LakeRidge Blog

HIPAA

Practical guidance on HIPAA privacy and security rule safeguards for covered entities and business associates.

Need help putting this into practice? See our HIPAA compliance services or the HIPAA handbook.

What Vendor Policies Should a Dental Office Review in Microsoft 365?

HIPAA ·Jul 2026

What Vendor Policies Should a Dental Office Review in Microsoft 365?

Use this Microsoft 365 vendor policy review checklist for dental offices to tier vendors, collect evidence, and document HIPAA due diligence.

What Google Cloud KPIs Show Health Plan Data Is Protected?

HIPAA ·Jul 2026

What Google Cloud KPIs Show Health Plan Data Is Protected?

Use google cloud kpis for health plan data protection to prove encryption, access, backups, monitoring, and incident reporting are working.

What Clauses Require Subcontractors to Secure ePHI Workstations?

HIPAA ·Jul 2026

What Clauses Require Subcontractors to Secure ePHI Workstations?

Use subcontractor contract clauses for ePHI workstations to require HIPAA-aligned use rules, physical safeguards, evidence, audit access, and termination.

What Caused the Shared Chromebook ePHI Incident? Postmortem

HIPAA ·Jul 2026

What Caused the Shared Chromebook ePHI Incident? Postmortem

This shared Chromebook ePHI incident postmortem explains how an unsecured signed-in session exposed patient data and how to prevent recurrence.

What Audit Log KPIs Should a Compliance Officer Report Monthly?

HIPAA ·Jul 2026

What Audit Log KPIs Should a Compliance Officer Report Monthly?

Use an audit log kpis monthly compliance report to show HIPAA log coverage, review completion, alert response, retention, and control gaps.

What Are Physical Access Requirements for Google Workspace Devices?

HIPAA ·Jul 2026

What Are Physical Access Requirements for Google Workspace Devices?

Learn hipaa physical access requirements google workspace devices: protect offices, endpoints, visitors, and emergency access under HIPAA.

What Are HIPAA Device and Media Control Requirements in Microsoft 365?

HIPAA ·Jul 2026

What Are HIPAA Device and Media Control Requirements in Microsoft 365?

HIPAA device and media control requirements Microsoft 365: govern ePHI devices, removal, disposal, reuse, movement records, and backups.

What Are Audit Log Requirements for Patient Records? (164.312(b))

HIPAA ·Jul 2026

What Are Audit Log Requirements for Patient Records? (164.312(b))

Understand audit log requirements for patient records under HIPAA 164.312(b), including what to log, who is covered, and practical evidence of compliance.

The Ultimate Guide to Email TLS for Patient Data

HIPAA ·Jul 2026

The Ultimate Guide to Email TLS for Patient Data

This email TLS for patient data ultimate guide explains HIPAA transmission security, implementation evidence, a testing checklist, and audit FAQs.

Single Breach vs Pattern: Which Triggers a Vendor Cure Plan?

HIPAA ·Jul 2026

Single Breach vs Pattern: Which Triggers a Vendor Cure Plan?

Single breach vs pattern vendor cure plan: HIPAA requires action when a known pattern creates material vendor contract violations.

How to Set Up Continuous Microsoft 365 Security Alerts

HIPAA ·Jul 2026

How to Set Up Continuous Microsoft 365 Security Alerts

Learn how to set up continuous microsoft 365 security alerts with prioritized telemetry, Sentinel queries, tuning, and incident response workflows.

How to Require HTTPS for PHI in Azure App Service in 30 Minutes

HIPAA ·Jul 2026

How to Require HTTPS for PHI in Azure App Service in 30 Minutes

Learn to require https for phi azure app service with HTTPS Only, TLS 1.2, validation, and HIPAA evidence in 30 minutes.

How to Move Shared Clinic PCs to Badge Login in 30 Days

HIPAA ·Jul 2026

How to Move Shared Clinic PCs to Badge Login in 30 Days

Run a hipaa shared clinic pc badge login migration in 30 days with a phased plan, rollback controls, and evidence for HIPAA workstation security.

How to Move From Untracked USBs to a Check-Out Log

HIPAA ·Jul 2026

How to Move From Untracked USBs to a Check-Out Log

Learn how to move from untracked USBs to a check-out log with a phased HIPAA-ready process for inventory, custody, encryption, and validation.

How to Add ePHI Safeguards to Plan Documents in 60 Minutes

HIPAA ·Jul 2026

How to Add ePHI Safeguards to Plan Documents in 60 Minutes

Use a focused amendment package to add ephi safeguards to group health plan documents and create assessment-ready evidence in 60 minutes.

7 SharePoint HIPAA Documentation Mistakes to Avoid

HIPAA ·Jul 2026

7 SharePoint HIPAA Documentation Mistakes to Avoid

Avoid hipaa documentation mistakes sharepoint teams make: retain, secure, update, and make HIPAA records available for six years.

What Written Policies Does a Healthcare Team Need in 4 Hours?

HIPAA ·Jul 2026

What Written Policies Does a Healthcare Team Need in 4 Hours?

Use this healthcare written policy requirements quick start to create, approve, store, and assign HIPAA documentation in four hours.

What Should a Board See in a Microsoft 365 Device Report?

HIPAA ·Jul 2026

What Should a Board See in a Microsoft 365 Device Report?

A microsoft 365 device control board report shows device custody, data-removal, backup, and exception risk under HIPAA.

What Is the Workstation Security Migration Plan for EHR Clinics?

HIPAA ·Jul 2026

What Is the Workstation Security Migration Plan for EHR Clinics?

A workstation security migration plan for ehr clinics moves devices to authorized-only EHR access with staged safeguards, testing, and evidence.

What Is the ROI of Security Policy Software for a 10-Person Clinic?

HIPAA ·Jul 2026

What Is the ROI of Security Policy Software for a 10-Person Clinic?

Calculate the roi of security policy software for a 10 person clinic by comparing subscription, labor, training, audit costs, and avoided risk.

What Is a Policy Documentation Maturity Rubric for SharePoint?

HIPAA ·Jul 2026

What Is a Policy Documentation Maturity Rubric for SharePoint?

A policy documentation maturity rubric SharePoint teams can use to score, evidence, and improve HIPAA policy governance from ad hoc to optimized.

What Is a HIPAA Workstation Tabletop Exercise for Front Desks?

HIPAA ·Jul 2026

What Is a HIPAA Workstation Tabletop Exercise for Front Desks?

A hipaa workstation tabletop exercise for front desks tests how staff protect ePHI when privacy, visitors, and interruptions collide.

What Google Cloud Evidence Proves a Vendor Breach Was Cured?

HIPAA ·Jul 2026

What Google Cloud Evidence Proves a Vendor Breach Was Cured?

Business associate breach cure evidence google cloud: collect dated, immutable proof that a vendor remediated a material HIPAA contract violation.

What Evidence Proves a Business Associate Breach Was Escalated?

HIPAA ·Jul 2026

What Evidence Proves a Business Associate Breach Was Escalated?

Business associate breach escalation evidence includes dated notices, receipt records, investigation decisions, cure actions, and retained Microsoft 365 audit logs.

What Does Facility Access Control Mean for AWS Dental Offices?

HIPAA ·Jul 2026

What Does Facility Access Control Mean for AWS Dental Offices?

Learn what facility access control aws dental office means under HIPAA, who must follow it, and the records an assessor expects to see.

What BAA Clauses Protect EHR Records From Improper Changes?

HIPAA ·Jul 2026

What BAA Clauses Protect EHR Records From Improper Changes?

See which baa clauses protect ehr records from improper changes, including flow-down, audit, and termination language for HIPAA vendors.

What Are Written Policy Requirements for Compliance Teams?

HIPAA ·Jul 2026

What Are Written Policy Requirements for Compliance Teams?

Learn the written policy requirements for compliance teams under HIPAA: document Security Rule policies, records, access, reviews, and retention.

What Are Server Room Access Requirements for Healthcare Offices?

HIPAA ·Jul 2026

What Are Server Room Access Requirements for Healthcare Offices?

Learn the server room access requirements for healthcare offices, including HIPAA roles, visitors, emergency entry, logs, and maintenance records.

What Are EHR Audit Log Requirements Under HIPAA?

HIPAA ·Jul 2026

What Are EHR Audit Log Requirements Under HIPAA?

HIPAA EHR audit log requirements require organizations to record and examine activity in systems that create, receive, maintain, or transmit ePHI.

