Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
Blog/Compliance Operations

Compliance Operations

Day-to-day HIPAA compliance for practices that need the work done — risk analysis, BAAs, training, audits, policies, and the operational discipline behind each.

75 articles

Compliance Operations covers the recurring, evidence-producing work that keeps a practice in compliance year over year. It's the part of HIPAA that auditors actually examine — risk analyses with documented methodology, training records with completion timestamps, BAA inventories with current signatures, policy revisions tied to regulatory changes, and incident logs with response timelines. The articles below are written for the office manager, compliance officer, or solo practitioner who has to do the work, not just describe it.

How a managed service provider delivers HIPAA compliance as a recurring service for healthcare practice clients
Compliance Operations·September 11, 2026

How to Offer HIPAA Compliance as a Managed Service

Healthcare clients ask their IT provider about HIPAA sooner or later. This is what the answer has to include if it is going to be a service rather than a favor.

Best HIPAA compliance software for HRT and TRT clinics in 2026
Compliance Operations·September 11, 2026

Best HIPAA Compliance Software for HRT and TRT Clinics (2026)

Testosterone is a Schedule III controlled substance. That single fact changes the entire compliance overlay for HRT/TRT clinics — DEA registration, prescription monitoring program reporting, state board scrutiny of telemedicine prescribing — none of which traditional HIPAA software was built to address.

Best HIPAA compliance software for GLP-1 weight management clinics in 2026
Compliance Operations·September 8, 2026

Best HIPAA Compliance Software for GLP-1 Clinics (2026)

GLP-1 clinics emerged as one of the fastest-growing independent healthcare categories in 2024-2026. The compliance workflow is genuinely new — no prior generation of HIPAA software anticipated the specific combination of compounding pharmacy supply, telehealth-first patient acquisition, state board scrutiny, and Schedule III-adjacent monitoring.

Best HIPAA compliance software for dermatology practices in 2026
Compliance Operations·September 4, 2026

Best HIPAA Compliance Software for Dermatology Practices (2026)

Dermatology practices run two compliance programs at once. The medical-dermatology side has biopsy chain-of-custody, dermatopathology lab BAAs, and skin cancer disclosure workflows. The cosmetic side adds photo PHI, before/after marketing, and social media exposure. Most platforms handle one side and ignore the other.

Best HIPAA compliance software for psychiatry practices in 2026
Compliance Operations·September 1, 2026

Best HIPAA Compliance Software for Psychiatry Practices (2026)

Psychiatric practice has the most heavily-layered confidentiality regime in U.S. healthcare. HIPAA is the floor — psychotherapy notes get separate handling, substance-use treatment has its own federal rule, state mental-health statutes overlap, and court-ordered disclosures are routine. Generic compliance platforms handle one of these well, sometimes two. None handle all four.

HIPAA training documentation requirements - what OCR investigators actually ask for during audits
Compliance Operations·August 28, 2026

HIPAA Training Documentation: What OCR Actually Asks For (2026)

OCR doesn't ask whether you trained your staff. OCR asks for the documentation that proves you trained your staff, on what content, when, with what acknowledgment. Every practice has training. Very few practices have the documentation that survives an inquiry.

Best HIPAA compliance software for concierge medicine practices in 2026
Compliance Operations·August 25, 2026

Best HIPAA Compliance Software for Concierge Medicine (2026)

Concierge medicine pays a premium for unhurried, available, personal care. That premium attracts patients who are also higher-value targets for PHI theft — and the compliance exposure scales with the patient demographic, not just the practice volume.

Best HIPAA compliance software for pediatric practices in 2026
Compliance Operations·August 21, 2026

Best HIPAA Compliance Software for Pediatric Practices (2026)

Pediatric practices have a HIPAA exposure profile that adult-focused compliance software wasn't built for — the patient often cannot legally consent, the parent usually but not always controls access, the immunization registry adds disclosure complexity, and at some age the minor's privacy interests start mattering. The software needs to handle all four.

HIPAA compliance plan template structure for independent healthcare practices
Compliance Operations·August 14, 2026

HIPAA Compliance Plan Template (2026): The 7-Element Format

A HIPAA compliance plan is not a single document — it's the framework that organizes every other compliance document the practice maintains. Most templates online produce a list. The plan should produce a system.

Best HIPAA compliance software for direct primary care practices in 2026
Compliance Operations·August 11, 2026

Best HIPAA Compliance Software for Direct Primary Care (2026)

Direct primary care eliminates the insurance company from the workflow but adds a layer of long-term continuous patient communication that traditional fee-for-service practices don't have. The HIPAA exposure shifts from claim transmission to message stream — and the compliance software needs to follow.

HIPAA risk assessment template format and required sections for independent healthcare practices
Compliance Operations·August 7, 2026

HIPAA Risk Assessment Template (2026): What It Must Contain

Most HIPAA risk assessment templates online are reformatted versions of the HHS SRA tool with the sharp edges sanded off. They satisfy a checkbox audit. They don't satisfy an investigator who reads the document and asks follow-up questions. This is the template format that does.

Best HIPAA compliance software for urgent care practices in 2026
Compliance Operations·August 4, 2026

Best HIPAA Compliance Software for Urgent Care Practices (2026)

Urgent care runs a different operational model than family practice — same regulatory framework, very different exposure surface. The 200-patient day, walk-in registration without prior chart, and multi-clinician rotation create HIPAA failure modes that vendors built for primary care don't anticipate.

HIPAA policy templates guide covering the 14 required policies for independent healthcare practices
Compliance Operations·July 24, 2026

HIPAA Policy Templates: The Independent Practice Guide (2026)

A free HIPAA policy template will satisfy a checkbox audit. It will not survive an actual OCR inquiry. The difference between the template and the policy is the operational detail — who specifically does what, when, with which system. That difference is where most independent practices have their actual exposure.

Best HIPAA compliant telehealth platforms comparison for independent practices in 2026
Compliance Operations·July 21, 2026

Best HIPAA-Compliant Telehealth Platforms (2026)

Most telehealth platform comparisons rank by video quality. None of them quite live where the compliance work actually happens — in the BAA, the recording controls, the integration BAA chain, and the audit log retention. This is the comparison done the other way around.

Independent healthcare practice compliance work — the quiet failure mode of HIPAA at small practices
Compliance Operations·July 21, 2026

The Quiet Failure of HIPAA in Independent Practices

HIPAA was designed for institutions. It gets applied unchanged to a solo dentist with no compliance department, no security team, and no dedicated IT staff. The failure mode this produces is quiet, and the industry has been solving the wrong problem.

OneDrive for Business HIPAA configuration guide covering tenant settings, sharing controls, DLP, and audit retention
Compliance Operations·July 17, 2026

OneDrive HIPAA Configuration Guide: The 8-Step Lockdown (2026)

Most OneDrive HIPAA findings are not about the BAA. The BAA is signed. The findings are about the seventeen configuration toggles Microsoft leaves wide open by default. This is the step-by-step lockdown an independent practice should run within the first week of any Microsoft 365 deployment.

DOJ 2026 $6.5B healthcare fraud takedown and the 120-day corporate self-disclosure window - what it means for independent practices
Compliance Operations·July 13, 2026

The 120-Day Sprint: What DOJ's $6.5B Fraud Sweep Means for Independent Practices

The patchwork of local voluntary self-disclosure policies is officially gone. Under DOJ's unified Corporate Enforcement Policy, an independent practice that receives an internal compliance report has approximately 120 days to investigate, decide whether to self-disclose, and act — before a whistleblower's external report closes the highest-value cooperation credit forever.

Med spa HIPAA compliance software comparison covering consent, photo PHI, social media, and injectable tracking
Compliance Operations·July 7, 2026

Best HIPAA Compliance Software for Med Spas (2026)

Most HIPAA platforms were built for a dental office. A med spa has the same regulatory exposure plus four others — consent for cosmetic procedures, photographic PHI, social-media marketing involving identifiable patients, and DEA-adjacent injectable tracking. The software that fits a dental office only covers half the surface area.

HIPAA compliance software cost breakdown by pricing model for independent practices in 2026
Compliance Operations·July 3, 2026

HIPAA Compliance Software Cost: A 2026 Buyer's Breakdown

A pricing page is the easiest part of a vendor site to read and the hardest to interpret. Two platforms can include or exclude the same modules at very different prices, and the practice finds out which at renewal.

HIPAA risk assessment cost breakdown for independent healthcare practices in 2026
Compliance Operations·June 30, 2026

How Much Does a HIPAA Risk Assessment Cost? (2026)

Three independent practices on the same block can pay $0, $2,400, and $18,000 for the same HIPAA risk assessment requirement. None of them are wrong. They are buying different things — and most are over- or underbuying without realizing it.

The Patient Protect Readiness Index — a 24-point evaluation framework for HIPAA compliance software in the 2026 Security Rule era
Compliance Operations·May 13, 2026

The Patient Protect Readiness Index (PPRI)

Eight criteria, three points each, applied to whatever you are evaluating. Derived from the proposed Security Rule and OCR's enforcement record — and the proposal is still a proposal, which the scoring says out loud.

Is Salesforce HIPAA compliant — HIPAA Covered Services and BAA requirements for healthcare practices
Compliance Operations·May 6, 2026

Is Salesforce HIPAA Compliant? Yes, by Named Service

Salesforce covers HIPAA by named service rather than by edition. Sales Cloud, Health Cloud, Service Cloud and Marketing Cloud Engagement are all on the covered list — what matters is whether your BAA includes the service you are actually using, and that is where most practices create exposure.

Is Twilio HIPAA compliant — SMS, Voice, Video, Conversations, and Flex HIPAA-eligible products with BAA requirements
Compliance Operations·May 6, 2026

Is Twilio HIPAA Compliant? Yes — With a BAA (2026)

Twilio can be HIPAA compliant on its HIPAA-eligible product set with a signed BAA, available only on Security or Enterprise Edition. SendGrid is not eligible and Twilio will not sign a BAA for it.

Is HubSpot HIPAA compliant — Enterprise tier BAA requirements and marketing-data PHI restrictions for healthcare practices
Compliance Operations·May 6, 2026

Is HubSpot HIPAA Compliant? Enterprise Only

HubSpot can be HIPAA compliant on Enterprise tiers with a signed BAA. Lower plans are not HIPAA-eligible. Here is what is covered, what is not, and how to configure it.

Is ServiceNow HIPAA compliant — Now Platform BAA scope and enterprise ITSM configuration for healthcare practices
Compliance Operations·May 6, 2026

Is ServiceNow HIPAA Compliant? Yes, With a Requested BAA

ServiceNow will enter into a BAA once you tell Sales Support you intend to store ePHI and request one — no edition or tier gate appears in the controlling document. The Healthcare and Life Sciences product line adds healthcare-specific data models but is not what confers coverage. Standard tenants are not HIPAA-eligible by default.

Is Microsoft OneDrive HIPAA compliant — Business plans, the Microsoft BAA, and anonymous-sharing lockdown requirements
Compliance Operations·May 6, 2026

Is OneDrive HIPAA Compliant? Yes — With a BAA (2026)

OneDrive for Business is in scope under Microsoft's HIPAA offering, with the BAA attaching through the DPA. Personal OneDrive and home subscriptions are not. The configuration is where exposure gets created.

Is Notion AI HIPAA compliant — Notion BAA explicitly excludes AI features, why PHI-in-prompt fails compliance
Compliance Operations·May 6, 2026

Is Notion AI HIPAA Compliant? Yes, on an Enabled Workspace

The widely repeated claim is that Notion carves AI out of its BAA. Notion's own documentation says the opposite. Here is what is actually excluded, and the administrator setting that decides whether the coverage holds.

