Practical guidance on HIPAA, security, and compliance — written for the people who actually have to implement it.
March 4, 2026
45 CFR 164.310(a)(2)(iv) covers maintenance records. This post walks through maintenance records for security-relevant repairs, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →
March 3, 2026
45 CFR 164.310(a)(2)(iii) covers access control and validation procedures. This post walks through validating who gets into clinical space, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →
March 2, 2026
45 CFR 164.310(a)(2)(ii) covers facility security plan. This post walks through a facility security plan that matches the building, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →
February 27, 2026
45 CFR 164.310(a)(2)(i) covers contingency operations. This post walks through contingency operations for physical access, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →
February 26, 2026
45 CFR 164.310(a)(1) covers facility access controls. This post walks through facility access controls in a leased clinical suite, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
February 25, 2026
45 CFR 164.308(b)(1) covers business associate contracts and other arrangements. This post walks through what the contract must require of a vendor, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
February 24, 2026
45 CFR 164.308(a)(8) covers evaluation. This post walks through the periodic evaluation most practices skip, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
February 23, 2026
45 CFR 164.308(a)(7)(ii)(E) covers applications and data criticality analysis. This post walks through ranking applications and data by criticality, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →
February 20, 2026
45 CFR 164.308(a)(7)(ii)(D) covers testing and revision procedures. This post walks through testing the contingency plan and recording the result, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →
February 19, 2026
45 CFR 164.308(a)(7)(ii)(C) covers emergency mode operation plan. This post walks through emergency mode operation when systems are down, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →