HIPAA Compliance for Healthcare Websites: Forms, Chat, and Patient Portals

HIPAA Compliance for Healthcare Websites: Forms, Chat, and Patient Portals A healthcare website is the one part of a covered entity that lives in public, on the patient’s side of the screen. Unlike an EHR sitting behind a login, a public site collects information from people before they are authenticated, and it runs third-party code […]
HIPAA Compliance for Multi-Location Healthcare Organizations

HIPAA Compliance for Multi-Location Healthcare Organizations HIPAA compliance gets harder the moment your organization runs more than one location. The rules do not change from site to site, but the Office for Civil Rights almost always treats a single legal entity as one covered entity. That means a lapse at your smallest satellite clinic is, […]
HIPAA Disaster Recovery Planning: Protecting PHI During Emergencies

HIPAA Disaster Recovery Planning: Protecting PHI During Emergencies Disaster recovery under HIPAA is not generic business continuity with a healthcare label. What makes it distinct is that the asset you are protecting is electronic protected health information (ePHI), and the Security Rule treats the ability to recover that data as a compliance obligation in its […]
HIPAA Access Controls: Role-Based Permissions and Least Privilege

HIPAA Access Controls: Role-Based Permissions and Least Privilege Access control is where HIPAA stops being a paperwork exercise and becomes an engineering decision. Most breaches that draw enforcement attention are not exotic hacks; they are ordinary accounts that could see far more protected health information than the person behind them ever needed. The two ideas […]
HIPAA and Genetic Information: GINA Compliance for Healthcare Providers

HIPAA and Genetic Information: GINA Compliance for Healthcare Providers Genetic information sits at the intersection of two federal laws, and that is what makes it distinct from the rest of the protected health information (PHI) a provider handles. HIPAA governs how genetic data is protected as PHI, while the Genetic Information Nondiscrimination Act (GINA) governs […]
Do Fitness Trackers and Health Apps Need HIPAA Compliance?

Do Fitness Trackers and Health Apps Need HIPAA Compliance? The question “do fitness trackers need HIPAA compliance” almost always gets answered wrong because people assume HIPAA follows the data. It does not. HIPAA follows the relationship. The same heart-rate reading can be completely outside HIPAA in one context and squarely inside it in another, depending […]
HIPAA Audit Log Requirements: What to Track and How Long to Keep Logs

HIPAA Audit Log Requirements: What to Track and How Long to Keep Logs Audit logs occupy an unusual place in HIPAA: they are both a control you are required to implement and the evidence you depend on when something goes wrong. The Security Rule names them directly but — by design — does not hand […]
HIPAA Incident Response Plan: How to Prepare for and Handle a Breach

HIPAA Incident Response Plan: How to Prepare for and Handle a Breach A HIPAA incident response plan is not the same thing as a breach notification, and confusing the two costs organizations precious time. The HIPAA Security Rule requires every covered entity and business associate to maintain security incident procedures under §164.308(a)(6): a documented way […]
HIPAA and Group Therapy: Privacy Considerations for Group Sessions

HIPAA and Group Therapy: Privacy Considerations for Group Sessions Group therapy creates a HIPAA problem that individual sessions never do: the patients themselves are in the room. When six people sit in a circle and one discloses a relapse, the others hear it. That shared exposure — and the documentation it generates — makes HIPAA […]
HIPAA Compliant Text Messaging: Can Healthcare Providers Text About Patients?

HIPAA Compliant Text Messaging: Can Healthcare Providers Text About Patients? Texting is fast, patients love it, and standard SMS is one of the least secure channels a healthcare provider can use. The short answer to “can we text about patients?” is yes — but how you do it, and who is on each end of […]