News
TheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data BreachQilin Ransomware Group Claims Attack on Hillebrand Home Health · Data BreachLake Region Healthcare Discloses May 2025 Network Intrusion Exposing Patient SSNs, Medical Records, and Financial Data · Data BreachFamily Health Centers of Southern Indiana Discloses January 2026 Network Intrusion Exposing Patient PHI Including Social Security Numbers · Data BreachInterlock Ransomware Group Claims 540 GB from Texas Hearing Institute, Nearly 30,000 Pediatric Patients Notified · Data BreachWisconsin Department of Health Services Reports HIPAA Breach Affecting 8,157 Medicaid Recipients After Benefits Letters Mailed to Wrong Addresses · Data BreachAmazon's One Medical Seniors Hit by ShinyHunters Extortion Group: 8.8TB of Legacy Patient Data at Risk · Data BreachTheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data BreachQilin Ransomware Group Claims Attack on Hillebrand Home Health · Data BreachLake Region Healthcare Discloses May 2025 Network Intrusion Exposing Patient SSNs, Medical Records, and Financial Data · Data BreachFamily Health Centers of Southern Indiana Discloses January 2026 Network Intrusion Exposing Patient PHI Including Social Security Numbers · Data BreachInterlock Ransomware Group Claims 540 GB from Texas Hearing Institute, Nearly 30,000 Pediatric Patients Notified · Data BreachWisconsin Department of Health Services Reports HIPAA Breach Affecting 8,157 Medicaid Recipients After Benefits Letters Mailed to Wrong Addresses · Data BreachAmazon's One Medical Seniors Hit by ShinyHunters Extortion Group: 8.8TB of Legacy Patient Data at Risk · Data Breach

Your HIPAA basics

Practice manager

Office managers, practice administrators, and those responsible for running the practice

This page is for you. 7 articles in your reading path.

Your reading path

Step 1 of 7, check off articles as you finish (saved in this browser).

  1. 1

    What is HIPAA and why does it apply to my office?

    HIPAA is a federal law protecting patient health information. Here's what it means for your practice in plain English.

  2. 2

    What patient information do we need to protect?

    Understand what counts as protected health information in a real office, not just charts, but conversations, schedules, and more.

  3. 3

    Your HIPAA basics checklist

    How to use medcomply.ai's plain-English checklist to see gaps before they become investigations.

  4. 4

    Do we need a Privacy Officer?

    Yes, someone must own HIPAA privacy for your organization. At a small practice, that can be a part-time role.

  5. 5

    Do we need to sign anything? Business Associate Agreements explained simply

    A plain-English look at BAAs, the contracts you need with vendors that touch patient information.

  6. 6

    What HIPAA training does our staff actually need?

    Everyone who touches patient information needs training, but the law leaves room for how you deliver it.

  7. 7

    What should I do if I think something went wrong?

    Wrong fax, strange email, lost phone, or coworker snooping, here's how to respond without making it worse.

Your checklist

Items most relevant to your role. Progress syncs with the full checklist.

See full checklist →

Your scenarios

See all scenarios →

Next steps

When you're ready to go deeper, explore insights and free tools.