LakeRidge Blog
HIPAA
Practical guidance on HIPAA privacy and security rule safeguards for covered entities and business associates.
Need help putting this into practice? See our HIPAA compliance services or the HIPAA handbook.
HIPAA ·Dec 2025
How to Implement HIPAA Facility Access Controls (164.310(a)(1)): A Step-by-Step Compliance Guide
A practical, step-by-step guide to implementing HIPAA Facility Access Controls (164.310(a)(1)) with actionable technical controls, policies, and small-business examples to meet HIPAA requirements.
HIPAA ·Dec 2025
How to Create and Maintain Written HIPAA Policies and Procedures (164.316(b)(1)) — Practical Implementation Checklist
Step-by-step guidance for creating, documenting, and maintaining HIPAA-compliant written policies and procedures to meet 164.316(b)(1) and demonstrate ongoing HIPAA conformance.
HIPAA ·Feb 2024
Oakwood Hospital Worker Fired For Facebook Comments in HIPAA Violation
Michigan healthcare provider, Oakwood Healthcare, Inc., has verified that an employee at Oakwood Hospital & Medical Center had their employment terminated for posting derogatory remarks about a patient on their Facebook page, leading to a HIPAA privacy violation
HIPAA ·Jan 2024
HIPAA Compliance Officer
To become HIPAA compliant, a Covered Entity or Business Associate need to understand the responsibilities of a HIPAA Compliance Officer. It is crucial to note that a HIPAA Compliance Officer is entrusted with two distinct roles that of a Privacy Officer and a Security Officer.
HIPAA ·Jan 2024
HIPAA Training Requirements
The HIPAA training requirements lean more towards offering guidance rather than enforcing strict laws. They recommend that training should be provided periodically and when specific events take place. We propose implementing a more organized training regimen and adopting best practices for Covered Entities and Business Associates when it comes to HIPAA training.
HIPAA ·Oct 2023
HIPAA and HITECH
Covered Entities and Business Associates must familiarize themselves with the HITECH Act as it closely relates to the HIPAA and HITECH regulations. It is essential to comprehend the similarities and distinctions between HIPAA and HITECH, and where to access further details about these Acts.
HIPAA ·Oct 2023
HIPAA Password Sharing Policy
A Password Sharing Policy that is compliant with HIPAA should explicitly forbid Covered Entities, Business Associates, and their staff members from sharing passwords that grant access to electronic Protected Health Information (ePHI). Additionally, it is highly recommended to disallow caregivers from using shared passwords to access patient portals.
HIPAA ·Oct 2023
HIPAA Risk Assessment
Performing a HIPAA risk assessment is crucial for ensuring compliance with HIPAA regulations, discovering potential areas of vulnerability and weakness that could lead to data breaches. Once these areas are identified, Privacy and Security Officers can then create a comprehensive Risk Management Plan and implement necessary measures to effectively safeguard against unauthorized disclosures of Protected Health Information (PHI).
HIPAA ·Oct 2023
HIPAA Social Media Policy
Healthcare organizations must prioritize HIPAA compliance when it comes to their social media policies. It is imperative that patient information remains confidential, protected, and is only shared with explicit consent. To prevent any HIPAA violations, healthcare employees need to create and enforce well-defined social media policies. These guidelines encompass various aspects and serve as a roadmap.