The HIPAA Journal is the leading provider of news, updates, and independent advice for HIPAA compliance

HIPAA Advice

Welcome to our HIPAA Compliance Advice section, your go-to resource for clear and concise information on Health Insurance Portability and Accountability Act (HIPAA) compliance. In this section, we provide straightforward answers to common questions related to HIPAA compliance and training. Our short articles offer practical advice, addressing key aspects such as privacy and security rules, breach notifications, risk assessments, and more. Additionally, we offer articles specifically focused on HIPAA training, providing actionable advice on educating your staff and maintaining a culture of compliance within your organization.

Is Wix HIPAA Compliant?

Is Wix HIPAA Compliant? HIPAAJournal.com

Wix is not HIPAA compliant, but it is still possible for covered entities and business associates to use Wix for...

HIPAA And Social Media Guidelines

HIPAA And Social Media

The most important rule for any HIPAA and social media guidelines is that social media content must NEVER include protected...

What is HIPAA Certification?

HIPAA Certification

HIPAA certification is the process in which an independent third party organization audits a medical organization or practice to certify...

How To Become HIPAA Compliant

HIPAA rules and regulations can be very confusing for healthcare professionals tasked with ensuring HIPAA compliance at their organization. 7...

HIPAA Compliance for Email

HIPAA Compliance for Email - HIPAAJournal.com

Standards relevant to HIPAA compliance for email appear throughout the HIPAA Administrative Simplification Regulations – from the applicability and preemption...

HIPAA Compliant Email Providers

HIPAA Compliant Email Providers

HIPAA compliant email providers are vendors of email services that have the capabilities to support HIPAA compliance either as an...

News Categories

Notices

Is it a HIPAA Violation to Email Patient Names?

Is it a HIPAA Violation to Email Patient Names? HIPAAJournal.com

It is not a HIPAA violation to email patient names provided emails do not contain patients’ health information, because patient...

What is a HIPAA Compliant Email Service?

What is a HIPAA Compliant Email Service? HIPAAJournal.com

A HIPAA compliant email service is an email service which includes the necessary capabilities to support compliance with HIPAA and...

What is Required for HIPAA Compliance?

What is Required for HIPAA Compliance? HIPAAJournal.com

What is required for HIPAA compliance is for covered entities and business associates to comply with all applicable standards and...

Who is Responsible for HIPAA Compliance?

Who is responsible for HIPAA compliance? HIPAAJournal.com

Covered entities and business associates are responsible for HIPAA compliance, the compliance of their workforces, and the compliance of any...

How Much Does HIPAA Compliance Cost?

How Much Does HIPAA Compliance Cost? HIPAAJournal.com

Estimates of how much does HIPAA compliance cost have risen sharply since HHS  forecast costs of between $458 and $3,602...

How to Make Microsoft Office 365 HIPAA Compliant

Microsoft Office 365 HIPAA Compliant

Microsoft Office is not HIPAA compliant by default and it is not sufficient to simply agree to the terms of...

Is HoneyBook HIPAA Compliant?

HoneyBook is not HIPAA compliant and cannot be used to create, collect, store, or transmit electronic Protected Health Information if...

HIPAA Violation Fines

HIPAA violation fines can be issued by the Department of Health and Human Services’ Office for Civil Rights (OCR) and...

HIPAA Compliance Software

The purpose of HIPAA compliance software is to provide a framework to guide a HIPAA-covered entity or business associate through...

HIPAA Security Rule Checklist

A HIPAA Security Rule checklist helps covered entities, business associates, and other organizations subject to HIPAA compliance to fulfil the...

HIPAA and HITECH

The relationship between HIPAA and HITECH began in 2009 with the American Recovery and Reinvestment Act – an Act introduced...

Patient Rights Under HIPAA

Patient rights under HIPAA include the ability to access and request corrections to their health information, receive notifications about how...

HIPAA Risk Assessment

A HIPAA risk assessment assesses threats to the privacy and security of PHI, the likelihood of a threat occurring, and...

Is QuickBooks HIPAA Compliant?

QuickBooks is not HIPAA compliant and cannot be used to create, collect, store, or transmit Protected Health Information unless the...

