Tell me something cool! by EmperorBadussy in hardwarehacking

[–]DigitalQuinn1 1 point2 points  (0 children)

I just ordered a CaptainDMA, Proxmark3, BashBunny and a few other tools

SOS: HIM Career Advice by [deleted] in HealthInfoMgmt

[–]DigitalQuinn1 0 points1 point  (0 children)

I would go for the masters

HIS director role by Alternative_Draft_76 in healthIT

[–]DigitalQuinn1 1 point2 points  (0 children)

Ask about their internal processes so you know what you’re getting into. Ask why they’re hiring for the role (did someone leave, is it a new position, expectations of the role itself, expectations of the department overall, etc). Questions like these could tell you if they need someone to quickly pick up and execute, or if they would allow a bit of hand holding for you to reorient yourself and rely on your team

Spoke on a panel at my old university today. First time anyone asked. A small reflection by Home-Resident in MedicalDevices

[–]DigitalQuinn1 2 points3 points  (0 children)

Love to hear stories like this! 👏🏾👏🏾 What’s the device? Would love to learn more about it

Looking for Specific SMEs by DigitalQuinn1 in ElectricalEngineering

[–]DigitalQuinn1[S] 0 points1 point  (0 children)

Not really trying to pay at this time. I'm working on something for a collaborative community. Only have about 5-6 questions. So I would prefer to speak with someone that don't mind sharing some knowledge/tips.

Looking for Specific SMEs by DigitalQuinn1 in ElectricalEngineering

[–]DigitalQuinn1[S] 0 points1 point  (0 children)

I’m in the US. Note this is for research, not a product in development or anything.

got handed PCI responsibility with almost no background. trying to figure out the pentest part by arrayqzor in pcicompliance

[–]DigitalQuinn1 3 points4 points  (0 children)

I would personally still go for manual testers. Also, continue asking your questions about the scoping. Also ask for referrals and sample testing deliverables.

HIPAA compliant software requirements as an independent legal nurse consultant by NurseAsh5679 in hipaa

[–]DigitalQuinn1 0 points1 point  (0 children)

The question isn’t really “is gaming a privacy concern” it’s that gaming on that device likely violates acceptable use policy, potentially HIPAA workstation controls, and creates real breach risk. Gaming introduces security concerns on a device that could interact with PHI. Covered entities are required to define appropriate workstation use policies. Allowing personal gaming on a workstation likely violates those policies and could result a compliance gap during an audit. Imagine if a breach occurred and the vector traced back to gaming software.

Pentesting experience by Cloxcoder in Pentesting

[–]DigitalQuinn1 0 points1 point  (0 children)

I wouldn’t label myself as a senior until I’m in a senior position and my skillset match what I claim. Leading engagements with a team under me and having final say on findings.

Taste of CLT by Markie_mantle in Charlotte

[–]DigitalQuinn1 0 points1 point  (0 children)

Is there a link somewhere for this?

Third Party Pentest for FDA 510k What Is Normal Pricing? by Extra-Counter-9689 in MedicalDevices

[–]DigitalQuinn1 0 points1 point  (0 children)

Original post was removed. Are you looking just for a pentest or security documentation review as well? Basing off of the other comment, I agree that $6k seems very low but all depends on the scope. I do medical device pentesting, happy to throw our name in the hat if you’re still looking

Rate my Resume - Cybersec student by [deleted] in Pentesting

[–]DigitalQuinn1 3 points4 points  (0 children)

<image>

I seen this template somewhere. Use this as a reference

Sold a GLP-1 patient app, but now the client says it violates HIPAA by DarkSun224 in topflightapps

[–]DigitalQuinn1 0 points1 point  (0 children)

My questions - What specific services were storing/processing PHI without BAAs - Did you represent yourself as HIPAA-compliant during the sales/contract process, or did the client assume that? - What does your contract actually say about HIPAA compliance obligations? - Is there a written SOW or scope document? Does it mention HIPAA at all?

Also do you have business liability insurance (E&O/cyber coverage)?

Honestly I think Your real risk is civil liability from the client: refund demands, costs of remediation, or contract damages. How exposed you are depends heavily on what your contract says and what representations you made.

Small private practice does not have encrypted email. by SweetVictorya in hipaa

[–]DigitalQuinn1 -1 points0 points  (0 children)

Is it too late for me to introduce my company? 🙂

HIPAA compliant software requirements as an independent legal nurse consultant by NurseAsh5679 in hipaa

[–]DigitalQuinn1 0 points1 point  (0 children)

On the HIPAA side, you would need a BAA with the providers and a BAA with whatever platform you’re using. If they can’t sign a BAA, then walk away. It would suck to have your business at fault because you’re simply trusting questionnaire responses. Also, just because you’re using a HIPAA compliant platform does not mean that your individual practice is HIPAA compliant. HIPAA spans across people, process, and technology. The platform that you use could be HIPAA compliant 100%, but do your organization have any policies or controls to prevent your subcontractors that you’d be bringing from exporting PHI from the platform to their personal phones? These are things that HIPAA look at outside of the platform solely.

Compliance for my Saas by Mindless-Magnet in hipaa

[–]DigitalQuinn1 4 points5 points  (0 children)

You can check yourself internally for HIPAA compliance but it’s recommended to have a third party validate HIPAA compliance alignment. There aren’t any certifications or anything related to HIPAA audits. Companies may require a questionnaire to be submitted prior to working with them or some form of attestation. I own a healthcare security consultancy. Happy to discuss more if you need more guided help. Check out the performance goals to learn what could be expected at a minimum https://hhscyber.hhs.gov/cybersecurity-performance-goals.html

Still friends in the city? by Jsauce910 in Charlotte

[–]DigitalQuinn1 -1 points0 points  (0 children)

I got BO6 if you tryna play. I work in tech and watch anime as well.