Skip to content
HIPAA

HIPAA — practitioner guides.

29 articles on HIPAA, ordered newest first. From the SentinelPanda team.

HIPAA 3 min
August 6, 2026

HIPAA vs ISO 42001

HIPAA regulates the data a clinical model is trained on. It has essentially nothing to say about whether the model is any good, or fair, or safe to rely on.

HIPAA 2 min
August 5, 2026

HIPAA vs ISO 27001

HIPAA obliges you but gives you nothing to show for it. ISO 27001 obliges you to nothing but hands you a certificate. That mismatch is why they pair well.

HIPAA 3 min
August 5, 2026

HIPAA vs the NIST CSF

HIPAA tells you what you are legally responsible for. The NIST CSF tells you how to organise the work. NIST has published the mapping between them.

HIPAA 3 min
August 5, 2026

HIPAA vs COBIT 2019

COBIT governs the IT that HIPAA regulates. For a large health system that distinction is useful. For a ten-person practice it is overhead with no payoff.

HIPAA 1 min
June 19, 2026

A practical HIPAA compliance checklist

HIPAA looks sprawling until you list it out. For a tech business associate it comes down to a risk analysis, the safeguards, BAAs, and a breach process — done and documented.

HIPAA 1 min
June 19, 2026

The HIPAA minimum necessary standard

HIPAA's minimum necessary rule is least privilege for health data: people see only the PHI they need for their job, nothing more.

HIPAA 1 min
June 19, 2026

HIPAA audit controls

HIPAA wants a record of who touched ePHI. After a breach, that audit log is the difference between "we know what happened" and a guess.

HIPAA 1 min
June 19, 2026

HIPAA encryption requirements

"Addressable" does not mean optional. With ePHI it means: encrypt it, or write a very good explanation of why you did not — and there rarely is one.

HIPAA 1 min
June 19, 2026

The HIPAA Omnibus Rule, explained

The Omnibus Rule is why your SaaS is directly on the hook for HIPAA — it extended liability from covered entities to their business associates and subcontractors.

HIPAA 1 min
June 19, 2026

HIPAA enforcement and penalties

HIPAA fines scale with how culpable you were, and willful neglect is the expensive tier. "We did not know" is only a defence if you genuinely could not have.

HIPAA 1 min
June 19, 2026

HIPAA de-identification: Safe Harbor and Expert Determination

Data that is properly de-identified is no longer PHI — and no longer your HIPAA problem. There are exactly two approved ways to get there.

HIPAA 1 min
June 19, 2026

The HIPAA right of access

The right of access is the HIPAA rule OCR fines most. Patients get their records, promptly, at reasonable cost — and "we were slow" is an expensive answer.

HIPAA 1 min
June 19, 2026

The HIPAA contingency plan

HIPAA's contingency plan is BC/DR for health data, with one part the law makes non-negotiable: you must back up ePHI and be able to restore it.

HIPAA 1 min
June 19, 2026

HIPAA vs SOC 2: do you need both?

HIPAA is the law; SOC 2 is the proof your customers ask for. Handling health data, you often end up doing both — and the work mostly overlaps.

HIPAA 1 min
June 19, 2026

HIPAA vs HITRUST: what is the difference?

HIPAA tells you what to do; HITRUST gives you a certificate that proves you did. In healthcare, big buyers increasingly ask for the certificate.

HIPAA 1 min
June 19, 2026

HIPAA risk management vs risk analysis

The risk analysis finds the risks to ePHI; risk management does something about them. HIPAA requires both, and skipping the second is a classic finding.

HIPAA 1 min
June 19, 2026

HIPAA workforce training

Everyone who touches PHI needs HIPAA training — and the record proving they got it. It is mostly your security awareness program with a health-data lens.

HIPAA 1 min
June 19, 2026

HIPAA incident response

Not every security incident is a HIPAA breach — but you need a process that can tell, fast, because the breach clock starts at discovery.

HIPAA 1 min
June 19, 2026

HIPAA subcontractor BAAs

Your obligations flow downhill. Every subcontractor that touches your customers' PHI needs its own BAA with you — and many vendors miss this.

HIPAA 1 min
June 19, 2026

HIPAA for SaaS and tech companies

You do not have to be a hospital for HIPAA to apply. Touch PHI on behalf of a covered entity and you are a business associate, on the hook.

HIPAA 1 min
June 19, 2026

HIPAA administrative safeguards

The administrative safeguards are most of the Security Rule, and they are about process, not technology — risk analysis, training, access management, and incident response.

HIPAA 1 min
June 19, 2026

HIPAA technical safeguards

The technical safeguards are the engineering half of HIPAA — and they map almost one-to-one onto the access, logging, and encryption controls you already build.

HIPAA 1 min
June 19, 2026

HIPAA physical safeguards

Like ISO 27001's physical controls, most HIPAA physical safeguards are inherited from your cloud provider — but your laptops and your media disposal are still on you.

HIPAA 1 min
June 19, 2026

The HIPAA Breach Notification Rule

HIPAA does not just ask you to prevent breaches — it dictates exactly who you tell, and when, if one happens. Encryption is the safe harbour.

HIPAA 1 min
June 17, 2026

The HIPAA policies and procedures you actually need

HIPAA does not hand you a checklist of documents. Here is the practical policy set that satisfies the Security Rule safeguards.

HIPAA 4 min
May 15, 2026

HIPAA Business Associate Agreements: when you need one and what it must contain

If your software touches PHI on behalf of a covered entity, you are a business associate. A signed BAA is the price of doing the work — and the obligations that come with it are not just contractual.

HIPAA 3 min
May 1, 2026

HIPAA Security Rule: administrative, physical, and technical safeguards

The 18 standards in the Security Rule are the spine of any HIPAA program. Knowing what is required versus addressable is the difference between a clean audit and a tense conversation with OCR.

HIPAA 1 min
March 31, 2026

HIPAA Security Rule risk analysis: what is required

The risk analysis is the foundation of HIPAA Security Rule compliance — and the single most common finding when something goes wrong.

HIPAA 3 min
March 24, 2026

HIPAA Privacy Rule vs Security Rule: what each covers

Engineers tend to default to "the Security Rule" when they say HIPAA. Most procurement reviews and breach notifications start with the Privacy Rule. Knowing the difference matters.