Cyber Insurance Readiness for Healthcare: What Underwriters Now Verify

Cyber Insurance Readiness for Healthcare: What Underwriters Now Verify Cyber insurance used to be a form you filled out. You checked a column of yes and no boxes, attested that the answers were true, and a policy showed up. That process is over for healthcare applicants. Carriers now reserve the right to verify what you […]
How to Choose a HIPAA Network Vulnerability Assessment Vendor

How to Choose a HIPAA Network Vulnerability Assessment Vendor Healthcare vulnerability assessment vendors sell one of three different things under the same name: a scanner that returns a list of CVEs, a penetration test scoped to a single application, or a managed assessment that scopes your environment, interprets the findings, and hands your team remediation […]
How to Choose HIPAA Vendor Risk Management Software: A 2026 Buyer’s Guide

How to Choose HIPAA Vendor Risk Management Software: A 2026 Buyer’s Guide HIPAA vendor risk management software should do four things: track every business associate and the status of its BAA, assess whether a vendor is able to protect PHI rather than only promising to, hold dated evidence an auditor will accept, and reassess vendors […]
AI Note-Taking Tools and HIPAA: Are Your Meeting Notes Exposing PHI?

AI Note-Taking Tools and HIPAA: Are Your Meeting Notes Exposing PHI? AI note-taking assistants have quietly become one of the most-used tools in healthcare offices. Someone joins a Zoom or Teams call, a bot slides in to “take notes,” and minutes later everyone has a tidy transcript and summary in their inbox. It feels harmless. […]
HIPAA, HITRUST, and SOC 2 Control Mapping: How to Stop Doing the Same Work Three Times

HIPAA, HITRUST, and SOC 2 Control Mapping: How to Stop Doing the Same Work Three Times If your organization handles protected health information, there is a good chance you are being asked about all three at once. A health-system customer wants a HITRUST certification. A payer’s procurement team wants a SOC 2 Type 2 report. […]
HIPAA Security Rule Update Delayed to July 2027: What It Means for Your Compliance Timeline

The HIPAA Security Rule overhaul has slipped to a July 2027 target. Here is what changed, what did not, and what to do in the meantime.
Conversational AI and the HIPAA Security Risk Assessment: What Changes in 2026

Conversational AI and the HIPAA Security Risk Assessment: What Changes in 2026 Ask most practice managers what they dread about HIPAA compliance and the same answer comes back: the annual Security Risk Analysis. It is required, it is detailed, and for many small organizations it still lives in a sprawling spreadsheet that nobody enjoys owning. […]
HIPAA-Compliant AI Dictation in 2026: Voice Dictation vs. Ambient AI, BAAs, and What’s Actually Safe

HIPAA-Compliant AI Dictation in 2026: Voice Dictation vs. Ambient AI, BAAs, and What’s Actually Safe Quick answer: AI dictation can be HIPAA compliant, but only when the vendor signs a Business Associate Agreement (BAA), the audio and transcripts are encrypted in transit and at rest, access is controlled and logged, and the tool is included […]
Ambient AI Documentation and HIPAA: A 2026 Compliance Guide for Healthcare

Ambient AI Documentation and HIPAA: A 2026 Compliance Guide for Healthcare Ambient AI documentation tools listen to a patient encounter, transcribe it, and draft a clinical note automatically — freeing clinicians from typing while the visit happens. Adoption has moved fast: ambient scribes from vendors like Nuance DAX, Abridge, Suki, and Nabla are now in […]
Shadow AI in Healthcare: The Compliance Risk Hiding in Plain Sight (2026)

Shadow AI in Healthcare: The Compliance Risk Hiding in Plain Sight Your clinicians are already using AI. Not the tools your security team vetted and signed a Business Associate Agreement for — the free ones. A physician pasting a patient summary into a public chatbot to draft a referral letter. A billing coordinator running a […]