What Are Business Associate Breach Requirements in Azure?

HIPAA ·Jul 2026

What Are Business Associate Breach Requirements in Azure?

hipaa business associate breach requirements azure require contracts, incident reporting, cure actions, and termination or HHS reporting for material violations.

The Ultimate Guide to EHR User Authentication: Checklist & FAQ

HIPAA ·Jul 2026

The Ultimate Guide to EHR User Authentication: Checklist & FAQ

This hipaa ehr user authentication guide explains how to verify EHR users, deploy MFA, document evidence, and pass a HIPAA review.

Jira Service Management vs ServiceNow: Pricing by Clinic Size

HIPAA ·Jul 2026

Jira Service Management vs ServiceNow: Pricing by Clinic Size

Compare hipaa incident management software pricing jira servicenow by clinic size: Jira fits lean teams; ServiceNow fits governed enterprises.

Intune vs JumpCloud: HIPAA PC Pricing Tiers by Clinic Size

HIPAA ·Jul 2026

Intune vs JumpCloud: HIPAA PC Pricing Tiers by Clinic Size

Compare intune vs jumpcloud hipaa workstation pricing by clinic size, including practical tiers, tradeoffs, and policy evidence needs.

How to Set Google Drive Sharing Settings for Plan ePHI

HIPAA ·Jul 2026

How to Set Google Drive Sharing Settings for Plan ePHI

Configure google drive sharing settings for plan ephi with a restricted Workspace unit, no external sharing, audit evidence, and access controls.

How to Set Azure RBAC Roles in Access Control (IAM)

HIPAA ·Jul 2026

How to Set Azure RBAC Roles in Access Control (IAM)

Learn how to set azure rbac roles in access control iam with least-privilege group assignments, verification, and HIPAA-ready evidence.

How to Run a Written Policy Tabletop Exercise in 90 Minutes

HIPAA ·Jul 2026

How to Run a Written Policy Tabletop Exercise in 90 Minutes

Use this written policy tabletop exercise facilitator guide to test policy access, retention, updates, and evidence capture in 90 minutes.

How to Report Policy Records to the Board Each Quarter

HIPAA ·Jul 2026

How to Report Policy Records to the Board Each Quarter

Learn to report policy documentation to board quarterly with clear risk, retention, access, and change metrics that support HIPAA oversight.

Cloud Entra ID vs On-Prem AD for Patient Data Access

HIPAA ·Jul 2026

Cloud Entra ID vs On-Prem AD for Patient Data Access

Choose cloud entra id vs on-prem active directory patient data access based on EHR, devices, and off-site needs while documenting HIPAA authorization.

Backup vs Disaster Recovery: You Need Both for Patient Records

HIPAA ·Jul 2026

Backup vs Disaster Recovery: You Need Both for Patient Records

Backup vs disaster recovery patient records: HIPAA requires retrievable copies, procedures to restore lost data, and plans to protect care operations.

7 Steps to Move a Noncompliant Vendor Contract to Compliance

HIPAA ·Jul 2026

7 Steps to Move a Noncompliant Vendor Contract to Compliance

Use noncompliant vendor contract compliance steps to cure BAA gaps, validate safeguards, preserve leverage, and document HIPAA-ready vendor oversight.

Which ISO 27001 Controls Match HIPAA Laptop Inventory?

HIPAA ·Jul 2026

Which ISO 27001 Controls Match HIPAA Laptop Inventory?

Map iso 27001 controls for hipaa laptop inventory to HIPAA, SOC 2, and NIST CSF with evidence that reduces duplicate audit work.

What Security Policies Does a Dental Office Need First? (2 Hours)

HIPAA ·Jul 2026

What Security Policies Does a Dental Office Need First? (2 Hours)

Use this dental office security policies checklist to document the first HIPAA Security Rule policies in two focused hours.

What KPIs Track PHI Device Movement in a Clinic?

HIPAA ·Jul 2026

What KPIs Track PHI Device Movement in a Clinic?

Use kpis for tracking PHI device movement in a clinic to prove documented custody, backup, secure reuse, and disposal during an EHR migration.

What Is Your Business Associate Breach Maturity Score?

HIPAA ·Jul 2026

What Is Your Business Associate Breach Maturity Score?

Use a business associate breach maturity assessment to score oversight from ad hoc contracts to optimized detection, cure, and termination decisions.

What Is EHR Access Control? The Ultimate HIPAA Guide

HIPAA ·Jul 2026

What Is EHR Access Control? The Ultimate HIPAA Guide

A hipaa ehr access control ultimate guide for limiting EHR access, documenting safeguards, and funding HIPAA-ready workflows.

What Is a Security Official in Google Workspace?

HIPAA ·Jul 2026

What Is a Security Official in Google Workspace?

Learn what is a security official in google workspace and how a healthcare practice can document HIPAA Security Rule accountability.

What Is a Business Associate Agreement for a Cloud Backup Vendor?

HIPAA ·Jul 2026

What Is a Business Associate Agreement for a Cloud Backup Vendor?

Learn when a business associate agreement cloud backup vendor is required, what HIPAA terms it needs, and what proof buyers expect.

What Evidence Do Auditors Need From SharePoint Version History?

HIPAA ·Jul 2026

What Evidence Do Auditors Need From SharePoint Version History?

SharePoint version history audit evidence shows auditors who changed ePHI, when prior copies were preserved, and how integrity controls are tested.

What Does Workstation Security Cost Per Clinic?

HIPAA ·Jul 2026

What Does Workstation Security Cost Per Clinic?

The workstation security cost per clinic typically runs $500–$1,100 per worker in year one; see a 50-person budget, ROI, and breakeven math.

What Clauses Require Annual Subcontractor Security Reviews?

HIPAA ·Jul 2026

What Clauses Require Annual Subcontractor Security Reviews?

Use a hipaa annual subcontractor security review clause to require documented yearly reviews, evidence, audit access, and remediation rights.

What Are the Minimum Identity Checks for Health Records? 2-Hour Baseline

HIPAA ·Jul 2026

What Are the Minimum Identity Checks for Health Records? 2-Hour Baseline

Establish minimum identity checks for health records in two hours with HIPAA §164.312(d) evidence an auditor can test.

What Are Patient Data Email Requirements in Microsoft 365?

HIPAA ·Jul 2026

What Are Patient Data Email Requirements in Microsoft 365?

Understand hipaa email requirements microsoft 365: secure patient data in transit, apply encryption when appropriate, and document safeguards.

Using Terraform to Enable S3 Versioning for HIPAA Integrity

HIPAA ·Jul 2026

Using Terraform to Enable S3 Versioning for HIPAA Integrity

terraform s3 versioning hipaa integrity helps preserve recoverable ePHI copies and detect improper deletion through repeatable infrastructure controls.

The Ultimate Guide to ePHI Workstation Security (164.310(c))

HIPAA ·Jul 2026

The Ultimate Guide to ePHI Workstation Security (164.310(c))

Understand hipaa workstation security requirements under 164.310(c), with remote-work safeguards, implementation steps, a checklist, and FAQs.

OneTrust vs LogicGate for vendor breaches: pricing tiers & size fit

HIPAA ·Jul 2026

OneTrust vs LogicGate for vendor breaches: pricing tiers & size fit

Compare onetrust vs logicgate vendor breach pricing tiers, size fit, and evidence workflows for HIPAA business-associate breach response.

How to Set ChromeOS Screen Lock: Devices > Chrome > Settings

HIPAA ·Jul 2026

How to Set ChromeOS Screen Lock: Devices > Chrome > Settings

Learn how to set ChromeOS screen lock Google Admin console settings to require timely locking and password-protected access on managed devices.

How to Run a Tabletop Exercise for a Stolen EHR Badge

HIPAA ·Jul 2026

How to Run a Tabletop Exercise for a Stolen EHR Badge

Run a stolen EHR badge tabletop exercise to test identity verification, revoke access, preserve evidence, and improve HIPAA response decisions.

How to Report Google Workspace Policy Changes to Your Board

HIPAA ·Jul 2026

How to Report Google Workspace Policy Changes to Your Board

Learn how to report Google Workspace policy changes to board members with clear risk, trend, and compliance evidence.

How to Fix Shared Dentrix Logins After an Audit Finding

HIPAA ·Jul 2026

How to Fix Shared Dentrix Logins After an Audit Finding

Learn how to fix shared Dentrix logins audit finding with unique accounts, access cleanup, evidence, and repeatable HIPAA controls.

