Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast podcast artwork

PODCAST · business

Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast

Fully Automated is your weekly rundown of the biggest healthcare cybersecurity stories, delivered in a conversational format by Alex and Jen, two AI hosts who break down breaches, vulnerabilities, and compliance news with clarity, a little dark humor, and always a practical takeaway. Perfect for healthcare IT leaders, administrators, and compliance officers who want to stay informed without wading through the noise.

Publisher-supplied feed metadata · PodParley refreshed Jul 31, 2026 · Source feed

  1. 88

    More ways to sign in securely with multi-factor authentication

    In this episode, Jen and Alex discuss Paubox's new MFA options, the ShinyHunters breach involving legacy Iora Health data, World Cup-related phishing scams, and a Senate bill addressing cybersecurity risks in Chinese-made medical devices. The hosts emphasize the importance of addressing legacy systems, conducting thorough asset inventories, and implementing foundational security controls to protect patient data.

  2. 87

    Attackers impersonate ChatGPT, Claude, and DeepSeek to deliver malware

    In this episode, we cover emerging threats targeting healthcare and enterprise organizations, including AI platform impersonation scams, the ShinyHunters attacks on Oracle PeopleSoft systems, and research showing AI email agents are vulnerable to phishing. We also discuss Paubox joining LegitScript's Compliance Collective and the Novo Nordisk clinical trial data breach investigation. Key takeaways include verifying AI tool sources, reviewing legacy system configurations, and applying least-privilege principles to AI agents.

  3. 86

    Conditional logic comes to Paubox Forms

    In this episode, we discuss Paubox Forms' new conditional logic feature, the Conduent breach affecting 62 million people, and critical findings from controlled tests revealing Amazon SES may transmit PHI in plaintext despite documentation claims. We also cover recent ransomware incidents at Mt. Baker, Northwest Radiologists, and Singing River Health System, along with key takeaways from the June Zoom social mixer on AI tooling and vendor management strategies for small IT teams.

  4. 85

    IBJI agrees to $4 million settlement after breach

    This episode examines recent healthcare data breaches and settlements, including the $4 million IBJI case involving extended attacker dwell time, Mission Community Hospital's $1.5 million RansomHouse extortion settlement, and third-party vendor risks exposed by the La Perouse billing breach. We also discuss Rutgers University research showing hospitals using third-party tracking pixels are 46 percent more likely to experience breaches, emphasizing the critical need for system patching, vendor oversight, and web property audits.

  5. 84

    Paubox Forms now includes a library of pre-built templates

    In this episode, Alex and Jen discuss new Paubox product updates including a Forms template library and API dashboard improvements, then analyze recent healthcare data breaches affecting Esse Health, Gandara Mental Health Center, and NYC Health + Hospitals. The conversation highlights common security gaps, the growing risk of third-party vendor breaches, and practical steps organizations can take to strengthen their compliance and security posture.

  6. 83

    Paubox CLI adds forms support: HIPAA compliant email and data collection in one tool

    This episode covers the new Paubox CLI support for Forms, the LockBit 5.0 ransomware attack on Mt. Spokane Pediatrics affecting over 32,000 patients, a CISA-flagged vulnerability in medical imaging software, and the FBI warning about the Kali365 phishing-as-a-service platform targeting Microsoft 365 credentials. The hosts discuss the security gaps facing small clinics and emphasize actionable steps including patching systems, network segmentation, and staff training to address these evolving threats.

  7. 82

    Send HIPAA compliant email from the terminal, or your agent

    In this episode, Jen and Alex break down the surge in QR code phishing attacks, the cautionary tale of a ransomware negotiator who defrauded healthcare clients, and practical strategies for reducing security friction. They also cover new tools for HIPAA-compliant email automation and self-service archive exports that streamline compliance workflows.

  8. 81

    SAG-AFTRA Health Plan settles phishing breach class action for $950,000

    In this episode, we break down the SAG-AFTRA Health Plan's $950,000 phishing settlement, Medtronic's nine-million-record breach, and the Inc Ransom attack on Sandhills Medical Foundation. We also highlight Henderson Behavioral Health's patient-centered approach and discuss practical takeaways for strengthening your organization's security posture through staff training, system patching, and incident response planning.

  9. 80

    Microsoft warns of a phishing campaign bypassing MFA protections

    In this episode, we examine a Microsoft-flagged phishing campaign that bypassed MFA across 13,000 organizations, analyze Saint Anthony Hospital's breach notification that expanded from 6,500 to 146,000 affected individuals, and discuss the ransomware attack impacting 92,000 patients at a Puerto Rico community hospital. Key takeaways include the importance of layered email security, thorough incident scoping, and addressing configuration blind spots before threat actors exploit them.

  10. 79

    FBI names healthcare the most targeted sector for ransomware

    In this episode, we break down the FBI's latest Internet Crime Report naming healthcare as the top ransomware target, OCR's four new HIPAA settlements totaling over $1 million, and the Medtronic data extortion incident affecting millions of records. We also examine findings from Paubox's Healthcare Email Security Maturity Index, which reveals critical gaps in AI-based defenses despite rising AI-driven attacks, and discuss what these trends mean for your organization's security posture.

  11. 78

    OrthopedicsNY faces $1.95M penalty after INC Ransom attack

    In this episode, we break down recent healthcare cybersecurity incidents including a $1.45 million class action settlement stemming from missing MFA and unencrypted data, a repeat ransomware attack on a small cardiology practice, and how attackers are bypassing traditional email authentication. We also discuss the emerging threat of AI-assisted cyberattacks and actionable steps organizations can take to address common security blind spots.

  12. 77

    Brockton Hospital hit by cyberattack, incident disrupts patient care

    This episode examines recent ransomware attacks affecting Brockton Hospital, Stockton Cardiology, and Rocky Mountain Care, alongside a Dutch supply chain breach impacting eleven hospitals. The hosts discuss the EvilTokens phishing kit that bypasses MFA through Microsoft 365 device code flow exploitation, and share practical defenses including conditional access policies, improved logging, and incident response planning. Key insights from the April Zoom social mixer cover monthly penetration testing, effective security awareness training, and AI adoption guardrails.

  13. 76

    Da Vinci robot maker Intuitive Surgical reports phishing breach

    This episode examines recent cybersecurity incidents affecting healthcare organizations, including breaches at Intuitive Surgical, Nacogdoches Memorial Hospital, and Innovative Pharmacy Packaging Corp, alongside a sophisticated job scam targeting professionals. Key takeaways include the critical importance of phishing training, network monitoring, vendor risk assessments, and reducing detection dwell time. The discussion reinforces that most breaches stem from preventable issues like misconfigurations, blind spots, and social engineering vulnerabilities.

  14. 75

    Microsoft Teams phishing campaign deploys A0Backdoor malware

    In this episode, Alex and Jen break down three recent cybersecurity incidents affecting healthcare and social services organizations: Microsoft Teams impersonation attacks targeting healthcare and financial sectors, fake AI apps harvesting credentials, and a ransomware breach at a nonprofit serving vulnerable populations. The discussion highlights how misconfigurations and overlooked security basics create exploitable gaps, and offers practical steps for locking down external communications, verifying app legitimacy, and strengthening defenses against ransomware.

  15. 74

    Navia Benefit Solutions announces breach impacting nearly 3 million

    In this episode, we break down recent healthcare cybersecurity incidents including the Navia benefits administrator breach affecting nearly three million individuals, ransomware attacks on Kettering Health and a US healthcare provider, and the Essen Medical Associates settlement. We examine common vulnerabilities across these cases—from inadequate privileged access monitoring to untested incident response plans—and discuss actionable steps organizations can take to strengthen their security posture. The key takeaway: most breaches stem from addressable gaps, and consistent attention to fundamentals remains the most effective defense.

  16. 73

    Paubox recognized as email encryption leader in G2 Spring 2026 Reports

    In this episode, Alex and Jen break down the latest cybersecurity incidents affecting healthcare, including ransomware targeting community health organizations, phishing attacks leveraging trusted cloud platforms, MFA bypass techniques, and the exploitation of legitimate admin tools in cloud environments. The discussion emphasizes that most breaches stem from preventable configuration gaps and offers actionable guidance on endpoint protection, network segmentation, and phishing-resistant authentication methods.

  17. 72

    68. Aja Anderson: "Bad actors are offering your employees incentives to help them."

    Episode 68 features Aja Anderson, Paubox Customer Success Manager. 

  18. 71
  19. 70

    66. Hoala Greevy: "Just automating one workflow creates an instant ROI for the business"

    Episode 66 of HIPAA Critical features an interview with Founder CEO, Hoala Greevy, about workflow automation. 

  20. 69

    65. Aja Anderson: "That's the sweet spot for threat actors coming after you because they know that there's money there."

    Episode 65 of HIPAA Critical recaps the HIPAA Breach Report details breaches from December 2021. 

