Saturday 28 April 2018

Goodwin Law and Paubox Social Mixer for 500 Startups Health Track

Dale Beermann, Rebecca Woodcock, Jonathan , Saleem

  • We co-hosted a social mixer for 500 Startups Health Track last night
  • We also launched a new HIPAA Compliant Email API service
  • There are 40 companies in the 500 Health portfolio

Last night we co-hosted a social mixer for 500 Startups Health Tracks with our legal counsel, Goodwin Law.

We held it at Covo and had catered food delivered from City Counter.

We used the event as a forcing function to launch our new JSON HIPAA Compliant Email API. We pushed hard this week to launch and we got it done. Proud of our team.

Enjoy the pics!


Tyler “Commish” Dornenburg (Leapcure) with a strong use of hand gestures.
Evan Fitzgerald, Traven Watase, Tyler Dornenburg
We launched our new JSON HIPAA Compliant Email API today. Stoked.
Greg Hoffman, Shannon Honda - Paubox Social Mixer
Bill Growney from Goodwin Law. Mahalo for hosting the event with us, Bill!
Bill Growney, Traven Watase
Renee Char and Evan Fitzgerald chillaxin after our API launch.
Renee Char, Evan Fitzgerald
Ari Tulla (BetterDoctor) and Rebecca Woodcock (500 Health) catching up.
Ari Tulla, Rebecca Woodcock
“Where do we put these banners?”
Evan Fitzgerald, Greg Hoffman - Goodwin Law Paubox Social MIxer
Ari Tulla’s phone was on point last night. Most likely a preview of the Mix Tape of Happiness
Rebecca Woodcock, Dale Beermann, Jonathan, Ari Tulla
Rebecca Woodcock, Dale Beermann (Pacifica), Robert “Rogus1” Ogus, Suraj Mehta
Rebecca Woodcock, Dale Beermann, Robert Ogus
Evan “Senor Agave” Fitzgerald espousing the numerous health benefits of the Tequila Diet.
Evan Fitzgerald espousing the Tequila Diet

The post Goodwin Law and Paubox Social Mixer for 500 Startups Health Track appeared first on Paubox.

Tuesday 24 April 2018

Base Plays from a Startup CEO

Base Plays from a Startup CEO - Paubox
Early Paubox Customer Map – July 2016

Earlier this month, I heard NFL legend Joe Montana speak at the JSV Book Club in San Francisco.

One of my key takeaways from that evening was Joe’s affinity for Base Plays.

Base Plays are the simple plays you learn early in the season. These are the same plays you go back to all the time.

I strongly felt we could incorporate Base Plays into Paubox, so we set about and compiled them.

For us, Base Plays are the simple tactics and habits that got us to where we are. If we get in a rut or hit a rough patch, we can go back to our Base Plays to get back on track.

For what it’s worth to startup founders out there, here are my base plays as CEO of Paubox.

Relevance. Always strive to be and remain relevant.
Hoala Greevy & Jeremiah Grossman - Paubox Base Plays

Arrive early. Do not be late.
Hoala Greevy & Sam Altman - Paubox Base Plays

Exercise. Paubox is gonna be a monster. Keep in shape, avoid burnout.
Paubox Base Plays - Exercise

Holoholo. Don’t forget to get in the water! This is who you are.
Holoholo. Paubox Base Plays

Customer Feedback. Never forget, use customer feedback as a roadmap of what to build and when to build it.
Dinner with Preston Terada - Paubox Base Plays

Dance with the one that brought you. Take care of the folks that got you here.
Dinner with Blaine Kahoonei - Paubox Base Plays

Community Service. The Leader always gives back.
Base Plays from a Startup CEO - Paubox

The post Base Plays from a Startup CEO appeared first on Paubox.

Don’t get phished: 3 email security lessons for healthcare companies

paubox 404 error, paubox 404 error page
Theft of medical records is so common that if it continues at its current rate, everyone’s healthcare data could be compromised by the year 2024. The problem is that employees are rarely as good at spotting phishing attacks as they think they are, and even the best anti-hacking measures can’t overcome human error.

Securing healthcare data has always been a priority, but it’s become much more of one over the past few years. In addition to the infamous WannaCry attack that crippled healthcare services around the world, 2017 also saw a spate of malware attacks aimed at providers.
Despite the increase in the frequency and visibility of attacks, healthcare providers continue to make a few mistakes that leave them vulnerable to phishing emails.
Read the full article on Healthcare Business & Technology.

The post Don’t get phished: 3 email security lessons for healthcare companies appeared first on Paubox.

Saturday 21 April 2018

HIPAA Breach Report for April 2018

hipaa breach reporting, hipaa breach, hipaa, reporting

The Paubox Breach Report analyzed HIPAA breach reporting submitted to the U.S. Department of Health & Human Services (HHS) in March to analyze the types of breaches of unsecured protected health information (PHI) affecting 500 or more people.

