<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>The Digital Strategikon — Byzantine Technologies</title><description>Strategic insights on healthcare IT, cybersecurity, HIPAA compliance, and resilient operations from the Byzantine Technologies team.</description><link>https://www.byztech.com/</link><language>en-us</language><copyright>© 2026 Byzantine Technologies LLC</copyright><atom:link href="https://www.byztech.com/rss.xml" rel="self" type="application/rss+xml"/><item><title>Device Code Phishing Is Bypassing MFA: What Small Practices Should Do</title><link>https://www.byztech.com/blog/device-code-phishing-mfa-bypass-healthcare/</link><guid isPermaLink="true">https://www.byztech.com/blog/device-code-phishing-mfa-bypass-healthcare/</guid><description>Device code phishing hijacks Microsoft 365 mailboxes without stealing a password — and standard MFA doesn&apos;t stop it. What it means for healthcare practices.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>HIPAA</category><category>MFA</category><category>Phishing</category><category>Microsoft 365</category><category>Healthcare</category><author>Byzantine Technologies</author></item><item><title>Vendor Risk Management for Small Healthcare Practices</title><link>https://www.byztech.com/blog/vendor-risk-management-small-healthcare-practices/</link><guid isPermaLink="true">https://www.byztech.com/blog/vendor-risk-management-small-healthcare-practices/</guid><description>Your patient data flows through dozens of outside companies. A practical way for a small practice to manage third-party and vendor risk on a real budget.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>HIPAA</category><category>Vendor Risk</category><category>BAA</category><category>Third-Party Risk</category><category>Healthcare</category><author>Byzantine Technologies</author></item><item><title>Beyond 3-2-1: Why Healthcare Practices Need a 3-2-1-1-0 Backup Strategy</title><link>https://www.byztech.com/blog/backup-strategy-3-2-1-1-0/</link><guid isPermaLink="true">https://www.byztech.com/blog/backup-strategy-3-2-1-1-0/</guid><description>The 3-2-1 rule was the gold standard for decades. Modern ransomware exposed its weakness. Here is why healthcare practices need to move to 3-2-1-1-0 — and how to know your backups will actually work when everything goes wrong.</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><category>Backup</category><category>Data Protection</category><category>Ransomware</category><category>Disaster Recovery</category><category>HIPAA</category><author>Byzantine Technologies</author></item><item><title>MFA for Healthcare: Where It Matters Most and Where Clinics Get It Wrong</title><link>https://www.byztech.com/blog/mfa-for-healthcare-where-it-matters/</link><guid isPermaLink="true">https://www.byztech.com/blog/mfa-for-healthcare-where-it-matters/</guid><description>Multi-factor authentication is the single highest-leverage security control a medical or dental practice can deploy. Here is where it matters most — and the gaps that quietly leave clinics exposed.</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><category>HIPAA</category><category>MFA</category><category>Passwordless</category><category>Healthcare</category><category>Security</category><author>Byzantine Technologies</author></item><item><title>Why Guest Wi-Fi Should Never Touch Your Clinical Network</title><link>https://www.byztech.com/blog/guest-wifi-should-never-touch-clinical-network/</link><guid isPermaLink="true">https://www.byztech.com/blog/guest-wifi-should-never-touch-clinical-network/</guid><description>A flat network is a quiet liability. Here is why network segmentation — keeping guest Wi-Fi, patient devices, IoT, and medical equipment away from clinical systems — is one of the most important architecture decisions a practice makes.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><category>Network Security</category><category>Segmentation</category><category>Healthcare</category><category>HIPAA</category><author>Byzantine Technologies</author></item><item><title>Cyber Insurance, HIPAA, and the New Baseline for Healthcare Security</title><link>https://www.byztech.com/blog/cyber-insurance-hipaa-new-baseline/</link><guid isPermaLink="true">https://www.byztech.com/blog/cyber-insurance-hipaa-new-baseline/</guid><description>Cyber insurers now expect MFA, EDR, tested backups, patching, incident response, and vendor oversight before they&apos;ll write a policy. The good news: those same controls map directly to HIPAA expectations.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>Cyber Insurance</category><category>HIPAA</category><category>Healthcare</category><category>Risk Management</category><author>Byzantine Technologies</author></item><item><title>HIPAA Security Rule 2026: What Small Medical and Dental Practices Need to Know Now</title><link>https://www.byztech.com/blog/hipaa-security-rule-2026-what-practices-need-to-know/</link><guid isPermaLink="true">https://www.byztech.com/blog/hipaa-security-rule-2026-what-practices-need-to-know/</guid><description>There are two layers to the HIPAA Security Rule landscape in 2026: the current enforceable rule and a proposed update from HHS. Here is a calm, practical breakdown of what&apos;s required today and what&apos;s coming.