Business Associate Agreement (BAA)
What a BAA must contain, who needs one, and why most organisations have fewer valid ones than they think.
Read →Guides
Plain-language guides to every part of HIPAA, written by people who implement it.
What a BAA must contain, who needs one, and why most organisations have fewer valid ones than they think.
Read →The largest safeguard category and the source of most findings — nine standards and what each demands operationally.
Read →What an OCR investigation looks like, what gets requested first, and what a customer-driven audit demands instead.
Read →A working checklist organised by rule and safeguard category, with the required-versus-addressable distinction made explicit.
Read →When to hire one, what to ask before you sign, and the four answers that should end the conversation.
Read →Honest ranges for software, services, and internal effort — by organisation size, with the variables that move the number.
Read →A platform differs from a tool: it holds the whole program — controls, evidence, people, vendors, and the audit trail connecting them.
Read →The full service catalogue, what each one produces, and how to sequence them without paying for overlap.
Read →What HIPAA compliance software actually does, what it cannot do, and how to evaluate it without being sold a certificate.
Read →The six-year rule, what must be in writing, and what 'available to those responsible for implementation' means in practice.
Read →Security incident versus breach, the four-factor test, the 60-day clock, and the documentation you will wish you had kept.
Read →Facility access, workstation use and security, and device and media controls — including the fully remote workforce.
Read →The policy set the rule requires, what separates a usable policy from a template, and how to keep acknowledgement records that hold.
Read →Uses and disclosures, minimum necessary, patient rights, and the operational workflows each one demands.
Read →The precise regulatory term, what a defensible one contains, and the methodology choices that hold up under scrutiny.
Read →The risk assessment is the foundational requirement of the Security Rule and the first document OCR requests after an incident.
Read →A plain-language walk through 45 CFR Part 164 Subpart C — every standard, what it means operationally, and where teams fail it.
Read →Access control, audit controls, integrity, authentication, and transmission security — specification by specification.
Read →Free, editable starting points for every required document — plus a warning about what templates cannot do.
Read →Who must be trained, how often, what counts as a record, and why annual video completion is not enough on its own.
Read →Building a vendor program that survives an audit: inventory, tiering, BAAs, reviews, and offboarding.
Read →