HIPAA Breaches Ranked by People Affected

Paubox HIPAA Breach Report: April 2018 - Breaches Ranked by People Affected

Top Three Breach Types

  • Email breaches ranked the highest with 89,180 people’s PHI hacked or stolen in March.
  • Electronic Medical Record breaches ranked second with PHI of 64,621 people breached.
  • Network Server breaches came in a distant third with 38,689 people having their PHI breached.

Bottom Three Breach Types

  • Desktop Computer ranked as the lowest number of people’s PHI being breached in March with 662 breaches.
  • Other Portable Electronic Device was the second lowest type of breach as ranked by people affected with 6,707.
  • Other was the third lowest type of breach as ranked by people affected with 10,793.

HIPAA Breaches Ranked by Occurrence

Paubox HIPAA Breach Report: April 2018 - Breaches Ranked by Occurrence

The Most Common

  • Email took the top spot as the most common breach type in March with 6 reported breaches.
  • Paper/Films came in as the second most common breach type with 5 incidents.
  • Other, Laptop, and Other Portable Electronic Device came in tied for third with 4 reported breaches each in March.

Takeaways

Email once again ranked first in both categories: Breaches Ranked by People Affected and Breaches Ranked by Occurrence. The last time email ranked first in both categories was in November 2017.

I believe we are seeing a correlation to the recent ransomware attacks across the nation and HIPAA Email Breaches.

Full Data

Click here to download the raw data.

About the Paubox HIPAA Breach Report

The Paubox HIPAA Breach Report analyzes breaches that affected 500 or more individuals as reported in the HHS Wall of Shame in March 2018.

Minimize the risk of email getting you on the list with Paubox Encrypted Email. Start your free trial today.

The post HIPAA Breach Report for April 2018 appeared first on Paubox.

Ben Holber: What is DTC?

dtc, direct to consumer, yoderm, churros

We recently sat down with Ben Holber, Founder CEO of YoDerm, for another episode of HIPAA Center.

Here is a transcript of how Ben is simplifying the dermatology prescription process. You can watch the entire interview here.

Ben Holber: In Telemedicine, do you have to see a dermatologist in your state?

Hoala Greevy: Okay and then I was doing a little bit more homework. I saw you mentioning DTC. The only thing I could find on it was in the – some kind of street dictionary, “Down to Churro”, so, probably not that. So what the heck does DTC mean?

Ben Holber: No, I mean I’m always Down to Churro. Always down. Direct to Consumer.

Hoala Greevy: Ah. Geez, guess I didn’t do that much homework.

Ben Holber: No, we just nailed it with the DTC, but no that’s right, Direct to Consumer. Because we’re not relying on a third party to pay, we are working with and providing value directly to consumers.

You know, I think something that’s admirable about that is it is a much clearer kind of supply and demand curve, right? We have to make sure that we provide a great enough service that patients are willing to open their wallet and the value that we’re providing is equivalent to the value they’re giving us.

And that’s a much clearer supply and demand curve that shows more, I think, equity in both the outcome and the income.

About YoDerm

YoDerm is the easiest way to get prescription medications from a board certified dermatologist. Their mission is to expand the access to dermatology services by making them more convenient and affordable.

The post Ben Holber: What is DTC? appeared first on Paubox.

Friday 20 April 2018

Ben Holber: In Telemedicine, do you have to see a dermatologist in your state?

telemedicine, telehealth, dermatology telemedicine, dermatology telehealth

We recently sat down with Ben Holber, Founder CEO of YoDerm, for another episode of HIPAA Center.

Here is a transcript of how Ben is simplifying the dermatology prescription process. You can watch the entire interview here.

Ben Holber: In Telemedicine, do you have to see a dermatologist in your state?

Hoala Greevy: So if I need some help, do I have to see a dermatologist that’s certified in the state I live in? How does that work? I’m a total outsider.

Ben Holber: Yeah, yeah. You’re absolutely right. Typically the way the legal precedent has come to fruition was that medicine and treatment occurs where the patient is located, not where the physician is located.

A patient is located in, say, New York, the physician doesn’t necessarily have to be located in New York, but they have to be licensed to practice medicine in New York.

So anytime you come to YoDerm and you get a consultation in your state, you will be treated by a physician who is licensed in that state.

Hoala Greevy: Got it. And do you folks cover all 50 states?

Ben Holber: We don’t. We cover like 34, I believe 35 states. The reasons why we aren’t in all 50 states is because first off not all 50 states have as progressive laws and regulations around telemedicine, around establishing a patient-physician relationship without an in-person consultation. And then also we’re continually growing our physician base as well as our partner pharmacy base to go into all the states we can.

Hoala Greevy: So some states don’t allow telemedicine? Is that what I heard?

Ben Holber: Yeah, essentially there are some states that just straight up do not allow telemedicine.

Hoala Greevy: Oh wow.

Ben Holber: And then, along with that, there are some states who will only allow telemedicine, but it has to be live video, right? And with us, it’s asynchronous. So you take a photo, you send it off, you can live chat, or message, right?

Hoala Greevy: Yeah.

Ben Holber: However, Maryland, Idaho, D.C., you actually have to do a Skype or a FaceTime essentially with the Doc in order for that to be compliant.

Hoala Greevy: Interesting.

About YoDerm

YoDerm is the easiest way to get prescription medications from a board certified dermatologist. Their mission is to expand the access to dermatology services by making them more convenient and affordable.

The post Ben Holber: In Telemedicine, do you have to see a dermatologist in your state? appeared first on Paubox.

Is Google 2-Step Verification Compatible with Paubox?

Is Google 2-Step Verification Compatible with Paubox?

We spoke to a prospect recently who asked us how Paubox integrates with 2-Factor Authentication methods for various email platforms.

One of the most popular business emails that Paubox integrates with is G Suite.

As we’ve written about before, G Suite can be made fully HIPAA compliant when integrated with Paubox. But how do you make sure your G Suite account itself is secure?

Two Factor Authentication (2FA) for the win

Choosing the right authentication type is one of the most important things healthcare organizations can do.

Single factor authentication is a process that uses one of the three factors (i.e. something you know, are, or have) to attain authentication. For example, password is something you know and is the only factor that would be required to authenticate a person or program. This would be considered a single factor authentication.

But multi-factor authentication (like 2FA) uses two or more factors to succeed authentication. For example, a private key on a smart card that is activated by a person fingerprint is considered a multi-factor token. The smart card is something you have, and something you are (the fingerprint) is necessary to activate the token (private key).

Obviously, 2FA is a better option if you can implement it.

Thankfully Google makes it easy to enable 2FA.

Enabling 2FA in G Suite and Paubox

Any admin of your G Suite setup can easily enable 2FA for your domain.

Google put together this handy checklist that walks you through the setup.

Once you have 2FA setup and rolled out for your users, you’re already done!

There are no extra steps needed to enable Paubox with your new 2FA in G Suite.

Instead Paubox seamlessly continues to work in the background making sure all sent emails are secure and HIPAA compliant.

With the setup this easy, if you’re using G Suite for your organization, it’s highly recommended that you enable 2FA.

Conclusion: Yes, Google Two-Step Authentication is compatible with Paubox.

The post Is Google 2-Step Verification Compatible with Paubox? appeared first on Paubox.

Thursday 19 April 2018

Ben Holber: How YoDerm is simplifying receiving dermatology prescriptions

dermatology prescription delivery, yoderm, prescription delivery, mailed prescriptions

We recently sat down with Ben Holber, Founder CEO of YoDerm, for another episode of HIPAA Center.

Here is a transcript of how Ben is simplifying the dermatology prescription process. You can watch the entire interview here.

Ben Holber: How YoDerm is simplifying receiving dermatology prescriptions

Hoala Greevy: Now I understand you folks are also – and I think you alluded to it a few minutes ago – you’re also in the mix when it comes to the delivery of the treatments?

Ben Holber: Yeah, that’s right. Yeah, absolutely.

Hoala Greevy: That’s cool.

Ben Holber: Yeah we initially started off just doing the consultations and the prescriber would create your treatment plan for you and if there was a prescription, we’d send it off to say CVS and you’d go pick it up.

We found that regardless of how easy we made the consult, it’s actually still really difficult to obtain the meds. You’re dealing with navigating your maze of co-pay, co-insurance, max amount of pocket, all that stuff.

And ultimately, you still have to find time to go to the pharmacy. We can make getting the treatment plan as conveniently as possible but if medication is still difficult, the treatment plan doesn’t matter, right?

So for a handful of conditions, we’re doing the fulfillment as well with partner pharmacies so we can send it directly to patients. And we found that our retention and our patient compliance has shot through the roof because of it.

Hoala Greevy: Oh, that’s great.

Ben Holber: Yeah, yeah. It’s a win-win for everybody.

Hoala Greevy: The last mile.

Ben Holber: Exactly.

Hoala Greevy: That’s awesome.

About YoDerm

YoDerm is the easiest way to get prescription medications from a board certified dermatologist. Their mission is to expand the access to dermatology services by making them more convenient and affordable.

The post Ben Holber: How YoDerm is simplifying receiving dermatology prescriptions appeared first on Paubox.

Wednesday 18 April 2018

Polk County Health Services, Inc Suffers HIPAA Email Breach

hipaa email breach, hipaa email data breach, paubox hipaa breach report

On April 12, 2018, Polk County Health Services, Inc submitted a HIPAA Email Breach to the U.S. Department of Health and Human Services (HHS).

Located in Des Moines, Iowa, Polk County’s email breach affected 1071 individuals’ protected health information.

Polk County Health Services, Inc is classified as a Health Plan.

According to Polk County’s press release:

…there was a breach in personal information related to some Polk County social work assessments.

There are 2,042 individuals whose information was included in the breach, which happened during the assessment period of some child and dependent adult abuse cases. Letters were mailed this week notifying these Iowans of the breach.

This occurred when two workers used personal email accounts, personal online storage accounts and personal electronic devices for work purposes. That caused confidential data to be transmitted outside the DHS secure network. The incidents happened over a 5-year period starting in 2008.

“There are no reports that any of the information was misused before it was deleted,” said Pat Penning, service area manager for the region including Polk County. “We’ve sent notification to individuals whose information was transmitted outside the secure network.”

The types of information involved included name, mailing address, Social Security number, state identification number, date of birth, health information and incident information.

The department began an internal investigation on January 17, 2014, once the issue was identified by a social work supervisor. Officials found that the workers did not follow DHS policy, which prohibits use of personal devices and transmitting information outside of the agency’s network. Appropriate personnel action was taken.

“The chance that this information was accessed through these password-protected accounts and devices was small,” said Penning, “but we realize the Iowans involved in these cases may wish to take steps to be sure their information wasn’t misused.”

DHS is taking further action including blocking access to online file storage sites, providing updated materials to staff on the department’s information technology policy and standard operating procedures, and continuing to require yearly cyber-security training for all employees.

HHS Wall of Shame

The HHS Wall of Shame is a website under the jurisdiction of HHS that lists all HIPAA breaches reported within the last 24 months. The Wall of Shame displays breaches that are currently under investigation by the Office for Civil Rights.

As part of section 13402(e)(4) of the HITECH Act, the HHS Secretary must post a list of breaches of unsecured protected health information affecting 500 or more individuals.

HIPAA Breach Report

The Paubox HIPAA Breach Report analyzes breaches that affected 500 or more individuals as reported in the HHS Wall of Shame.

The post Polk County Health Services, Inc Suffers HIPAA Email Breach appeared first on Paubox.

Ben Holber’s YoDerm brings on-demand dermatology care to dermatology patients

ben holber yoderm paubox hipaa center

Millions of Americans suffer from some type of skin condition – whether it’s acne that affects 50 million Americans, or rosacea, or even male pattern baldness.

Wait times to see a dermatologist can be one to two months, and considering most conditions need ongoing treatment, the period between appointments can feel like forever.

Ben Holber was one dermatology patient who was tired of waiting, so he created YoDerm: an on-demand dermatology service that takes care of your skin on your time.

Ben Holber HIPAA Center

0:000:57 = What problems YoDerm solves

0:582:33 = Ben’s personal connection to skin issues

2:333:10 = What inspired the name YoDerm?

3:114:02 = Conducting over 40,000 consultations

4:024:45 = Do consultations only involve faces?

4:455:40 = YoDerm’s prescription fulfillment solution

5:407:14 = Can you only see a dermatologist in your state?

7:158:16 = Being in a B2C healthcare space

8:168:45 = YoDerm patients and mobile devices

8:4510:00 = What is D2C?

10:0011:25 = Future of the industry

11:2513:54 = Paubox Lightning Round

About YoDerm

YoDerm is the easiest way to get prescription medications from a board certified dermatologist. Their mission is to expand the access to dermatology services by making them more convenient and affordable.

The post Ben Holber’s YoDerm brings on-demand dermatology care to dermatology patients appeared first on Paubox.

Saturday 14 April 2018

Diagnostic Radiology & Imaging Suffers HIPAA Email Breach

On April 5, 2018, Diagnostic Radiology & Imaging submitted a HIPAA Email Breach to the U.S. Department of Health and Human Services (HHS).

Located in Greensboro, NC, Diagnostic Radiology & Imaging’s email breach affected 800 individuals’ protected health information.

Diagnostic Radiology & Imaging is classified as a Healthcare Provider.

According to Diagnostic Radiology & Imaging’s press release:

On January 31, 2018, DRI became aware of an impermissible disclosure of limited health information about approximately 800 patients. An investigation revealed that on November 11, 2017, an employee of DRI became the victim of a phishing attack. “Phishing” is a type of cybercrime in which individuals are targeted and tricked into revealing sensitive or confidential information. In this case, an attacker emailed DRI employees using an email address that appeared to be legitimate, and one DRI employee revealed information to the attacker that allowed the attacker to access the DRI employee’s work-related email account. Within that DRI employee’s email account, we found a limited amount of information about patients, including names, a general description of imaging services received (including date, type, and location of imaging service), medical record numbers, and in some cases, email addresses and phone numbers. In just a few cases, the patient’s date of birth was also included. As a result, the attacker gained access to that information.

Please note that the attacker did not have access to any of our patients’ Social Security Numbers or other financial information, and for that reason, we do not believe there is any risk of financial harm to our affected patients as a result of this phishing attack.

In accordance with DRI policy, and as required by federal law, DRI is notifying affected patients via first-class mail.

We take the confidentiality and secure handling of patients’ information seriously. Our investigation involved external forensic investigators as well as attorneys with experience in handling these types of incidents. We have policies and procedures in place regarding the confidentiality and security of patient information, and we train our employees on these policies and procedures on a regular basis. In response to this cybercrime, we have retrained our employees and contractors on our policies and procedures relating to privacy and security. We have also implemented more specific training on phishing and other types of cybercrimes to better educate our employees and contractors.

We are very sorry that this happened, and we are taking steps to try to prevent situations like this in the future. 

HHS Wall of Shame

The HHS Wall of Shame is a website under the jurisdiction of HHS that lists all HIPAA breaches reported within the last 24 months. The Wall of Shame displays breaches that are currently under investigation by the Office for Civil Rights.

As part of section 13402(e)(4) of the HITECH Act, the HHS Secretary must post a list of breaches of unsecured protected health information affecting 500 or more individuals.

HIPAA Breach Report

The Paubox HIPAA Breach Report analyzes breaches that affected 500 or more individuals as reported in the HHS Wall of Shame.

The post Diagnostic Radiology & Imaging Suffers HIPAA Email Breach appeared first on Paubox.

Guardian Pharmacy of Jacksonville Suffers HIPAA Email Breach

On March 30, 2018, Guardian Pharmacy of Jacksonville submitted a HIPAA Email Breach to the U.S. Department of Health and Human Services (HHS).

Located in Jacksonville, FL, Guardian Jacksonville’s email breach affected 11521 individuals’ protected health information.

Guardian Pharmacy of Jacksonville is classified as a Healthcare Provider.

According to Guardian Jacksonville’s press release:

Guardian Pharmacy of Jacksonville, LLC (“Guardian”) is notifying certain patients of the unauthorized access to certain limited pieces of patient information, including patient name, prescription medication information, treatment details, and diagnosis information.

For a small number of individuals, this information also included Social Security numbers and health insurance information.  Although we are unaware of any actual or attempted misuse of protected health information, Guardian is providing its impacted patients with information about the event, steps taken since discovering the incident to mitigate the risk of misuse of the information, and what can be done to better protect against potential harm resulting from this event.

On October 3, 2017, Guardian identified unusual activity in an employee email account. As part of Guardian’s immediate and ongoing investigation into the event, on February 14, 2018, it was determined that certain pieces of patient information were accessible to an unauthorized individual(s).

“We take this event very seriously,” Khristy McCelland, President of Guardian Pharmacy of Jacksonville, stated.  “Upon learning of the event, we immediately changed the credentials to the email account and launched an extensive internal investigation, which was supported by a third-party forensic investigation firm, into the nature and scope of the incident.  Once we confirmed that protected health information was accessible to an unauthorized individual(s), we immediately took steps to mitigate the risk to our impacted patients and to notify them of the incident.  In response to this incident, we have augmented our password security policies and provided additional training to employees.”

In addition to mailing letters to its impacted patients, Guardian disclosed this incident to the U.S. Department of Health and Human Services, the Florida Attorney General, and the major consumer reporting agencies on March 30, 2018.

Guardian is unaware of any actual or attempted misuse of its patients’ information and cannot confirm if their information was accessed without authorization.

Nevertheless, Guardian encourages its patients to review their Guardian account statements, health insurance account records, and explanation of benefits forms for suspicious activity.  Any suspicious activity should be immediately reported to the institution that issued the record.  Credit monitoring and identity restoration services are being offered to patients whose Social Security numbers were potentially impacted by this event.

HHS Wall of Shame

The HHS Wall of Shame is a website under the jurisdiction of HHS that lists all HIPAA breaches reported within the last 24 months. The Wall of Shame displays breaches that are currently under investigation by the Office for Civil Rights.

As part of section 13402(e)(4) of the HITECH Act, the HHS Secretary must post a list of breaches of unsecured protected health information affecting 500 or more individuals.

HIPAA Breach Report

The Paubox HIPAA Breach Report analyzes breaches that affected 500 or more individuals as reported in the HHS Wall of Shame.

The post Guardian Pharmacy of Jacksonville Suffers HIPAA Email Breach appeared first on Paubox.

Thursday 12 April 2018

Paubox Encrypted Email Can Secure Outbound Emails from Salesforce

paubox encrypted email, sending encrypted emails from salesforce, sending secure emails from salesforce

Paubox Encrypted Email redefines the secure email experience. By eliminating portals, plug-ins and extra steps, Paubox is the only solution that enables zero-step encryption on all sent emails and eliminates frustration for your staff and recipients.

Paubox seamlessly integrates with business email providers such as G Suite, Office 365, and Microsoft Exchange.

If you have Salesforce’s Lightning Experience, you can send Salesforce emails from your Gmail or Office 365 account. Emails sent in Lightning Experience look like they were sent from your Gmail or Office 365 inbox. You can also see the emails you’ve sent in your Gmail or Office 365 Sent Items folder.

If you enable this Salesforce feature and are a Paubox encrypted email user, you can inherently send HIPAA compliant emails from Salesforce.

Follow the tutorial below to activate this Paubox secret bonus in Salesforce.

READ MORE: Paubox Becomes a G Suite Authorized Reseller

How to send HIPAA compliant emails from Salesforce

To get started, enable two basic user permissions: permission to send email and permission to access to the record the email is sent from. Move on to the next step after enabling these permissions.

Salesforce still sends workflow emails and trigger emails. However, external email accounts do not support bounce management.

Also, email delivery information when sending emails through Gmail or Office 365 is not available in the Salesforce email logs. Obtain email logs from your Gmail or Office 365 instead.

To integrate Salesforce with your G Suite or Office 365 account:

  1. From your personal settings, enter My Email Settings in the Quick Find box, and select My Email Settings.
  2. Select how you’d like to send your email. Your Salesforce admin can enable either Gmail or Office 365 for your organization. You can’t choose between the two.
  3. Click Save.

After completing these steps, you will have successfully configured your G Suite or Office 365 account to send email from your Salesforce account.

Your outbound mail flow will now look like this: Salesforce > GSuite/Office365 > Paubox > delivered securely to your end recipient.

Thank you for choosing Paubox to secure your emails. Happy emailing!

The post Paubox Encrypted Email Can Secure Outbound Emails from Salesforce appeared first on Paubox.

Wednesday 11 April 2018

Laura Merrick: Medical Home Network wants to reinforce the centrality of the medical home

When you hear the phrase “medical home”, you might think of a nursing home, but actually, a medical home is a place where a patient can receive everything they need for primary care (such as behavioral health, community resources, etc.)

Laura Merrick, Operations Project Manager of Medical Home Network, shares how their work not only affects the primary care community, but also hospitals.

Here is a transcript from our conversation with Laura. You can watch the entire interview here.

Laura Merrick Interview

Hoala Greevy: Howzit, this is Hoala Greevy, Founder CEO of Paubox. We’re here at HIMSS18 in Las Vegas. I’m here with Laura Merrick and she’s with Medical Home Network. I just met her a few minutes ago, so let’s get started with another version of HIPAA Center. Laura, thanks for joining us.

Laura Merrick: Thank you for having me.

Hoala Greevy: Can you tell us more about the scope of your work at Medical Home Network?

Laura Merrick: Certainly, certainly. So Medical Home Network is a formal provider collaborative that was founded and funded in Chicago, Illinois. Our focus was improving healthcare delivery and innovation, focusing on reinforcing the centrality of the medical home.

So we began our work about 9 years ago, bringing providers together to share around a common vision to support the Medicaid patients that were so disparately separated across the southside of Chicago.

We had several opportunities along the way and one of those was that we formed a Medicaid ACO known as the MHN ACO.

So the Medical Home Network ACO, known as MHN ACO, supports 9 federally qualified health centers and 3 Hospital systems through an Innovative – through our Innovation and technology in healthcare delivery. We are connected with 25 hospitals around the county area and 180 unique medical homes to support the care for Medicaid recipients outside on the southside of Chicago.

Hoala Greevy: Medical home, is that a skilled nursing home? What exactly is that?

Laura Merrick: No, don’t let our name fool you. At the time, when we first started the work we were really focused on, reinforcing Primary Care – a term for a medical home is a term where a patient can receive everything that they need around primary care. That might be access to behavioral health or Community Resources, and it’s a place where they can not only seek the care that they need but also the help to get the care that they need by their care manager.

So the network that we created in the beginning of our work was really about bringing providers together both in that medical home setting to drive that primary care model. We were able to do that with not only the primary care community but also hospitals, and really drive communication and that was really key to really engaging and reaching patients.

Hoala Greevy: Healthcare is notorious for lack of. Definitely.

Laura Merrick: Right.

Hoala Greevy: So MHN has been around for 9 years if I heard you correctly. How long have you been with the company?

Laura Merrick: Since it was founded, I believe it was 2008. I was one of the second employees.

Hoala Greevy: Wow. So almost from the beginning.

Laura Merrick: Yes.

Hoala Greevy: Wow. So HIMSS18, what was your biggest takeaway from this year?

Laura Merrick: You know, I think for the work that we do, it’s validation that we’re on the right track: driving innovation across our area. That there are opportunities to share best practices with others that are doing the work that we’re doing across the nation, and that there is more that we can do around improving access to data, and ultimately the care for our patients.

Hoala Greevy: Laura, is HIMSS part of your annual conference schedule or is it your first time here?

Laura Merrick: It is my first time here.

Hoala Greevy: Oh wow. Well you picked the right location because last year it was Orlando, and I – this is more preferably for me. Closer and a bit more fun.

Laura Merrick: Yeah.

Hoala Greevy: Great, and last question – where do you see the future of your industry going?

Laura Merrick: I think it’s innovation, it’s healthcare innovation. And that is wrapped around not only technology but how we implement the technology and the meaning behind how we connect data to get access to care for these patients. So I really think it’s continued innovation to empower care management activities, to empower reaching beyond the healthcare ecosystem into the community, and to really think a little bit bigger about how we really provide care.

Hoala Greevy: Man, Laura, thanks for submitting time with us, we really appreciate it. Nice to meet you. Aloha!

Medical Home Network

Medical Home Network (MHN) is a not-for-profit collaborative that has fundamentally changed how care is delivered.

Their proven model of care unites provider communities and diverse healthcare entities around a common goal: to redesign healthcare delivery and transform the way care is managed at the practice level.

Medical Home Network provides the tools and processes to help care teams engage patients and help them become an accountable member of the team. By connecting providers and delivering real-time information, they enable coordinated care management, improve transitions of care, and promote timely follow-up.

The post Laura Merrick: Medical Home Network wants to reinforce the centrality of the medical home appeared first on Paubox.

Tuesday 10 April 2018

Is Microsoft Teams HIPAA Compliant?

Is Microsoft Teams HIPAA Compliant? - Jerry Wu, Eddie Waits, Hoala Greevy

We sometimes get asked by customers and prospects about Microsoft Teams and their ability to use it in a HIPAA compliant manner.

We know the HIPAA industry is vast so we can empathize with just how many people need to use cloud services in this sector.

In previous posts, we’ve covered the following cloud solutions and their capabilities for HIPAA compliance:

Today, we will determine if Microsoft Teams offers HIPAA compliant service or not.

SEE ALSO: HIPAA Breaches and Cloud Providers

Microsoft Teams

Microsoft Teams is a cloud platform that combines workplace chat, meetings, notes, and attachments. First launched in 2017, Microsoft Teams is Microsoft’s competitive rebuttal to Slack and Google Hangouts Chat.

Microsoft Teams and the Business Associate Agreement

We’ve previously talked about how a Business Associate Agreement is a written contract between a Covered Entity and a Business Associate. It is required by law for HIPAA compliance.

We checked Microsoft’s site and found a page called:

On it, Microsoft states:

[Microsoft] Teams is Tier C-compliant at launch. This includes the following standards: ISO 27001, ISO 27018, SSAE16 SOC 1 and SOC 2, HIPAA, and EU Model Clauses (EUMC).

To get more information on what Tier C-compliance means, we tracked down a doc in the Microsoft Download Center called:

On page 2 of that doc, we can see that Tiers B and up include a Business Associate Agreement:


Is Microsoft Teams HIPAA Compliant? - Paubox

At the top of page 3, we can also see that Microsoft Teams comes enabled by default in Tiers C & D:


Is Microsoft Teams HIPAA Compliant? - Paubox

We can see then, that a BAA is included with a subscription to Microsoft Teams.

Does Microsoft Teams Offer HIPAA Compliant Service?

The Business Associate Agreement is a key component to HIPAA compliance between a covered entity and a business associate.

With some directed research, we were able determine that Microsoft is willing to sign a Business Associate Agreement that covers Microsoft Teams.

Conclusion: Microsoft Teams is HIPAA compliant.

The post Is Microsoft Teams HIPAA Compliant? appeared first on Paubox.

Ari Tulla: Why Digital Health Entrepreneurs Shouldn’t Use the Word “Pilot”

We recently sat down with Ari Tulla, CEO and Founder of BetterDoctor, at their office in San Francisco’s SOMA district.

Here is a transcript from why Ari thinks digital entrepreneurs should stop using the word “pilot”. You can watch the entire interview here.

Ari Tulla: Why Digital Health Entrepreneurs Shouldn’t Use the Word “Pilot”

Hoala Greevy: I understand that when it comes to healthcare and digital health startups, you don’t like the word “pilot”. Why is that and is there a better word for digital health entrepreneurs to focus in on?

Ari Tulla: I think this is specific for many of us who started healthcare companies in the B2C realm, going to consumers and trying to do something for them. And often many of them have been moving into B2B [or] B2E, working with the big enterprise companies.

In healthcare, the money is in three buckets: it’s in health plans, health insurance companies; it’s in the hospitals and the providers; and it is in the pharma.

Those are the ones that own 80% of the 3 trillion dollars today that we spend every year.

So you have to go there and shake those trees to make money. The money is not coming from the consumers because they don’t pay anything directly.

So you basically have to go to the big companies, and when you work with these big companies – we have experienced this a little bit and we have seen, and I have seen, many horror stories on the idea of “Hey, let’s do a pilot.”

Every big organization has an innovation team, and these innovation teams, they are there to work with the startups, with the new entrants and do small tests.

But very rarely those ideas and those early tests are leading into full implementations. So the “pilot”, it sounds like a doom interval from the beginning.

So you can do 100 pilots that might lead nothing in the end. So I try to just use the vocabulary and say, “Let’s go from pilot and talk about proof of concept.” If we already have something that works, let’s do a small implementation in some market. Let’s not do a pilot. Pilot means, “Let’s just do something little and try it, and it might not work.”

Hoala Greevy: Man, that’s a good takeaway. I’m sure people are going to want to hear about that.

BetterDoctor

BetterDoctor helps patients find the right doctors when they need them.

It starts with helping health plans, provider groups, health care systems and health start up companies get high quality data.

They build tools to bring trust, confidence, and transparency to the process of finding a doctor.

The post Ari Tulla: Why Digital Health Entrepreneurs Shouldn’t Use the Word “Pilot” appeared first on Paubox.

Sunday 8 April 2018

Mississippi State Department of Health Suffers HIPAA Email Breach

On March 26, 2018, Mississippi State Department of Health submitted a HIPAA Email Breach to the U.S. Department of Health and Human Services (HHS).

Located in Jackson, MS, the Mississippi State Department of Health’s email breach affected 30799 individuals’ protected health information.

Mississippi State Department of Health is classified as a Healthcare Provider.

According to Mississippi State Department of Health press release:

Health information, including names, date of birth, Social Security number, or lab results, were released Jan. 25 to J Michael Consulting, a contractor for the Centers for Disease Control and Prevention.

“This could have resulted in an unauthorized disclosure, since the information was not meant to be shared,” MSDH officials said in a news release.

MSDH officials became aware Jan. 30 that an employee “unknowingly” emailed an Excel spreadsheet containing patients’ protected health information.

“Each person who mistakenly received the spreadsheet said they deleted all traces of the email from their inbox and did not share the email or what was in it. It is unlikely that the personal information was viewed by anyone,” MSDH officials added. “However, because this email was sent unprotected, there is a possibility that it was seen by someone who could misuse it. MSDH has taken steps to increase security and lessen any harm that could be caused to any individual patient.”

Officials ask that anyone who was treated at the Mississippi State Department of Health, or any of its clinics, in 2017 and is concerned about possible unauthorized disclosure of information contact Nicole Litton or Christin Williams at 601-576-7874.

The Mississippi State Department of Health will offer free credit monitoring protection for one year, for clients whose information was included in the spreadsheet.

HHS Wall of Shame

The HHS Wall of Shame is a website under the jurisdiction of HHS that lists all HIPAA breaches reported within the last 24 months. The Wall of Shame displays breaches that are currently under investigation by the Office for Civil Rights.

As part of section 13402(e)(4) of the HITECH Act, the HHS Secretary must post a list of breaches of unsecured protected health information affecting 500 or more individuals.

HIPAA Breach Report

The Paubox HIPAA Breach Report analyzes breaches that affected 500 or more individuals as reported in the HHS Wall of Shame.

The post Mississippi State Department of Health Suffers HIPAA Email Breach appeared first on Paubox.

Saturday 7 April 2018

Ari Tulla: The Mix Tape of Happiness

We recently sat down with Ari Tulla, CEO and Founder of BetterDoctor, at their office in San Francisco’s SOMA district.

Here is a transcript from Ari’s concept of the Mix Tape of Happiness. You can watch the entire interview here.

Ari Tulla: The Mix Tape of Happiness

Hoala Greevy: Can you share your concept of the “Mix Tape of Happiness”?

Ari Tulla: Yeah, this is good research from your part. So Mix Tape of Happiness is a fun thing that you get to do every now and then.

I used to work at Nokia for quite a while and I was helping the Nokia research center on finding new ideas how to use VR (virtual reality) and alternate reality.

We were working on a project that I think never saw the light of day so I can’t really talk about the details of that. But one big company, they start ten things, they kill nine of them. And some of those go pretty far before they get killed.

Anyway, we were working on a glass concept that was a little like Google Glass maybe – maybe ten years ago. One of the concepts that we came up with was Mix Tape of Happiness.

And the idea is that you basically have a frame on you where you have video rolling all the time, so you can 24/7 record video, like you can do with Google Glass basically. And then you store the video and we were also looking at can you incorporate simple brain wave tracking into the frame so you can look at the brain and understand simple brain waves.

There are six, seven different types of waves and you have to have a hat on if you want to get all of them, but in here you can find the simple things like in the case of happiness, excitement.

So we’re thinking about okay, we are recording 24/7, why not find when you are happy and excited and take that moment in your life and move that into the cloud and call it the Mix Tape of Happiness? Who wouldn’t want to go back in our life and when we feel sad or we are blue anyway, we can go look at the last year, the best moments of our life on a video, like you saw them yourself.

I think that would be a great thing to do.

Hoala Greevy: What’s that Netflix show? Black Mirror?

Ari Tulla: Yep.

Hoala Greevy: There’s an episode that’s very similar to that.

Ari Tulla: Yep. And that’s on my list, I mean it’s on my queue that I need to see.

Hoala Greevy: I’ll send you the link for it.

Ari Tulla: But anyone listening, this has never been done. I don’t think there really is a full-blown patent filed on this. Go on and do this, this is really I think a fun idea that can be done with the current tech. Ten years ago, it was harder.

Hoala Greevy: Yeah, wow.

BetterDoctor

BetterDoctor helps patients find the right doctors when they need them.

It starts with helping health plans, provider groups, health care systems and health start up companies get high quality data.

They build tools to bring trust, confidence, and transparency to the process of finding a doctor.

The post Ari Tulla: The Mix Tape of Happiness appeared first on Paubox.