Business Associate Agreement (BAA)
What a BAA must contain, who needs one, and why most organisations have fewer valid ones than they think.
Read →Guides
Plain-language guides to every part of HIPAA, written by people who implement it.
What a BAA must contain, who needs one, and why most organisations have fewer valid ones than they think.
Read →The largest safeguard category and the source of most findings — nine standards and what each demands operationally.
Read →What an OCR investigation looks like, what gets requested first, and what a customer-driven audit demands instead.
Read →A working checklist organised by rule and safeguard category, with the required-versus-addressable distinction made explicit.
Read →When to hire one, what to ask before you sign, and the four answers that should end the conversation.
Read →Honest ranges for software, services, and internal effort — by organisation size, with the variables that move the number.
Read →A platform differs from a tool: it holds the whole program — controls, evidence, people, vendors, and the audit trail connecting them.
Read →The full service catalogue, what each one produces, and how to sequence them without paying for overlap.
Read →What HIPAA compliance software actually does, what it cannot do, and how to evaluate it without being sold a certificate.
Read →The six-year rule, what must be in writing, and what 'available to those responsible for implementation' means in practice.
Read →Security incident versus breach, the four-factor test, the 60-day clock, and the documentation you will wish you had kept.
Read →Facility access, workstation use and security, and device and media controls — including the fully remote workforce.
Read →The policy set the rule requires, what separates a usable policy from a template, and how to keep acknowledgement records that hold.
Read →Uses and disclosures, minimum necessary, patient rights, and the operational workflows each one demands.
Read →The precise regulatory term, what a defensible one contains, and the methodology choices that hold up under scrutiny.
Read →The risk assessment is the foundational requirement of the Security Rule and the first document OCR requests after an incident.
Read →A plain-language walk through 45 CFR Part 164 Subpart C — every standard, what it means operationally, and where teams fail it.
Read →Access control, audit controls, integrity, authentication, and transmission security — specification by specification.
Read →Free, editable starting points for every required document — plus a warning about what templates cannot do.
Read →Who must be trained, how often, what counts as a record, and why annual video completion is not enough on its own.
Read →Building a vendor program that survives an audit: inventory, tiering, BAAs, reviews, and offboarding.
Read →Eight HIPAA compliance tools compared honestly — depth of risk analysis, in-house services, independent reports, and pricing transparency.
Read →How HIPAA interacts with California's CMIA, the CCPA/CPRA medical-data carve-outs, and state breach notification rules — in plain terms.
Read →How Texas HB 300 and the Texas Medical Records Privacy Act extend HIPAA — broader covered entities, faster records access, mandatory training.
Read →How the NY SHIELD Act's reasonable safeguards and breach notification rules interact with HIPAA, and what New York organisations must add.
Read →How the Florida Information Protection Act layers a 30-day breach clock and per-record penalties on top of HIPAA, and what to build into your plan.
Read →The four penalty tiers with current ranges, notable OCR settlements, the violations that actually get cited, and state AG enforcement.
Read →Plain-language definitions of 45+ HIPAA terms — PHI, ePHI, BAA, minimum necessary, safe harbor, designated record set, and the rest.
Read →