News
Do I Need a BAA With My Vendor? A Plain-English Guide to Which Vendors Require a Business Associate Agreement · Business AssociatesYour 'Success Story' Program Just Cost This Rehab Facility $182,000: The Cadia Healthcare HIPAA Settlement · OCR EnforcementAn Accounting Firm Just Paid a HIPAA Fine: BST and Co. CPAs and What It Means for Professional Services Firms · OCR Enforcement15 Million Records, a $10,000 Fine, and a Company That No Longer Exists: The MMG Fusion Story · OCR EnforcementOCR Creates Religious Discrimination Units: What the Restructuring Means for HIPAA Enforcement · Rule UpdateOCR Director: The Cost of Doing Nothing Is Very High · Rule UpdateHIPAA Victims May Soon Receive a Share of OCR Fines: What the Proposed Compensation Program Means · Rule UpdateOCR Restructured: Three New Divisions and What It Means for HIPAA Enforcement · Rule UpdateRehab Center Pays $103,000 After Phishing Attack: OCR's 11th Risk Analysis Enforcement Action · OCR EnforcementConcentra Pays $112,500 After Patient Made Six Records Requests Over 13 Months · OCR EnforcementHIPAA Security Rule Final Rule: May Deadline Passes With No Announcement · Rule UpdateDo I Need a BAA With My Vendor? A Plain-English Guide to Which Vendors Require a Business Associate Agreement · Business AssociatesYour 'Success Story' Program Just Cost This Rehab Facility $182,000: The Cadia Healthcare HIPAA Settlement · OCR EnforcementAn Accounting Firm Just Paid a HIPAA Fine: BST and Co. CPAs and What It Means for Professional Services Firms · OCR Enforcement15 Million Records, a $10,000 Fine, and a Company That No Longer Exists: The MMG Fusion Story · OCR EnforcementOCR Creates Religious Discrimination Units: What the Restructuring Means for HIPAA Enforcement · Rule UpdateOCR Director: The Cost of Doing Nothing Is Very High · Rule UpdateHIPAA Victims May Soon Receive a Share of OCR Fines: What the Proposed Compensation Program Means · Rule UpdateOCR Restructured: Three New Divisions and What It Means for HIPAA Enforcement · Rule UpdateRehab Center Pays $103,000 After Phishing Attack: OCR's 11th Risk Analysis Enforcement Action · OCR EnforcementConcentra Pays $112,500 After Patient Made Six Records Requests Over 13 Months · OCR EnforcementHIPAA Security Rule Final Rule: May Deadline Passes With No Announcement · Rule Update

All insights

HIPAA compliance insights

Deep dives mapped to the Privacy, Security, and Breach Notification Rules, written for operators who need plain-English explanations, CFR citations, and practical checklists.

Try: BAA, Security Rule, breach notification, PHI, OCR enforcement

Rule Update

OCR Director: The Cost of Doing Nothing Is Very High

OCR Acting Director Paula Stannard used her HIMSS 2026 address to defend the proposed HIPAA Security Rule update, warning that weak cybersecurity controls have enabled a wave of ransomware attacks that harm patients and that inaction is not a cost-free option.

Updated May 20, 20264 min read

OCR Enforcement

Warby Parker Fined $1.5 Million by OCR: What Retailers With Health Plans Must Know

OCR imposed a $1.5 million civil money penalty on Warby Parker in February 2025 for HIPAA Security Rule violations following credential stuffing attacks. The case is a landmark warning for any non-healthcare company that operates an employer health plan or handles employee health data.

Updated May 12, 20266 min read

Data Breach

How to Respond to a HIPAA Breach — A Step-by-Step Guide

A complete guide to HIPAA breach response — from the moment of discovery through notification to HHS, individuals, and media. Includes the four-factor risk assessment, deadlines, and role-specific responsibilities.

Updated May 11, 202612 min read

Data Breach

HIPAA Breach Notification Overview

Overview of the HIPAA Breach Notification Rule — what triggers notification, who must be notified, and when. See our complete guide for full coverage.

Updated May 11, 20261 min read

Rule Update

OCR Begins Enforcing Part 2: What Behavioral Health Providers Must Know

As of February 16, 2026, OCR began civil enforcement of the updated Part 2 regulations protecting substance use disorder patient records. Behavioral health providers face a new compliance obligation that runs alongside and partially overlaps with HIPAA.

Updated May 3, 20266 min read

Security Rule

The HIPAA Security Rule: A Complete Guide for 2026

Everything covered entities and business associates need to know about the HIPAA Security Rule: administrative, physical, and technical safeguards explained.

Updated Apr 21, 20266 min read

SaaS & Technology

HIPAA for SaaS and technology vendors

When HIPAA applies to software companies, how BAAs fit product roadmaps, and which Security Rule themes customers audit most often.

Updated Apr 13, 20264 min read

Security Rule

HIPAA Security Rule overview for compliance teams

A structured overview of the HIPAA Security Rule, administrative, physical, and technical safeguards, with CFR anchors and practical implementation notes.

Updated Apr 12, 20265 min read

Privacy Rule

What counts as PHI under HIPAA?

Understand Protected Health Information (PHI), the 18 identifiers, limited data sets, and the Safe Harbor method for de-identification, with regulatory citations.

Updated Apr 10, 20265 min read