Practical guidance on HIPAA, security, and compliance — written for the people who actually have to implement it.
February 3, 2026
45 CFR 164.308(a)(4) covers information access management. This post walks through role-based access that maps to real job functions, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
February 2, 2026
45 CFR 164.308(a)(3)(ii)(C) covers termination procedures. This post walks through closing access the day someone leaves, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →
January 30, 2026
45 CFR 164.308(a)(3)(ii)(B) covers workforce clearance procedure. This post walks through workforce clearance that fits a small practice, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →
January 29, 2026
45 CFR 164.308(a)(3)(ii)(A) covers authorization and/or supervision. This post walks through authorization and supervision for staff who touch ePHI, with the language of the requirement itself and the evidence an assessor asks to see. It is an addressable specification, which means documenting your reasoning is part of the requirement.
Read more →
January 28, 2026
45 CFR 164.308(a)(2) covers assigned security responsibility. This post walks through naming a security official and giving the role real authority, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
January 27, 2026
45 CFR 164.308(a)(1)(ii)(D) covers information system activity review. This post walks through reviewing system activity without drowning in logs, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
January 26, 2026
45 CFR 164.308(a)(1)(ii)(C) covers sanction policy. This post walks through writing a sanction policy you will actually apply, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
January 23, 2026
45 CFR 164.308(a)(1)(ii)(B) covers risk management. This post walks through turning risk findings into tracked remediation, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →
January 22, 2026
45 CFR 164.308(a)(1)(ii)(A) covers risk analysis. This post walks through what a defensible analysis has to contain, with the language of the requirement itself and the evidence an assessor asks to see. It is a required specification, so there is no documented-alternative route.
Read more →