VanRein Compliance Podcast
Learn how you can secure the future of your business with a clear plan to reduce your risk. We discuss all compliance and data security matters of SOC2, ISO27001, HIPAA, GDPR, CPRA, NYShield, Texas HB300, ISO27001, HiTRUST and include life stories as well. It's NOT just a boring BizCast. We also talk about our Family Business and how you can start your own Family Business that will reshape your future.
VanRein Compliance Podcast
HHS Just Told Us What’s Coming — Are You Ready?
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
We distill the biggest takeaways from the HHS NIST annual cybersecurity conference into clear actions for healthcare leaders who need to stay HIPAA compliant without getting buried. We connect breach trends, OCR enforcement priorities, ransomware realities, and AI governance into one practical roadmap for reducing risk and protecting patient care.
• healthcare breach trends and why hacking plus email and servers dominate
• why HIPAA compliance must include MFA, access controls, backups, and vendor controls
• OCR enforcement priorities, including right of access and risk analysis expectations
• how to run a real risk analysis by following ePHI across systems and third parties
• why medical device security and proper disposal can make or break compliance
• patient safety as the core cybersecurity outcome during outages and downtime
• emerging threats like quishing, social engineering, nation-state activity, and DDoS
• third-party risk lessons from the Change Healthcare ransomware incident
• practical AI governance using the NIST AI Risk Management Framework
• next steps, including AI inventory, incident response testing, and workforce training
Thank You for Listening to the VRC Podcast!
Visit us at VanRein Compliance
You can Book a 15min Call with a Guide
Follow us on LinkedIn
Follow us on X
Follow us on Facebook
Welcome And Conference Takeaways
RobWelcome to the Van Ryan Compliance Podcast with Rob and Don. We help growing teams reduce risks, build trust, and stay audit ready without the overwhelm. Welcome back to the Van Ryan Compliance Podcast. I'm Rob.
DawnAnd I'm Don.
RobHey, Don. We had a very enjoyable time last week, didn't we?
DawnYes, it was a bit dry, but uh we got through it, got some good info.
RobWe sat through two days of the HHS NIST annual cybersecurity conference to focus on healthcare compliance and security. Uh went through HIPAA ransomware, enforcement, to AI to medical device security, and all that. So instead of giving you hours of conference content, what are we going to do?
DawnWe're just going to give you parts you actually need to know and especially what this means for healthcare organizations, trying to manage compliance, cybersecurity, and AI. So we are going to go through it, kind of break it down step by step. Um, so let's get into it, Rob.
RobYep, let's do it.
Healthcare Breach Trends And Attack Types
RobSo let's start with data breaches, because they always love to start with data breaches on the first day as we go through everything. Um, healthcare breaches went from 736 reported breaches, affecting about 290 million people's lives in 2024. This year, we're sitting at 650 breaches, affecting about 45.7 million lives at the end of 2025. Uh, if we remember the big change, healthcare was the big impact in 2024 and about 45 million in 25. Looks like we're on track to actually go back over 45 million so far with the recent uh care cloud massive incident and breach about two weeks ago, which impacted three and a half million people in just one breach.
DawnRight. Right. It sounds like a major improvement. Oh, it went down. The graph went down. But until you look at the attack types, um, through July 26, hacking accounted for 75% of healthcare breaches.
SPEAKER_01Yep.
DawnAnd network servers plus email represented about 88% of breach locations. So fewer people were affected during the 2024 peak, but instance we're seeing, uh the instance we're seeing right now or they're seeing are increased, increasing uh cyber attacks. So that's why HIPAA compliance today can't just be the policies and trainings, your emails, servers, access controls, vendors, and backups are all part of this compliance conversation.
SPEAKER_01Yep.
DawnSo if you're one of our customers, you do know this. This is what we talk about all the time. It's not just a policy procedure and a check the box on the training.
