Practical guidance on HIPAA, security, and compliance — written for the people who actually have to implement it.
July 13, 2026
NIST CSF 2.0 RC.RP-01 covers recovery plan execution. This post walks through executing recovery and proving it worked, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
July 10, 2026
NIST CSF 2.0 RS.MI-01 covers incident containment. This post walks through containing an incident without destroying evidence, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
July 9, 2026
NIST CSF 2.0 RS.CO-02 covers internal and external notification. This post walks through notification duties under CSF and HIPAA together, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
July 8, 2026
NIST CSF 2.0 RS.AN-03 covers incident analysis. This post walks through determining what actually happened, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
July 7, 2026
NIST CSF 2.0 RS.MA-01 covers incident management execution. This post walks through running an incident from detection to closure, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
July 6, 2026
NIST CSF 2.0 DE.AE-06 covers event information sharing. This post walks through getting event data to the people who act on it, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
July 2, 2026
NIST CSF 2.0 DE.AE-02 covers adverse event analysis. This post walks through analyzing events instead of collecting them, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
July 1, 2026
NIST CSF 2.0 DE.CM-09 covers computing hardware and software monitoring. This post walks through endpoint monitoring that surfaces real signals, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 30, 2026
NIST CSF 2.0 DE.CM-01 covers network monitoring. This post walks through monitoring the network with a small team, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 29, 2026
NIST CSF 2.0 PR.IR-01 covers network protection. This post walks through segmenting the clinical network, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →