Healthcare compliance resource

Healthcare compliance, in plain language

An independent reference on HIPAA, the Security and Privacy Rules, risk analysis, and Washington State health-data law for compliance-minded organizations.

HIPAA Basics

Who HIPAA covers, what it protects, and how it is enforced.

HIPAA Basics

HIPAA Penalties and Enforcement

How OCR enforces HIPAA: complaints, investigations, corrective action, the tiered penalty structure, and possible criminal referrals.

6 min

Security Rule

Safeguards for electronic protected health information.

Security Rule

An Overview of the HIPAA Security Rule

What the HIPAA Security Rule requires: protecting ePHI through administrative, physical, and technical safeguards, and the role of required vs. addressable specs.

6 min
Security Rule

Access Controls and Authentication

How the HIPAA Security Rule treats access control and authentication, including unique user IDs, least privilege, and multi-factor authentication.

6 min
Security Rule

Encryption and the Security Rule

Why encryption is addressable under HIPAA, how it relates to the breach safe harbor, and practical guidance for data at rest and in transit.

6 min

Privacy Rule

Rules for using, disclosing, and protecting health information.

Privacy Rule

An Overview of the HIPAA Privacy Rule

What the HIPAA Privacy Rule does: setting national standards for how PHI may be used and disclosed, and the rights it gives patients.

6 min
Privacy Rule

Permitted Uses and Disclosures of PHI

When HIPAA lets you use or disclose PHI without authorization, including treatment, payment, operations, and public-interest exceptions.

7 min
Privacy Rule

The Minimum Necessary Standard

How HIPAA's minimum necessary standard works, when it applies, when it does not, and how to operationalize it with role-based access.

5 min
Privacy Rule

Patient Rights Under the Privacy Rule

The rights HIPAA gives patients, including access to records, amendments, accounting of disclosures, restrictions, and confidential communications.

6 min

Risk & Audits

Risk analysis, breach response, and building a compliance program.

Risk & Audits

Breach Notification Requirements

What the HIPAA Breach Notification Rule requires: the breach definition, risk assessment factors, and who must be notified and when.

7 min
Risk & Audits

Building a HIPAA Compliance Program

The building blocks of a sustainable HIPAA compliance program: governance, risk analysis, policies, training, vendor management, and incident response.

7 min

Washington State

Washington health-data law beyond HIPAA, including the My Health My Data Act.