How to Fix Overbroad Google Cloud IAM Roles After an Audit

HIPAA ·Jul 2026

How to Fix Overbroad Google Cloud IAM Roles After an Audit

Learn how to fix overbroad google cloud iam roles audit finding with scoped replacements, validation evidence, and repeatable review controls.

EHR Login Verification Policy Template: 7 Clauses Explained

HIPAA ·Jul 2026

EHR Login Verification Policy Template: 7 Clauses Explained

Use this ehr login verification policy template to document seven HIPAA-aligned clauses for verifying every EHR user and entity.

Do 5-Person Clinics Need a Security Policy Binder?

HIPAA ·Jul 2026

Do 5-Person Clinics Need a Security Policy Binder?

Do 5-person clinics need a security policy binder? Yes—but it should be a practical, documented set of HIPAA policies, not a generic manual.

7 Microsoft 365 Audit Log Mistakes and How to Avoid Them

HIPAA ·Jul 2026

7 Microsoft 365 Audit Log Mistakes and How to Avoid Them

Avoid microsoft 365 audit log mistakes by enabling complete logging, retaining evidence, reviewing alerts, and documenting audit controls.

7 Group Health Plan Document Mistakes With Sponsor ePHI

HIPAA ·Jul 2026

7 Group Health Plan Document Mistakes With Sponsor ePHI

Avoid group health plan document mistakes sponsor ePHI: seven fixes for sponsor access, safeguards, vendors, and incident reporting.

What Should an EHR Access Control Policy Template Include?

HIPAA ·Jul 2026

What Should an EHR Access Control Policy Template Include?

An ehr access control policy template should define who receives EHR access, how it is approved, reviewed, removed, and audited under HIPAA.

What Questions Belong in a Business Associate RFP Template?

HIPAA ·Jul 2026

What Questions Belong in a Business Associate RFP Template?

Use business associate rfp template questions to assess safeguards, subcontractors, incident response, and contract readiness before vendor selection.

What HIPAA Documents Should You Collect From SharePoint?

HIPAA ·Jul 2026

What HIPAA Documents Should You Collect From SharePoint?

Collect hipaa audit documents sharepoint evidence for policies, risk actions, access reviews, training, change records, and retention proof.

What Are Plan Sponsor Safeguard Requirements for Azure EPHI?

HIPAA ·Jul 2026

What Are Plan Sponsor Safeguard Requirements for Azure EPHI?

Understand plan sponsor safeguard requirements for Azure EPHI: plan document duties, separation, Azure evidence, and incident reporting.

Using PowerShell to Track Business Associate Cure Deadlines

HIPAA ·Jul 2026

Using PowerShell to Track Business Associate Cure Deadlines

Build a powershell business associate cure deadline tracker that calculates cure dates, flags escalation windows, and preserves review evidence.

Splunk vs Datadog for HIPAA Audit Logs: 200-User Pricing

HIPAA ·Jul 2026

Splunk vs Datadog for HIPAA Audit Logs: 200-User Pricing

Compare splunk vs datadog hipaa audit log pricing for a 200-user firm, including cost drivers, retention, BAA fit, and alternatives.

How to Set an Intune Auto-Lock Timer for Clinic PCs

HIPAA ·Jul 2026

How to Set an Intune Auto-Lock Timer for Clinic PCs

Set a 5-minute intune device lock auto-lock timer clinic pcs policy in Microsoft Intune and document HIPAA-ready proof of enforcement.

How to Fix a Missing EPHI Clause After a Plan Audit

HIPAA ·Jul 2026

How to Fix a Missing EPHI Clause After a Plan Audit

Learn how to fix missing ephi clause after plan audit with a targeted plan amendment, evidence file, and HIPAA control validation.

How to Build a Nurse Workstation Training Plan for ePHI

HIPAA ·Jul 2026

How to Build a Nurse Workstation Training Plan for ePHI

Build a hipaa nurse workstation training plan with role-based lessons, practical checks, and audit-ready evidence for ePHI workstation use.

Business Associate Breach vs Violation: Cure Breaches, End Violations

HIPAA ·Jul 2026

Business Associate Breach vs Violation: Cure Breaches, End Violations

hipaa business associate breach vs violation: distinguish a curable contract breach from an ongoing violation and document the required response.

How to Implement HIPAA Facility Access Controls (164.310(a)(1)): A Step-by-Step Compliance Guide

HIPAA ·Dec 2025

How to Implement HIPAA Facility Access Controls (164.310(a)(1)): A Step-by-Step Compliance Guide

A practical, step-by-step guide to implementing HIPAA Facility Access Controls (164.310(a)(1)) with actionable technical controls, policies, and small-business examples to meet HIPAA requirements.

How to Create Audit-Ready HIPAA 164.316(a) Policies and Procedures: Templates, Documentation, and Change Control

HIPAA ·Dec 2025

How to Create Audit-Ready HIPAA 164.316(a) Policies and Procedures: Templates, Documentation, and Change Control

Step-by-step guidance for building audit-ready HIPAA 164.316(a) policies and procedures within your HIPAA — templates, evidence, and change control best practices.

How to Create and Maintain Written HIPAA Policies and Procedures (164.316(b)(1)) — Practical Implementation Checklist

HIPAA ·Dec 2025

How to Create and Maintain Written HIPAA Policies and Procedures (164.316(b)(1)) — Practical Implementation Checklist

Step-by-step guidance for creating, documenting, and maintaining HIPAA-compliant written policies and procedures to meet 164.316(b)(1) and demonstrate ongoing HIPAA conformance.

Oakwood Hospital Worker Fired For Facebook Comments in HIPAA Violation

HIPAA ·Feb 2024

Oakwood Hospital Worker Fired For Facebook Comments in HIPAA Violation

Michigan healthcare provider, Oakwood Healthcare, Inc., has verified that an employee at Oakwood Hospital & Medical Center had their employment terminated for posting derogatory remarks about a patient on their Facebook page, leading to a HIPAA privacy violation

HIPAA for Managed Service Providers

HIPAA ·Feb 2024

HIPAA for Managed Service Providers

Understanding HIPAA is crucial for Managed Service Providers offering services to the healthcare sector or to organizations that assist the healthcare industry

HIPAA Disaster Recovery

HIPAA ·Feb 2024

HIPAA Disaster Recovery

Having a disaster recovery plan for HIPAA is crucial when it comes to contingency planning

HIPAA Password Sharing

HIPAA ·Jan 2024

HIPAA Password Sharing

Password sharing in healthcare may contribute to productivity in certain situations, however, it is crucial to maintain strict control over this practice and never allow it for accessing electronic protected health information (ePHI), a HIPAA violation.

HIPAA Release Form Texas

HIPAA ·Jan 2024

HIPAA Release Form Texas

Our Free HIPAA Release Form for Texas serves as a means to request medical records while ensuring compliance with the regulations outlined in the Health Insurance Portability and Accountability Act (HIPAA).

HIPAA Release Form Florida

HIPAA ·Jan 2024

HIPAA Release Form Florida

Our Free HIPAA Release Form for Florida serves as a means to request medical records while ensuring compliance with the regulations outlined in the Health Insurance Portability and Accountability Act (HIPAA).

HIPAA Release Form California

HIPAA ·Jan 2024

HIPAA Release Form California

Our Free HIPAA Release Form for California serves as a means to request medical records while ensuring compliance with the regulations outlined in the Health Insurance Portability and Accountability Act (HIPAA).

HIPAA Compliance for Medical Centers

HIPAA ·Jan 2024

HIPAA Compliance for Medical Centers

Medical centers must comply with the Administrative Simplification standards of HIPAA in order to be HIPAA compliant.

HIPAA Compliance In Urgent Care

HIPAA ·Jan 2024

HIPAA Compliance In Urgent Care

The correlation between HIPAA compliance in urgent care is not seamless, due to the potential for heightened emotions during emergency events.

HIPAA Compliance Officer

HIPAA ·Jan 2024

HIPAA Compliance Officer

To become HIPAA compliant, a Covered Entity or Business Associate need to understand the responsibilities of a HIPAA Compliance Officer. It is crucial to note that a HIPAA Compliance Officer is entrusted with two distinct roles that of a Privacy Officer and a Security Officer.

HIPAA Email Compliance

HIPAA ·Jan 2024

HIPAA Email Compliance

Covered entities and business associates are obligated to implement various safeguards to ensure compliance with the standards for HIPAA email regulations.

HIPAA Compliant Hosting

HIPAA ·Jan 2024

HIPAA Compliant Hosting

In order to safeguard sensitive patient information stored in the cloud, healthcare organizations are required to opt for hosting companies that comply with HIPAA regulations when hosting applications, websites, and databases.

HIPAA Text message (SMS) Regulations

HIPAA ·Jan 2024

HIPAA Text message (SMS) Regulations

Text message (SMS) regulations under HIPAA outline the specific circumstances in which communication with a patient via text message (SMS) is permitted, as well as the necessary precautions for all other text messages (SMS).

HIPAA Security Officer

HIPAA ·Jan 2024

HIPAA Security Officer

The primary responsibility of a HIPAA Security Officer is to create and execute guidelines and protocols that safeguard the authenticity of electronic Protected Health Information.

HIPAA Training Requirements

HIPAA ·Jan 2024

HIPAA Training Requirements

The HIPAA training requirements lean more towards offering guidance rather than enforcing strict laws. They recommend that training should be provided periodically and when specific events take place. We propose implementing a more organized training regimen and adopting best practices for Covered Entities and Business Associates when it comes to HIPAA training.

HIPAA 101

HIPAA ·Nov 2023

HIPAA 101

Everything you need to know about HIPAA; what it is, who it applies to, and more.

HIPAA and HITECH

HIPAA ·Oct 2023

HIPAA and HITECH

Covered Entities and Business Associates must familiarize themselves with the HITECH Act as it closely relates to the HIPAA and HITECH regulations. It is essential to comprehend the similarities and distinctions between HIPAA and HITECH, and where to access further details about these Acts.

HIPAA Password Sharing Policy

HIPAA ·Oct 2023

HIPAA Password Sharing Policy

A Password Sharing Policy that is compliant with HIPAA should explicitly forbid Covered Entities, Business Associates, and their staff members from sharing passwords that grant access to electronic Protected Health Information (ePHI). Additionally, it is highly recommended to disallow caregivers from using shared passwords to access patient portals.

HIPAA Medical Records

HIPAA ·Oct 2023

HIPAA Compliance for Medical Records

Safeguarding the security of medical records are required to meet HIPAA compliance requirements, this can be best achieved through cloud services.

HIPAA Risk Assessment

HIPAA ·Oct 2023

HIPAA Risk Assessment

Performing a HIPAA risk assessment is crucial for ensuring compliance with HIPAA regulations, discovering potential areas of vulnerability and weakness that could lead to data breaches. Once these areas are identified, Privacy and Security Officers can then create a comprehensive Risk Management Plan and implement necessary measures to effectively safeguard against unauthorized disclosures of Protected Health Information (PHI).

HIPAA Dentists

HIPAA ·Oct 2023

HIPAA Guide for Dentists

The master guide for HIPAA compliance for all dentists, regardless of whether they are self-contained entities or not.

HIPAA Encryption

HIPAA ·Oct 2023

HIPAA Encryption Requirements

Everything you need to know about HIPAA encryption requirements

HIPAA Covered Entity

HIPAA ·Oct 2023

HIPAA Covered Entity

What is a HIPAA Covered Entity? and everything you need to know about them.

HIPAA Telemedicine

HIPAA ·Oct 2023

HIPAA Telemedicine

The comprehensive HIPAA guide for telemedicine and the proper methods for transmitting electronic protected health information (ePHI) during remote healthcare services

HIPAA Social Media Policy

HIPAA ·Oct 2023

HIPAA Social Media Policy

Healthcare organizations must prioritize HIPAA compliance when it comes to their social media policies. It is imperative that patient information remains confidential, protected, and is only shared with explicit consent. To prevent any HIPAA violations, healthcare employees need to create and enforce well-defined social media policies. These guidelines encompass various aspects and serve as a roadmap.

HIPAA Violation Penalty Tiers Explained

HIPAA ·Sep 2023

HIPAA Violation Fines

HIPAA violation fines are given by the Department of Health and Human Services Office for Civil Rights (OCR) and state attorneys general to entities that fail to comply with HIPAA regulations.

UnitedHealthcare Pays Settlement for HIPAA violation over Patient Medical Records Request

HIPAA ·Sep 2023

UnitedHealthcare Pays Settlement for HIPAA violation over Patient Medical Records Request

UnitedHealthcare Settles for $80,000