HIPAA Vendor Risk Assessment Questionnaire: What to Ask Every Business Associate in 2026

HIPAA Vendor Risk Assessment Questionnaire: What to Ask Every Business Associate in 2026 Every healthcare organization depends on outside vendors — billing companies, cloud hosts, analytics platforms, AI scribes, e-fax providers, managed IT. The moment one of them creates, receives, maintains, or transmits protected health information (PHI) on your behalf, they become a business associate, […]
Is ChatGPT HIPAA Compliant? What Healthcare Teams Need to Know in 2026

Is ChatGPT HIPAA Compliant? What Healthcare Teams Need to Know in 2026 Short answer: it depends entirely on which version of ChatGPT you use and whether you have a signed Business Associate Agreement (BAA) in place. The consumer ChatGPT that most people log into is not HIPAA compliant, and entering protected health information (PHI) into […]
HIPAA-Compliant AI Tools: A 2026 Buyer’s Guide for Healthcare Teams

HIPAA-Compliant AI Tools: A 2026 Buyer’s Guide for Healthcare Teams Artificial intelligence is now embedded in nearly every layer of healthcare operations — from ambient scribes that draft clinical notes to chatbots that triage patient questions. But “AI tool” and “HIPAA-compliant AI tool” are not the same thing. A tool becomes usable with protected health […]
Medcurity Compliance Digest — Week of June 15, 2026

Medcurity Compliance Digest — Week of June 15, 2026 Each week we read the OCR enforcement feed and the HHS breach portal so you don’t have to — and translate what’s there into what it means for the kind of practice you actually run. Here’s the week of June 15. The short version: a quiet […]
HIPAA Compliance for Oncology Practices and Cancer Centers (2026)

HIPAA Compliance for Oncology Practices and Cancer Centers (2026) Oncology handles some of the most sensitive protected health information in all of medicine. A single cancer patient’s record can combine a diagnosis, genomic sequencing results, clinical trial enrollment, mental health notes, and reporting to a state cancer registry — each governed by HIPAA, and several […]
Medcurity vs. Kiteworks: HIPAA Compliance Platform Comparison (2026)

Medcurity vs. Kiteworks: HIPAA Compliance Platform Comparison (2026) Healthcare teams shopping for “HIPAA software” often end up comparing tools that solve very different problems. Medcurity and Kiteworks are a good example. Both appear in HIPAA conversations, but they sit at different layers of a compliance program: Kiteworks secures how sensitive data moves, while Medcurity runs […]
OCR Investigation Response: What to Do When HHS Contacts You (2026)

OCR Investigation Response: What to Do When HHS Contacts You The envelope — or the email — says U.S. Department of Health and Human Services, Office for Civil Rights. Before anything else, know this: an OCR investigation letter is not a finding, not a fine, and not rare. It is a document request with a […]
Medcurity Compliance Digest — Week of June 8, 2026

Your weekly five-minute read on OCR enforcement, new breach reports, and what they mean for your healthcare practice.
HIPAA Compliance for Small Hospitals (Under 50 Beds): The 2026 Guide

Small hospitals face the same HIPAA rules as large systems with a fraction of the staff. What OCR expects from sub-50-bed facilities in 2026.
The BAA Inventory Checklist: Account for Every Business Associate Agreement

The BAA Inventory Checklist: Account for Every Business Associate Agreement Most HIPAA enforcement actions involving business associates come down to one document that was never signed. A BAA inventory — a living list of every vendor relationship that touches protected health information, matched to an executed agreement — is the fastest way to find the […]