Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

Blog

Practical guidance for independent practices.

Articles on compliance strategy, breach economics, AI risk, and the security decisions that matter most for small healthcare teams.

For real-time breach alerts, enforcement actions, and compliance intelligence — visit HIPAA Pulse — updated multiple times daily.

All articles

Is Zapier HIPAA compliant — no BAA on any plan, why workflow automation creates PHI exposure
Practice Operations·May 6, 2026

Is Zapier HIPAA Compliant? No — No BAA on Any Plan (2026)

Zapier does not sign BAAs. That alone disqualifies it for any workflow involving PHI. Practices that use Zapier to glue together healthcare tools are creating compliance exposure they may not see until an audit.

List of most common HIPAA violations in chiropractic practices with OCR enforcement data
Breach Intelligence·April 30, 2026

The Most Common HIPAA Violations in Chiropractic Practices (2026)

Chiropractic practices face a HIPAA violation landscape shaped by personal injury records, open treatment environments, and high-volume billing — patterns most compliance guides miss. Here are the five violations OCR cites most.

Q1 2026 State of Compliance report — concentration of healthcare breach impact across four upstream vendors
Research & Analysis·April 29, 2026

Four vendors held most of the risk in Q1

Today we publish the inaugural Q1 2026 State of Compliance — drawn from seven authoritative sources after the OCR portal alone showed almost no March activity. The headline finding is concentration: four upstream vendor breaches drove 67.6% of all Q1 patient impact.

Microsoft Teams HIPAA compliance settings and configuration guide
Practice Operations·April 15, 2026

Is Microsoft Teams HIPAA Compliant? (2026)

Microsoft Teams can meet HIPAA requirements — but only with the right Microsoft 365 plan, a BAA, and admin configuration. Here is the full guide.

Fax machine HIPAA compliance requirements for healthcare practices
Compliance Operations·April 15, 2026

Is Faxing HIPAA Compliant? Rules & Risks (2026)

Faxing gets a pass under HIPAA that email does not — but cloud fax, online fax services, and email-to-fax gateways create compliance obligations most practices overlook.

HIPAA compliance requirements for healthcare voicemail messages
Compliance Operations·April 15, 2026

Is Voicemail HIPAA Compliant? Rules & Tips (2026)

HIPAA does not prohibit voicemail. But voicemail messages containing PHI must follow minimum necessary rules, and voicemail systems must meet security requirements.

Common HIPAA violations chart based on HHS OCR enforcement data — risk analysis, BAA, and access control gaps lead the list
Breach Intelligence·April 12, 2026

10 HIPAA Violations That Cost Practices $50K–$2M (2026)

OCR enforcement actions reveal which HIPAA violations are most common and most costly. The consistent finding is not malice — it is that compliance was treated as a one-time event rather than an ongoing system.

HIPAA compliance overview for dental practices covering imaging ePHI and vendor BAA requirements
Breach Intelligence·April 12, 2026

HIPAA Compliance for Dental Practices: The Complete 2026 Guide

Dental offices are covered entities under HIPAA — subject to the same rules as hospitals. This guide covers what the law requires, where dental practices are most exposed, which vendors need BAAs, and the step-by-step path to full compliance.

Patient Protect platform walkthrough showing initial setup, dashboard overview, and first compliance actions
Product & Platform·April 11, 2026

Your First Hour on Patient Protect

Most compliance platforms hand you a questionnaire and wish you luck. Patient Protect covers ~70% of HIPAA requirements before you write a single policy. Here's the minute-by-minute breakdown.

Warning signs that an independent healthcare practice will fail a HIPAA audit
Compliance Operations·April 11, 2026

Top 10 Signs Your Practice Will Fail a HIPAA Audit

OCR investigators don't fish for sophisticated vulnerabilities. They look for predictable operational gaps. These are the ten signs they find most often — visible to the practice long before the audit notice arrives.

HIPAA Security Rule technical safeguards reference — 45 CFR 164.312 access control, audit, integrity, transmission security
Compliance Operations·April 10, 2026

HIPAA Technical Safeguards: §164.312 Checklist (2026)

The Security Rule's technical safeguards are the controls that actually protect ePHI inside your systems. This is the complete reference — every standard, every implementation specification, and what each one means for your practice.

Visualization of the platform deficit between compliance documentation and operational enforcement
Product & Platform·April 10, 2026

The Platform Deficit: If Your Software Doesn't Have It, It Can't Enforce It

Most HIPAA compliance platforms cannot enforce what they do not contain. If the platform lacks secure messaging, it cannot prevent staff from texting patients. If it lacks real-time monitoring, it cannot detect drift between audits. The gap between what compliance software covers and what HIPAA actually requires is the platform deficit — and it is where most breaches start.

Business Associate Agreement red flags that independent healthcare practices miss before signing
Compliance Operations·April 5, 2026

Top 6 BAA Red Flags Every Independent Practice Misses

A signed BAA is HIPAA's required floor — but most BAAs that practices sign protect the vendor far more than the practice. These are the six clauses that separate a real contract from a checkbox.

Signal messaging app icon with HIPAA compliance requirements checklist showing failures across administrative controls
Security & Threats·March 28, 2026

Is Signal HIPAA Compliant? Why Strong Encryption Isn't Enough (2026)

Signal has the strongest encryption of any consumer messenger. It is still not HIPAA compliant. Encryption protects messages in transit — HIPAA requires protection of the entire lifecycle of PHI, and Signal provides none of the organizational controls that demands.

Checklist of HIPAA employee training requirements including required topics, documentation standards, and 2026 rule changes
Compliance Operations·March 24, 2026

HIPAA Employee Training Requirements Checklist (2026)

HIPAA requires workforce training. Most practices know that much. What they don't know: exactly what topics must be covered, when training must happen, what documentation OCR expects, and what changes with the proposed 2026 Security Rule amendments.

Warning illustration showing risks of healthcare staff using ChatGPT with unprotected patient data
Security & Threats·March 19, 2026

Is ChatGPT HIPAA Compliant? No — Here's the Risk

A front desk coordinator pastes chart notes into ChatGPT. A medical assistant summarizes a referral. A biller drafts an appeal. Nobody flagged any of it as a problem. Because it didn't feel like a breach. It felt like being resourceful.

HIPAA compliance software explained — what it does, what it doesn't, and what independent practices actually need
HIPAA Fundamentals·March 11, 2026

What Is HIPAA Compliance Software? A Plain-English Guide (2026)

HIPAA compliance software describes products that work in fundamentally different ways. Understanding the three categories — documentation platforms, guided compliance tools, and enforcement-based systems — is essential before choosing one.

Common HIPAA training mistakes that lead to OCR audits and enforcement
Workforce Compliance·February 15, 2026

Top 6 HIPAA Training Mistakes That Trigger OCR Audits

Training is required, documented, and frequently audited. Six mistakes show up repeatedly in the practices that fail. Each is procedural — meaning each is fixable without new technology.

Dark web marketplace visualization showing stolen patient health records listed for sale
Security & Threats·November 9, 2025

The Dark Market Has Better Data on Your Patients Than You Do

Hundreds of thousands of patient records have been found exposed online — unencrypted and unprotected. The problem is not just theft — it is that attackers now have better intelligence than defenders.

Cost analysis showing hidden compliance expenses burdening independent healthcare practices
Security & Threats·November 9, 2025

The Hidden Tax on Independent Healthcare

Small healthcare practices carry the same HIPAA obligations as major hospital systems. The difference is that a single breach can end the practice entirely.

Patient rights framework showing access, amendment, and accounting obligations under HIPAA Privacy Rule
Compliance Operations·September 30, 2025

Strengthen Patient Rights (Step 7 of 17)

HIPAA gives patients specific, enforceable rights over their health information. Most independent practices comply with some of them and overlook the rest.

Physical security diagram showing access controls for protecting electronic health information in facilities
Compliance Operations·May 4, 2025

Lock Down Physical Access to ePHI (Step 4 of 17)

Most practices think physical security means locking the server room. It actually means controlling every point where someone could see, touch, or walk away with patient data.

Step-by-step visual guide simplifying HIPAA compliance into actionable stages for healthcare providers
HIPAA Fundamentals·April 2, 2020

HIPAA Compliance Made Simple: A Step-by-Step Guide

HIPAA (Health Insurance Portability and Accountability Act) is a federal law that protects sensitive patient information. This guide explains how to get started with HIPAA compliance, the key components involved, and how you can make the process easier.

Healthcare provider reviewing HIPAA compliance documentation with a patient in a clinical setting
Compliance Operations·February 1, 2019

Accelerating Patient Trust Through HIPAA Compliance

Patients are paying attention to how their data is handled. Practices that treat compliance as a trust-building tool — not just a legal requirement — outperform on retention, reputation, and referrals.

HIPAA Pulse newsletter

One email. Every other Wednesday. The HIPAA changes worth knowing.

Breach analysis, OCR enforcement updates, regulatory tracking, and the operational guidance for independent practices — synthesized into one editorial briefing. No spam. Unsubscribe anytime.

Every other Wednesday · Free · Unsubscribe anytime