Phishing Prevention for Healthcare: Protecting PHI from Social Engineering

Phishing Prevention for Healthcare: Protecting PHI from Social Engineering Phishing is the single most common entry point for healthcare data breaches, and the reason is structural: hospitals and clinics run on email, staff are busy and trained to be helpful, and a single set of stolen credentials can unlock an inbox full of protected health […]
HIPAA and Ransomware: Prevention, Response, and Breach Notification

HIPAA and Ransomware: Prevention, Response, and Breach Notification Ransomware is different from most HIPAA security topics because the Office for Civil Rights has been explicit about it: when ransomware encrypts electronic protected health information (ePHI), that encryption is a “disclosure” not permitted under the Privacy Rule, and it is presumed to be a reportable breach […]
HIPAA Compliance for Occupational Therapy Practices

HIPAA Compliance for Occupational Therapy Practices Occupational therapy sits in a corner of healthcare where protected health information (PHI) rarely stays inside a clinic. OT practitioners document patients in their kitchens, their classrooms, and their workplaces, and the records they keep — functional capacity evaluations, activities-of-daily-living (ADL) assessments, home-safety photos, adaptive-equipment recommendations, and detailed progress […]
HIPAA Third-Party Risk Management: Vendor Assessment Best Practices

HIPAA Third-Party Risk Management: Vendor Assessment Best Practices A growing share of healthcare data breaches no longer start inside the provider — they start at a vendor. Billing companies, cloud platforms, EHR hosts, and IT service providers all touch protected health information, and each one extends an organization’s attack surface. That is what makes third-party […]
HIPAA Compliance for Hospice and Palliative Care Organizations

HIPAA Compliance for Hospice and Palliative Care Organizations Quick Answer: Hospice and palliative-care organizations face HIPAA challenges that most providers do not: care delivered in patients’ homes, heavy involvement of family and informal caregivers, interdisciplinary teams sharing PHI across settings, and frequent disclosures to clergy, volunteers, and bereavement services. A current Security Risk Analysis plus […]
HIPAA Compliance for Radiology and Imaging Centers

HIPAA Compliance for Radiology and Imaging Centers Radiology and imaging centers handle some of the most data-rich protected health information (PHI) in healthcare. A single CT or MRI study can contain thousands of individual images, and every one of them carries patient identifiers embedded directly in its DICOM metadata header — name, date of birth, […]
HIPAA Compliance for mHealth Apps: Developing Compliant Mobile Health Solutions

HIPAA Compliance for mHealth Apps: Developing Compliant Mobile Health Solutions The first question for any mobile health app is not “how do we make it HIPAA compliant” but “does HIPAA even apply.” That answer is genuinely specific to mHealth and it is not obvious. HIPAA follows the relationship, not the data: an app applies under […]
HIPAA vs FERPA: Compliance for School-Based Health Centers

HIPAA vs FERPA: Compliance for School-Based Health Centers Quick Answer: School-based health centers (SBHCs) sit at the intersection of HIPAA and FERPA, serve minors whose consent rules vary by state, and share space and staff with schools. The key is knowing when records are HIPAA-covered versus FERPA-covered, applying state minor-consent law correctly, and running a […]
HIPAA and Health Information Exchanges (HIEs): Secure Data Sharing

HIPAA and Health Information Exchanges (HIEs): Secure Data Sharing A Health Information Exchange exists to do the one thing HIPAA spends the most energy governing: move protected health information between organizations that do not share a roof, a network, or a patient-consent form. That is what makes HIE compliance distinct. In a single clinic, PHI […]
HIPAA Compliance for Medical Marijuana Programs and Dispensaries

HIPAA Compliance for Medical Marijuana Programs and Dispensaries Medical marijuana sits in an unusual regulatory position, and the first question for anyone handling its records is deceptively simple: does HIPAA even apply? The answer depends entirely on who is holding the data. A storefront dispensary and a physician who certifies a patient for a state […]