RobSo
OCR Priorities And Real Risk Management
Robthat's exactly right. And the OCR also identified four enforcement priorities. So this is what we always look listen for is what are they looking for? What is the government looking for in the next year? Uh well, and the first the first point is the HIPAA security rule, which was supposed to get updated in June of this year, has now got pushed an entire year. So we won't see new law until July of 2027. Uh that may get moved up, but probably not being government. So we have another year to wait. But we also know that they like to drop a little bit, a little bit of nugget enforcements as I call them, right? Little breadcrumbs get leading to the main overall in July. Um but that's kind of what we're seeing so far.
DawnRight. And some of those key key things to highlight, uh points to highlight, are the right of access, which is the right of access to your health records, risk analysis and risk management. They were big on this. Yeah. Thank God. Hacking and ransomware and 42 CFR part two. So those were big. Um, and you know, they've completed in regards to right of access, which they they highlighted was probably the first big highlight. Um, and then risk analysis and risk management were the were second. Um they completed 55 right of access enforcement actions. So they've done that, and there's been 14 risk analysis related actions. They definitely are watching, auditing, paying attention to what's going on, um, and basically help your organization uh really make sure you're you're on point and and you're you're doing what you need to do is it identify any outdated systems. Identify if you're missing MFA, if you have excessive access, uh a vendor issue, or unencrypted devices. So um that's really what you'll want to address um, you know, it you know, here uh one of the one of the big things that they wanted to make sure people address. Um there's other things too, but that's just kind of the the kind of the highlight on on those on those items.
RobSo those are the key pieces. And so a risk assessment sitting in a folder isn't the finish line, right? It's really the start. So when we do an audit, we first do an audit, we look, we find the remediations, uh excuse me, find the the issues that we that we need to have remediated and put together. And then what that does is creates a uh working plan for the next six to twelve months.
SPEAKER_01Right.
RobSometimes clients get it done in a couple months, but usually it's about about six months. Um there's also practical guidance about what a thorough risk analysis should look like. And you mentioned this earlier, Dawn, is they are really focused on a risk analysis. And this is what we do. This is a starting point. You you don't know what you don't know until you dive in and really identify the risk, not only into your processes and systems, but also looking at other vendors, outside vendors, from AI to platforms to all of that. Um that's really what they're focusing on.
DawnYep. And they basically said, you know, follow the EPHI. Where is it?
RobFollow the background.
DawnWhere is it? You know, where does it move internally? How does it leave? Is it encrypted? Where's the data? Who can access it? Um, what systems and vendors touch it? And where could something go wrong? This is a huge key. Uh, again, third-party vendors. You need to be assessing them, vetting them, and making sure that you know where that data is, is and if it's encrypted. So that was big. I was happy to hear that they they uh highlighted
Following EPHI Through Vendors And Systems
Dawnthat.
unknownRight.
RobYeah. And if you put if you put AI to the side, don't forget we still have the same platforms that we worked with for years. There's email, there's fax, file transfers, APIs, MCPs now, collaboration tools, and uh, even equipment disposal. They were big on medical equipment. Yes. So anybody that uses medical equipment um that has health information, that is a big, big um security risk, not only for the company, but also the patients. Uh where's the data? Where's it located, and where is it going? Uh that's one thing they're really seeing. Another piece is how is it disposed properly? Where is it really getting disposed? Are the drives and memory erased? Is it physically destroyed? What does that look like?
DawnRight.
RobYep. Um, and now then enforcement, you know, isn't just for large health systems. So it goes down to the one-person courier service up to you know billion-dollar health systems. Uh and they also showed a long list of recent settlements, didn't they, Don? People are paying up.
DawnYeah, yep, they did. They didn't even bring up the HIPAA wall of shame, but they had their own uh their own list of the HIPAA wall of shame and their own graphs. So yep. Definitely, yeah. And in there are all kinds of organizations that were involved clinics, imaging companies, health plans, healthcare facilities, business associates, settlements from 10 grand to 550,000. The idea that you're too small for OCR to care about us, we're under the radar. No, that's not those days are gone.
RobThese are never there. It doesn't matter how big you are. If you have health information, you're an entity.
DawnExactly. Exactly.
RobSo and watching the NIST controls are big. You know, they've they're updating. There's 2.0 that's out. They're gonna slowly update things over the next few months, so that's where we are here to make sure we stay ahead of those. And we roll in NIST plus HIPAA. And now we actually are our auditing is HIPAA plus NIST plus AI. It's all kind of wrapped into one right now. Correct. Um and the HIPAA security rule changes are still proposed, right? We just talked about this earlier. Yeah but we're gonna we're gonna wait till July of 27.
DawnYep. Yep. And one of the one of the significant proposed changes, which um this always surprises us, is is they're moving encryption from addressable to required. Really?
unknownYeah.
DawnIf you haven't made encryption a requirement, I you know, I don't know. Uh maybe you shouldn't be in business. I um it it's just kind of funny. And but the the lady, nice lady, she uh she did say, Oh, these are still proposed. So um, you know, kind of the the typical government answer, but um but it they're trying to put some teeth into it. Um definitely they understand there's a lot of risk out there, and so they know what they need to do, but again, are they doing enough? You know, this is where you as an organization need to make sure you're you're doing as much as you can.
RobUm so yeah, and then also the towards the end of the first day and of the second, they really talked about patient safety. That was kind of the big thing. Um when there's outages, you put the risk of the patient in in harm's way, right? It could be anywhere from a driving service, a courier service, an answering service, uh interoperative, uh neurological monitoring service, it could be a medical practice, it could be an ER, it could be anything. Uh if you're even if your platforms are down, what it what if you're you're built off of Azure or AWS or GCP and that's down? That is all ties into patient safety. So every bit and piece that you have uh ties into how uh how safe your operating room is to just seeing a PCP just to get blood draw, just basics like that.
DawnYeah. Yeah, and the the data was interesting on hospitals, and again, they were very concerned about patients' um care getting disrupted. Uh 30% hospitals experience cyber attacks. Um, it's not just a IT problem, it's care. The care gets disrupted. So clinicians lose access to records, patients get diverted, operations stop, you know, it becomes patient safety, patient safety issue. That was really good that they really highlighted that in making sure that, you know, and also they they did say too, you could you could have lots of money. Yeah, you could have lots of money and try to get the best security.
RobYeah.
DawnAnd if you don't have things in place, if you don't have the right things in in in place and you haven't done the right things, doesn't matter how much money you spent. So um, but yeah, that definitely patient care was uh and patient safety was a top priority.
RobAnd the first thing you have to do is a thorough risk analysis and audit
Patient Safety Downtime And Medical Devices
Roband understanding everything where everything is. And then safeguards, putting the safeguards in place and then actually implementing all that. I think the big thing that I noticed is that um there's been an estimated 21, uh $21 billion in downtime, downtime losses since 2018 just from cyber attacks or ransomware. Uh average healthcare breach costs in 24 is about 9.7 million. So an average breach for a, you know, those are medium to large healthcare entities um $9 million, just like that. So that's why, yes, you need your health, you need your insurance plans. But remember, insurance carriers are there to actually ensure they do not have to pay. So you got to make sure that you're doing everything right. Those are the key pieces that we're really focused on. Uh and medical devices continue to be part of the problem. I I think of them as a medical device, but also any entity that assists with that device. Uh, you know, there's over 26,000 connected devices per hospital. That's crazy. Everything's like the whole internet of things, and 53% carrying critical data. That's just remarkable.
DawnYep.
RobYep.
DawnYep. And and 85% of medical devices operate on outdated legacy networks. Um, we did have this years ago. Well, not that, not many years ago. Customers that were um purchasing used equipment, ultrasound equipment, and they had patient data still on the equipment that they bought. Yeah. I mean, it it is it is a huge, huge issue. Yep. Um, so and you know, if they're on legacy networks, can you patch them? You know, are they still be you know being supported? Um, so that is a that is a big issue too. And so they were big on, you know, end-of-life planning inventory. So they did spend quite a bit of time on medical devicing devices as well.
RobAnd the key thing is if it's not supported by the manufacturer or whatever operating system is on there, yeah, then um you can't use it. It's outdated. And attackers know the patch levels. You know, it's it's a business. Attacking large amounts of data in large entities is a business.
SPEAKER_01Yeah.
RobAnd so they know if there's a outdated Microsoft or Apple or Linux patch that hasn't been rolled out, they're gonna look for that vulnerability. So then we kind of talked about the uh ISAC ISAC also gave us a snapshot of current targeted alerts. So, what were kind of some of the targeted alerts on that you had captured during our two-day conference?
DawnWell, I like the I like the term quishing because you know they always come up with you know phishing, quishing, the QR code thing. The QR code phishing. This is super interesting. Uh, we were just at a football game this weekend, and up on the big jumbo screen, click the QR code to do the uh the game. You know, who's gonna win, you know, whatever, the game. Click one, whatever. You know how many of us click these QR codes? I mean, through everything we do. I mean, there's there's the demo, there's this and that. The key to the QR code is if there isn't a logo inside that QR code, do not click it.
New Threats From Quishing To DDoS
unknownYeah.
DawnBecause that's how hackers are hacking into those basic QR codes. They're getting into however whatever they're doing, um, you know, they're but they're getting into them. So it's called quishing. So be very, very mindful of your QR code. If you're business, if you're going to conferences and that type of thing, make sure it's your logo in the middle. Make sure people know it's they're clicking on you and your QR code, and it's not just a random black and white QR code. Yeah. Um, so that was interesting. Then, you know, there's all the there's also newer social engineering attacks like quick fix, file fix, where fake system errors convince users to run a code. There's always something, always someone out there trying to steal something. All right. So there's always news.
RobWe spent all these years teaching people to not click on fraudulent emails. Now don't whip out your phone and scan a fraudulent code. So I don't scan anything because that's just tracks, it just puts cookies on everything. Yeah, very, very dangerous. And then obviously the nation state threats, right? Yeah. It's the same players, South Korea, well, not South Korea. Let's try North Korea. North Korea, North Korea. There we go. Oops. Um North Korea, China, it's uh the uh Middle East, it's Iran, you know, it's all the bad state threats. Uh it's the same thing that we see uh day in and day out. Right. And so um what we're seeing is a lot of state-backed activity linked to China is probably the largest where they're stealing data and stealing information. Uh North Korea has operating remote IT workers, that's a big thing. Where you'll like, for example, uh we you know, interview for an opportunity or a job here in the States. Say, like, Don, if you interviewed and you got the job, um, they use your background, your information, your credentials, your education, you get the job, and then all of a sudden um your you know laptop is shipped from you know Texas to like Oklahoma. You're like, okay, that's weird. Why is he going to a different state? And then um someone that would you know be part of the team but never show their face, never talk. Um they're just there to be a state, you know, espage agent and and infiltrate networks and companies with ransomware. Just unbelievable. Yeah.
DawnYeah.
RobUm what about the DDoS attacks, Don? I talked about that as well.
DawnYeah. Um the data wiping compromise camera feeds.
RobYeah. Yeah.
DawnI mean, it, you know, it's crazy. They just they need to understand, everyone needs to understand. They need to make sure they they keep up on this. And and our government does keep up on cyber threats and that type of thing. I mean, there's they definitely know what's going on. But yourself and your business, be really smart. Be really smart about who you're doing business with, really smart about what cameras that you are engaging in. I'm sure everyone's heard about the flock cameras. Um, you know, just just make sure you understand who you're doing business with um and where your data is going. Um, and that that's really the key here. Um, so yeah.
RobIt is. And then they rolled into that, they brought the change healthcare uh risk cyber attack from uh 24. Um, and that was 190 million people. So 190 people's lives are impacted by the change health. And so they went back to that because that was a third-party risk that was infiltrated. Um Black Cat, also known as the ELF V, identified as a threat actor and reported $22 million ransom was paid. So they got $22 million US dollars for impacting 190 million lives by attacking change health. It's business people. And it doesn't matter if you're business, small, big, whatever you think it is, you will be impacted. And for small businesses, I would say under 50 people, they're gonna start a million to two million dollar ransom. And it is illegal to pay them. You have to get the FBI involved and go through the steps to determine how how that data is uh is secured. And you need to also be able to have a good disaster recovery plan to roll back to the day prior.
DawnWhat do I say? What do I say at every on every podcast and with in every conversation is third-party risk?
unknownYep.
RobIt's always vendor management.
DawnVendor management.
RobYep.
DawnDo you have a BA? What happens if that vendor disappears? We have a lot of AI right now. They're not all gonna make it. So something you're using today could be gone tomorrow. Where's that data? How are you getting that data? How do you get the data from there? Can you still operate? Is it tied into everything? Um, you know, so are you gonna have downtime? You know, there's a lot of companies you work with that are 24-7. Can't afford to have downtime. So vendor management is huge.
RobYeah. So and you mentioned AI, let's move into that. I mean, that's kind of the big piece is you know, AI is not bad. It's not evil, it's not coming gardi's job. Um, I see it's actually gonna make things easier, cleaner, and better. However, um, there is a great opportunity where AI agents will create other AI agents that will create websites or data flows. And all of that information has to be explicitly listed into a business associate agreement
Change Healthcare Ransom Vendor Lessons
Roband under contract because it's going so fast and it's 24-7 now that things, you know, these bots work day and night. So it's not all bad, but the big thing to do is focus on the NIST AI risk management framework. That's the really that's the key. Um it's it's voluntary, which it should be regulated, but it's not. Um, but we offer it as here's Van Ryan, and we're starting to wee this into our HIPAA audits already, and it centers on those four functions of govern, map, measure, and manage. Those are the four functions that the NIST AI risk management framework is focused on.
DawnYep.
unknownYep.
DawnYep. And to break that down, govern is who's responsible. Map is where are we using AI. Yeah. Measure is what risk does it create, and manage what are we doing about those risks? So it works whether you're running dozens of AI models or you're running one AI transcription tool or one small bot. Um so it's definitely um adaptable to your environment. Yep.
RobYep. Those are key pieces. And AI doesn't get an exception. So the law is to the law. And and the law is 30 plus years old. It is very pliable, it is a massive funnel. You can throw any type of technology from AI to new hardware, new software, anything, and it still falls under the law. It doesn't change. There's no exceptions. Um, you still must have your business associate agreements in place, your risk analysis, your risk management and access controls. Those are all key pieces that they hit on. And that's the things that we we look at. But the big piece as well is the AI inventory. Um right, Don. What are the what are some of the things on the AI inventory that uh that they had mentioned or what we look for?
DawnSo on your third-party vendor management list, you should have AI on there. And what what tool is it? What AI tool are you using? How many are using? What data are they receiving? Who's approving them, those AI tools in your organization? How long does the vendor retain the information? And is a human reviewing the output before it affects something important? So is there a human in the middle? A lot of what we're doing right now is there needs to be human in the middle for a lot of things. Um, you know, you say, oh, I can look up this law or look up this what to do on Chat GBT, but they're not a legal entity. So you've got to make sure that, okay, here's some information, but I need to really ask an attorney for, you know, making sure that's correct. So it's just being cautious, being cautious about what you're using and how you're using it.
RobYep. And be careful on the agentic AI systems. They're very powerful. Um, so if you're using them for, you know, maybe finances or marketing or sales or outreach or or any type of um anything natures that like that, make sure you know where the bots are going. Make sure are they internal to the systems? Are they going out to other third-party sites, right? A lot of them will do that, getting credentials and stuff like that. The eugenic
AI Governance With NIST AI RMF
Robpieces, those are the key pieces. Um as you move into like the AI and cybersecurity, you know, it's all converging, it's all coming together. So that cyber AI profile. File, which is important, which is key. You need to map all your AI-specific considerations in the cybersecurity framework. We have frameworks. We and we audit against the frameworks. And these are this is the best roadmaps we have for AI. Even if you look at Hitrust or ISO 42001, there's some good bits and pieces of how things are implemented, but it really doesn't give you the framework of how to. It's auditing against those standards. And those are the things that we're really looking for.
