Hi friend,

Earlier this month, I was pleased to participate in LeadingAge Southeast in Orlando. I speak at several conferences throughout the year, but this experience was especially rewarding because the discussion clearly resonated with the audience.

The topic was AI, Cybersecurity, and the Law in Senior Living. I joined Angie Roher of Freedom Plaza, Christopher Tomlin, President and CEO of Methodist Homes of Alabama and Northwest Florida, and Alexandra Moylan of Baker Donelson as we covered several practical areas: the legal and regulatory landscape, security risk analysis and enforcement, breach and litigation exposure, and AI governance in senior living using real-world case studies.

Although news had just broken that the HHS was delaying any changes to the existing HIPAA Security Rule until 2027, the audience was ready and eager to hear our thoughts on new expectations around encryption, MFA, and annual asset inventories. Many of the attendees who joined our session have already been focused on working through what those changes could mean for their organizations over the last few months.

What was so rewarding was the level of engagement among the attendees. Not only were they poised and ready to hear our thoughts, but the combination of legal and regulatory context and our real-world examples made the difference. The stories grounded the risks in reality, and hearing the experience directly from an organization that has been through it created a level of trust that only a shared experience can bring.

Angie walked through a phishing incident that illustrated how one clicked link compromised an account, how the breach spread through a shared ownership structure, and what it took to rebuild trust with residents and families afterward. Another real-life story involved a significant ransom demand followed by substantial recovery costs. Sharing the proactive controls that were implemented afterward provided invaluable context.

The robust discussion led us to examine another, more recent mandate: OCR’s Risk Analysis Initiative, launched in October 2024. The enforcement history behind it was eye-opening. A prior federal audit found that only 14% of covered entities met their risk-analysis obligations. Risk analysis failures remain among the most cited issues under the HIPAA Security Rule.

As the audience’s questions quickly shifted toward prevention, the inevitable topic of AI surfaced, and attendees sought guidance on managing their staff who use unapproved tools to draft notes, resident communications, or family emails without leadership’s visibility. Acceptable-use policies and the distinction between enterprise and public AI tools gave attendees a practical starting point they could bring back to their teams.

Linking our knowledge with firsthand experiences not only provides value but also enriches those who work to make senior living communities more resilient.

John DiMaggio
Managing Director
BlueOrange Compliance

 

 

Bringing AI to our Security Risk Assessments

As artificial intelligence becomes more common across healthcare organizations, it’s introducing new security, governance, and operational risks.

To help clients address these emerging concerns, we are adding an AI-focused component to all Security Risk Assessments. This enhancement will evaluate how AI is being used across the organization, identify potential gaps, and provide practical recommendations as part of the existing SRA process—at no additional cost.

It’s another way we are continuing to expand the value of its assessments as the healthcare technology landscape evolves.

Stay tuned for more information coming soon.

Don’t wait until compliance deadlines or cyber incidents put your hospital at risk. Partner with BlueOrange Compliance for a HIPAA Security Risk Assessment that strengthens both compliance and patient safety. Learn more →


Consider Penetration Testing

You may be armed with firewalls, antivirus, and MFA, but are you confident that what you’ve done could prevent today’s sophisticated attackers from finding their way in? Are you able to document that your security controls are doing their job? CloudWave and BlueOrange’s Penetration Testing is a solid start. It can also provide actionable insight you can use to close security gaps, strengthen compliance, and protect patient care.

Learn more →


Become a Cybersecurity Insider

We’re excited to invite you to join our Cybersecurity Insider Program (CIP) — your exclusive gateway to the latest healthcare cybersecurity insights and resources.

Register today to get these exclusive benefits:

  • On-Demand Learning Library
  • Exclusive Member Offers
  • Early Access to Specialized Content
  • CIP Roundtables, Webinars, & Events

 


Events & Webinars

LeadingAge Annual Meeting  | October 25 – 28 | Philadelphia, PA | Convention Center, Learn more

📅 View All Events →


Product & Platform Updates

  • BlueOrange Compliance Elevates Cybersecurity with NIST CSF 2.0
    Healthcare organizations continue to face rising cyber threats, tighter regulatory scrutiny, and increasing operational pressure. In this environment, a strong, future-ready cybersecurity and compliance posture is essential. That’s why BlueOrange Compliance is proud to announce our transition to the NIST Cybersecurity Framework (CSF) 2.0, fully integrated with NIST SP 800-53 Rev. 5 and NIST SP 800-66 Rev. 2. This upgrade replaces our previous assessment approach rooted in 800-53 Rev. 4 and 800-66 Rev. 1, offering a more comprehensive, modernized, and aligned path to security and HIPAA compliance. Read More →
  • EDR Powered by SentinelOne: Simplify endpoint protection and visibility. Read More →

Resources & Insights

Thank you for being part of our BlueOrange Compliance customer community. We’re proud to support your mission to keep healthcare safe, connected, and resilient.

Stay tuned for next month’s issue!

– The BlueOrange Team