HIPAA Audit Preparation Checklist

The HIPAA Audit Preparation Checklist: What OCR Actually Asks For HIPAA audits aren’t pop quizzes on regulation trivia — they’re document requests. When the HHS Office for Civil Rights (OCR) audits or investigates, it sends a list: your risk analysis, your policies, your training records, your business associate agreements, your breach log. Organizations fail not […]
HIPAA Enforcement & Breach Trends Through Mid-2026: A Medcurity Analysis of HHS OCR Public Data

Original analysis of HHS OCR’s 2026 resolution agreements and Breach Portal data: 283 H1 breaches, 87% hacking share, and the risk-analysis pattern in every Security Rule settlement.
HIPAA Risk Assessment for Behavioral Health Practices (2026 Guide)

Behavioral health HIPAA risk assessment 2026: 42 CFR Part 2 overlap, telehealth Security Rule updates, fragmented vendor landscape addressed plainly.
HIPAA Risk Assessment for Pediatric Practices (2026 Guide)

Pediatric HIPAA risk assessment 2026: parental access until 18, minor confidentiality exceptions, VFC vaccine registry interfaces, FERPA-HIPAA boundaries.
HIPAA Security Risk Assessment for Illinois Community Health Centers (2026 Guide)

A practical 2026 guide to HIPAA Security Risk Assessments for Illinois CHCs: federal Section 330 overlay, PIPA, BIPA, and the Mental Health Confidentiality Act.
How Much Does a HIPAA Security Risk Assessment Cost in 2026?

How Much Does a HIPAA Security Risk Assessment Cost in 2026? Quick answer: In 2026, a HIPAA Security Risk Assessment costs anywhere from $0 (the free ONC/OCR SRA Tool, fully DIY) to $15,000+ (a consultant-led onsite assessment for a multi-site organization). Software-led assessments for small and mid-sized practices typically start around $499/year (Medcurity Small Practice […]
HIPAA Security Risk Assessment for Texas FQHCs

HIPAA Security Risk Assessment for Texas FQHCs Quick answer: Texas FQHCs operate under both the federal HIPAA Security Rule and the Texas Medical Records Privacy Act (HB 300, codified at Texas Health & Safety Code Chapter 181), which imposes stricter-than-federal requirements — including expanded “covered entity” definitions, mandatory customized employee training within 90 days of […]
How to Switch from Compliancy Group to Medcurity (2026 Migration Guide)

How to Switch from Compliancy Group to Medcurity (2026 Migration Guide) If you’re a Compliancy Group customer weighing a move in 2026, this guide walks you through the switch end-to-end. It’s written for HIPAA compliance officers, practice managers, and IT leads at small-to-mid healthcare organizations — independent practices, dental groups, FQHCs, and clinics — who’ve […]
HIPAA Security Risk Assessment for California FQHCs

HIPAA Security Risk Assessment for California FQHCs Quick answer: California Federally Qualified Health Centers must conduct an annual HIPAA Security Risk Analysis covering all administrative, physical, and technical safeguards across every site. Because California layers the Confidentiality of Medical Information Act (CMIA) and CCPA-era privacy expectations on top of federal HIPAA, a California FQHC’s risk […]
2026 HIPAA SRA Software Landscape: How the Leading Tools Compare

An honest, vendor-by-vendor comparison of eight leading HIPAA Security Risk Analysis platforms for 2026 — pricing, healthcare depth, audit defensibility, and which org types fit which tools.