DawnAnd then NIST did finalize an updated ransomware risk management profile in June of this year.
RobYep.
DawnSo that was they they highlighted that too, that they they beefed that up. So that's definitely worth mentioning as well.
RobYep. That's a good point. Very good. Um AI does have a you know real upside as well. Yeah, I would say the conference was not anti-AI. I know we're not anti-AI. I think it's just how you roll it out. Um I I know there was some very positive reports. There was a couple pairs that talked about a 400% increase in productivity to just close out claims. Uh and we know claims processing is horrible. Anytime you go you need to the dentist, get your teeth cleaned. It takes forever to get any of that information back or get the claims processed. So if you can do a 400% productivity in increase in just a week, yeah, I do it. That's great. But make sure you have the frameworks put in place and everything as secure as where they should be. So absolutely.
DawnYep.
RobSo, Don, what are some of the things we should do next with all this great information?
DawnYeah. I would um first there there's probably five about five things to focus on. Uh review your risk analysis. Yes. Um, make sure you're actually managing what it identifies.
SPEAKER_01Yep.
DawnUm, do you even know what your risks are? Make sure you're maybe done a risk assessment, but you kind of, okay, yeah, I did it. I'm done. Um identify critical vendors. What happens if they go offline? If they're critical vendors, you should be auditing them at least annually.
SPEAKER_01Yeah.
DawnIf not sooner. Um third, inventory your AI tools and try building an AI governance program around that using that NIST um AI governance, the controls there. And fourth, um, test your instant response downtime procedures.
SPEAKER_01Yeah.
DawnIf you don't have, if you don't have a plan, uh, or you know, if you just have a plan, that's great, but you need to practice it.
SPEAKER_01Yep.
DawnYou know what happens.
SPEAKER_01Yep. Those are the key bases.
DawnAnd and lastly, and this is where what's near and dear to our heart as well, um, is workforce training. Oh is constantly we're constantly updating our cybersecurity training, email phishing training, is constantly updating with what the recent attacks and and that type of thing um so your employees know what to look for.
RobSo and the good thing is you don't have to build this from scratch. You know, we've got all the resources. The government actually has a lot of these for free, but it is like you mentioned last week, Dawn, it's very complicated. Um,
Five Next Steps And Closing
Roband we're here to to clarify the complicated compliance. Yeah. And that's what Van Ryan does. But everything from cyber gateways to OCR rules to ASPR, I mean, there's so many acronyms, typical government stuff. But we just need to um make those simplified like we do and walk you through them and make sure you're you're adhering to the law, not only the law, but also protecting your business that should work very hard to build up.
DawnSo absolutely.
RobYep. Yeah, very good. So sum it up, Rob. Sum it up. Well Sum it up. I think to summarize everything, um, everything from healthcare compliance, cybersecurity, and AI governance are becoming harder and harder to separate. It is all blended into one. Um, and that's why we we've we've already combined, like a compliance sandwich, right? Must be even near lunchtime, um, is HIPAA plus AI plus NIST. It's really the best of those of those worlds. Even better than a certification because it actually dives deeper into the law, gives you the roadmaps that you need. But that's why we're here too is help help show you how to do the audit, get the audit done, give you the roadmap, and then hold you accountable so that you can have it all done and you're secure, you're secure in your environment and your and um and your business.
DawnSo absolutely.
RobYep.
DawnGood sum up. All right.
RobGood. Well, until next week, everybody, thanks for joining us, the Van Ryan Compliance Podcast. I'm Rob.
DawnAnd I'm Don. All right.
RobUntil next week. Bye-bye.
DawnGoodbye.