Practical guidance on HIPAA, security, and compliance — written for the people who actually have to implement it.
February 18, 2026
45 CFR 164.308(a)(7)(ii)(B) covers disaster recovery plan. This post walks through a disaster recovery plan sized to your practice, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
February 17, 2026
45 CFR 164.308(a)(7)(ii)(A) covers data backup plan. This post walks through backups you have actually restored from, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
February 13, 2026
45 CFR 164.308(a)(6)(ii) covers response and reporting. This post walks through response and reporting, and where breach analysis begins, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
February 12, 2026
45 CFR 164.308(a)(6)(i) covers security incident procedures. This post walks through incident procedures before you need them, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
February 11, 2026
45 CFR 164.308(a)(5)(ii)(D) covers password management. This post walks through password management after the 2024 NIST guidance, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →
February 10, 2026
45 CFR 164.308(a)(5)(ii)(C) covers log-in monitoring. This post walks through log-in monitoring and reporting discrepancies, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →
February 9, 2026
45 CFR 164.308(a)(5)(ii)(B) covers protection from malicious software. This post walks through malware protection on clinical endpoints, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →
February 6, 2026
45 CFR 164.308(a)(5)(ii)(A) covers security reminders. This post walks through security reminders that change behavior, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →
February 5, 2026
45 CFR 164.308(a)(5)(i) covers security awareness and training. This post walks through training that produces evidence an assessor accepts, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
February 4, 2026
45 CFR 164.308(a)(4)(ii)(C) covers access establishment and modification. This post walks through granting and changing access with a paper trail, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →