, does not only come from outside attackers. Inside threats are real and can go undetected for potentially longer periods of time.