  21. 68

    64. Dave Ledoux: "I'm ready to pivot at any time."

    Episode 64 of HIPAA Critical features an interview with Dave Ledoux, CIO of Innovive Health. 

  22. 67

    63. Aja Anderson: "As long as people can make money, they're gonna keep [attacking]. As long as your systems are not secure, you're at risk."

    Episode 63 of HIPAA Critical features a discussion with Aja Anderson on this month's Paubox HIPAA Breach Report. 

  23. 66

    62. Hector Rodriguez: "In healthcare, we have the challenges of cybersecurity, disaster recovery, and recovery strategies for ransomware mitigation."

    Episode 62 of HIPAA Critical features an interview with Hector Rodriguez, Principal Industry Specialist, Healthcare & Life Sciences - AWS

  24. 65
  25. 64

    60. Brian Fritton: "If you make it easy for attackers to find email addresses, they're gonna phish you."

    Episode 60 of HIPAA Critical features an interview with Brian Fritton, CEO of Havoc Shield. 

  26. 63

    59. Aja Anderson: "If you don't have something that's actually examining your encrypted HTTPS traffic, you're missing 9 out of 10 instances of malware."

    Episode 59 of HIPAA Critical covers the Paubox HIPAA Breach Report for October 2021 and other cybersecurity trends with guest Aja Anderson, Paubox Customer Success Manager. 

  27. 62

    58. Matt Cooper: "The eternal weakness is human error."

    Episode 58 of HIPAA Critical includes an interview with Matt Cooper, Cybersecurity & Data Privacy Principal at Vanta. 

  28. 61

    57. Hoala Greevy: "It's a matter of sorting the data, training the data, and then using those new learnings to provide greater phishing detection."

    Episode 57 of HIPAA Critical features an interview about AI with Paubox Founder CEO, Hoala Greevy. 

  29. 60

    56. Sara Sosa: "An informed team is an effective team."

    Episode 56 of HIPAA Critical features an interview with Sara Sosa, Director of Information Services at Vista Care. 

  30. 59

    55. Aja Anderson: "It is frustrating to take the extra steps, yet it is keeping us safe."

    Episode 56 of HIPAA Critical welcomes back Paubox Customer Success Manager, Aja Anderson, to discuss the findings of the Paubox HIPAA Breach Report for September 2021.  

  31. 58

    54. Jane Harper: "All organizations have some risks. Risk is inherent."

    Episode 54 includes an interview with Jane Harper. Jane is the senior director, information security risk management and business engagement at Eli Lilly and Company. 

  32. 57

    53. Anshul Pande: "All of these changes brought about a new set of problems to solve and challenges as we implemented those technologies."

    Episode 53 of the HIPAA Critical podcast features an interview with Anshul Pande, vice president and chief technology officer at Stanford Children's Health. 

  33. 56

    52. Aja Anderson: "No matter how tight your budget is you should routinely assess the risk of your systems."

    Episode 52 of HIPAA Critical welcomes back Paubox Customer Success Manager, Aja Anderson, to discuss the findings of the Paubox HIPAA Breach Report for August 2021. 

  34. 55

    51. Dr. Eric Cole: "It's the same fundamental problem: we're not learning our lessons and keep repeating them over and over again."

    Episode 51 of HIPAA Critical includes an interview with Dr. Eric Cole, a former CIA hacker and founder of Secure Anchor.Read the transcript here. More about Paubox: www.paubox.com 

  35. 54

    50. Fred Kwong: "Risk is a language that business understands."

    Fred Kwong, CISO of Delta Dental is featured on episode 50 of HIPAA Critical.Read the full transcription here.  

  36. 53

    49. Aja Anderson: "This isn't unique to healthcare. This is happening in every industry."

    Episode 49 covers the findings of the Paubox HIPAA Breach Report for July 2021. Aja Anderson, customer success manager at Paubox, joins the episode to discuss key trends, share insights, and give cybersecurity tips. 

  37. 52

    48. Todd Pang: "We had to do a lot of training and awareness building for what actually constitutes PHI."

    Episode 48 of the HIPAA Critical Podcast includes an interview with Todd Pang, president and co-owner of Caring Manoa. 

  38. 51

    47. Jeff Karlsson: "The Biggest Threat That Our Customers Have Is Not Having a Contingency Plan."

    The challenges of 2020 are still lingering in many industries we might be in a new year. But the effects of the covid-19 pandemic reach far and wide. The way we work and the way business operated changed dramatically and almost overnight. Jeff Karlsson is on today's episode. Jeff is the chief operating officer of Divergent Business Consulting, a Salesforce and financial consulting company. Jeff and Sierra Langston sit down to discuss the COVID-19 pandemic, how to force change across many industries, and emerging healthcare trends. 

