HIPAA Guide
Plain-English HIPAA guides
Straight answers on the HIPAA Security Rule for practices, from the team behind the HIPAA Security Check.
- Is BYOD a HIPAA Violation?Personal devices are not banned under HIPAA, but unmanaged ones touching patient data are a violation waiting to happen. Here is what the rules actually require, and how to make BYOD compliant.
- Do You Need a HIPAA Security Risk Analysis?A written risk analysis is required for every practice that touches patient data, no matter how small, and it is the single most-cited failure in HIPAA enforcement. Here is what it is and how to do it.
- Is Regular Email HIPAA Compliant?Plain email is not automatically a HIPAA violation, but sending patient information through a standard inbox usually is. Here is when email is allowed and how to do it right.
- Do You Need a BAA With Your IT Company?If your IT provider can access systems that hold patient data, HIPAA requires a signed Business Associate Agreement, and without one, their breach becomes your liability.