HCC

Season one

Twelve episodes. Zero fluff.

Ransomware and downtime, HIPAA and documentation, secure texting, agency staff and mobile devices, vendor risk, incident response, AI governance, surveys, and the decisions that create or prevent the next crisis.

01

Why Cybersecurity Is a Care Issue

A cyber event hits care delivery, documentation, staffing, medication processes, resident safety, surveys, finances, and reputation. It is never just computers.

02

The Risk Assessment That Cannot Collect Dust

What a real HIPAA Security Rule risk analysis looks like, how it differs from a checkbox exercise, and how findings become an owned remediation plan.

03

Ransomware: What Happens After the Click?

A realistic senior-care ransomware scenario, from phishing email to downtime, clinical workarounds, legal decisions, communications, and recovery.

04

The Inside Threat Is Usually Not an Insider

Unintentional risk from busy staff: reused passwords, misdirected messages, lost devices, sketchy USB drives, and well-intentioned workarounds.

05

Texting, Email, and PHI: Convenience Has a Cost

Secure texting, email encryption, message retention, carrier and device risks, documentation expectations, and practical policy calls.

06

The Mobile Workforce: BYOD, Agency Staff, and Access

Agency staff, contractors, remote workers, personal devices, role-based access, onboarding and offboarding, and mobile-device management.

07

Backup Is Not Recovery

Having backups is not the same as being able to restore. Recovery priorities, RTO, restore testing, downtime workflows, and vendor dependencies.

08

The Devices Nobody Thinks About

IoT, connected clinical devices, printers, copier memory, faxing, shared workstations, facilities tech, and who is accountable for all of it.

09

Training That Changes Behavior

Past annual checkbox training: role-based, short, repeatable education, phishing reporting, agency-staff training, and leadership modeling.

10

When AI Enters the Building

Where AI is quietly showing up: documentation, admissions, call centers, referrals, utilization review, EHR features, and employee-built workflows.

11

AI, Documentation, and the Human Being Who Is Still Responsible

Hallucinated documentation, clinical validation, bias, human review, and why "the tool said so" is never a sufficient defense.

12

Building an AI Policy That People Will Actually Follow

A pragmatic AI governance program: use-case inventory, permitted and prohibited uses, PHI guardrails, approvals, controls, and ownership.

On the whiteboard

The future-topic bank. What season two could sound like.

What Boards Should Ask About Cyber RiskBreach Response: The First 24 HoursVendor Risk Is Resident RiskMFA Is Not a Strategy, but It Is Still EssentialCyber Insurance: What Are You Actually Buying?Privacy in the Age of Smart Cameras and MonitoringPhishing Is Now an HR Problem TooThe Surveyor, the Record, and the AlgorithmThird Parties at 2 A.M.Keeping IT and Compliance in the Same Room