
The New HIPAA Security Rule Is Delayed to 2027 — What Healthcare Orgs Should Do Now
HHS pushed the updated HIPAA Security Rule back to at least July 2027 after comments called it too costly. The 2013 rule still applies — here's what to do now.
I don't know why they call things "basic" when they are often hard to do. Musings on Cybersecurity, Information Technology, and other topics.
Subscribe:.rss.atom.json.md.m3u.pls
Live Last read · last published · next check

HHS pushed the updated HIPAA Security Rule back to at least July 2027 after comments called it too costly. The 2013 rule still applies — here's what to do now.

Fraudulent wire or compromised inbox? What to do in the first 24 hours of a business email compromise — the bank call, the evidence, and evicting the attacker

458 packages. 5 ship to production. The rest are attack surface.

A serverless pipeline that watches RSS feeds, summarizes new posts with an LLM, and emails subscribers, built entirely with Azure Logic Apps, Terraform, and no long-lived secrets.

Vulnerability management hinges on good architecture practices. AI-powered vulnerability discovery doesn't solve for this in any meaningful way.

The Vercel incident is a good reminder: do you actually control what OAuth apps can access your Google Workspace?

Textbook PyPI supply chain attack, now targeting AI infrastructure. Treat your LLM stack like any other production dependency.

Since the widespread adoption of the Internet in the 1990s, many internet providers and online companies have offered free email to anyone able to come up with a username.

Here are the slides and playbooks discussed in the BlueTeamCon presentation, "Easy Playbooks to Make Ransomware Criminals Cry" on August 28, 2022.
Presentation given at CypherCon, March 31, 2023

Have you ever felt that unsettling moment when you suspect your online accounts have been breached?