HIPAA Compliant Patient Portals: Security Requirements and Best Practices

HIPAA Compliant Patient Portals: Security Requirements and Best Practices A patient portal is unusual among healthcare systems because it deliberately puts protected health information into the hands of people outside your walls. Every other safeguard in HIPAA is about keeping PHI inside a trusted boundary; a portal’s entire purpose is to push lab results, visit […]
HIPAA Compliance for Nonprofit Health Organizations and Free Clinics

HIPAA Compliance for Nonprofit Health Organizations and Free Clinics Nonprofit health organizations and free clinics face the same HIPAA obligations as any for-profit provider, but with a different set of pressures: tight budgets, a workforce that often includes volunteers and rotating students, grant-reporting requirements, and donor relationships that have to be kept separate from patient […]
HIPAA Compliance for Medical Transcription: Securing Dictated Records

HIPAA Compliance for Medical Transcription: Securing Dictated Records Medical transcription sits at a HIPAA pressure point that other workflows do not: the protected health information is almost always handled by someone outside the practice. Dictated clinical notes are sent to a transcription service, typed up, and returned, which means a provider’s most sensitive narrative records, […]
HIPAA and Workers Compensation: When Privacy Rules Apply to Workplace Injuries

HIPAA and Workers’ Compensation: When Privacy Rules Apply to Workplace Injuries When an employee is injured on the job, their medical information moves through a chain of parties — the treating provider, the employer, the workers’ compensation insurer, and often a state administrative board. Workers’ compensation is one of the few areas where HIPAA explicitly […]
HIPAA and Provider Credentialing: Protecting Physician Data

HIPAA and Provider Credentialing: Protecting Physician Data Provider credentialing occupies an unusual place under HIPAA, and understanding that nuance is the heart of compliance here. Credentialing is primarily about the provider, not the patient — verifying a clinician’s education, training, board certifications, NPI and DEA registrations, malpractice history, work history, and peer references. Because protected […]
HIPAA Compliance for Clinical Research: Using PHI in Studies

HIPAA Compliance for Clinical Research: Using PHI in Studies Research is the one corner of HIPAA where a covered entity has several different legal routes to use the same protected health information, and where a second federal framework — the Common Rule — runs alongside the Privacy Rule. Knowing which pathway you are on, and […]
HIPAA Compliance for Telehealth in 2026: A Provider’s Playbook

HIPAA Compliance for Telehealth in 2026: A Provider’s Playbook The 2026 HIPAA Security Rule update is the first time HIPAA’s technical safeguards have been rewritten with a video-visit, mobile-first care model in mind. For telehealth providers, that means encryption, MFA, session logging, and BAA inventory are no longer best practice — they’re the floor. Here’s […]
HIPAA Compliance for Nurse Practitioners: 2026 Security Rule Update for Solo NP Practices and NP-Owned Clinics

HIPAA Compliance for Nurse Practitioners: 2026 Security Rule Update for Solo NP Practices and NP-Owned Clinics Why Nurse Practitioners Are an OCR Audit Target in 2026 Nurse practitioners now provide primary care for over 1 in 4 American patients. With expanded scope-of-practice laws across more than two dozen states authorizing full practice authority, NP-owned clinics […]
The HIPAA Business Associate Agreement (BAA): What’s Required, What’s Optional, and How to Track Yours in 2026

The HIPAA Business Associate Agreement (BAA): What’s Required, What’s Optional, and How to Track Yours in 2026 A Business Associate Agreement is a contract between a HIPAA-covered entity and any vendor that creates, receives, maintains, or transmits protected health information (PHI) on its behalf. It’s required — not optional — under 45 CFR 164.504(e). Without […]
HIPAA Compliance in Revenue Cycle Management: From Intake to Collections

HIPAA Compliance in Revenue Cycle Management: From Intake to Collections Revenue cycle management (RCM) is where protected health information (PHI) travels the farthest. From the moment a patient is registered, the same data flows through eligibility verification, coding, claim submission, clearinghouses, payer adjudication, patient statements, and — when accounts go unpaid — collections. Every handoff […]