Practical guidance on HIPAA, security, and compliance — written for the people who actually have to implement it.
June 11, 2026
NIST CSF 2.0 ID.AM-05 covers asset prioritization. This post walks through prioritizing assets by clinical impact, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 10, 2026
NIST CSF 2.0 ID.AM-02 covers software inventory. This post walks through knowing what software touches patient data, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 9, 2026
NIST CSF 2.0 ID.AM-01 covers hardware inventory. This post walks through an asset inventory that stays current, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 8, 2026
NIST CSF 2.0 GV.OV-01 covers strategy review. This post walks through reviewing the program against measured outcomes, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 5, 2026
NIST CSF 2.0 GV.SC-04 covers supplier criticality. This post walks through ranking vendors by what they can reach, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 4, 2026
NIST CSF 2.0 GV.SC-01 covers supply chain risk management. This post walks through vendor risk beyond the signed BAA, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 3, 2026
NIST CSF 2.0 GV.PO-01 covers cybersecurity policy. This post walks through a policy set that maps to HIPAA and CSF at once, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 2, 2026
NIST CSF 2.0 GV.RR-02 covers roles and responsibilities. This post walks through assigning cybersecurity roles in a clinical org, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
June 1, 2026
NIST CSF 2.0 GV.RM-01 covers risk management objectives. This post walks through setting risk objectives leadership will stand behind, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →
May 29, 2026
NIST CSF 2.0 GV.OC-01 covers organizational mission and risk. This post walks through stating what the security program is protecting, with the language of the requirement itself and the evidence an assessor asks to see.
Read more →