</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate><category>HIPAA</category><category>Compliance</category><category>Security Rule</category><category>Healthcare</category><author>Byzantine Technologies</author></item><item><title>Why Your HIPAA Risk Analysis Cannot Be a Checkbox Exercise</title><link>https://www.byztech.com/blog/risk-analysis-cannot-be-a-checkbox/</link><guid isPermaLink="true">https://www.byztech.com/blog/risk-analysis-cannot-be-a-checkbox/</guid><description>A HIPAA risk analysis is not a form to fill out once a year. It&apos;s a structured process of technical discovery, ePHI mapping, vulnerability assessment, and remediation tracking — and the difference matters when OCR comes asking.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><category>HIPAA</category><category>Risk Analysis</category><category>Compliance</category><category>Healthcare</category><author>Byzantine Technologies</author></item><item><title>Where Is Your ePHI? A Practical Guide to Asset Inventories and Network Maps</title><link>https://www.byztech.com/blog/where-is-your-ephi-asset-inventories-network-maps/</link><guid isPermaLink="true">https://www.byztech.com/blog/where-is-your-ephi-asset-inventories-network-maps/</guid><description>Most clinics dramatically underestimate how many systems touch protected health information. A current asset inventory and network map are the foundation of security — and an expected control under the proposed HIPAA rule.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>HIPAA</category><category>Asset Inventory</category><category>Network Map</category><category>Healthcare</category><author>Byzantine Technologies</author></item><item><title>The 72-Hour Recovery Conversation Every Healthcare Practice Should Have</title><link>https://www.byztech.com/blog/72-hour-recovery-conversation-healthcare/</link><guid isPermaLink="true">https://www.byztech.com/blog/72-hour-recovery-conversation-healthcare/</guid><description>If your systems went down right now, how would you still see patients? A practical look at downtime, backups, EHR access, phones, imaging, claims, prescriptions, and emergency-mode operations.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><category>Business Continuity</category><category>Disaster Recovery</category><category>Healthcare</category><category>HIPAA</category><author>Byzantine Technologies</author></item><item><title>Encryption at Rest and in Transit: What That Actually Means for a Doctor&apos;s Office</title><link>https://www.byztech.com/blog/encryption-at-rest-and-in-transit-doctors-office/</link><guid isPermaLink="true">https://www.byztech.com/blog/encryption-at-rest-and-in-transit-doctors-office/</guid><description>Encryption sounds technical, but for a practice it comes down to concrete questions about laptops, servers, email, backups, cloud storage, VPNs, and messaging. Here&apos;s what the terms actually mean for you.</description><pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate><category>Encryption</category><category>HIPAA</category><category>Healthcare</category><category>Security</category><author>Byzantine Technologies</author></item><item><title>HIPAA Incident Response: What Happens in the First 24 Hours Matters</title><link>https://www.byztech.com/blog/hipaa-incident-response-first-24-hours/</link><guid isPermaLink="true">https://www.byztech.com/blog/hipaa-incident-response-first-24-hours/</guid><description>When a security incident hits a practice, the first 24 hours shape everything that follows. A practical guide to reporting paths, containment, escalation, insurer notice, evidence handling, and keeping patient care going.</description><pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate><category>Incident Response</category><category>HIPAA</category><category>Healthcare</category><category>Security</category><author>Byzantine Technologies</author></item><item><title>Business Associates, BAAs, and MSPs: Who Is Responsible for What?</title><link>https://www.byztech.com/blog/business-associates-baas-msps-who-is-responsible/</link><guid isPermaLink="true">https://www.byztech.com/blog/business-associates-baas-msps-who-is-responsible/</guid><description>A signed Business Associate Agreement does not magically make a vendor secure. Here&apos;s what a BAA actually does, what it doesn&apos;t, and why your practice still needs real oversight and documentation.</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate><category>HIPAA</category><category>Business Associates</category><category>Vendor Management</category><category>Compliance</category><author>Byzantine Technologies</author></item><item><title>The Digital Strategikon: Origins and Historical Significance</title><link>https://www.byztech.com/blog/digital-strategikon-origins/</link><guid isPermaLink="true">https://www.byztech.com/blog/digital-strategikon-origins/</guid><description>How a 6th-century Byzantine military manual on defense-in-depth and layered fortification maps perfectly onto modern cybersecurity doctrine.</description><pubDate>Tue, 12 Aug 2025 00:00:00 GMT</pubDate><category>History</category><category>Strategy</category><category>Byzantine</category><author>Byzantine Technologies</author></item><item><title>Modern IT Operations: Best Practices for 2025</title><link>https://www.byztech.com/blog/modern-it-operations-best-practices/</link><guid isPermaLink="true">https://www.byztech.com/blog/modern-it-operations-best-practices/</guid><description>A practical framework for healthcare practices to manage IT operations in 2025 — monitoring, automation, patching, and building resilience without an enterprise budget.</description><pubDate>Mon, 30 Jun 2025 00:00:00 GMT</pubDate><category>IT Operations</category><category>Monitoring</category><category>Automation</category><author>Byzantine Technologies</author></item><item><title>HIPAA Compliance for Small Clinics: A Practical Guide</title><link>https://www.byztech.com/blog/hipaa-compliance-for-small-clinics/</link><guid isPermaLink="true">https://www.byztech.com/blog/hipaa-compliance-for-small-clinics/</guid><description>A plain-English breakdown of HIPAA&apos;s four rules, what they mean for small practices, and where to focus your compliance energy first.</description><pubDate>Sat, 14 Jun 2025 00:00:00 GMT</pubDate><category>HIPAA</category><category>Compliance</category><category>Healthcare</category><author>Byzantine Technologies</author></item><item><title>EDR vs. Traditional Antivirus: What Should Your Organization Choose?</title><link>https://www.byztech.com/blog/edr-vs-antivirus-what-to-choose/</link><guid isPermaLink="true">https://www.byztech.com/blog/edr-vs-antivirus-what-to-choose/</guid><description>Traditional antivirus catches known threats. EDR catches what antivirus misses. Here&apos;s what the difference means for a healthcare practice in 2025.</description><pubDate>Sat, 31 May 2025 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>EDR</category><category>Antivirus</category><author>Byzantine Technologies</author></item><item><title>Cost Optimization in Cloud and On-Premises IT: A Strategic Approach</title><link>https://www.byztech.com/blog/cost-optimization-in-cloud-and-on-prem/</link><guid isPermaLink="true">https://www.byztech.com/blog/cost-optimization-in-cloud-and-on-prem/</guid><description>Healthcare practices often overpay for IT infrastructure or underpay in ways that create risk. Here&apos;s how to find and close those gaps strategically.</description><pubDate>Wed, 14 May 2025 00:00:00 GMT</pubDate><category>Cost Optimization</category><category>Cloud</category><category>Infrastructure</category><author>Byzantine Technologies</author></item><item><title>VoIP Reliability and Call Quality: Engineering Excellence for Healthcare</title><link>https://www.byztech.com/blog/voip-reliability-and-call-quality/</link><guid isPermaLink="true">https://www.byztech.com/blog/voip-reliability-and-call-quality/</guid><description>Poor call quality in a healthcare practice isn&apos;t just an annoyance — it disrupts patient communication and erodes trust. Here&apos;s how to engineer VoIP that actually works.</description><pubDate>Wed, 30 Apr 2025 00:00:00 GMT</pubDate><category>VoIP</category><category>Healthcare</category><category>Communications</category><author>Byzantine Technologies</author></item><item><title>Security Awareness Training That Actually Works: Beyond Click-Through Compliance</title><link>https://www.byztech.com/blog/security-awareness-that-actually-works/</link><guid isPermaLink="true">https://www.byztech.com/blog/security-awareness-that-actually-works/</guid><description>Annual click-through training satisfies an auditor but doesn&apos;t change behavior. Here&apos;s what security awareness that actually reduces risk looks like in a healthcare practice.</description><pubDate>Mon, 14 Apr 2025 00:00:00 GMT</pubDate><category>Security Training</category><category>Cybersecurity</category><category>Human Factors</category><author>Byzantine Technologies</author></item><item><title>Building a Secure Remote Work Stack: Beyond VPN and Hope</title><link>https://www.byztech.com/blog/building-a-secure-remote-work-stack/</link><guid isPermaLink="true">https://www.byztech.com/blog/building-a-secure-remote-work-stack/</guid><description>A VPN alone doesn&apos;t make remote work secure. Here&apos;s how healthcare practices can build a remote access architecture that protects ePHI without destroying the user experience.</description><pubDate>Fri, 14 Mar 2025 00:00:00 GMT</pubDate><category>Remote Work</category><category>Security</category><category>VPN</category><author>Byzantine Technologies</author></item></channel></rss>