Starting from:

$179

2026 Healthcare Cybersecurity Essentials: HIPAA & Breach Prevention

Presenter: Jake Yates, MBA, CHC, AIP-HC

Date: Tuesday, October 27, 2026

Time: 1 pm ET | 12 pm CT | 11 am MT | 10 am PT

Duration: 60 minutes


Course Description

Healthcare organizations face an increasingly complex cybersecurity environment in which ransomware, phishing, insider threats, vulnerable medical devices, and third-party risks can compromise patient information and disrupt care. Recent breach reports highlight the financial, operational, regulatory, and reputational consequences of failing to protect electronic protected health information (ePHI). This webinar will provide healthcare professionals with a practical understanding of how HIPAA compliance and cybersecurity work together to strengthen organizational resilience.

Participants will explore the purpose and scope of the HIPAA Security Rule, including its administrative, physical, and technical safeguards. The session will explain why a comprehensive Security Risk Analysis (SRA) is the foundation of an effective security program—not merely a checklist or an IT responsibility. Attendees will learn how to identify where ePHI is stored, received, maintained, and transmitted; document threats and vulnerabilities; evaluate existing safeguards; assess likelihood and impact; prioritize risks; and maintain clear, ongoing documentation.

Through healthcare-focused breach scenarios involving ransomware, phishing, compromised credentials, inadequate monitoring, and missing multifactor authentication, the webinar will connect compliance requirements to real-world consequences and lessons learned. It will also address practical safeguards such as MFA, encryption, secure remote access, mobile-device protection, vulnerability scanning, timely patching, access-log monitoring, phishing simulations, incident response planning, and workforce training.

The program will emphasize that cybersecurity is a shared responsibility requiring leadership commitment, continuous education, transparent reporting, vendor oversight, and a culture of compliance. Attendees will leave with actionable steps to evaluate their organization’s current posture, improve protection of patient data, and support confidentiality, integrity, and availability while preparing for evolving cyber and technology-related risks, including the growing use of artificial intelligence in medical practices.


Learning Outcomes

  • Identify common cybersecurity threats facing healthcare organizations.
  • Explain the purpose of the HIPAA Security Rule.
  • Describe HIPAA’s administrative, physical, and technical safeguards.
  • Explain the importance of conducting a comprehensive SRA.
  • Identify where ePHI is stored, accessed, and transmitted.
  • Recognize common threats and vulnerabilities.
  • Assess the likelihood and impact of identified risks.
  • Apply safeguards such as MFA, encryption, and access monitoring.
  • Develop basic ransomware and breach-response strategies.
  • Maintain an ongoing culture of cybersecurity and HIPAA compliance.

Areas Covered in the Session

  • The Current Cybersecurity Landscape in Healthcare
    • Why healthcare remains a high-value target
    • Increasing ransomware, phishing, and data-breach risks
    • Impact on patient care, trust, and operations
    • Financial, regulatory, and reputational consequences
  • HIPAA Security Rule Fundamentals
    • Purpose of the HIPAA Security Rule
    • Confidentiality, integrity, and availability of ePHI
    • Covered entities, business associates, and subcontractors
    • Administrative, physical, and technical safeguards
  • Security Risk Analysis: Purpose and Scope
    • What a Security Risk Analysis (SRA) is—and is not
    • Why an SRA is the foundation of HIPAA compliance
    • Determining the scope of the assessment
    • Understanding an organization’s unique risk environment
  • Identifying ePHI Locations and Data Flows
    • Where ePHI is created, received, stored, maintained, and transmitted
    • Electronic systems, cloud platforms, mobile devices, and medical equipment
    • Data storage and transmission inventories
    • Documenting information gathered from workforce interviews and existing records
  • Threats and Vulnerabilities Affecting Healthcare Organizations
    • Ransomware and extortion attacks
    • Phishing, business email compromise, and credential theft
    • Insider threats and human error
    • Medical-device and system vulnerabilities
    • Third-party and vendor-related risks
  • Administrative Safeguards
    • Security management processes
    • Assigned security responsibility
    • Workforce security and access management
    • Security awareness and training
    • Evaluation and contingency planning
  • Physical Safeguards
    • Facility access controls
    • Workstation use and security
    • Device and media controls
    • Secure disposal of electronic equipment
    • Protection of mobile and remote-work devices
  • Technical Safeguards for ePHI
    • User and system access controls
    • Person or entity authentication
    • Audit controls and access-log monitoring
    • Integrity controls
    • Transmission security
  • Risk Assessment and Prioritization
    • Determining the likelihood of threat occurrence
    • Evaluating potential organizational impact
    • Assigning likelihood and impact ratings
    • Prioritizing high-risk vulnerabilities
    • Creating a practical risk-management roadmap
  • Multifactor Authentication and Access Security
    • Why passwords alone are insufficient
    • Implementing MFA for workforce and privileged accounts
    • Role-based and least-privilege access
    • Managing terminated, transferred, and inactive users
  • Phishing Prevention and Workforce Awareness
    • Recognizing suspicious emails and social-engineering tactics
    • Phishing simulations and targeted education
    • Reporting suspicious activity without fear of retaliation
    • Building a culture of shared cybersecurity responsibility
  • Ransomware Readiness and Incident Response
    • Preparing for operational disruption
    • Backup, recovery, and business-continuity considerations
    • Incident-response roles and escalation procedures
    • Encryption and other protective safeguards
    • Post-incident review and corrective action
  • Vulnerability Management and Secure Technology Use
    • Regular vulnerability scanning
    • Patch management and system updates
    • Secure remote access and mobile-device controls
    • Medical-device cybersecurity considerations
    • Evaluating emerging technologies, including artificial intelligence
  • Breach Response, Reporting, and Regulatory Compliance
    • Initial response following a suspected breach
    • Preserving evidence and documenting investigations
    • HIPAA notification obligations
    • Coordination among compliance, legal, IT, leadership, and communications teams
    • Common compliance failures identified in healthcare breach cases
  • Maintaining and Improving the Security Program
    • Reviewing and updating the SRA at least annually
    • Reassessing risks after significant operational or technology changes
    • Keeping policies, procedures, and training current
    • Measuring the effectiveness of implemented safeguards
    • Using lessons learned to strengthen long-term organizational resilience
  • Interactive Q&A Session with Jake Yates.

Recommended Participants

  • Healthcare Compliance Officers (CHC, CHCP, CHC-F)
  • HIPAA Privacy Officers
  • HIPAA Security Officers
  • Chief Information Security Officers (CISOs)
  • Chief Information Officers (CIOs)
  • Health Information Management Professionals (RHIA, RHIT)
  • Privacy and Security Professionals (HCISPP, CISSP)
  • Information Technology Directors and Managers
  • Healthcare Cybersecurity Analysts
  • Medical Practice Administrators (CMPE, FACMPE)
  • Hospital Administrators (MHA, FACHE)
  • Physicians (MD, DO)
  • Nurse Practitioners (NP, APRN, FNP-C)
  • Registered Nurses (RN, BSN)
  • Certified Nursing Assistants (CNA)
  • Clinical Documentation Integrity Specialists (CCDS, CDIP)
  • Risk Management Professionals (CPHRM)
  • Internal Auditors (CIA, CISA)
  • Medical Practice Managers (CMPE, CPC)
  • Healthcare Legal and Regulatory Professionals (JD, CHC)

About the Presenter

Jake Yates, MBA, CHC, AIP-HC is a seasoned healthcare professional with over 15 years of experience in mental health, risk adjustment, healthcare audits, and compliance. As a Compliance Consultant and Virtual Compliance Officer, he works closely with billing companies, Managed Service Organizations, private physician practices, medical groups, medical centers, and hospitals to help them navigate the complex landscape of HIPAA, OSHA, and corporate regulatory compliance. Having previously worked in Medicare audits for nearly a decade, Jake has seen firsthand the importance of a thorough compliance and auditing program and its impact on the well-being of healthcare organizations.

Prior to joining Healthcare Compliance Pros, Jake worked as a National Account Manager at Ciox Health and a Client Services Manager at Cotiviti. During this time, he assisted with hundreds of Medicare audits for several of the top 10 largest U.S. health insurance companies. In 2019, he led a team that validated over $130 million in Medicare overpayments to a Medicare Advantage health plan. Since then, he has focused his efforts on regulatory compliance to help organizations ensure they are meeting their requirements and safeguarding their businesses.

Jake’s expertise spans a wide range of compliance areas, including CMS audits, RAPS and EDS claims submissions, healthcare risk management, and regulatory healthcare compliance. His extensive experience working with top U.S. payors has equipped him with a deep understanding of healthcare compliance, Medicare Advantage, HEDIS, and RADV audits.

Jake holds a Bachelor’s Degree in Social Work from the University of Utah and a Master of Business Administration and Healthcare Management degree from Western Governors University. He has also earned several professional certifications, including Certified in Healthcare Compliance (CHC), Certified Artificial Intelligence Professional in Healthcare Compliance (AIP-HC), Certified Healthcare Compliance Professional (CHCP), Project Management, and Lean Six Sigma. He is an active member of the Health Care Compliance Association (HCCA) and regularly presents on compliance topics through webinars, speaking engagements, and professional social media content.


Additional Information

After Registration:
You will receive an email with login information and handouts (presentation slides) that you can print and share with all participants at your location.

System Requirement:
  • Internet Speed: Preferably above 1 Mbps
  • Headset: Any decent headset and microphone which can be used to talk and hear clearly

Can't Listen Live?
No problem. You can get access to an On-Demand webinar. Use it as a training tool at your convenience.

For more information, you can reach out to the below contact:

Toll-Free No: 1-302-444-0162
Email: care@skillacquire.com
Address: 651 N. Broad Street, Suite 206, Middletown, DE 19709

Snippets From Our Previous Session