Healthcare compliance resource

Healthcare compliance, in plain language

An independent reference on HIPAA, the Security and Privacy Rules, risk analysis, and Washington State health-data law for compliance-minded organizations.

HIPAA BasicsSecurity RulePrivacy RuleRisk & AuditsWashington State

HIPAA Basics

Who HIPAA covers, what it protects, and how it is enforced.

HIPAA Basics

What Is HIPAA? A Plain-Language Overview

A plain-language overview of HIPAA: what the law is, what it protects, its main rules, and who has to follow it.

6 min
HIPAA Basics

Covered Entities vs. Business Associates

Understand the difference between covered entities and business associates under HIPAA, and why business associate agreements matter.

6 min
HIPAA Basics

What Is Protected Health Information (PHI)?

Learn what counts as protected health information under HIPAA, the 18 identifiers, and how de-identification removes data from HIPAA's scope.

6 min
HIPAA Basics

HIPAA Penalties and Enforcement

How OCR enforces HIPAA: complaints, investigations, corrective action, the tiered penalty structure, and possible criminal referrals.

6 min

Security Rule

Safeguards for electronic protected health information.

Security Rule

An Overview of the HIPAA Security Rule

What the HIPAA Security Rule requires: protecting ePHI through administrative, physical, and technical safeguards, and the role of required vs. addressable specs.

6 min
Security Rule

Administrative, Physical, and Technical Safeguards

A breakdown of the three Security Rule safeguard categories - administrative, physical, and technical - with practical examples for each.

7 min
Security Rule

Access Controls and Authentication

How the HIPAA Security Rule treats access control and authentication, including unique user IDs, least privilege, and multi-factor authentication.

6 min
Security Rule

Encryption and the Security Rule

Why encryption is addressable under HIPAA, how it relates to the breach safe harbor, and practical guidance for data at rest and in transit.

6 min
Security Rule

The Proposed Security Rule Updates: What to Watch

An overview of the proposed HIPAA Security Rule updates (NPRM). These changes are proposed and not yet final - what they would do and how to prepare.

6 min

Privacy Rule

Rules for using, disclosing, and protecting health information.

Privacy Rule

An Overview of the HIPAA Privacy Rule

What the HIPAA Privacy Rule does: setting national standards for how PHI may be used and disclosed, and the rights it gives patients.

6 min
Privacy Rule

Permitted Uses and Disclosures of PHI

When HIPAA lets you use or disclose PHI without authorization, including treatment, payment, operations, and public-interest exceptions.

7 min
Privacy Rule

The Minimum Necessary Standard

How HIPAA's minimum necessary standard works, when it applies, when it does not, and how to operationalize it with role-based access.

5 min
Privacy Rule

Patient Rights Under the Privacy Rule

The rights HIPAA gives patients, including access to records, amendments, accounting of disclosures, restrictions, and confidential communications.

6 min

Risk & Audits

Risk analysis, breach response, and building a compliance program.

Risk & Audits

What Is a HIPAA Security Risk Analysis?

Understand the HIPAA security risk analysis: what it requires, why it is foundational, and how it differs from a gap assessment.

6 min
Risk & Audits

Conducting a Risk Assessment Step by Step

A practical, step-by-step walkthrough of a HIPAA security risk assessment, from scoping and data mapping to risk rating and remediation.

7 min
Risk & Audits

Breach Notification Requirements

What the HIPAA Breach Notification Rule requires: the breach definition, risk assessment factors, and who must be notified and when.

7 min
Risk & Audits

Building a HIPAA Compliance Program

The building blocks of a sustainable HIPAA compliance program: governance, risk analysis, policies, training, vendor management, and incident response.

7 min

Washington State

Washington health-data law beyond HIPAA, including the My Health My Data Act.

Washington State

Washington's My Health My Data Act Explained

An overview of Washington's My Health My Data Act: who it covers, consumer rights, the private right of action, and how it differs from HIPAA.

7 min
Washington State

Washington State Medical Records Retention

How long Washington providers should retain medical records, the difference from HIPAA's documentation retention, and where to verify the rules.

6 min
Washington State

Reporting a Health Data Breach in Washington

How health data breach reporting works in Washington: HIPAA federal duties, the state breach notification law, and the Attorney General's role.

6 min