HIPAA — practitioner guides.
25 articles on HIPAA, ordered newest first. From the SentinelPanda team.
A practical HIPAA compliance checklist
HIPAA looks sprawling until you list it out. For a tech business associate it comes down to a risk analysis, the safeguards, BAAs, and a breach process — done and documented.
The HIPAA minimum necessary standard
HIPAA's minimum necessary rule is least privilege for health data: people see only the PHI they need for their job, nothing more.
HIPAA audit controls
HIPAA wants a record of who touched ePHI. After a breach, that audit log is the difference between "we know what happened" and a guess.
HIPAA encryption requirements
"Addressable" does not mean optional. With ePHI it means: encrypt it, or write a very good explanation of why you did not — and there rarely is one.
The HIPAA Omnibus Rule, explained
The Omnibus Rule is why your SaaS is directly on the hook for HIPAA — it extended liability from covered entities to their business associates and subcontractors.
HIPAA enforcement and penalties
HIPAA fines scale with how culpable you were, and willful neglect is the expensive tier. "We did not know" is only a defence if you genuinely could not have.
HIPAA de-identification: Safe Harbor and Expert Determination
Data that is properly de-identified is no longer PHI — and no longer your HIPAA problem. There are exactly two approved ways to get there.
The HIPAA right of access
The right of access is the HIPAA rule OCR fines most. Patients get their records, promptly, at reasonable cost — and "we were slow" is an expensive answer.
The HIPAA contingency plan
HIPAA's contingency plan is BC/DR for health data, with one part the law makes non-negotiable: you must back up ePHI and be able to restore it.
HIPAA vs SOC 2: do you need both?
HIPAA is the law; SOC 2 is the proof your customers ask for. Handling health data, you often end up doing both — and the work mostly overlaps.
HIPAA vs HITRUST: what is the difference?
HIPAA tells you what to do; HITRUST gives you a certificate that proves you did. In healthcare, big buyers increasingly ask for the certificate.
HIPAA risk management vs risk analysis
The risk analysis finds the risks to ePHI; risk management does something about them. HIPAA requires both, and skipping the second is a classic finding.
HIPAA workforce training
Everyone who touches PHI needs HIPAA training — and the record proving they got it. It is mostly your security awareness program with a health-data lens.
HIPAA incident response
Not every security incident is a HIPAA breach — but you need a process that can tell, fast, because the breach clock starts at discovery.
HIPAA subcontractor BAAs
Your obligations flow downhill. Every subcontractor that touches your customers' PHI needs its own BAA with you — and many vendors miss this.
HIPAA for SaaS and tech companies
You do not have to be a hospital for HIPAA to apply. Touch PHI on behalf of a covered entity and you are a business associate, on the hook.
HIPAA administrative safeguards
The administrative safeguards are most of the Security Rule, and they are about process, not technology — risk analysis, training, access management, and incident response.
HIPAA technical safeguards
The technical safeguards are the engineering half of HIPAA — and they map almost one-to-one onto the access, logging, and encryption controls you already build.
HIPAA physical safeguards
Like ISO 27001's physical controls, most HIPAA physical safeguards are inherited from your cloud provider — but your laptops and your media disposal are still on you.
The HIPAA Breach Notification Rule
HIPAA does not just ask you to prevent breaches — it dictates exactly who you tell, and when, if one happens. Encryption is the safe harbour.
The HIPAA policies and procedures you actually need
HIPAA does not hand you a checklist of documents. Here is the practical policy set that satisfies the Security Rule safeguards.
HIPAA Business Associate Agreements: when you need one and what it must contain
If your software touches PHI on behalf of a covered entity, you are a business associate. A signed BAA is the price of doing the work — and the obligations that come with it are not just contractual.
HIPAA Security Rule: administrative, physical, and technical safeguards
The 18 standards in the Security Rule are the spine of any HIPAA program. Knowing what is required versus addressable is the difference between a clean audit and a tense conversation with OCR.
HIPAA Security Rule risk analysis: what is required
The risk analysis is the foundation of HIPAA Security Rule compliance — and the single most common finding when something goes wrong.
HIPAA Privacy Rule vs Security Rule: what each covers
Engineers tend to default to "the Security Rule" when they say HIPAA. Most procurement reviews and breach notifications start with the Privacy Rule. Knowing the difference matters.