News
Aesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data BreachAesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data Breach

Your HIPAA basics

Healthcare provider

Doctors, nurses, therapists, pharmacists, and all clinical staff who treat patients

This page is for you. 6 articles in your reading path.

Your reading path

Step 1 of 6, check off articles as you finish (saved in this browser).

  1. 1

    What is HIPAA and why does it apply to my office?

    HIPAA is a federal law protecting patient health information. Here's what it means for your practice in plain English.

  2. 2

    What patient information do we need to protect?

    Understand what counts as protected health information in a real office, not just charts, but conversations, schedules, and more.

  3. 3

    What are we actually allowed to say about patients?

    Confirming an appointment, talking to family, taking a call: what staff can and cannot say about patients under HIPAA, with real front-desk examples.

  4. 4

    HIPAA and Patient Care: Talking to Other Providers

    Coordinating care is allowed; oversharing in public is not. Here's the balance.

  5. 5

    HIPAA and Mental Health: Extra Sensitivity

    Mental health information is still PHI, and some parts get additional protections.

  6. 6

    What should I do if I think something went wrong?

    Wrong fax, strange email, lost phone, or coworker snooping, here's how to respond without making it worse.

Your checklist

Items most relevant to your role. Progress syncs with the full checklist.

See full checklist →

Your scenarios

See all scenarios →

Next steps

When you're ready to go deeper, explore insights and free tools.