HIPAA Security Risk Assessment for Texas FQHCs

HIPAA compliance for community health centers and FQHC clinics — Medcurity platform for multi-site clinics.

HIPAA Security Risk Assessment for Texas FQHCs Quick answer: Texas FQHCs operate under both the federal HIPAA Security Rule and the Texas Medical Records Privacy Act (HB 300, codified at Texas Health & Safety Code Chapter 181), which imposes stricter-than-federal requirements — including expanded “covered entity” definitions, mandatory customized employee training within 90 days of […]

How to Switch from Compliancy Group to Medcurity (2026 Migration Guide)

HIPAA compliance for multi-location hospitals and hospital networks — Medcurity platform.

How to Switch from Compliancy Group to Medcurity (2026 Migration Guide) If you’re a Compliancy Group customer weighing a move in 2026, this guide walks you through the switch end-to-end. It’s written for HIPAA compliance officers, practice managers, and IT leads at small-to-mid healthcare organizations — independent practices, dental groups, FQHCs, and clinics — who’ve […]

HIPAA Security Risk Assessment for California FQHCs

HIPAA compliance for community health centers and FQHC clinics — Medcurity platform for multi-site clinics.

HIPAA Security Risk Assessment for California FQHCs Quick answer: California Federally Qualified Health Centers must conduct an annual HIPAA Security Risk Analysis covering all administrative, physical, and technical safeguards across every site. Because California layers the Confidentiality of Medical Information Act (CMIA) and CCPA-era privacy expectations on top of federal HIPAA, a California FQHC’s risk […]

HIPAA 2026 Updates: New Security Rule Changes Every Organization Must Know

HIPAA compliance for multi-location hospitals and hospital networks — Medcurity platform.

HIPAA 2026 Updates: New Security Rule Changes Every Organization Must Know Quick Answer: The proposed 2026 HIPAA Security Rule update (published as an NPRM in December 2024, not yet finalized) would introduce mandatory encryption for all ePHI, required multi-factor authentication, network segmentation standards, defined vulnerability-management timeframes, enhanced audit-log requirements, and annual compliance assessments. When finalized, […]

HIPAA BYOD Policy: Managing Personal Devices in Healthcare Settings

HIPAA compliance for multi-location hospitals and hospital networks — Medcurity platform.

HIPAA BYOD Policy: Managing Personal Devices in Healthcare Settings Bring-your-own-device (BYOD) is now the default in most healthcare settings. Clinicians check schedules on personal phones, nurses message colleagues from their own tablets, and administrators answer email on home laptops. What makes BYOD a distinct HIPAA problem is ownership: the organization is responsible for protecting electronic […]

HIPAA and Penetration Testing: When and How to Test Your Security

HIPAA compliance for multi-location hospitals and hospital networks — Medcurity platform.

HIPAA and Penetration Testing: When and How to Test Your Security Penetration testing answers a question a risk analysis on paper cannot: if a real attacker targeted your network today, would your safeguards actually hold? For healthcare organizations, that distinction matters. A Security Risk Analysis identifies where ePHI lives and what could go wrong; a […]

Zero Trust Security for Healthcare: Implementing HIPAA-Aligned Architecture

HIPAA compliance for multi-location hospitals and hospital networks — Medcurity platform.

Zero Trust Security for Healthcare: Implementing HIPAA-Aligned Architecture Most healthcare networks were built on a model that no longer holds up: trust everything inside the firewall, scrutinize everything outside it. Zero trust inverts that assumption. It treats every request for electronic protected health information (ePHI) as untrusted until the user, device, and context are verified, […]