<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Iron Rod Security Blog</title>
    <description>Cybersecurity advisory built for EMS and Fire agencies. Protect operations, ensure compliance, and stay prepared for real-world cyber threats.</description>
    <link>https://www.ironrodsecurity.com/blog</link>
    <atom:link href="https://www.ironrodsecurity.com/feed.xml" rel="self" type="application/rss+xml"/>
    <lastBuildDate>Thu, 28 May 2026 00:30:30 GMT</lastBuildDate>
    <language>en-us</language>
    <item>
      <title>Public Records Security: What To Never Release</title>
      <description>A public safety security review: what records adversaries request, the statutory exemptions, and a review process every agency needs.</description>
      <link>https://www.ironrodsecurity.com/blog/public-records-security-what-to-never-release</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/public-records-security-what-to-never-release</guid>
      <pubDate>Wed, 27 May 2026 00:17:57 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Public Records</category>
      <category>Foia</category>
      <category>Cad Logs</category>
      <category>Operational Security</category>
      <category>Passive Reconnaissance</category>
      <category>Incident Response Plans</category>
    </item>
    <item>
      <title>Cyber Insurance for Small EMS and Volunteer Fire Services — The Clauses That Matter</title>
      <description>What the policy clauses, MFA warranties, ransomware sublimits, and IR panel restrictions actually mean for small EMS and volunteer fire departments.</description>
      <link>https://www.ironrodsecurity.com/blog/cyber-insurance-for-small-ems-and-volunteer-fire-services-the-clauses-that-matte</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/cyber-insurance-for-small-ems-and-volunteer-fire-services-the-clauses-that-matte</guid>
      <pubDate>Tue, 26 May 2026 00:16:17 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Cyber Insurance</category>
      <category>Mfa Warranty</category>
      <category>Ransomware Sublimit</category>
      <category>Incident Response Panel</category>
      <category>Ems Security</category>
      <category>Volunteer Fire Department</category>
    </item>
    <item>
      <title>The Offboarding Gap That Leaves ePCR Access Open for Days</title>
      <description>The gap between HR termination and ePCR access revocation in EMS agencies. How ImageTrend, ESO, and Zoll sessions stay alive and the same-day checklist that kills them.</description>
      <link>https://www.ironrodsecurity.com/blog/the-offboarding-gap-that-leaves-epcr-access-open-for-days</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/the-offboarding-gap-that-leaves-epcr-access-open-for-days</guid>
      <pubDate>Mon, 25 May 2026 01:12:23 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Epcr Offboarding</category>
      <category>Imagetrend</category>
      <category>Eso</category>
      <category>Zoll</category>
      <category>Hipaa</category>
      <category>Insider Threat</category>
    </item>
    <item>
      <title>BEC Against EMS Billing: The ACH Form That Costs Six Figures</title>
      <description>EMS agencies lose six figures to BEC attacks on billing staff. Here is how the ACH change form scam works and the dual-approval workflow that stops it.</description>
      <link>https://www.ironrodsecurity.com/blog/bec-against-ems-billing-the-ach-form-that-costs-six-figures</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/bec-against-ems-billing-the-ach-form-that-costs-six-figures</guid>
      <pubDate>Sun, 24 May 2026 00:12:48 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Business Email Compromise</category>
      <category>Ems Billing Security</category>
      <category>Ach Fraud Prevention</category>
      <category>Dual Approval Workflow</category>
      <category>Revenue Cycle Management Security</category>
      <category>Bec Healthcare</category>
    </item>
    <item>
      <title>Social Engineering the Dispatch Center: Attack Scenarios and Verification Protocols</title>
      <description>Three realistic social engineering attacks targeting public safety dispatch centers and the verification protocols that stop them.</description>
      <link>https://www.ironrodsecurity.com/blog/social-engineering-the-dispatch-center-attack-scenarios-and-verification-protoco</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/social-engineering-the-dispatch-center-attack-scenarios-and-verification-protoco</guid>
      <pubDate>Sat, 23 May 2026 00:10:06 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Dispatch Center Security</category>
      <category>Social Engineering</category>
      <category>Vishing</category>
      <category>Psap</category>
      <category>Public Safety</category>
      <category>Verification Protocols</category>
    </item>
    <item>
      <title>Retiring MDTs: NIST 800-88, True Wipes vs. Factory Reset, and HIPAA Audit Proof</title>
      <description>How NIST 800-88 applies to retiring EMS tablets, why factory resets leave PHI exposed, and the documentation needed for a HIPAA audit.</description>
      <link>https://www.ironrodsecurity.com/blog/retiring-mdts-nist-800-88-true-wipes-vs-factory-reset-and-hipaa-audit-proof</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/retiring-mdts-nist-800-88-true-wipes-vs-factory-reset-and-hipaa-audit-proof</guid>
      <pubDate>Fri, 22 May 2026 00:12:01 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Mdt Sanitization</category>
      <category>Nist 800 88</category>
      <category>Hipaa Compliance</category>
      <category>Epcr Data Security</category>
      <category>Chain Of Custody</category>
      <category>Ems Cybersecurity</category>
    </item>
    <item>
      <title>Pre-Plan Security: The PHI-Adjacent Data Most Fire Departments Leave Unlocked</title>
      <description>Alarm codes, Knox box combinations, occupant medical conditions, and hazmat locations live in your pre-plan system with weaker access controls than your ePCR. Here is the fix.</description>
      <link>https://www.ironrodsecurity.com/blog/pre-plan-security-the-phi-adjacent-data-most-fire-departments-leave-unlocked</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/pre-plan-security-the-phi-adjacent-data-most-fire-departments-leave-unlocked</guid>
      <pubDate>Thu, 21 May 2026 00:16:04 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Pre Plan Security</category>
      <category>Knox Box</category>
      <category>Phi</category>
      <category>Fire Department</category>
      <category>Access Control</category>
      <category>Mfa</category>
    </item>
    <item>
      <title>The Texting Problem: When SMS Between Crews Becomes a HIPAA Issue</title>
      <description>When does SMS between EMS crews cross from operational chatter into a HIPAA violation? Direct guidance on OCR rules, secure messaging policy, and what a defensible mobile policy looks like.</description>
      <link>https://www.ironrodsecurity.com/blog/the-texting-problem-when-sms-between-crews-becomes-a-hipaa-issue</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/the-texting-problem-when-sms-between-crews-becomes-a-hipaa-issue</guid>
      <pubDate>Wed, 20 May 2026 00:14:44 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Sms Hipaa Violation</category>
      <category>Hipaa Compliant Messaging Ems</category>
      <category>Mobile Messaging Policy Fire Department</category>
      <category>Ocr Sms Guidance</category>
      <category>Operational Chatter Phi</category>
    </item>
    <item>
      <title>NEMSIS Data Submission and PHI Exposure — What Your Vendor Sends and Why You Should Verify It</title>
      <description>Your ePCR vendor transmits full PHI through the NEMSIS V3 pipeline. The narrative field is an unguarded re-identification risk most agencies never audit. Here is how to validate the payload.</description>
      <link>https://www.ironrodsecurity.com/blog/nemsis-data-submission-and-phi-exposure-what-your-vendor-sends-and-why-you-shoul</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/nemsis-data-submission-and-phi-exposure-what-your-vendor-sends-and-why-you-shoul</guid>
      <pubDate>Tue, 19 May 2026 00:45:25 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Nemsis V3</category>
      <category>Phi Exposure</category>
      <category>Epcr Security</category>
      <category>Ems Data</category>
      <category>Hipaa Compliance</category>
      <category>Re Identification Risk</category>
    </item>
    <item>
      <title>The HIPAA Risk Analysis That Holds Up Under OCR Review</title>
      <description>OCR expects a risk analysis that maps threats to vulnerabilities, not a generic compliance checklist. Here is what 45 CFR 164.308(a)(1)(ii)(A) actually requires and how to build it for your EMS agency.</description>
      <link>https://www.ironrodsecurity.com/blog/the-hipaa-risk-analysis-that-holds-up-under-ocr-review</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/the-hipaa-risk-analysis-that-holds-up-under-ocr-review</guid>
      <pubDate>Mon, 18 May 2026 22:20:06 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Hipaa Risk Analysis</category>
      <category>Ocr Review</category>
      <category>45 Cfr 164 308</category>
      <category>Ems Security</category>
      <category>Ephi</category>
      <category>Compliance</category>
    </item>
    <item>
      <title>Building an Incident Response Plan That Survives Contact With a Real EMS Cyber Incident</title>
      <description>Generic IT incident response plans fail in EMS. Build a plan that accounts for clinical continuity, dispatch, NEMSIS, and the 2 a.m. runbook.</description>
      <link>https://www.ironrodsecurity.com/blog/building-an-incident-response-plan-that-survives-contact-with-a-real-ems-cyber-i</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/building-an-incident-response-plan-that-survives-contact-with-a-real-ems-cyber-i</guid>
      <pubDate>Wed, 13 May 2026 00:18:06 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Incident Response</category>
      <category>Ransomware</category>
      <category>Ems</category>
      <category>Clinical Continuity</category>
      <category>Nemsis</category>
      <category>Runbook</category>
    </item>
    <item>
      <title>Beyond the Password: Moving EMS to Identity-Based Security</title>
      <description>Shared passwords fail HIPAA requirements for unique user identification. WPA2-Enterprise and certificate-based authentication close the gap.</description>
      <link>https://www.ironrodsecurity.com/blog/beyond-the-password-moving-ems-to-identity-based-security</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/beyond-the-password-moving-ems-to-identity-based-security</guid>
      <pubDate>Tue, 12 May 2026 00:14:08 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Wpa2 Enterprise</category>
      <category>Certificate Based Authentication</category>
      <category>Ems</category>
      <category>Hipaa</category>
      <category>Shared Passwords</category>
      <category>Mdm</category>
    </item>
    <item>
      <title>MFA for the Ambulance: Why Just Use a YubiKey Isnt the Answer</title>
      <description>YubiKeys, SMS codes, and authenticator apps fail in the field. Here is a layered MFA approach designed for the back of an ambulance.</description>
      <link>https://www.ironrodsecurity.com/blog/mfa-for-the-ambulance-why-just-use-a-yubikey-isnt-the-answer</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/mfa-for-the-ambulance-why-just-use-a-yubikey-isnt-the-answer</guid>
      <pubDate>Mon, 11 May 2026 01:23:32 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Mfa</category>
      <category>Authentication</category>
      <category>Ems</category>
      <category>Hipaa</category>
      <category>Yubikey</category>
      <category>Biometrics</category>
    </item>
    <item>
      <title>PHI in Training Videos: The HIPAA Exposure Most Agencies Miss</title>
      <description>Body-cam footage, QA clips, and training videos contain invisible PHI. Most agencies fail Safe Harbor. Here is a defensible workflow.</description>
      <link>https://www.ironrodsecurity.com/blog/phi-in-training-videos-the-hipaa-exposure-most-agencies-miss</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/phi-in-training-videos-the-hipaa-exposure-most-agencies-miss</guid>
      <pubDate>Sun, 10 May 2026 00:15:48 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Hipaa</category>
      <category>Phi</category>
      <category>Body Camera</category>
      <category>Training Videos</category>
      <category>De Identification</category>
      <category>Safe Harbor</category>
    </item>
    <item>
      <title>Vendor Risk Management for Small EMS Agencies Without a CISO</title>
      <description>How to manage vendor risk for a small EMS agency without a CISO. A lean 80-20 approach focusing on the vendors that handle PHI and keep the trucks running.</description>
      <link>https://www.ironrodsecurity.com/blog/vendor-risk-management-for-small-ems-agencies-without-a-ciso</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/vendor-risk-management-for-small-ems-agencies-without-a-ciso</guid>
      <pubDate>Sat, 09 May 2026 01:04:03 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Vendor Risk</category>
      <category>Ems</category>
      <category>Hipaa</category>
      <category>Baa</category>
      <category>Ciso</category>
      <category>Third Party Risk</category>
    </item>
    <item>
      <title>When the Ambulance Is the Endpoint: Zero Trust for the Rig</title>
      <description>An ambulance is a mobile data center. Here is how to apply zero trust principles to secure the modem, tablet, monitor, and camera without breaking clinical workflow.</description>
      <link>https://www.ironrodsecurity.com/blog/when-the-ambulance-is-the-endpoint-zero-trust-for-the-rig</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/when-the-ambulance-is-the-endpoint-zero-trust-for-the-rig</guid>
      <pubDate>Fri, 08 May 2026 00:29:41 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Zero Trust</category>
      <category>Ambulance</category>
      <category>Ems</category>
      <category>Epcr</category>
      <category>Network Security</category>
      <category>Micro Segmentation</category>
    </item>
    <item>
      <title>Scaling 100 Trucks: Automation Strategies for Fire and EMS IT</title>
      <description>How to deploy and manage 100 connected EMS vehicles using cloud management consoles, variable-driven templates, and MDM without manual per-truck setup.</description>
      <link>https://www.ironrodsecurity.com/blog/scaling-100-trucks-automation-strategies-for-fire-and-ems-it</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/scaling-100-trucks-automation-strategies-for-fire-and-ems-it</guid>
      <pubDate>Thu, 07 May 2026 00:13:17 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Cradlepoint</category>
      <category>Sierra Wireless</category>
      <category>Mdm</category>
      <category>Firstnet</category>
      <category>Zero Touch Provisioning</category>
      <category>Fleet Automation</category>
    </item>
    <item>
      <title>The cPanel Bug That Compromised Thousands of Sites and Why Your Agency Should Care</title>
      <description>CVE-2026-41940 in cPanel has compromised thousands of servers. Here is why your fire or EMS agency needs to check its hosting provider and what to ask.</description>
      <link>https://www.ironrodsecurity.com/blog/the-cpanel-bug-that-compromised-thousands-of-sites-and-why-your-agency-should-care</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/the-cpanel-bug-that-compromised-thousands-of-sites-and-why-your-agency-should-care</guid>
      <pubDate>Wed, 06 May 2026 00:27:46 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Fire Department</category>
      <category>Ransomware</category>
      <category>Cve 2026 41940</category>
      <category>Web Security</category>
      <category>Ems</category>
      <category>Hosting</category>
    </item>
    <item>
      <title>Ransomware Hit the Hospital: The EMS Dependency Map Nobody Draws</title>
      <description>When ransomware hits a hospital, EMS operations take a direct hit too. Here is the dependency map most agencies have not drawn and what to do about it.</description>
      <link>https://www.ironrodsecurity.com/blog/ransomware-hit-the-hospital-the-ems-dependency-map-nobody-draws</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/ransomware-hit-the-hospital-the-ems-dependency-map-nobody-draws</guid>
      <pubDate>Tue, 05 May 2026 00:54:02 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Ransomware</category>
      <category>Hospital</category>
      <category>Ems</category>
      <category>Epcr</category>
      <category>Ed Notification</category>
      <category>Bed Status</category>
    </item>
    <item>
      <title>The 60-Day Clock: HIPAA Breach When the Medic Loses the Phone</title>
      <description>A lost phone with the ePCR app means the HIPAA 60-day clock starts immediately. MDM controls and encryption change the math.</description>
      <link>https://www.ironrodsecurity.com/blog/the-60-day-clock-hipaa-breach-when-the-medic-loses-the-phone</link>
      <guid isPermaLink="true">https://www.ironrodsecurity.com/blog/the-60-day-clock-hipaa-breach-when-the-medic-loses-the-phone</guid>
      <pubDate>Mon, 04 May 2026 00:47:41 GMT</pubDate>
      <author>Steven Carlson</author>
      <category>Hipaa</category>
      <category>Breach Notification</category>
      <category>Epcr</category>
      <category>Mdm</category>
      <category>Encryption</category>
      <category>Ems</category>
    </item>
  </channel>
</rss>