  39. 50

    46. John Benbrook: "In Order to Safeguard That Sensitive Information, We Needed to Implement Encryption."

    Elderly care organizations need to comply with HIPAA regulations and security rules, especially if they deal with their patient’s medications, doctors, or other sensitive information. What is the best way for these types of organizations to approach HIPAA compliance and secure data? How do we keep the most vulnerable members of our society safe from bad actors? John Benbrook, president of Oasis Senior Partners, and Paul Giovacchini, enterprise customer success manager at Paubox, join Sierra Langston on today’s episode to discuss HIPAA compliance training, assessing risk management, and unencrypted data vulnerabilities.

  40. 49

    45. Greg Reber: "This Is the Biggest Information Breach That We've Ever Seen."

    Cybersecurity protocols and practices will never be a one-size-fits-all solution. Different industries have different requirements for compliance. Healthcare has vague but vast security rules to follow under HIPAA. So how do organizations stay ahead of the cybersecurity curve?Greg Reber, Founder and CEO, of AsTech Consulting, is with us on today’s episode. He and Sierra Langston discuss the changes and challenges in cybersecurity, including implementing solutions that meet regulatory standards, the evolving threat landscape, and how information sharing is a key to the future of cybersecurity.

  41. 48

    44. Jared Vinson: "It Started With a Phishing Attack, but It Ended With a Whole Mess of Other Things."

    With more than 500 reported HIPAA breaches in the last year, why are healthcare organizations slow to update their cybersecurity protocols and technology stacks? Is it possible for the healthcare industry to get ahead of bad actors? Today, Sierra Langston speaks with Jared Vinson, director of cybersecurity at Hill Country Tech Guys on all things healthcare security, including phishing scams, best practices, and the aftermath of a HIPAA breach.

  42. 47

    43. Michael Mead: "Training Is Not Just for HIPAA Security, but Cybersecurity."

    The healthcare industry is slow to change and, at times, even slower to embrace innovation. Fax machines, patient portals, and complicated compliance solutions are everywhere. The challenges of these outdated and vulnerable technologies only make data breaches, HIPAA fines, and cybersecurity threats more prevalent.  On today's episode, Sierra Langston and Michael Mead of The Medical Cost Savings Solution discuss HIPAA compliance, healthcare industry challenges, and unencrypted data transfers.

  43. 46

    42. Bonnie Castonguay: "What We've Always Wanted Was the Ability for More Seniors to Have Access to Home Care."

    Almost overnight, the pandemic changed telehealth and how our most vulnerable populations receive the medical care they desperately need.  As many Americans start to take care of their aging parents at home or through an elder care center, they find navigating the complicated world of HIPAA and the American healthcare system to be confusing, expensive, and daunting. On today's episode, Paubox Founder and CEO, Hoala Greevy, interviews Bonnie Castonguay, co-founder of Ho'okele Health on the effects COVID-19 has on in-home care, the positive changes telehealth has brought to her clients and their families, and how easy Paubox has made HIPAA compliance for her company. 

  44. 45

    41. Eoin Gregory: "You Say the Word HIPAA, and Our Providers Cringe or Turn Their Brains off."

    If you work in healthcare, you know what HIPAA is, but do you and your organization understand how to maintain HIPAA compliance regarding email security and encryption? Is HIPAA compliance a “one size fits all” situation? How do organizations keep their employees and their partners compliant and safe?Today Sierra Langston sits down with Eoin Gregory of Family Billing Solutions and Travis Taylor of Paubox to discuss email encryption, the HHS Wall of Shame, and how to keep your staff, partners, and yourself educated on the vague but vast world of HIPAA compliance.

  45. 44

    40. Ken Dabkowski: "As a Tech-Centered Company, We Want to Make Sure We're Meeting the Highest Standards Possible."

    What is medical cost-sharing? Is it the future of healthcare? What can modern healthcare learn from this historical industry? In this episode, Sierra Langston sits down with Ken Dabkowski, Senior Project Manager of Sedera, to discuss medical cost-sharing and Sedera's IT and cybersecurity stack.

  46. 43

    39. Hannah Trum: "Certifications are a No-Brainer in the Healthcare Industry."

    In this episode, you'll hear Sierra Langston, marketing manager, and Hannah Trum, marketing specialist, give their top takeaways from Paubox Spring Summit, Secure Communication During a Pandemic. Panelists from this event include:Hoala Greevy, Founder CEO, PauboxAnshul Pande, Vice President, and Chief Technology Officer, Stanford Children's HealthChris Lindley, Chief Population Health Officer, Vail HealthJulie Jackson, Director Applications and Informatics, Vail HealthSusan Ibáñez, Chief Information Officer, Vail HealthPaddy Padmanabhan, CEO, Damo Consulting, Inc.Aaron Collins, System Administrator, Developmental Center of the OzarkBrian Kline, Principal, Webb AdamsDan Dorszynski, Software Engineer, PauboxHoward Rosen, MBA, CEO & Founder, LifeWIREMatthew Wallace, Vice President of Strategic Initiatives and Partnerships, Easterseals LouisianaMichael Mead, BCPA, Chief Operating Officer, The Medical Cost Savings SolutionMichael Parisi, Vice President, Business Development & Adoption, HITRUSTNick Wong, Email API Specialist, PauboxTony UcedaVélez, CEO & Founder, VerSpriteFor a full recap of Paubox Spring Summit, click here. For more information about Paubox Spring Summit, click here. 

  47. 42

    38. Tony UcedaVélez: "A Risk-Centric Approach is Trying to Prove the Most Likely Threats That Could Affect a Healthcare Entity."

    You may be asking yourself what threat modeling is and why it is important?In this episode, that is what you are going to find out. Healthcare has been under attack for a slew of reasons for the past 10 years. Threat modeling, very simply put, is a way to model threats. Whether you are in healthcare tech or an insurance provider, there is a benefit to understanding who your adversaries are and where you are vulnerable to threat actors.Today we are speaking with Tony UcedaVélez, founder and CEO of the security consulting firm VerSprite, based in Atlanta. 

  48. 41

    37. Brian Kline: "Writing a Policy that Prohibits Sending Sensitive Information is Probably Not a Realistic Option"

    Have you ever wondered how to streamline HITRUST, SOC 2 as well as other certifications and attestations?Well, in this episode, that is what you will find out.We’re going to explain how to streamline the process of developing policies and procedures, how to conduct a gap assessment & risk assessment, how to facilitate incident response exercises, how to upload evidence and meet with auditors.

  49. 40

    36. Anya Schiess: “Telemedicine is Just an Example of What COVID has Catalyzed”

    Today, we're talking with Anya Schiess, Co-founder and General Partner of Healthy Ventures. She will shed light on a variety of topics such as challenges for health systems, why modern data architecture is important, FinTech, and what is on the horizon for healthcare.

  50. 39

    35. Elena Yau: “Email Is The Most Convenient But Is Also The Highest Threat.”

    Ransomware, malware, phishing attacks, and PHI email breaches continue to spike in 2021.Malware, the malicious software, is built to exploit chinks in the armor of our operating systems. This can involve pop-up ads or using it as part of a distributed denial-of-service attack.This is why HIPAA Compliant training is so important.Have you ever wondered how other healthcare organizations are training their team on HIPAA Compliance or protecting their email?Well, in this episode, that is what you will find out.Elena Yau, Director of IT and HIPAA Security Officer at FiveAcres is going to give you an in-depth look at their HIPAA compliance processes and procedures.

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

TOPICS IN THIS SHOW

Click any topic to search every transcript on PodParley for moments someone mentioned it.

Loading reviews...

ABOUT THIS SHOW

Fully Automated is your weekly rundown of the biggest healthcare cybersecurity stories, delivered in a conversational format by Alex and Jen, two AI hosts who break down breaches, vulnerabilities, and compliance news with clarity, a little dark humor, and always a practical takeaway. Perfect for healthcare IT leaders, administrators, and compliance officers who want to stay informed without wading through the noise.

HOSTED BY

Paubox

CATEGORIES

Frequently Asked Questions

How many episodes does Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast have?

Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast currently has 50 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast about?

Fully Automated is your weekly rundown of the biggest healthcare cybersecurity stories, delivered in a conversational format by Alex and Jen, two AI hosts who break down breaches, vulnerabilities, and compliance news with clarity, a little dark humor, and always a practical takeaway. Perfect for...

How often does Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast release new episodes?

Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast has 50 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast?

You can listen to Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast?

Paubox Weekly Fully Automated - A HIPAA compliant email security Podcast is created and hosted by Paubox.
URL copied to clipboard!