This page contains an archive of 3Lions Publishing Inc.'s monthly HIPAA Compliance Newsletters and Important Announcements! The current issue of the newsletter is not available here until after the month it was issued.
ANNOUNCEMENTS
Enterprise MVP
We are happy to announce the availability of our Enterprise MVP product. Our MVP solves the three most insidious and disruptive requirements of the proposed Privacy Rule. It is ready and shippable day one when the Rule drops and it will be included as part of our Subscription (i.e., Subscribers acquire it free as a value-add part of their Subscription). We also are announcing our MVP Jumpstart professional services offering, which is a fee-based engagement for organizations that want 3Lions to drive our MVP implementation within their respective organizations. See attached data sheet.
Third Party Audit
We are likewise happy to announce our fee based third party audit engagement. We have completely demystified third-party audits by combining our Compliance Equation® with our Privacy and Security Checklists (both contain all requirements for each Rule), requiring asking one and only one question to determine compliance with a requirement: “Does your implementation of the requirement satisfy the Compliance Equation®?” If the answer is “Yes” even though your implementation score is “Basic” (i.e., according to our Scorecards) then you comply, otherwise you don’t. Subscribers have left our competitors whose audit methodology requires answering dozens of questions per requirement. By disrupting the audit process, 3Lions has improved the quality, rigor, and speed of the audit while significantly reducing costs. Further, 3Lions’ outside counsel, a nationally recognized HIPAA authority, will certify the audit, with a signed opinion letter, as part of the engagement.
Phishing Maxims
3Lions once again has delivered process innovation by delivering a set of ordered Phishing Maxims that eliminate the lion’s share of Phishing emails that require review, significantly reducing the possibility that a Phishing email will penetrate your network, causing a Breach or ransomware incident. Our Maxims eliminate unnecessary Phishing terms of art (e.g., spear fishing, whale fishing, etc.). The latter served to confuse the workforce, adding no additional value. Our existing Security Reminders monthly service, part of our Subscription, will now also include Phishing reminders that illustrate how the “bad guys” are innovating to circumvent industry standard email defenses. This additional service creates awareness and helps further develop defenses. Phishing emails still represent over 95% of the vectors by which the “bad guys” penetrate your network and deposit their malware payload.
To get a current version of the FREE Newsletter and Webinars you can subscribe here. Don't forget to sign up for the newsletter if you haven't already. You will receive monthly articles on HIPAA and Compliance topics as well as notification of upcoming FREE Webinars.
NEWSLETTERS
January 2023
Our article this month is entitled: CPRA Overview: Policies, Processes, and Tracking Mechanisms
December 2022 No Newsletter or Webinar this month.
November 2022
Our article this month is entitled: Security Incidents Revisited
October 2022
Our article this month is entitled: Why Hierarchy kills Cross-functional Product/Process Innovation Always
September 2022
Our article this month is entitled: The Compliance Equation: Demystifying Compliance Audits
August 2022
Our article this month is entitled: Risk Management without Quantification is Voodoo Science
July 2022
Our article this month is entitled: A Universal Grammar for Managing Organizational Risk: How to effectively and dramatically reduce cost and accelerate the risk decision process.
Our article this month is entitled: Unraveling the enigma of the 21st Century Cures Act in the Proposed Privacy Rule
Our article this month is entitled: OCR Audits Revisited
Our article this month is entitled: Components of a Mature Compliance Program
Our article this month is entitled: Intersection of the Proposed Privacy Rule, Information Blocking, and changes to 42 CFR Part2 regarding case management and case coordination
Our article this month is entitled: Stuck on Stupid: The FINAL 2021 Privacy & the Purported Experts
Our article this month is entitled: The difference between Privacy and Security regimes
Our article for December was a re-do of: Re-Do: A Massively Transformative and Disruptive Rule for 2021
Our article this month is entitled: A Massively Transformative and Disruptive Rule for 2021
Our article this month is entitled: HIPAA Security Rule Risks
Our article this month is entitled: Access to Protected Health Information
Our article this month is entitled: Compliance Dynamism
Our article this month is entitled: Creating a Culture of Compliance
Our article this month is entitled: RMF and Swim Lane Diagrams
Our article this month is entitled: Poking through the Privacy Rule
Our article this month is entitled: Compliance and Black Swan Events
Our article this month is entitled: COVID, Telemedicine and HIPAA
Our article this month is entitled: HIPAA Enforcement is Alive & Well
Our article this month is entitled: What makes a Compliance Officer Competent?
Our article this month is entitled: Visible, Demonstrable Evidence
Our article this month is entitled: Stuck on Stupid: Managing Multiple Compliance Regimes
Our article this month is entitled: Stuck on Stupid Revisited
Our article this month is entitled: Why SOC-2 will Derail your Cyber-Security Initiative
Our article this month is entitled: No, Actually You Don’t Have HIPAA Under Control
Our article this month is entitled: Ransomware & Cyber Insurance
Our article this month is entitled: COVID-19 ("C-19") and Ransomware
Our article this month is entitled: Ransomware Resilience: Only the Paranoid Survive!
Our article this month is entitled: A Short History of Cyber War and Why it Matters
Our article this month is entitled: In the Digital Economy, Only the Paranoid Survive
Our article this month is entitled: What you need is a Workflow
Our article this month is entitled: What makes a Compliance Officer Competent?
Our article this month is entitled: Security Reminders
Our article this month is entitled: Business Partner Vetting Challenges
Our article this month is entitled: Information System Review Challenges
Our article this month is entitled: A Deeper Dive into 42 CFR Part 2
Our article this month is entitled: The Self-Audit Process
Our article this month is entitled: HHS' Reduction in Enforcement Penalties
Our article this month is entitled: Ten (10) Magic Security Controls
Our article this month is entitled: The Importance of Taxonomies
Our article this month is entitled: 42 CFR Sections A-D
Our article this month is entitled: Privacy by Design and Privacy by Default