IRON RODSecurity

EMS Cybersecurity Insights & Resources

42 CFR Part 2 in the Field: Substance-Use Disorder Confidentiality That HIPAA Doesn’t Cover

Most EMS agencies know HIPAA cold. They train on it at orientation, build their ePCR workflows around it, audit for it. And then 42 CFR Part 2 walks in thr

42 cfr part 2ConsentSudRe disclosureCompliance

Crew Phones and Social Media at the Scene: A HIPAA Framework Built for Reality

A practical HIPAA framework for EMS agencies managing crew phone photos, social media posts, and scene documentation on personal devices. No blanket bans, just real workflows.

Social mediaPersonal devicesEMSPolicyDe identification

The Offboarding Gap That Leaves ePCR Access Open for Days

The gap between HR termination and ePCR access revocation in EMS agencies. How ImageTrend, ESO, and Zoll sessions stay alive and the same-day checklist that kills them.

Insider threatAccess revocationEsoImagetrendZoll

Beyond the Password: Moving EMS to Identity-Based Security

Shared passwords fail HIPAA requirements for unique user identification. WPA2-Enterprise and certificate-based authentication close the gap.

Shared passwordsCertificate based authenticationEMSMdmIdentity based security

MFA for the Ambulance: Why Just Use a YubiKey Isnt the Answer

YubiKeys, SMS codes, and authenticator apps fail in the field. Here is a layered MFA approach designed for the back of an ambulance.

AmbulanceMFACertificate based authenticationYubikeyEMS

PHI in Training Videos: The HIPAA Exposure Most Agencies Miss

Body-cam footage, QA clips, and training videos contain invisible PHI. Most agencies fail Safe Harbor. Here is a defensible workflow.

Body cameraExpert determinationTraining videosEMSSafe harbor

Vendor Risk Management for Small EMS Agencies Without a CISO

How to manage vendor risk for a small EMS agency without a CISO. A lean 80-20 approach focusing on the vendors that handle PHI and keep the trucks running.

BAAVendor riskThird party riskCisoEMS

The 60-Day Clock: HIPAA Breach When the Medic Loses the Phone

A lost phone with the ePCR app means the HIPAA 60-day clock starts immediately. MDM controls and encryption change the math.

EncryptionEMSMdmePCRBreach notification

Don't Click That Link: Email Phishing Targeting EMS Agencies for Payroll and Patient Data

EMS agencies are prime targets for phishing attacks targeting payroll and patient data. Here is how to stop them.

RansomwarePayrollEMSCADePCR

AI, HIPAA, and EMS ePCR Narrative Risk

Using personal AI accounts to draft EMS ePCR narratives creates HIPAA exposure, weak provenance, and patient record integrity risk that agencies need to stop now.

AIEMSePCRHIPAAPHI
EMS Cybersecurity Blog and Resources | Iron Rod Security