BLOG

Board-Ready Cyber Risk Reporting for Healthcare

Typical cyber risk reporting quite often fails because it is written to describe operations rather than governance. In healthcare, the stakes are even higher. The goal is to establish a framework that generates an explainable, repeatable, report that drives prioritization and accountability. Read More

Expert Spotlight - Bethany Page Ishii

Meet Bethany Page Ishii, VP of Cybersecurity Strategy and Advisory at Meditology. Bethany leads our advisory and professional services practice, helping healthcare organizations strengthen cybersecurity, governance, risk management, and regulatory compliance. Read More

OCR Readiness: Be Prepared for Investigations and Corrective Action Plans

When the Office for Civil Rights (OCR) comes knocking, the stress level in any healthcare organization inevitably spikes. However, a proactive approach to OCR investigation readiness can transform a high-pressure audit into an opportunity for organizational growth. Effective preparation is not just about “surviving” an audit; it is about demonstrating a culture of compliance that protects patient data and organizational reputation. Read More

HIPAA Risk Analysis, Risk Assessment, & Evaluation: Is There a Difference?

We hear the terms risk assessment, risk analysis, and evaluation used routinely in healthcare settings, often in the context of HIPAA compliance. The big question: is there a material difference between these terms from a HIPAA regulatory perspective? Answering this question correctly is critical to maintaining HIPAA compliance and staying out of hot water with regulators. Many organizations that have misunderstood and misapplied these terms have ended up facing multi-million-dollar settlements with the Office for Civil Rights (OCR) for failure to comply with the HIPAA Security Rule. Read More

New NIST Guidance on Compliance with the HIPAA Security Rule

NIST has released new guidance for covered entities to comply with the HIPAA Security Rule. The publication is titled: "Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide". This blog post provides a summary of key points in the new NIST publication alongside Meditology’s analysis and further recommendations in support of NIST’s guidance. Read More

PCI DSS v4.0 Released: Compliance Requirements for Healthcare Organizations

The PCI Security Standards Council has released the much-anticipated PCI DSS version 4.0 this week. The update is several years in the making and includes significant control requirement overhauls. Healthcare organizations must update policies, procedures, and control requirements to maintain compliance with the new PCI v4.0 standard. This blog post provides details about the new requirements for PCI v4.0 and the timing for compliance for healthcare entities. Read More