Skip to content
Artwork for HIPAA Insider

HIPAA Insider

HIPAA Insider

Join us for informative and entertaining discussions about how to make your business or practice more secure with HIPAA compliance. We'll cover topics like healthcare IT, HIPAA cloud hosting, telemedicine and healthcare applications, cybersecurity risk, PHI. WordPress etc.,
Sponsored by HIPAA Vault: https://www.hipaavault.com/

Play
  • 20 episodes
  • Avg 16 min
  • English
  • #120
    Wednesday · 12 min

    From AI Sandbox to HIPAA-Compliant Cloud: The Vibe Coding Escape Route

    You built your healthcare app with AI. The prototype works. Now how do you get it out of the sandbox and into a secure environment? This week on the HIPAA Insider Show, we continue our Vibe Coding series with Phase 2: From Sandbox to Secure Cloud. AI development tools can help healthcare founders and developers move from an idea to a working application incredibly fast. But before that application starts handling real Protected Health Information (PHI), there’s another critical step: taking control of the code, credentials, infrastructure, and production environment. In this episode, we break down the AI escape route, including: How to extract your raw codebase from the original development environment Why moving your code into a repository you control matters How to identify and remove hardcoded API keys, credentials, and secrets Why AI-generated code should be reviewed before production Moving from a multi-tenant sandbox into a HIPAA-compliant Virtual Private Cloud (VPC) Preparing your infrastructure before introducing real PHI What healthcare developers should consider when moving from prototype to production The takeaway? Prototype-ready ≠ production-ready. AI can dramatically accelerate development, but healthcare teams still need visibility and control over what was built, where it runs, which services it communicates with, and how sensitive healthcare data will be protected. Build fast. Take control of your code. Secure the environment before introducing PHI. If you're a digital health founder, developer, CTO, healthcare IT professional, or compliance leader building with AI, this episode is for you. Learn more about HIPAA Vault Interested in becoming a guest on the HIPAA Insider Show?

  • #120
    September 9 · 13 min

    The AI Sandbox Trap: Is Your Vibe-Coded Health App Breaking HIPAA?

    Is your vibe-coded healthcare app actually ready to handle PHI? This week on the HIPAA Insider Show, we dive into the “AI Sandbox Trap”—a growing challenge for digital health founders and developers using AI-powered tools to build healthcare applications faster than ever. Vibe coding can take an idea from concept to working prototype incredibly quickly. But a functioning app isn't automatically a HIPAA-compliant app. In this episode, we explore what can happen when AI-generated healthcare applications move from experimentation into production, including: Where default configurations can expose Protected Health Information (PHI) The hidden compliance risks of AI-generated code and workflows Walled-garden platforms vs. portable development environments Why Business Associate Agreements (BAAs) matter when vendors handle PHI How third-party integrations can introduce unexpected data flows What founders and developers should evaluate before using real patient data How to think about moving an AI-built prototype into a secure production environment We also discuss tools and development approaches such as Bubble and Cursor, and why understanding where your code, infrastructure, and patient data live becomes critical when building for healthcare. The takeaway: Working code ≠ HIPAA-compliant code. If you're a digital health founder, developer, CTO, healthcare IT professional, or compliance leader experimenting with AI development and vibe coding, this episode is for you. Learn more about HIPAA Vault Interested in joining the HIPAA Insider Show as a guest?

  • #118
    August 19 · 8 min

    HIPAA Rule Delayed – What Now for Your Practice?

    The HIPAA Security Rule overhaul has been delayed. So what should healthcare organizations do now? In this episode of the HIPAA Insider Show, Adam Z. and HIPAA Vault CEO Gil Vidals unpack the latest developments surrounding the proposed HIPAA Security Rule update and what the longer regulatory timeline means for healthcare providers, covered entities, and business associates. While the anticipated cybersecurity overhaul has been pushed back, that doesn't mean organizations should put security improvements on hold. The current HIPAA Security Rule remains enforceable, cyber threats continue to evolve, and the additional time creates an opportunity to prepare without a last-minute compliance scramble. In this episode, we discuss: Why a regulatory delay doesn't mean cybersecurity can wait The importance of multi-factor authentication (MFA) Why encryption should remain a priority Vulnerability scanning and penetration testing The challenges facing smaller and rural healthcare providers How organizations can identify security and compliance gaps now How to turn the extended timeline into a strategic advantage The takeaway: The rule may be delayed, but cyber threats aren't. Use the extra runway to strengthen your security posture, address vulnerabilities, and prepare your organization for whatever comes next. Learn more about HIPAA Vault Interested in becoming a guest on the HIPAA Insider Show?

