Free Guides
Short, sourced guides to the rules and practices behind the data on this site: what the breach portal shows, what OCR cites, what the performance goals ask for, and what the Security Rule proposal would change.
Read the guide, then watch the data move
Every guide links to the live register or feed it describes. Subscribers get alerts when a vendor or topic they care about shows up, and the lessons OCR published for cases like theirs.
- Breaches and enforcement7 min readReading the HHS Breach Portal
What the HHS OCR breach portal actually shows, what each column means, why records move between the two lists, and how to use it without misreading it.
- Breaches and enforcement9 min readHIPAA Breach Notification in Practice
The four-factor risk assessment, the 60-day clocks, who must be notified and how, and what business associates owe covered entities under the HIPAA Breach Notification Rule.
- Guidance and regulation8 min readThe Security Rule Risk Analysis
Why the risk analysis is the requirement OCR cites most, what an accurate and thorough one contains, and how NIST SP 800-66 maps the process to the rule.
- Guidance and regulation8 min readThe HPH Cybersecurity Performance Goals
The ten essential and ten enhanced goals HHS published for the healthcare and public health sector, what each asks for, and how they relate to HIPAA and 405(d).
- Breaches and enforcement8 min readBusiness Associate Due Diligence
What a business associate agreement must contain, what it cannot substitute for, how to assess vendor risk proportionately, and how to watch vendors after signing.
- Vulnerabilities7 min readBuilding a HIPAA Technology Asset Inventory
How to build the technology asset inventory and network map the Security Rule proposal would require, what to record, and how it turns vulnerability feeds into your own alerts.
- Guidance and regulation9 min readThe 2025 Security Rule Proposal: What Would Change
The main changes in the January 2025 HIPAA Security Rule notice of proposed rulemaking: required specifications, inventories, MFA, encryption, restoration timelines, audits and testing, and where the rule stands.