Practical guidance on HIPAA, security, and compliance — written for the people who actually have to implement it.
August 24, 2026
NIST Privacy Framework GV.MT-P1 covers privacy program monitoring. This post walks through monitoring the privacy program for drift, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
August 21, 2026
NIST Privacy Framework GV.PO-P1 covers privacy governance policies. This post walks through privacy policies that govern rather than describe, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
August 20, 2026
NIST Privacy Framework ID.DE-P2 covers data flow mapping. This post walks through mapping data flows across systems and vendors, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
August 19, 2026
NIST Privacy Framework ID.RA-P3 covers privacy risk assessment. This post walks through assessing privacy risk distinctly from security risk, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
August 18, 2026
NIST Privacy Framework ID.BE-P1 covers privacy role in the organization. This post walks through placing privacy inside the business, not beside it, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
August 17, 2026
NIST Privacy Framework ID.IM-P7 covers data processing purpose. This post walks through stating the purpose for each processing activity, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
August 14, 2026
NIST Privacy Framework ID.IM-P1 covers data processing inventory. This post walks through inventorying how patient data is actually processed, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
August 13, 2026
NIST AI RMF MANAGE 4.1 covers ai post-deployment monitoring. This post walks through catching drift before it reaches a patient, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
August 12, 2026
NIST AI RMF MANAGE 3.1 covers third-party ai risk management. This post walks through managing risk you do not control, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
August 11, 2026
NIST AI RMF MANAGE 2.2 covers ai deployment controls. This post walks through controls that ride with the deployment, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →