Documents to Gather Before an OCR Onsite Investigation of a Reported HIPAA Breach
Risk Assessment Documentation. What to collect. Your most recent enterprise-wide HIPAA Secur...
How to Tier Vendors by PHI Volume in a Health System Vendor Management Program
Effective vendor tiering anchors your third‑party oversight to what matters most: the amount and ...
How to Track HIPAA BAA Renewals Across a Multi‑Specialty Group with 50+ Vendors
Importance of Compliance Tracking. Why renewals matter. Business Associate Agreements (BAAs) ar...
How to Prepare Your Small Dental Practice for an OCR HIPAA Desk Audit: Step-by-Step Checklist
An OCR HIPAA desk audit focuses on whether your documentation proves compliance. As a small denta...
How to Prove ePHI at Rest Is Encrypted for a HIPAA OCR Compliance Review
Understand HIPAA Encryption Requirements. What OCR expects to see. During an OCR review, you mu...
How to Respond to an HHS OCR Data Request for Six Years of Policies Without Overproducing
Understanding HHS OCR Data Requests. When the HHS Office for Civil Rights (OCR) sends a data req...
Do Patient Financing Companies Need a BAA to Review Medical Bills with Diagnosis Codes?
Short answer: yes—if a patient financing company reviews identifiable medical bills on a provider...
HIPAA-Compliant Social Media Policy: Stop Staff from Posting Workplace Selfies with Visible PHI
Social platforms move fast, but HIPAA does not. To maintain HIPAA Social Media Compliance, you ne...
Do Patient Scheduling Chatbot Vendors Need a BAA Before Reading Appointment Reasons Under HIPAA?
Definition of Protected Health Information. Protected Health Information (PHI) is any individual...
HIPAA Compliance Checklist for a Mobile MRI Truck Serving Rural Clinics
You operate in tight spaces, on shifting schedules, and with intermittent connectivity. This HIPA...
How to Require Penetration Test Summaries from Patient Portal White‑Label Vendors
Requesting Penetration Test Summaries. Define the requirement early. Set the expectation in you...
HIPAA Breach Assessment: What to Do When a Discharged Patient Finds Another Patient’s Lab Results in Their Portal
HIPAA Breach Definition. In this scenario, a discharged patient views another person’s lab resul...
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Kevin Henry
CEO @Accountable
As founder and CEO of Accountable, Kevin leads our mission to simplify HIPAA compliance for healthcare organizations. With a background in healthcare technology and healthcare, he has been instrumental in developing innovative solutions that make compliance accessible and manageable for organizations of all sizes.