HIPAA Audit Checklist

What is an Internal HIPAA Audit Checklist? An internal HIPAA audit checklist is a document covered entities and business associates...

Guide to HIPAA Safeguards

Compared to the specific HIPAA safeguards of the Security Rule (the Administrative, Physical, and Technical Safeguards), most other references to...

Is Google Workspace HIPAA Compliant?

Google Workspace is HIPAA compliant for services that have “covered functionality”, provided HIPAA-covered organizations subscribe to a Workspace Plan that...

What is PHI in HIPAA?

PHI in HIPAA is an acronym for Protected Health Information – health information that is created, collected, maintained, or transmitted...

HIPAA History

HIPAA History: Why was HIPAA Created? Our HIPAA history lesson starts on August 21, 1996, when the Healthcare Insurance Portability...

HIPAA Compliance for Medical Centers

HIPAA compliance for medical centers consists of complying with the Administrative Simplification standards of the Health Insurance Portability and Accountability...

HIPAA Compliance Regulations

HIPAA Compliance Regulations The latest version of the HIPAA compliance regulations were enacted in the Final Omnibus Rule of 2013....

HIPAA Guidelines on Telemedicine

The HIPAA guidelines for telemedicine start with preparing for the remote delivery of healthcare by auditing procedures, analyzing risks, training...

Is ChatGPT HIPAA Compliant?

ChatGPT is not HIPAA compliant and cannot be used to (for example) summarize patients’ notes or compile letters to patients...

What are HIPAA Covered Entities?

The term HIPAA Covered Entities is most often defined as health plans, healthcare clearinghouses, and healthcare providers that create, receive,...

HIPAA Compliance Tools

HIPAA compliance tools are most often an online service or platform that guides covered entities and business associates through the...

HIPAA Compliance for Pediatricians

HIPAA compliance for pediatricians is complicated by the provisions of the Privacy Rule relating to personal representatives of unemancipated minors...

HIPAA Compliance Plan

A HIPAA compliance plan starts life as a framework for using and disclosing Protected Health Information as required or permitted...

Is iCloud HIPAA Compliant?

iCloud is not HIPAA compliant and cannot be used to store, sync, or share media containing Protected Health Information (PHI)...

What is HIPAA?

HIPAA is an acronym for the Health Insurance Portability and Accountability Act – an Act primarily intended to reform the...

What is a HIPAA Subpoena?

A HIPAA subpoena is a legal document that compels HIPAA-regulated entities to release information such as patient medical records that...

Is Dropbox HIPAA Compliant?

Dropbox is HIPAA compliant and can be used to store, sync, and share Protected Health Information provided organizations subscribe to...

HIPAA Compliance for HR Departments

HIPAA compliance for HR departments consists of understanding what HIPAA standards are applicable to the department and implementing policies and...

HIPAA for Therapists

When discussing HIPAA for therapists, it is important to be aware that a therapist can be a solo Covered Entity,...

HIPAA Compliance Solutions

If you conduct an Internet search for HIPAA compliance solutions, you will get thousands of results. Unfortunately most HIPAA compliance...

Is WebEx HIPAA Compliant?

Webex is HIPAA compliant and, provided policies relating to disclosures are complied with, can be used to disclose PHI during...

HIPAA Permitted Disclosures

The HIPAA permitted disclosures of PHI are summarized in §164.502 of the Privacy Rule, with more details about each type...

HIPAA Consulting

HIPAA consulting firms are most often firms of compliance experts with a deep understanding of the Health Insurance Portability and...

When Was HIPAA Enacted?

HIPAA was enacted at various stages following the passage of the Health Insurance Portability and Accountability Act in 1996, with...

HIPAA Training for Dental Offices

HIPAA training in dental offices is mandatory for all staff who come into contact with Protected Health Information (PHI), requiring...

Is Box HIPAA Compliant?

Box is HIPAA compliant and can be used to store, manage, and share files and folders containing Protected Health Information...

What Does PHI Stand For?

PHI stands for Protected Health Information – a term is commonly referred to in connection with the Health Insurance Portability...

HIPAA Compliance for SaaS

HIPAA compliance for SaaS consists of ensuring the software product or service complies with all applicable Security Rule standards, and...

Is SurveyMonkey HIPAA Compliant?

SurveyMonkey is HIPAA compliant and – when organizations subscribe to an Enterprise Plan and agree to SurveyMonkey’s Business Associate Agreement...

HIPAA Compliance for Hospitals

There is no one-size-fits-all approach HIPAA compliance for hospitals because of the many different types of hospitals, the different types...

HIPAA Compliance for Optometrists

HIPAA compliance for optometrists is mandatory for most optometry professionals; however, the responsibility for HIPAA compliance can vary depending on...

HIPAA Exceptions

The text of the Healthcare Insurance Portability and Accountability Act is full of HIPAA exceptions – adding to the complexity...

HIPAA Explained

Our HIPAA explained article provides information about the Health Insurance Portability and Accountability Act (HIPAA) and the Administrative Simplification Regulations...

HIPAA Compliance for Dentists

HIPAA compliance for dentists consists of complying with the applicable standards of the HIPAA Administrative Simplifications Regulations, state regulations with...

HIPAA Privacy Rule

The HIPAA Privacy Rule is a federal floor of privacy standards that protect individual’s health information and other identifying information...

What Does HIPAA Stand For?

The acronym HIPAA stands for Health Insurance Portability and Accountability Act of 1996 and that led to the development of...

Does HIPAA Apply to Employers?

HIPAA applies to employers in certain circumstances and, although HIPAA does not protect individually identifiable health information maintained by a...

What Does HIPAA Cover?

HIPAA – via the Administrative Simplification Regulations – covers the privacy of individually identifiable health information when it is created,...

Who Does HIPAA Apply To?

HIPAA applies to everyone as individuals inasmuch as everyone has personally identifiable health information that they have the right to...

Why is HIPAA Important?

HIPAA is important because, due to the passage of the Health Insurance Portability and Accountability Act, the Department of Health...

What is a HIPAA Violation?

A HIPAA violation refers to the failure to comply with HIPAA rules, which can include unauthorized access, use, or disclosure...

HIPAA Security Officer

All Covered Entities and Business Associates are required by 45 CFR 164.308 – the Administrative Safeguards of the HIPAA Security Rule...

What is the HITECH Act?

The Health Information Technology for Economic and Clinical Health Act or HITECH Act is the part of the American Recovery...

What Are Covered Entities Under HIPAA?

Covered entities under HIPAA are individuals, institutions, or organizations that transmit protected health information electronically in transactions for which the...

What is the Purpose of HIPAA?

The purpose of HIPAA was originally to ensure more employees could continue to receive health insurance coverage when they were...

HIPAA Retention Requirements

The HIPAA retention requirements are that certain types of documents must be maintained for six years from the date of...

HIPAA Compliance for Pharmacies

HIPAA compliance for pharmacies can include compliance with all the Administrative Simplification Regulations in addition to the Privacy, Security, and...

What is Protected Health Information?

Protected Health Information is an individual’s health, treatment, or payment for treatment information – and any information maintained in the...

What is Considered PHI Under HIPAA?

Under HIPAA PHI is considered to be an individual’s health, treatment, and payment information, and any further information maintained in...

What is Texas HB300?

Texas HB300 is a bill passed by the Texas legislature in 2011 that updates Chapter 181 of the Texas Health...

Florida HIPAA Laws

Florida HIPAA laws are the laws that apply in Florida to Covered Entities and Business Associates that preempt, or are...

Psychotherapy Notes and HIPAA

The relationship between psychotherapy notes and HIPAA is more complex than with most other types of health information because, under...

HIPAA Compliant Hosting

HIPAA compliant hosting is a service most often provided by cloud service providers that enables covered entities and business associates...

HITECH Compliance Checklist

Any businesses subject to HIPAA are advised to use a HITECH compliance checklist to help ensure they meet the requirements...

Who Enforces HIPAA?

HIPAA is enforced by multiple federal agencies including the Department of Health and Human Services, the Department of Labor, the...

HIPAA Policies and Procedures

HIPAA policies and procedures are comprehensive guidelines that healthcare organizations must implement and regularly update to ensure the confidentiality, integrity,...

Can HIPAA be Waived?

Although HIPAA cannot be waived in its entirety, some provisions of the Privacy Rule can be waived in certain circumstances...

Is G Suite HIPAA Compliant?

G Suite is HIPAA compliant provided organizations subscribe to a Google Workspace Business Account that includes the capabilities to support...

HIPAA Compliance for Hospices

HIPAA compliance for hospices has to take into account that many members of the workforce may be volunteers or clergy...

HIPAA Security Rule

The HIPAA Security Rule is a subpart of the HIPAA Privacy Rule inasmuch as the Privacy Rule applies to all...

HIPAA Compliance for Nurses

Generally, HIPAA compliance for nurses is considered to mean adhering to policies and procedures developed by an organization’s HIPAA Privacy...

Is Gossip a HIPAA Violation?

Gossip can be a HIPAA violation – potentially resulting in a sanction for the gossiper – depending on who is...

HIPAA Compliant Remote Access Software

HIPAA compliant remote access software provides HIPAA-covered entities and their busines associates with a secure way of remotely accessing systems...

HIPAA Disclosure Accounting

Section §164.528 of the Privacy Rule is better known as the HIPAA disclosure accounting standard which states an individual has...

HIPAA Compliance for Call Centers

HIPAA compliance for call centers that operate as business associates for covered entities consists of complying with the Security and...

Is Google Docs HIPAA Compliant?

Google Docs is HIPAA compliant provided that, before using the service to create, receive, maintain, or transmit PHI, organizations subscribe...

Does HIPAA Apply to Schools?

HIPAA applies to schools in certain circumstances, such as when a school is a private school, when it provides medical...

HIPAA Rules for Dentists

The HIPPA Rules for dentists are the same as for any other healthcare provider that qualifies as a HIPAA covered...

HIPAA Compliant SFTP Server

If FTP is required to transfer protected health information, healthcare providers, health plans, healthcare clearinghouses and business associates of HIPAA-covered entities...

HIPAA for MSPs

HIPAA for MSPs is a complicated subject to approach, as not only do MSPs count as Business Associates if they...

HIPAA Continuity of Care

HIPAA continuity of care is when ongoing care is provided within a healthcare organization or Organized Health Care Arrangement, or...

HITECH Act and Meaningful Use

When the HITECH ACT and Meaningful Use incentive program was enacted in 2009, it was described as “the most important...

Is Airdroid Business HIPAA Compliant?

Airdroid is a HIPAA-compliant all-in-one Android Mobile Device Management (MDM) solution for small businesses and enterprises that can be used...

Is WhatsApp HIPAA Compliant?

WhatsApp is not HIPAA compliant and should not be used for receiving, storing, or sending Protected Health Information unless a...

When Did HIPAA Take Effect?

HIPAA took effect in various stages following the passage of the Health Insurance Portability and Accountability Act in 1996, with...

What is HIPAA Enforcement Discretion?

HIPAA enforcement discretion occurs when the Secretary for Health and Human Services (HHS) announces the Department will exercise discretion in...

Is Paubox HIPAA Compliant?

Paubox is HIPAA compliant and as an email encryption solution supports HIPAA compliance and can be used by Covered Entities...

Is Qualtrics HIPAA Compliant?

The issue with answering the question is Qualtrics HIPAA compliant is that, although the “experience management” platform appears to support...

HIPAA Compliance Guidelines

The HIPAA compliance guidelines provide a comprehensive starting point for HIPAA compliance in three distinct sections. Part One: An examination...

HIPAA Compliance for Dermatologists

A number of sources discussing HIPAA compliance for dermatologists suggest all dermatologists are required to comply with HIPAA because they...

Does HIPAA Apply to Minors?

The privacy standards of HIPAA apply to minors inasmuch as a minor’s health information is subject to the same Privacy...

What Are HIPAA Laws?

The main objective of HIPAA law is to protect the privacy of an individuals’ health information while at the same...

What is a HIPAA Security Incident?

Misunderstandings can sometimes exist with the distinction between a HIPAA security incident and the definition of a HIPAA breach. Although...

HIPAA Privacy Laws

The Objectives of the HIPAA Privacy Laws The HIPAA privacy laws were first enacted in 2002 with the objective of...

What Does HIPAA Mean?

HIPAA stands for the Health Insurance Portability and Accountability Act – an Act passed by Congress in 1996 with the...

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist