Practical guidance on HIPAA, security, and compliance — written for the people who actually have to implement it.
April 1, 2026
45 CFR 164.314(a)(2)(i) covers business associate contracts. This post walks through the clauses the Security Rule makes mandatory, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
March 31, 2026
45 CFR 164.312(e)(2)(ii) covers encryption. This post walks through encryption in transit and the safe harbour it buys, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →
March 30, 2026
45 CFR 164.312(e)(2)(i) covers integrity controls. This post walks through integrity controls on data in transit, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →
March 27, 2026
45 CFR 164.312(e)(1) covers transmission security. This post walks through transmission security for email, fax and portals, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
March 26, 2026
45 CFR 164.312(d) covers person or entity authentication. This post walks through person or entity authentication beyond a password, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
March 25, 2026
45 CFR 164.312(c)(2) covers mechanism to authenticate electronic protected health information. This post walks through authenticating that ePHI was not altered, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →
March 24, 2026
45 CFR 164.312(c)(1) covers integrity. This post walks through integrity controls for the record itself, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
March 23, 2026
45 CFR 164.312(b) covers audit controls. This post walks through audit controls and what your logs must capture, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
March 20, 2026
45 CFR 164.312(a)(2)(iv) covers encryption and decryption. This post walks through encryption at rest and the addressable analysis, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →
March 19, 2026
45 CFR 164.312(a)(2)(iii) covers automatic logoff. This post walks through automatic logoff on clinical workstations, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →