HIPAA Fundamentals
The building blocks of HIPAA compliance—from getting started, to managing documentation and understanding key regulatory concepts.
How to Become HIPAA Compliant
7 Steps for HIPAA Compliance from the HHS’s “Seven Fundamental Elements of an Effective Compliance Program.” This will help you…
Small Practice Owners Guide to HIPAA Compliance Programs
How to run your HIPAA program as the practice owner, you carry the responsibility for HIPAA compliance regardless of who…
Do You Know the HIPAA Obligations of Small Practices?
Small medical practices have the same HIPAA obligations as large organizations.
Why You Don’t Need to Understand HIPAA to Make Your Practice HIPAA Compliant
HIPAA when you don't know HIPAA.
How to Choose HIPAA Compliance Software
The best HIPAA compliance software runs your HIPAA program and reduces the administrative burden and lessens the likelihood of an…
Building a HIPAA Compliance Program as a Dental Office Manager
HIPAA advice for dental practice managers.
HIPAA Compliance Made Easy for Small Practices
What HIPAA compliance requires from a small practice.
Clinical Managers and Directors and Ongoing HIPAA Compliance Programs in Small Practices
7 steps for small practice HIPAA compliance
Building a HIPAA Compliance Program as a Practice Administrator in a Small Practice
HIPAA compliance steps for small practices.
How to Get Small Practices HIPAA Compliant in a Few Hours
HIPAA Compliance software can make HIPAA Compliance fast and easy.
HIPAA Compliance for HR Managers and Directors in Small Medical Practices
HIPAA priorities for dental HR managers.
Take the Guesswork out of Small Practice HIPAA Compliance
How to make HIPAA compliance programs reliable.
EMR Practice Management Software Buyer’s Guide
Selecting EMR practice management software requires evaluating scheduling, specialty support, charting flexibility, billing, patient engagement tools, support, integrations, future product…
HIPAA Compliant Email: Best Practice To Avoid Violations & Breaches
This practical guide to HIPAA compliant email services explains how to ensure 100% compliance by avoiding the common misunderstandings and…
Director of Operations and HIPAA Compliance Oversight in Small Practices
8 HIPAA program management management priorities.
What is Medical Practice Management Software?
Medical practice management software is a clinic operations system that helps a medical practice schedule patients, manage medical billing and…
The HIPAA Journal Launches the Gold Standard in HIPAA Training for Employees
Comprehensive HIPAA training courses.
What is the Best EMR for Small Practices in 2026?
Whether you are starting a new practice or looking to grow your existing business, choosing the right electronic medical record…
Why Staff in Small Medical Practices need Additional Specially-Designed HIPAA Training
HIPAA training for small practices.
How Much Does an EMR for a Small Practice Cost?
For a small practice, EMR software cost commonly totals $3,000 to $25,000 in the first year and $2,000 to $15,000…
HIPAA Regulations
In-depth articles on the implementation of HIPAA rules and standards.
Take the Guesswork out of HIPAA Compliance for Small Practices
Removing guesswork from HIPAA compliance means replacing assumptions about what a practice has covered with a documented process that maps…
Why Healthcare Staff Need HIPAA Training for Social Media
Avoiding social media violations by staff.
Why Your HIPAA Business Associate Should Invest in HIPAA Training
Why training protects Covered Entities.
HIPAA Security Rule
The HIPAA Security Rule contains the security standards for the protection of electronic Protected Health Information (ePHI) that apply when…
What is HIPAA Incident Management?
All HIPAA covered entities and business associates are required to have procedures in place for identifying and responding to suspected…
The HIPAA Minimum Necessary Rule Standard
The HIPAA minimum necessary rule standard applies to uses and disclosures of PHI that are permitted under the HIPAA Privacy…
What Are Covered Entities Under HIPAA?
Examples of covered entities under HIPAA include qualifying health plans, health care clearinghouses, and healthcare providers that transmit Protected Health…
HIPAA Continuity of Care
HIPAA continuity of care is when ongoing care is provided within a healthcare organization or Organized Health Care Arrangement, or…
What are the HIPAA Breach Notification Requirements?
The HIPAA breach notification requirements are that HHS’ Office for Civil Rights and individuals whose unsecured Protected Health Information (PHI)…
What is HIPAA Authorization?
A HIPAA authorization is a form that must be completed by a patient or a health plan member when a…
Mandatory Medical Privacy Regulations in California You Must Comply With
California medical privacy laws.
Mandatory Medical Privacy Regulations in Texas You Must Enforce Across Your Organization
In addition to HIPAA and the Texas Medical Records Privacy Act/HB300, several other laws apply to the privacy and security…
What is Considered PHI Under HIPAA?
Under HIPAA PHI is considered to be an individual’s health, treatment, and payment information, and any related information maintained in…
HIPAA Privacy Rule
The HIPAA Privacy Rule provides a federal floor of privacy standards that protects individuals’ health information and other identifying information…
Can Medical Records be Subpoenaed?
Medical records can be subpoenaed because every type of record can be subpoenaed, and a more relevant question would be…
HIPAA Social Media Guidelines
An organization’s HIPAA social media guidelines should not only eliminate misunderstandings about online disclosures of Protected Health Information but also…
HIPAA Updates and HIPAA Changes in 2026
HIPAA updates and changes happen more frequently than many people are aware of because of the nature of the updates…
HIPAA Disclosure Accounting
Section §164.528 of the Privacy Rule is better known as the HIPAA disclosure accounting standard and states that an individual…
What is the OIG Stark Law?
The OIG Stark Law in healthcare is the section of the Social Security Act that prohibits physicians from referring Medicare…
When does State Privacy Law Supersede HIPAA?
State privacy law supersedes HIPAA when a state law provides greater privacy protections for individually identifiable health information than HIPAA…
Why Covered Entities Should Provide HIPAA Training to All Members of the Workforce
The provision of HIPAA training is not only a regulatory requirement. It is also an investment. Effective HIPAA training reduces…
Effective HIPAA Policy Management
Effective management of HIPAA policies is one of the most constructive ways in which organizations can support HIPAA compliance by…
HIPAA Rules and Regulations
The HIPAA rules and regulations are the standards and implementation specifications adopted by federal agencies to streamline healthcare transactions and…
What is the HITECH Act?
The Health Information Technology for Economic and Clinical Health Act or HITECH Act is the part of the American Recovery…
Can Doctors Share Patient Information with Other Doctors?
Doctors can share patient information with other doctors provided the disclosure complies with the HIPAA Privacy Rule – and a…
HIPAA Certification for Mental Health Professionals
HIPAA certification for mental health professionals is a practical way to prove you understand how to protect Protected Health Information…
HIPAA Permitted Disclosures
The HIPAA permitted disclosures of PHI are summarized in §164.502 of the Privacy Rule, with more details about each type…
What are the Physical Safeguards of HIPAA’s Security Rule?
The Physical Safeguards of HIPAA’s Security Rule are the standards and implementation specifications that must be applied when applicable “to…
The 7 HIPAA Compliance Rules for Covered Entities
The 7 HIPAA compliance rules for covered entities are the rules within the HIPAA Administrative Simplification Regulations that covered entities…
HIPAA Transactions and Code Sets Rules
The HIPAA transactions and code sets rules have the objective of replacing non-standard descriptions of healthcare activities with standard formats…
News Updates
HIPAA updates and news, plus the latest data breaches and fines.
Requirements by Practice Type
Guidance on HIPAA compliance across different medical specialties.
- HIPAA Compliance for Behavioral Health
- HIPAA Compliance for Dentists
- HIPAA Compliance for Dermatologists
- HIPAA Compliance for Home Health Care
- HIPAA Compliance for Medical Centers
- HIPAA Compliance for Optometrists
- HIPAA Compliance for Pediatricians
- HIPAA Compliance for Pharmacies
- HIPAA Compliance for Psychiatrists
- HIPAA Compliance for Psychologists
- HIPAA Compliance for Therapists
HIPAA Breaches & Penalties
Detailed analysis and examples of data breaches to help you understand how to avoid penalties.
Memorial Healthcare Services Settles Pixel Litigation
Memorial Healthcare Services, a nonprofit healthcare provider serving patients in Southern California, has agreed to settle a class action lawsuit…
Serviceaide Pays $1.8 Million to Settle Data Breach Litigation
Serviceaide, Inc., a provider of AI-powered solutions to boost productivity and enhance service delivery, has agreed to pay $1.8 million…
Allina Health System to Pay $12.5 Million to Settle Pixel Litigation
Allina Health System, a nonprofit health system based in Minneapolis, Minnesota, that serves patients in Minnesota and Western Wisconsin, has…
Get Our Free Guide To
HIPAA Compliance Software
Learn Why HIPAA Compliance Software Is Perfect For Small Medical Practices
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Spencer Gifts Pays $450,000 Penalty to Resolve HIPAA Failures
The national retail company Spencer Gifts LLC has agreed to a $450,000 settlement to resolve alleged violations of the HIPAA…
Delta Dental Fined $2.25 Million Over 2023 MOVEit Transfer Hack
Delta Dental Insurance and Delta Dental of New York (Delta Dental) have agreed to pay a fine of $2.25 million…
South Texas Oncology and Hematology Pays $1.1M to Settle Data Breach Lawsuit
South Texas Oncology and Hematology, a San Antonio, TX-based provider of leading-edge cancer treatment and other medical services, has settled…
OCR Fines Four Regulated Entities for HIPAA Violations That Led to Ransomware Attacks
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced four financial penalties to…
Ransomware Attack on Hospital Caribbean Medical Center Affects 92,000 Individuals
A ransomware attack on Hospital Caribbean Medical Center in Puerto Rico has affected up to 92,000 individuals. Data breaches have…
Illinois Bone and Joint Institute Settles Class Action Data Breach Lawsuit for $4M
Illinois Bone and Joint Institute (IBJI), one of the largest orthopedic group practices in Illinois, has agreed to settle a…
Anne Arundel Dermatology Pays $2.4M to Settle Data Breach Lawsuit
Anne Arundel Dermatology has agreed to pay $2,400,000 to settle a consolidated class action lawsuit stemming from a cybersecurity incident…
Cardiovascular Consultants Pays $3.85M to Settle Data Breach Litigation
Cardiovascular Consultants in Arizona has settled a class action lawsuit stemming from a 2023 data breach involving the protected health…
Excelsior Orthopaedics; Buffalo Surgery Center Pay $2.4 Million to Settle Data Breach Lawsuit
A settlement has been reached to resolve class action data breach litigation against Excelsior Orthopaedics and Buffalo Surgery Center. The…
Top of the World Ranch Treatment Center Settles Alleged Risk Analysis HIPAA Violation
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its first financial penalty of…
New York Attorney General Fines Capital Region Orthopedic Practice $500K for 2023 Data Breach
Orthopedics NY LLP (aka OrthoNY; OrthopedicsNY), a New York orthopedic medicine practice, has been fined $500,000 by the New York…
AccuCare Home Health Services Pays $20,000 Fine for Employing Excluded Individual
The Department of Health and Human Services Office of Inspector General (HHS-OIG) has agreed to a $20,000 settlement with AccuCare…
Delaware Rehab Facilities Settle Social Media and Breach Notification HIPAA Violations
A $182,000 settlement has been agreed between the HHS’ Office for Civil Rights and five Delaware healthcare providers to resolve…
Two Disability Service Providers Announce Data Breaches Affecting 8,100 Patients
Two providers of disability services have announced security incidents. The cyberattacks on Reimagine Network in California and the Center for…
FTC Imposes $1.9 Million Penalty on Evoke Wellness for Deceptive Marketing Campaign
The Federal Trade Commission (FTC) has proposed a $1.9 million settlement to resolve claims that Evoke Wellness, a Florida-based substance…
Phishing Attack and Late Breach Notifications Lead to $600K HIPAA Fine for PIH Health
The HHS’ Office for Civil Rights (OCR) has announced its 6th financial penalty of the year to resolve alleged violations…
HHS-OIG Fines Two Healthcare Providers for EMTALA Violations
The Department of Health and Human Services Office of Inspector General (HHS-OIG) has entered into settlement agreements with two healthcare…
Oregon Health & Science University Pays $200,000 Penalty for HIPAA Right of Access Failure
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has imposed its second financial penalty…
Examples of Avoidable HIPAA Violations by Employers
Examples of HIPAA violations by employers are easy to find because almost every avoidable HIPAA violation is indirectly attributable to…
OCR Phishing Investigation Uncovers HIPAA Training Failure; Children’s Hospital Colorado Fined $548,265
The HHS’ Office for Civil Rights (OCR) has announced another civil monetary penalty for a HIPAA-regulated entity to address non-compliance…
Failure to Terminate Access Rights Results in $1.19 Million HIPAA Fine
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has imposed a $1.19 million civil…
Californian Mental Health Center Fined $100,000 for HIPAA Violation
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has imposed a $100,000 civil monetary penalty…
$500,000 HIPAA Penalty for South Dakota Plastic Surgery Practice
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has agreed to settle an investigation of…
OCR Imposes $240,000 HIPAA Fine on Californian Healthcare Provider
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has imposed a $240,000 civil monetary penalty…
American Medical Response Pays $115K Civil Monetary Penalty for HIPAA Violation
American Medical Response (AMR), a private ambulance company, has paid a $115,200 civil monetary penalty to the HHS’ Office for…
OSHA Proposes $163K Fine for Home Health Agency After Murder of Home Health Worker
The Occupational Safety and Health Administration (OSHA) has proposed a $163, 627 fine for a home healthcare provider that the…
FTC Fines Mental Health Company Cerebral $7.1 Million for Consumer Privacy Violations
The Federal Trade Commission (FTC) has fined the mental health startup Cerebral $7.1 million for consumer privacy violations and deceptive…
Refuah Health Center Pays $450K HIPAA Fine; Agrees to $1.2 Million Cybersecurity Investment
New York Attorney General Letitia James has announced that an agreement has been reached with Refuah Health Center Inc. to…
St. Joseph’s Medical Center Pays $80,000 HIPAA Fine for PHI Disclosure to a Reporter
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its 11th HIPAA penalty of…
OCR Fines Arkansas Business Associate $350,000 for Impermissibly Disclosing ePHI
The HHS’ Office for Civil Rights (OCR) has agreed to settle a HIPAA investigation of an Arkansas business associate that…
Pittsburgh Counselor Fined $15,000 for HIPAA Right of Access Violation
The HHS’ Office for Civil Rights has announced its 44th enforcement action under its HIPAA Right of Access initiative with…
OCR Fines California Dental Practice for PHI Disclosures on Yelp
The HHS’ Office for Civil Rights (OCR) has announced a settlement has been reached with a Californian dental practice to…
3 Dental Practices Fined for HIPAA Right of Access Violations
The HHS’ Office for Civil Rights (OCR) has agreed to settle three HIPAA investigations of potential HIPAA Right of Access…
New Jersey Fines Hackensack Healthcare Providers for PHI Breach and HIPAA Violations
The New Jersey Division of Consumer Affairs has agreed to settle a data breach investigation that uncovered violations of the…
Adventist Health Physicians Network Fined $40,000 for Privacy Breach
Adventist Health Physicians Network in Simi Valley, California has been ordered to pay $40,000 in civil momentary penalties by the…

