Monthly Tips Roundup

We’ve curated our weekly tips shared on LinkedIn every Tuesday into this monthly blog for your convenience. August 4, 2026 Risk Assessment Process for Breaches A breach is, generally, an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of PHI. An impermissible use or disclosure of unsecured PHI is…

Read More

HIPAA Tip: What Are You Waiting For?

NOW is the time to finish the Disaster Recovery Plan. TODAY is the day to review policies and procedures that have been pushed to the side for the last two years. Before Q4 2026 book the annual Security Risk Analysis (SRA). What are you waiting for? If a breach occurs can you produce the required…

Read More

HIPAA Tip: HIPAA Common Sense

We talk all the time about the same things: long, complex passwords, updating/patching systems and applications containing ePHI, enabling two-factor/multi-factor authentication whenever possible for systems storing ePHI (connecting either onsite or remotely), enabling encryption on business devices, especially if they will be traveling out of the office/center. When you think about some of the areas…

Read More

HIPAA Tip: HIPAA Statistics

Healthcare cyber attacks - HIPAA security and data protection

How about this one to grab you: HIPAA statistics in 2026 highlight that over 935 million individuals have had their Protected Health Information (PHI) compromised since 2009—over 2.6 times the entire US population! The ten largest breaches reported so far this year show threat actors are continuing to target healthcare organizations of all sizes, focusing…

Read More

HIPAA Tip: HIPAA Responses

Healthcare cyber attacks - HIPAA security and data protection

We all know how much our coworkers love HIPAA requirements, annual training(s) and constant (I hope!) reminders from management and the compliance team. We are also well aware of the push-back and comments when it comes to communicating and executing HIPAA requirements to staff, physicians and owners. Here are some TIPS on how to respond…

Read More

HIPAA Tip: HHS OCR HIPAA Enforcement

Healthcare cyber attacks - HIPAA security and data protection

You need me – oh yes you do! Every OCR breach investigation in 2026 cited the failure to conduct an accurate and thorough HIPAA Security Risk Analysis (SRA). It’s not good enough to put together a HIPAA compliance policy and procedure manual, put it on a shelf, never share with staff or update policies and…

Read More

HIPAA Tip: Stay on Top of HIPAA Requirements

Healthcare cyber attacks - HIPAA security and data protection

We’ve all heard about the HIPAA Security Rule Notice of Proposed Rule Making (NPRM) submitted in December 2024. Fast forward, we were expecting some of the proposals to come into enforcement in May 2026. The Department of Health and Human Services (HHS) is reviewing the rule, with no confirmed date for finalization. What does this…

Read More

HIPAA Tip: Fight Back!

Healthcare cyber attacks - HIPAA security and data protection

For those of you who know me, you’ve heard me say probably more than once, we are all patients somewhere. And as patients we want to be treated with importance and feel confident knowing our medical information is private with those providing our care and secure from a hacking incident, ransomware attack or data breach.…

Read More

HIPAA Tip: Checklist for Information Technology Team

Healthcare cyber attacks - HIPAA security and data protection

Your Information Technology (IT) team needs to be one of your nearest and dearest comrades in securing the organization from all the scary and nasty threat actors trying to steal patient data, sabotage critical software (EMRs, scheduling, billing), or worse, halt patient care with a ransomware attack or breach. Confirm the following with your IT…

Read More

HIPAA Tip: Staff Training

Healthcare cyber attacks - HIPAA security and data protection

Staff training goes without saying, but what does this look like in your organization? Would this be an annual PowerPoint for HIPAA training that has been presented year after year? Is there a mandatory online training course that ensures all staff (including physicians) complete, but does not alert management to those who failed the training?…

Read More