Practical guidance on HIPAA, security, and compliance — written for the people who actually have to implement it.
July 27, 2026
NIST AI RMF GOVERN 6.1 covers third-party ai risk. This post walks through diligence on an AI vendor that touches PHI, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
July 24, 2026
NIST AI RMF GOVERN 5.1 covers external ai feedback. This post walks through collecting feedback from clinicians and patients, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
July 23, 2026
NIST AI RMF GOVERN 4.1 covers organizational ai risk culture. This post walks through building a culture that reports AI failures, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
July 22, 2026
NIST AI RMF GOVERN 3.2 covers human oversight of ai. This post walks through keeping a person accountable for the output, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
July 21, 2026
NIST AI RMF GOVERN 2.1 covers ai roles and responsibilities. This post walks through who owns an AI decision in a clinical setting, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
July 20, 2026
NIST AI RMF GOVERN 1.5 covers ongoing ai monitoring. This post walks through monitoring a model after it goes live, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
July 17, 2026
NIST AI RMF GOVERN 1.3 covers risk management processes for ai. This post walks through sizing AI risk management to the use case, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
July 16, 2026
NIST AI RMF GOVERN 1.2 covers trustworthy ai characteristics. This post walks through defining what trustworthy means for clinical AI, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
July 15, 2026
NIST AI RMF GOVERN 1.1 covers legal and regulatory requirements for ai. This post walks through classifying an AI tool before deployment, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
July 14, 2026
NIST CSF 2.0 RC.CO-03 covers recovery communication. This post walks through telling patients and staff what happened, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →