Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast podcast artwork

PODCAST · business

Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast

Fully Automated is your weekly rundown of the biggest healthcare cybersecurity stories, delivered in a conversational format by Alex and Jen, two AI hosts who break down breaches, vulnerabilities, and compliance news with clarity, a little dark humor, and always a practical takeaway. Perfect for healthcare IT leaders, administrators, and compliance officers who want to stay informed without wading through the noise.

Publisher-supplied feed metadata · PodParley refreshed Sep 18, 2026 · Source feed

  1. 95

    Fake Medicare kit emails borrow the MyChart brand nationwide

    This episode examines three critical developments in healthcare cybersecurity and compliance: widespread MyChart phishing campaigns targeting Medicare patients across 30+ health systems, the $15 million DaVita settlement following the 2025 Interlock ransomware attack, and California's new AB 1979 legislation restricting autonomous AI clinical decision-making. Key takeaways include proactive patient communication strategies, incident response planning, and auditing AI workflows to ensure appropriate human oversight.

  2. 94

    Schedule email sends with the Paubox Email API

    In this episode, Alex and Jen discuss recent cybersecurity threats affecting healthcare organizations, including the ShinyHunters breach of oncology company Novocure and the FBI disruption of a China-linked botnet targeting hospitals. They also cover new Paubox Email API features for scheduled sends and the Senate HELP Committee's advancement of legislation to extend HIPAA-style protections to health data held by non-covered entities.

  3. 93

    Paubox leads in G2 Fall 2026 Reports

    In this episode, we discuss Paubox's recognition in G2's Fall 2026 reports, a surge in MyChart phishing scams targeting patient credentials, and a Chicago cardiology practice breach that went undetected for ten weeks. We also cover the new customizable reply-to feature in Paubox Forms and examine how ransomware groups are now using AI-generated legal risk reports as a pressure tactic against victims.

  4. 92

    Create HIPAA compliant forms via PDF or from Claude Chat

    In this episode, Alex and Jen discuss Paubox's new PDF import feature for HIPAA compliant forms, unified scoped API keys, and the latest IBM data on healthcare breach costs, which remain the highest of any industry at $6.6 million on average. They also cover an emerging credential theft scam targeting professionals on X and share insights from a recent Paubox Table dinner in New York, emphasizing that most security vulnerabilities stem from fixable configuration issues rather than sophisticated attacks.

  5. 91

    Come build your first form with us at Paubox Forms office hours

    In this episode, Alex and Jen discuss the latest healthcare cybersecurity threats including a major data extortion claim against NYC Health + Hospitals, sophisticated phishing campaigns using fake font files, and an in-flight Wi-Fi attack targeting travelers. They also cover the $650,000 settlement by Highland Health Systems following a 2023 breach and emphasize that most security incidents stem from preventable gaps rather than sophisticated attacks.

  6. 90

    Aitkin County Health reports 83k breach after email phishing incident

    In this episode, we break down recent healthcare data breaches including an 83,000-record phishing incident at Aitkin County Health and a nine-year undetected email forwarding leak at Child Care Resource Center. We also cover the HHS 2026 Unified Agenda timeline, the Health-ISAC warning on ShinyHunters threat actors targeting cloud identity infrastructure, and key takeaways for strengthening your organization's security fundamentals.

  7. 89

    Preview quarantined attachments without downloading the email

    In this episode, Jen and Alex cover new Paubox features including attachment preview for quarantined messages and dark mode, then discuss the alleged Abbott Laboratories data breach, emerging threats from malicious AI skills and ClickFix attacks, and privacy implications of ChatGPT Health's nationwide launch. The hosts emphasize actionable steps including vendor audits, user training, and understanding the limitations of HIPAA protection when patient data moves to consumer AI platforms.

  8. 88

    Craneware healthcare billing software investigates major attack

    In this episode, we break down four major healthcare cybersecurity incidents: the Craneware billing platform attack, a nonprofit breach affecting 75,000 individuals, Medtronic's exposure of nearly 370,000 patient records, and ApolloMD's $4.02 million settlement following a ransomware attack. These cases underscore critical lessons for healthcare organizations on vendor management, network segmentation, and incident response planning.

  9. 87

    Start from a template gallery in the Paubox Email API

    In this episode, Alex and Jen discuss a major breach affecting 542,000 individuals at Centers Laboratory, a $500,000+ ransomware settlement involving a Pennsylvania treatment facility, and the HHS delay of the final HIPAA Security Rule update to 2027. They also cover practical tools like the new Paubox Email API template gallery and emphasize how consistent security fundamentals can prevent costly incidents.

  10. 86

    Attackers abuse Microsoft 365 Groups to create phishing invitations

    This episode examines three emerging cybersecurity threats affecting healthcare organizations: Microsoft 365 Groups being exploited for calendar-based phishing attacks, newly discovered vulnerabilities in the widely used DICOM Toolkit that could impact medical imaging systems, and a data breach that originated through social engineering targeting third-party applications. The hosts provide actionable guidance on tightening platform configurations, vetting vendors, and strengthening staff training to address these preventable security gaps.

  11. 85

    More ways to sign in securely with multi-factor authentication

    In this episode, Jen and Alex discuss Paubox's new MFA options, the ShinyHunters breach involving legacy Iora Health data, World Cup-related phishing scams, and a Senate bill addressing cybersecurity risks in Chinese-made medical devices. The hosts emphasize the importance of addressing legacy systems, conducting thorough asset inventories, and implementing foundational security controls to protect patient data.

  12. 84

    Attackers impersonate ChatGPT, Claude, and DeepSeek to deliver malware

    In this episode, we cover emerging threats targeting healthcare and enterprise organizations, including AI platform impersonation scams, the ShinyHunters attacks on Oracle PeopleSoft systems, and research showing AI email agents are vulnerable to phishing. We also discuss Paubox joining LegitScript's Compliance Collective and the Novo Nordisk clinical trial data breach investigation. Key takeaways include verifying AI tool sources, reviewing legacy system configurations, and applying least-privilege principles to AI agents.

  13. 83

    Conditional logic comes to Paubox Forms

    In this episode, we discuss Paubox Forms' new conditional logic feature, the Conduent breach affecting 62 million people, and critical findings from controlled tests revealing Amazon SES may transmit PHI in plaintext despite documentation claims. We also cover recent ransomware incidents at Mt. Baker, Northwest Radiologists, and Singing River Health System, along with key takeaways from the June Zoom social mixer on AI tooling and vendor management strategies for small IT teams.

  14. 82

    IBJI agrees to $4 million settlement after breach

    This episode examines recent healthcare data breaches and settlements, including the $4 million IBJI case involving extended attacker dwell time, Mission Community Hospital's $1.5 million RansomHouse extortion settlement, and third-party vendor risks exposed by the La Perouse billing breach. We also discuss Rutgers University research showing hospitals using third-party tracking pixels are 46 percent more likely to experience breaches, emphasizing the critical need for system patching, vendor oversight, and web property audits.

  15. 81

    Paubox Forms now includes a library of pre-built templates

    In this episode, Alex and Jen discuss new Paubox product updates including a Forms template library and API dashboard improvements, then analyze recent healthcare data breaches affecting Esse Health, Gandara Mental Health Center, and NYC Health + Hospitals. The conversation highlights common security gaps, the growing risk of third-party vendor breaches, and practical steps organizations can take to strengthen their compliance and security posture.

  16. 80

    Paubox CLI adds forms support: HIPAA compliant email and data collection in one tool

    This episode covers the new Paubox CLI support for Forms, the LockBit 5.0 ransomware attack on Mt. Spokane Pediatrics affecting over 32,000 patients, a CISA-flagged vulnerability in medical imaging software, and the FBI warning about the Kali365 phishing-as-a-service platform targeting Microsoft 365 credentials. The hosts discuss the security gaps facing small clinics and emphasize actionable steps including patching systems, network segmentation, and staff training to address these evolving threats.

  17. 79

    Send HIPAA compliant email from the terminal, or your agent

    In this episode, Jen and Alex break down the surge in QR code phishing attacks, the cautionary tale of a ransomware negotiator who defrauded healthcare clients, and practical strategies for reducing security friction. They also cover new tools for HIPAA-compliant email automation and self-service archive exports that streamline compliance workflows.

  18. 78

    SAG-AFTRA Health Plan settles phishing breach class action for $950,000

    In this episode, we break down the SAG-AFTRA Health Plan's $950,000 phishing settlement, Medtronic's nine-million-record breach, and the Inc Ransom attack on Sandhills Medical Foundation. We also highlight Henderson Behavioral Health's patient-centered approach and discuss practical takeaways for strengthening your organization's security posture through staff training, system patching, and incident response planning.

  19. 77

    Microsoft warns of a phishing campaign bypassing MFA protections

    In this episode, we examine a Microsoft-flagged phishing campaign that bypassed MFA across 13,000 organizations, analyze Saint Anthony Hospital's breach notification that expanded from 6,500 to 146,000 affected individuals, and discuss the ransomware attack impacting 92,000 patients at a Puerto Rico community hospital. Key takeaways include the importance of layered email security, thorough incident scoping, and addressing configuration blind spots before threat actors exploit them.

  20. 76

    FBI names healthcare the most targeted sector for ransomware

    In this episode, we break down the FBI's latest Internet Crime Report naming healthcare as the top ransomware target, OCR's four new HIPAA settlements totaling over $1 million, and the Medtronic data extortion incident affecting millions of records. We also examine findings from Paubox's Healthcare Email Security Maturity Index, which reveals critical gaps in AI-based defenses despite rising AI-driven attacks, and discuss what these trends mean for your organization's security posture.

  21. 75

    OrthopedicsNY faces $1.95M penalty after INC Ransom attack

    In this episode, we break down recent healthcare cybersecurity incidents including a $1.45 million class action settlement stemming from missing MFA and unencrypted data, a repeat ransomware attack on a small cardiology practice, and how attackers are bypassing traditional email authentication. We also discuss the emerging threat of AI-assisted cyberattacks and actionable steps organizations can take to address common security blind spots.

  22. 74

    Brockton Hospital hit by cyberattack, incident disrupts patient care

    This episode examines recent ransomware attacks affecting Brockton Hospital, Stockton Cardiology, and Rocky Mountain Care, alongside a Dutch supply chain breach impacting eleven hospitals. The hosts discuss the EvilTokens phishing kit that bypasses MFA through Microsoft 365 device code flow exploitation, and share practical defenses including conditional access policies, improved logging, and incident response planning. Key insights from the April Zoom social mixer cover monthly penetration testing, effective security awareness training, and AI adoption guardrails.

  23. 73

    Da Vinci robot maker Intuitive Surgical reports phishing breach

    This episode examines recent cybersecurity incidents affecting healthcare organizations, including breaches at Intuitive Surgical, Nacogdoches Memorial Hospital, and Innovative Pharmacy Packaging Corp, alongside a sophisticated job scam targeting professionals. Key takeaways include the critical importance of phishing training, network monitoring, vendor risk assessments, and reducing detection dwell time. The discussion reinforces that most breaches stem from preventable issues like misconfigurations, blind spots, and social engineering vulnerabilities.

  24. 72

    Microsoft Teams phishing campaign deploys A0Backdoor malware

    In this episode, Alex and Jen break down three recent cybersecurity incidents affecting healthcare and social services organizations: Microsoft Teams impersonation attacks targeting healthcare and financial sectors, fake AI apps harvesting credentials, and a ransomware breach at a nonprofit serving vulnerable populations. The discussion highlights how misconfigurations and overlooked security basics create exploitable gaps, and offers practical steps for locking down external communications, verifying app legitimacy, and strengthening defenses against ransomware.

  25. 71

    Navia Benefit Solutions announces breach impacting nearly 3 million

    In this episode, we break down recent healthcare cybersecurity incidents including the Navia benefits administrator breach affecting nearly three million individuals, ransomware attacks on Kettering Health and a US healthcare provider, and the Essen Medical Associates settlement. We examine common vulnerabilities across these cases—from inadequate privileged access monitoring to untested incident response plans—and discuss actionable steps organizations can take to strengthen their security posture. The key takeaway: most breaches stem from addressable gaps, and consistent attention to fundamentals remains the most effective defense.

  26. 70

    Paubox recognized as email encryption leader in G2 Spring 2026 Reports

    In this episode, Alex and Jen break down the latest cybersecurity incidents affecting healthcare, including ransomware targeting community health organizations, phishing attacks leveraging trusted cloud platforms, MFA bypass techniques, and the exploitation of legitimate admin tools in cloud environments. The discussion emphasizes that most breaches stem from preventable configuration gaps and offers actionable guidance on endpoint protection, network segmentation, and phishing-resistant authentication methods.

  27. 69

    68. Aja Anderson: "Bad actors are offering your employees incentives to help them."

    Episode 68 features Aja Anderson, Paubox Customer Success Manager. 

  28. 68
  29. 67

    66. Hoala Greevy: "Just automating one workflow creates an instant ROI for the business"

    Episode 66 of HIPAA Critical features an interview with Founder CEO, Hoala Greevy, about workflow automation. 

  30. 66

    65. Aja Anderson: "That's the sweet spot for threat actors coming after you because they know that there's money there."

    Episode 65 of HIPAA Critical recaps the HIPAA Breach Report details breaches from December 2021. 

  31. 65

    64. Dave Ledoux: "I'm ready to pivot at any time."

    Episode 64 of HIPAA Critical features an interview with Dave Ledoux, CIO of Innovive Health. 

  32. 64

    63. Aja Anderson: "As long as people can make money, they're gonna keep [attacking]. As long as your systems are not secure, you're at risk."

    Episode 63 of HIPAA Critical features a discussion with Aja Anderson on this month's Paubox HIPAA Breach Report. 

  33. 63

    62. Hector Rodriguez: "In healthcare, we have the challenges of cybersecurity, disaster recovery, and recovery strategies for ransomware mitigation."

    Episode 62 of HIPAA Critical features an interview with Hector Rodriguez, Principal Industry Specialist, Healthcare & Life Sciences - AWS

  34. 62
  35. 61

    60. Brian Fritton: "If you make it easy for attackers to find email addresses, they're gonna phish you."

    Episode 60 of HIPAA Critical features an interview with Brian Fritton, CEO of Havoc Shield. 

  36. 60

    59. Aja Anderson: "If you don't have something that's actually examining your encrypted HTTPS traffic, you're missing 9 out of 10 instances of malware."

    Episode 59 of HIPAA Critical covers the Paubox HIPAA Breach Report for October 2021 and other cybersecurity trends with guest Aja Anderson, Paubox Customer Success Manager. 

  37. 59

    58. Matt Cooper: "The eternal weakness is human error."

    Episode 58 of HIPAA Critical includes an interview with Matt Cooper, Cybersecurity & Data Privacy Principal at Vanta. 

  38. 58

    57. Hoala Greevy: "It's a matter of sorting the data, training the data, and then using those new learnings to provide greater phishing detection."

    Episode 57 of HIPAA Critical features an interview about AI with Paubox Founder CEO, Hoala Greevy. 

  39. 57

    56. Sara Sosa: "An informed team is an effective team."

    Episode 56 of HIPAA Critical features an interview with Sara Sosa, Director of Information Services at Vista Care. 

  40. 56

    55. Aja Anderson: "It is frustrating to take the extra steps, yet it is keeping us safe."

    Episode 56 of HIPAA Critical welcomes back Paubox Customer Success Manager, Aja Anderson, to discuss the findings of the Paubox HIPAA Breach Report for September 2021.  

  41. 55

    54. Jane Harper: "All organizations have some risks. Risk is inherent."

    Episode 54 includes an interview with Jane Harper. Jane is the senior director, information security risk management and business engagement at Eli Lilly and Company. 

  42. 54

    53. Anshul Pande: "All of these changes brought about a new set of problems to solve and challenges as we implemented those technologies."

    Episode 53 of the HIPAA Critical podcast features an interview with Anshul Pande, vice president and chief technology officer at Stanford Children's Health. 

  43. 53

    52. Aja Anderson: "No matter how tight your budget is you should routinely assess the risk of your systems."

    Episode 52 of HIPAA Critical welcomes back Paubox Customer Success Manager, Aja Anderson, to discuss the findings of the Paubox HIPAA Breach Report for August 2021. 

  44. 52

    51. Dr. Eric Cole: "It's the same fundamental problem: we're not learning our lessons and keep repeating them over and over again."

    Episode 51 of HIPAA Critical includes an interview with Dr. Eric Cole, a former CIA hacker and founder of Secure Anchor.Read the transcript here. More about Paubox: www.paubox.com 

  45. 51

    50. Fred Kwong: "Risk is a language that business understands."

    Fred Kwong, CISO of Delta Dental is featured on episode 50 of HIPAA Critical.Read the full transcription here.  

  46. 50

    49. Aja Anderson: "This isn't unique to healthcare. This is happening in every industry."

    Episode 49 covers the findings of the Paubox HIPAA Breach Report for July 2021. Aja Anderson, customer success manager at Paubox, joins the episode to discuss key trends, share insights, and give cybersecurity tips. 

  47. 49

    48. Todd Pang: "We had to do a lot of training and awareness building for what actually constitutes PHI."

    Episode 48 of the HIPAA Critical Podcast includes an interview with Todd Pang, president and co-owner of Caring Manoa. 

  48. 48

    47. Jeff Karlsson: "The Biggest Threat That Our Customers Have Is Not Having a Contingency Plan."

    The challenges of 2020 are still lingering in many industries we might be in a new year. But the effects of the covid-19 pandemic reach far and wide. The way we work and the way business operated changed dramatically and almost overnight. Jeff Karlsson is on today's episode. Jeff is the chief operating officer of Divergent Business Consulting, a Salesforce and financial consulting company. Jeff and Sierra Langston sit down to discuss the COVID-19 pandemic, how to force change across many industries, and emerging healthcare trends. 

  49. 47

    46. John Benbrook: "In Order to Safeguard That Sensitive Information, We Needed to Implement Encryption."

    Elderly care organizations need to comply with HIPAA regulations and security rules, especially if they deal with their patient’s medications, doctors, or other sensitive information. What is the best way for these types of organizations to approach HIPAA compliance and secure data? How do we keep the most vulnerable members of our society safe from bad actors? John Benbrook, president of Oasis Senior Partners, and Paul Giovacchini, enterprise customer success manager at Paubox, join Sierra Langston on today’s episode to discuss HIPAA compliance training, assessing risk management, and unencrypted data vulnerabilities.

  50. 46

    45. Greg Reber: "This Is the Biggest Information Breach That We've Ever Seen."

    Cybersecurity protocols and practices will never be a one-size-fits-all solution. Different industries have different requirements for compliance. Healthcare has vague but vast security rules to follow under HIPAA. So how do organizations stay ahead of the cybersecurity curve?Greg Reber, Founder and CEO, of AsTech Consulting, is with us on today’s episode. He and Sierra Langston discuss the changes and challenges in cybersecurity, including implementing solutions that meet regulatory standards, the evolving threat landscape, and how information sharing is a key to the future of cybersecurity.

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

TOPICS IN THIS SHOW

Click any topic to search every transcript on PodParley for moments someone mentioned it.

Loading reviews...

ABOUT THIS SHOW

Fully Automated is your weekly rundown of the biggest healthcare cybersecurity stories, delivered in a conversational format by Alex and Jen, two AI hosts who break down breaches, vulnerabilities, and compliance news with clarity, a little dark humor, and always a practical takeaway. Perfect for healthcare IT leaders, administrators, and compliance officers who want to stay informed without wading through the noise.

HOSTED BY

Paubox

CATEGORIES

Frequently Asked Questions

How many episodes does Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast have?

Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast currently has 50 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast about?

Fully Automated is your weekly rundown of the biggest healthcare cybersecurity stories, delivered in a conversational format by Alex and Jen, two AI hosts who break down breaches, vulnerabilities, and compliance news with clarity, a little dark humor, and always a practical takeaway. Perfect for...

How often does Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast release new episodes?

Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast has 50 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast?

You can listen to Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast?

Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast is created and hosted by Paubox.
URL copied to clipboard!