How to Contain a Ransomware Attack That Encrypted Your Clinic’s Imaging Archive
A ransomware lock on your PACS/VNA threatens patient safety, continuity of care, and regulatory e...
North Carolina Identity Theft Protection Act: Hospital Breach Notification Rules, Deadlines, and Requirements
Definition of Security Breach. Under North Carolina’s Identity Theft Protection Act, a “security...
What a Hyperbaric Oxygen Clinic Must Do Before Storing Chamber Session Videos: Consent, HIPAA, and Security Checklist
HIPAA Compliance for Video Recordings. Identify PHI and scope. Assume chamber session videos co...
HIPAA Requirements for School‑Based Health Clinics When Sharing Records with District Nurses
School-based health clinics sit at the intersection of healthcare and education. When you share s...
Maryland Online Data Privacy Act (MOPDA): Compliance Obligations for Telehealth Companies
Validate the input components (main keyword, secondary keywords, and outline) to align scope a...
When Does a Cloud Dictation Service Become a HIPAA Business Associate for Clinic Notes?
Cloud Dictation Services as Business Associates. A cloud dictation platform becomes a HIPAA busi...
Is a background check vendor a HIPAA business associate if they see employee health clearance forms?
If you’re asking, “Is a background check vendor a HIPAA business associate if they see employee h...
Is a Stolen Clinic Phone with Unencrypted Voicemail Transcripts a HIPAA Breach? Risk Analysis and Next Steps
If a clinic phone is stolen and it contains unencrypted voicemail transcripts, you should presume...
How to Offboard a Retired Fax Vendor That Still Holds Archived PHI Images (HIPAA‑Compliant Guide)
Retiring an old fax service doesn’t end your obligations when the vendor still hosts archived Pro...
How to Write a Sanctions Policy That Separates Accidental Disclosures from Willful Neglect
When a compliance breach happens, the first question is intent. This guide shows you how to write...
How to Protect Inmate Medical Records When a Correctional Telehealth Vendor Joins Rounds
When a correctional telehealth vendor joins clinical rounds, you must protect inmate medical reco...
HIPAA BAA Obligations for Medical Interpreter Agencies Receiving Discharge Summaries
When a hospital or clinic shares discharge summaries with your agency, you receive Protected Heal...
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Kevin Henry
CEO @Accountable
As founder and CEO of Accountable, Kevin leads our mission to simplify HIPAA compliance for healthcare organizations. With a background in healthcare technology and healthcare, he has been instrumental in developing innovative solutions that make compliance accessible and manageable for organizations of all sizes.