How to Respond to a Credential Stuffing Attack on Your 340B Portal
Credential Stuffing Definition. Credential stuffing is an automated attack where adversaries use...
42 CFR Part 2 and HIPAA for Addiction Counseling: A Practical Compliance Guide
42 CFR Part 2 Overview. Purpose and scope. 42 CFR Part 2 establishes federal rules for Substanc...
HIPAA Compliance for Offsite Backup Vendors: Requirements, BAAs, and Security Checklist
HIPAA Data Backup Requirements. Offsite backup vendors help you preserve the confidentiality, in...
How to Conduct a Security Risk Assessment (SRA) for Ambient AI Scribing in a Midwifery Birth Center
Ambient AI scribing can ease documentation, protect clinician time, and strengthen patient narrat...
HIPAA Training Checklist for Festival Medical Tent Leads Before Filming Cabin Care for Marketing Reels
This HIPAA training checklist equips you to film “Cabin Care” content for marketing reels without...
HIPAA Training for OPO Requestors: Requirements Before Issuing PHI Portal Logins
Before you issue PHI portal logins to Organ Procurement Organization (OPO) requestors, you must e...
HIPAA Training for Critical Access Hospital Nurses: What You Must Know Before Exporting Call Recordings to Personal Laptops
Understanding the HIPAA Security Rule. As a critical access hospital nurse, call recordings you ...
Alabama Privacy Laws for Retina Injection Logs in Outpatient ASCs: A Practical Compliance Guide
Retina injection logs document high-stakes clinical details—diagnoses, medications, lot numbers, ...
What to Do When a Vendor Refuses to Sign a Business Associate Agreement (BAA)
Understanding Vendor Classification. When a vendor is a Business Associate. A vendor becomes a ...
Do Hospital-at-Home Kit Vendors Need a BAA When Biometric Streams Enter the Inpatient EHR?
Business Associate Agreement Requirements. Yes—if a hospital-at-home kit vendor creates, receive...
HIPAA BAA Obligations for Pharmacy Adherence Packaging Vendors Printing Labels with Patient Directions
Business Associate Agreement Requirements. When a pharmacy outsources adherence packaging or lab...
Is a Sickle Cell Registry Vendor HIPAA Compliant If Pain Crisis Timelines Include MRNs?
Short answer: yes—if the registry vendor treats the dataset as Protected Health Information, oper...
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Kevin Henry
CEO @Accountable
As founder and CEO of Accountable, Kevin leads our mission to simplify HIPAA compliance for healthcare organizations. With a background in healthcare technology and healthcare, he has been instrumental in developing innovative solutions that make compliance accessible and manageable for organizations of all sizes.