  • #115
    May 20 · 13 min

    HIPAA Rules Just Changed: Security Is No Longer Optional

    The 2026 HIPAA Rule Updates: From “Addressable” to Required HIPAA compliance is entering a new phase—and “optional” security measures are quickly disappearing. In this episode of the HIPAA Insider Show, Adam Z. and cloud security expert Gil Vidals break down the major HIPAA Security Rule updates shaping healthcare compliance in 2026. As regulators push key safeguards from “addressable” to REQUIRED, healthcare organizations of all sizes must rethink how they approach security, infrastructure, and risk management. We discuss: What HIPAA changes are already active Which requirements are still pending New mandatory encryption expectations The proposed 12-month penetration testing requirements Why MFA and stronger safeguards are becoming essential How smaller healthcare organizations can stay compliant without enterprise-level budgets This episode provides a practical look at how providers, MSPs, and health-tech teams can prepare for the next era of healthcare cybersecurity and compliance. Learn more about HIPAA Vault: https://www.hipaavault.com/ Become a guest on the HIPAA Insider Show: https://www.hipaavault.com/podcast-guest/

  • #114
    May 6 · 7 min

    When Trust Is the Vulnerability: The UK Biobank Data Scandal

    In this episode of the HIPAA Insider Show, Adam Z. breaks down the alarming UK Biobank scandal involving reports of 500,000 health records listed for sale on Alibaba and what it reveals about the future of healthcare security. We discuss: How “authorized” users became the vulnerability Why “de-identified” data may not truly be anonymous The growing risks of healthcare data sharing Insider threats and failures in data governance What U.S. healthcare organizations can learn from this case Practical mitigation strategies to reduce HIPAA risk As healthcare organizations continue expanding AI, analytics, and third-party integrations, insider threats are becoming one of the most important cybersecurity challenges to address. If you work in healthcare IT, compliance, cybersecurity, or digital health, this episode provides critical insights into protecting patient trust and securing sensitive data. Learn more about HIPAA Vault: https://www.hipaavault.com/ Become a guest on the HIPAA Insider Show: https://www.hipaavault.com/podcast-guest/

  • #113
    April 29 · 11 min

    AI Coding Trap: Hidden HIPAA Costs

    Building a healthcare app with AI has never been easier—but it may be setting you up for costly problems down the road. In this episode of the HIPAA Insider Show, we dive into the risks of “vibe coding” using platforms like Bubble, Glide, and Base44, and how these tools can lock you into “walled garden” environments that limit scalability, security, and compliance. We break down: What the AI coding trap really is How “walled garden” platforms create hidden technical debt Why many apps hit a HIPAA compliance wall before launch The importance of code portability for long-term success What it means to be VPC-ready How to avoid expensive rebuilds before handling patient data If you're a founder, developer, or healthcare operator building with AI tools, this episode provides a practical roadmap to avoid hidden costs and stay compliant from day one. Learn more about HIPAA Vault: https://www.hipaavault.com/ Become a guest on the HIPAA Insider Show: https://www.hipaavault.com/podcast-guest/

  • #112
    April 22 · 8 min

    The 2026 Compliance Overhaul: Audit-Proofing Your AI and Infrastructure

    HIPAA compliance is entering a new era—and 2026 will mark a major turning point. In this episode of the HIPAA Insider Show, Adam Z. and HIPAA Vault CEO Gil Vidals break down the upcoming modernization of the HIPAA Security Rule and the growing wave of AI disclosure regulations impacting healthcare organizations. As key safeguards shift from “addressable” to required, and states introduce stricter rules around AI transparency, providers, IT teams, and health-tech companies must rethink how they approach compliance. We cover: What the 2026 HIPAA updates mean in practice The shift from recommended to mandatory security controls Why multi-factor authentication (MFA) is no longer optional “Break Glass” protocols for AI systems and emergency access New expectations around AI transparency and accountability How to prepare for audits without enterprise-level budgets If you're handling patient data or deploying AI in healthcare, this episode provides a clear, practical roadmap to stay compliant and reduce risk in the evolving regulatory landscape. Download the HIPAA Compliance Checklist: https://www.hipaavault.com/are-you-hipaa-compliant/ Learn more about HIPAA Vault: https://www.hipaavault.com/ Become a guest on the HIPAA Insider Show: https://www.hipaavault.com/podcast-guest/

  • #111
    April 15 · 15 min

    HIPAA Basics for 2026 Secure Your Practice

    HIPAA compliance doesn’t have to be complex—or expensive. In this episode of the HIPAA Insider Show, Adam Z. and HIPAA Vault CEO Gil Vidals go back to fundamentals, breaking down the essential tools healthcare practitioners need in 2026 to stay secure and compliant without overspending. Whether you're a solo provider, private practice, or growing clinic, this episode provides a practical roadmap to modernize your operations safely. We cover: The core tools every practice needs for HIPAA compliance Securing email and document collaboration with platforms like Google Workspace Protecting your website with HIPAA-compliant hosting When to implement advanced solutions like patient intake forms Using HIPAA SFTP for secure, large data transfers If you’re looking to simplify compliance while leveraging modern technology, this episode shows how to build a secure, cost-effective foundation for your practice. Learn more about HIPAA Vault: https://www.hipaavault.com/ Become a guest on the HIPAA Insider Show: https://www.hipaavault.com/podcast-guest/

  • April 3 · 17 min

    Launching Your Vibe-Coded App: The HIPAA Vault Framework

    You’ve built your healthcare app with AI. The MVP works. The “vibe” is right. But now comes the critical step: making it secure and HIPAA-compliant for real patient data. In this episode of the HIPAA Insider Show, Adam Z. and HIPAA Vault CEO Gil Vidals move beyond theory and into execution—breaking down the exact framework used to transform AI-built applications into production-ready, compliant systems. After exploring data strategy, synthetic data, and security gaps in previous episodes, this conversation focuses on what founders actually need to do next. We cover: How to migrate AI-built apps into secure, compliant environments Identifying and fixing hidden security vulnerabilities Validating infrastructure for HIPAA requirements Preparing applications to safely handle Protected Health Information (PHI) Launching without building a full DevOps or security team If you’ve built an app using tools like Replit, Cursor, or v0, this episode provides a practical roadmap to go from prototype to secure production. 🔐 Learn more about HIPAA Vault: https://www.hipaavault.com/ 🎙 Become a guest on the HIPAA Insider Show: https://www.hipaavault.com/podcast-guest/

  • #109
    March 27 · 27 min

    Securing the Next Generation of AI-Built Healthcare Apps

    AI is accelerating how healthcare applications are built—but it’s also exposing a growing gap between innovation and security. In this episode of the HIPAA Insider Show, Adam Z. sits down with Mike Armistead, CEO of Pulse Security AI and a serial tech entrepreneur with over 30 years of experience, to explore how AI-assisted coding is reshaping healthcare development—and what it means for security and compliance. We discuss: How AI-assisted coding is changing the way healthcare apps are built The emerging “security value gap” between tools and real business risk Why traditional security approaches are falling short What a true system of record for security leaders looks like Key trends founders and IT professionals need to watch If you're building or managing healthcare technology, this episode highlights how to balance speed, innovation, and security in an AI-driven landscape. Learn more about Pulse Security AI: https://pulsesecurity.ai/ Security Impact Circle: https://www.securityimpactcircle.org/ Learn more about HIPAA Vault: https://www.hipaavault.com/?utm_source=spotify&utm_medium=podcast&utm_campaign=mike_armistead

  • #108
    March 20 · 27 min

    Beyond the BAA: Using Privacy-Preserving Tech to Win at AI

    In healthcare, signing a Business Associate Agreement (BAA) is only the beginning. To safely deploy AI, organizations must go beyond paperwork and implement privacy-preserving technologies (PETs) that protect patient data at the architectural level. In this episode of the HIPAA Insider Show, Adam Z. is joined by Timothy Nobles to explore how healthcare leaders can innovate with AI while maintaining trust, security, and compliance. We cover: Why BAAs alone are not enough for modern healthcare AI How synthetic data enables safe development and testing The role of differential privacy in protecting sensitive information Practical ways to build privacy guardrails into AI systems How clinics, MSPs, and health-tech teams can innovate without exposing PHI If you're working with AI in healthcare, this episode provides a roadmap for moving from checkbox compliance to real data protection. Learn more about Integral: https://www.useintegral.com/ Connect with Timothy Nobles: https://www.linkedin.com/in/timothynobles Learn more about HIPAA Vault: https://www.hipaavault.com/?utm_source=spotify&utm_medium=podcast&utm_campaign=timothy_nobles Become a podcast guest: https://www.hipaavault.com/podcast-guest/?utm_source=spotify&utm_medium=podcast&utm_campaign=timothy_nobles

  • #107
    March 13 · 11 min

    Built Your AI Health App? Now Make It HIPAA Compliant

    AI coding tools are enabling a new wave of healthcare innovators. Doctors, clinicians, and founders are now “vibe coding” applications using tools like Replit, Cursor, and v0—rapidly building MVPs with the help of large language models. But what happens when those apps start handling real patient data? In this episode of the HIPAA Insider Show, host Adam Z. and HIPAA Vault CEO Gil Vidals explore how healthcare innovators can safely move from an AI development sandbox to a secure, HIPAA-compliant production environment. They discuss: • The rise of “vibe coding” in healthcare startups • The risks of handling PHI in AI-generated applications • The Safe Landing Zone strategy for compliant deployment • Using “Magic Prompts” to document AI-generated tech stacks • Why serverless architecture can help meet enterprise security standards while keeping infrastructure costs low • How founders can launch secure healthcare apps without building a full DevOps team If you’ve built an AI-powered healthcare MVP and are ready to scale responsibly, this episode provides a practical roadmap for bridging the gap between rapid innovation and HIPAA compliance. Learn more about HIPAA Vault: https://www.hipaavault.com/?utm_source=spotify&utm_medium=podcast&utm_campaign=vibe_coding Become a guest on the HIPAA Insider Show: https://www.hipaavault.com/podcast-guest/?utm_source=spotify&utm_medium=podcast&utm_campaign=vibe_coding

  • #106
    March 6 · 24 min

    HIPAA Data Strategy Roadmap & The Risks of “Vibe Coding”

    Artificial intelligence is rapidly transforming healthcare—but without the right data strategy, innovation can quickly turn into a compliance nightmare. In this episode of the HIPAA Insider Show, Adam Z. sits down with Franck Leveneur, CEO of Data-Sleek, to discuss how healthcare organizations can bridge the gap between AI innovation and HIPAA compliance. They explore why many healthcare AI initiatives fail and why a data-first strategy is essential for protecting Protected Health Information (PHI) while enabling scalable AI development. The conversation also dives into the emerging trend of “Vibe Coding”—using large language models to generate software—and why this approach can create serious risks for data integrity, governance, and regulatory compliance in healthcare environments. Topics covered include: • Why healthcare AI projects fail• The importance of data governance and architecture• Protecting PHI in AI-driven systems• The risks of “Vibe Coding” in regulated industries• Building AI responsibly in healthcare If you're building healthcare technology, deploying AI, or managing sensitive health data, this episode highlights the strategies needed to innovate without compromising compliance. Learn more about Data-Sleek: https://data-sleek.com Learn more about HIPAA Vault: https://www.hipaavault.com/?utm_source=spotify&utm_medium=podcast&utm_campaign=franck_leveneur Become a podcast guest: https://www.hipaavault.com/podcast-guest/?utm_source=spotify&utm_medium=podcast&utm_campaign=franck_leveneur

  • #105
    February 27 · 23 min

    From Service to SaaS: The Compliance MUST-HAVES for a 10X Valuation

    What separates a service-based health-tech company from a scalable, high-valuation SaaS platform? In this episode of the HIPAA Insider Show, Adam Z. welcomes Ghazenfer Mansoor, CEO & Founder of Technology Rivers, to break down the strategic roadmap from custom services to enterprise-ready SaaS. With over 15 years of experience building AI-driven, HIPAA-compliant platforms, Ghazenfer shares: Why most health-tech software projects fail The compliance architecture investors and enterprise buyers expect How security maturity impacts valuation The transition from project-based revenue to recurring SaaS growth How healthcare organizations can prepare for the AI revolution If you’re building, scaling, or investing in digital health, this episode explains why compliance isn’t a cost center — it’s a valuation multiplier. Learn more about Ghazenfer: https://ghazenfer.com/ Technology Rivers: https://technologyrivers.com/ Learn more about HIPAA Vault: https://www.hipaavault.com/?utm_source=spotify&utm_medium=podcast&utm_campaign=chazenfer-mansoor

  • #104
    February 20 · 23 min

    Security Questionnaires: Saying “Yes” Isn’t Security

    Filling out a security questionnaire doesn’t mean you’re secure. In healthcare and digital health, startups often spend weeks checking “Yes” on 300-row spreadsheets — believing that equals compliance. But enterprise buyers are looking for something very different: proof of security maturity. In this episode of the HIPAA Insider Show, Adam Z. sits down with Larry Trotter II, Founder of Inherent Security, to unpack: Why “HIPAA Compliant” tech still fails enterprise security reviews The dangerous gap between questionnaire responses and operational reality What healthcare buyers are actually evaluating Why checkbox compliance silently kills deals How to demonstrate real security maturity If you sell into healthcare, this episode may explain why deals stall — even when you answered every question correctly. Connect with Larry Trotter II: https://www.linkedin.com/in/larry-trotter-ii Inherent Security: https://www.inherentsecurity.com/ Learn more about HIPAA-compliant infrastructure: https://www.hipaavault.com/?utm_source=spotify&utm_medium=podcast&utm_campaign=larry-trotter-ii Interested in being a guest on the HIPAA Insider Show? https://www.hipaavault.com/podcast-guest/?utm_source=spotify&utm_medium=podcast&utm_campaign=larry-trotter-ii

  • #103
    February 13 · 29 min

    Most AI Tools Aren’t Legal for Healthcare — Here’s What Works

    Most AI tools being used in healthcare today are not compliant with 42 CFR Part II — and that creates serious legal and regulatory risk. In this episode of the HIPAA Insider Show, host Adam Zeineddine sits down with former federal regulator and national security professional Sam Hart, founder of Hathr.AI, to unpack what healthcare organizations must understand before deploying Generative AI. We cover: Why standard AI platforms fail 42 CFR Part II requirements The difference between FedRAMP Moderate vs. FedRAMP High When GovCloud environments are necessary How substance use disorder (SUD) data triggers stricter federal controls What a legally defensible AI architecture actually looks like If your organization handles behavioral health or SUD data, this episode explains how to innovate with AI without violating federal law. Connect with Sam Hart: https://www.linkedin.com/in/samuel-e-hart/ Learn more about HIPAA-compliant infrastructure with HIPAA Vault: https://www.hipaavault.com/?utm_source=spotify&utm_medium=podcast&utm_campaign=sam_hart Interested in being a guest on the HIPAA Insider Show? https://www.hipaavault.com/podcast-guest/?utm_source=spotify&utm_medium=podcast&utm_campaign=sam_hart

  • #102
    February 6 · 22 min

    Exposed: The Hidden Market for Your Health Data (And How to Opt Out)

    Your health data may be for sale — without you ever knowing. In this episode of the HIPAA Insider Show, we uncover the invisible industry of health data brokers and how so-called “de-identified” medical records are legally sold to advertisers, insurers, and third parties. Host Adam Z. is joined by Dr. Edward Sharpless, Co-Founder of HealthConsent, to discuss: How health data is monetized behind the scenes Why “de-identified” doesn’t always mean anonymous The loopholes in U.S. health privacy laws Where HIPAA protections stop How individuals and employees can automate their privacy rights and opt out of data sales This episode is essential listening for anyone concerned about medical data privacy, patient rights, and who truly controls health information in the U.S. Learn more about HealthConsent: https://myhealthconsent.org Learn more about HIPAA Vault: https://www.hipaavault.com/?utm_source=spotify&utm_medium=podcast&utm_campaign=health_data Interested in being a guest on the HIPAA Insider Show? https://www.hipaavault.com/podcast-guest/?utm_source=spotify&utm_medium=podcast&utm_campaign=health_data

  • #101
    January 30 · 8 min

    WormGPT & the Villains of AI: How Defenders Can Fight Back

    The cyber war has entered a new phase — Good AI vs. Bad AI. In this episode of the HIPAA Insider Show, host Adam Z. explores how the release of WormGPT in 2023 sparked a dangerous AI arms race, giving rise to tools like FraudGPT and DarkBERT that have automated cybercrime at an unprecedented scale. AI-driven phishing attacks have surged over 1,000%, deepfake scams are stealing millions, and healthcare organizations are increasingly in the crosshairs. In this episode, we break down: What WormGPT and other malicious AI tools really do How AI is being weaponized against healthcare Why traditional security defenses are no longer enough A practical, three-step strategy defenders can use to fight fire with fire using defensive AI If your organization handles sensitive healthcare data, understanding this new AI threat landscape is no longer optional — it’s essential. 🔐 Learn more about HIPAA-compliant security and infrastructure with HIPAA Vault: https://www.hipaavault.com/?utm_source=spotify&utm_medium=podcast&utm_campaign=wormGPT 🎙 Interested in being a guest on the HIPAA Insider Show? https://www.hipaavault.com/podcast-guest/?utm_source=spotify&utm_medium=podcast&utm_campaign=wormGPT

  • #100
    January 21 · 10 min

    Unlimited HIPAA Forms? Yes Please. Drag-and-Drop Simplicity

    Collecting patient data shouldn’t be expensive or complicated. In this episode of the HIPAA Insider Show, Adam is joined by HIPAA Vault CEO Gil Vidals to unveil the new HIPAA Forms & Workflow product—built to simplify secure patient intake from start to finish. We break down how healthcare organizations can: Build HIPAA-compliant online forms with drag-and-drop simplicity Eliminate per-user and per-submission fees Use unlimited users and unlimited submissions Secure PHI with encryption and a signed Business Associate Agreement (BAA) Create a fully compliant patient intake lifecycle without technical headaches If your organization collects patient intake forms, registrations, or any PHI online, this episode shows how to do it securely, affordably, and at scale. Learn more about HIPAA Forms by HIPAA Vault: https://www.hipaavault.com/hipaa-compliant-forms/?utm_source=spotify&utm_medium=podcast&utm_campaign=hipaa_forms Want to be a guest on the HIPAA Insider Show? https://www.hipaavault.com/podcast-guest/?utm_source=spotify&utm_medium=podcast&utm_campaign=hipaa_forms

  • #99
    January 7 · 12 min

    New HIPAA Requirements in 2026: Are You Ready for What’s Coming?

    Major changes to HIPAA are coming — and they will impact every healthcare organization, regardless of size. In this episode of the HIPAA Insider Show, Adam Z. and HIPAA Vault CEO Gil Vidals break down the proposed 2026 updates to the HIPAA Security Rule and why these changes represent a mandatory shift toward stronger technology controls across healthcare. We cover the non-negotiable technical requirements expected to become standard, including: Mandatory Multi-Factor Authentication (MFA) Encryption at rest for ePHI Annual penetration testing and security validation Tighter enforcement and reduced tolerance for “best-effort” compliance You’ll also learn: The expected finalization timeline How the compliance grace period is likely to work When your systems must be ready to avoid enforcement risk How smaller organizations can meet enterprise-level security demands with the right cloud strategy If your organization handles ePHI, this episode provides a clear, technology-first roadmap to prepare for HIPAA compliance in 2026. Learn more about HIPAA-compliant hosting and cloud security: https://www.hipaavault.com/hipaa-hosting-solutions/?utm_source=spotify&utm_medium=podcast&utm_campaign=rule_2026

Showing 1–20 of 20 episodes