Practical guidance on HIPAA, security, and compliance — written for the people who actually have to implement it.
June 26, 2026
NIST CSF 2.0 PR.PS-05 covers unauthorized software prevention. This post walks through stopping unapproved software on clinical machines, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 25, 2026
NIST CSF 2.0 PR.PS-01 covers configuration management. This post walks through hardening baselines for clinical endpoints, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 24, 2026
NIST CSF 2.0 PR.DS-02 covers data-in-transit protection. This post walks through protecting data moving between systems, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 23, 2026
NIST CSF 2.0 PR.DS-01 covers data-at-rest protection. This post walks through protecting stored patient data, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 22, 2026
NIST CSF 2.0 PR.AT-01 covers personnel awareness training. This post walks through awareness training that maps to CSF and HIPAA, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 18, 2026
NIST CSF 2.0 PR.AA-05 covers access permissions. This post walks through least privilege in practice, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 17, 2026
NIST CSF 2.0 PR.AA-01 covers identity management. This post walks through managing identities across clinical systems, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 16, 2026
NIST CSF 2.0 ID.IM-01 covers improvement from evaluations. This post walks through feeding assessment findings back into the program, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 15, 2026
NIST CSF 2.0 ID.RA-05 covers risk prioritization. This post walks through ranking risk by likelihood and impact, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 12, 2026
NIST CSF 2.0 ID.RA-01 covers vulnerability identification. This post walks through finding vulnerabilities on a real schedule, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →