Editorial Standards

Editorial Standards: How We Review

Washington Compliance publishes plain-language explanations of HIPAA and Washington State health-data law. This page explains how we source, write, and correct our content.

What we rely on

Every rule we describe traces back to its primary legal text: the eCFR for 45 CFR Parts 160 and 164 (the HIPAA Privacy, Security, and Breach Notification Rules), HHS.gov and the HHS Office for Civil Rights for guidance and enforcement, the Washington State Legislature for RCW text including the My Health My Data Act, and the Washington Attorney General's Office for state breach-reporting guidance. We link to the primary source rather than paraphrasing a secondhand summary.

How we handle proposed vs. final rules

We are careful to distinguish law that is final and in effect from rules that are only proposed. Where we discuss the proposed HIPAA Security Rule updates (the NPRM), we label them as proposed and not yet final, and we do not describe them as current legal requirements.

Corrections

Found an error — a broken source link, an outdated regulatory reference, or a factual mistake? Tell us and we correct it. Use the contact page to reach us.

Update cadence

Articles are reviewed periodically and updated when a cited rule, proposed rule, or agency guidance changes. Each article notes when it was last updated.

Independence

Washington Compliance is an independent educational resource. We are not a government agency, law firm, or vendor, and we have no affiliation with the U.S. Department of Health and Human Services, the Office for Civil Rights, or the State of Washington. This site is part of a network of educational resources operated by Medcurity, Inc.