Comparison of HIPAA-compliant cloud storage providers for healthcare practices
Compliance Operations·May 1, 2026

10 Best HIPAA-Compliant Cloud Storage Providers (2026)

Ten cloud storage providers that will sign a BAA, ranked by fit for independent healthcare practices. What each is built for, where each falls short, and the configuration trap behind most cloud breaches.

Gmail HIPAA compliance requirements and configuration guide
Compliance Operations·April 15, 2026

Is Gmail HIPAA Compliant? Workspace Only

Free Gmail fails HIPAA requirements. Google Workspace paid plans with a BAA and the right configuration can work — here is the full breakdown.

Dropbox HIPAA compliance requirements for healthcare file storage
Compliance Operations·April 15, 2026

Is Dropbox HIPAA Compliant? Yes, on Team Plans

Dropbox offers HIPAA-eligible plans for healthcare — but only on Business tiers with a BAA. Here is what to configure before storing patient data.

Slack HIPAA compliance requirements for healthcare team messaging
Compliance Operations·April 15, 2026

Is Slack HIPAA Compliant? Only in an Enabled Workspace

Slack can carry PHI, but coverage does not follow the contract. Salesforce's BAA Restrictions require an enterprise plan, the HIPAA Enabled SKU, and the specific organization or workspace to be designated — coverage does not extend to every workspace you own.

Fax machine HIPAA compliance requirements for healthcare practices
Compliance Operations·April 15, 2026

Is Faxing HIPAA Compliant? Rules & Risks (2026)

Faxing gets a pass under HIPAA that email does not — but cloud fax, online fax services, and email-to-fax gateways create compliance obligations most practices overlook.

Warning signs that an independent healthcare practice will fail a HIPAA audit
Compliance Operations·April 11, 2026

Top 10 Signs Your Practice Will Fail a HIPAA Audit

OCR investigators don't fish for sophisticated vulnerabilities. They look for predictable operational gaps. These are the ten signs they find most often — visible to the practice long before the audit notice arrives.

HIPAA Security Rule technical safeguards reference — 45 CFR 164.312 access control, audit, integrity, transmission security
Compliance Operations·April 10, 2026

HIPAA Technical Safeguards: §164.312 Checklist (2026)

The Security Rule's technical safeguards are the controls that actually protect ePHI inside your systems. This is the complete reference — every standard, every implementation specification, and what each one means for your practice.

Business Associate Agreement red flags that independent healthcare practices miss before signing
Compliance Operations·April 5, 2026

Top 6 BAA Red Flags Every Independent Practice Misses

A signed BAA is HIPAA's required floor — but most BAAs that practices sign protect the vendor far more than the practice. These are the six clauses that separate a real contract from a checkbox.

DocuSign HIPAA compliance requirements for healthcare electronic signatures
Compliance Operations·March 25, 2026

Is DocuSign HIPAA Compliant? Yes, Through Sales

Docusign acts as a business associate for eSignature documents containing PHI, with a signed BAA. Its pricing comparison places HIPAA support through BAA behind Contact sales, not the self-service plans.

Notion HIPAA compliance requirements for healthcare documentation and knowledge bases
Compliance Operations·March 19, 2026

Is Notion HIPAA Compliant? Yes, on Enterprise (2026)

Notion can hold PHI on the Enterprise plan, with the BAA signed and HIPAA compliance enabled in workspace settings — and Notion states the AI features are covered too. Most practices using Notion are on plans that do not qualify.

QuickBooks HIPAA compliance analysis for healthcare practice billing and accounting
Compliance Operations·March 14, 2026

Is QuickBooks HIPAA Compliant? No BAA Offered

QuickBooks Online states it is not compliant with the HIPAA privacy standards and recommends against entering individually identifiable health information. Billing data is where PHI hides.

Square HIPAA compliance analysis for healthcare payment processing
Compliance Operations·March 13, 2026

Is Square HIPAA Compliant? Yes, in Scope

Square publishes a HIPAA BAA that applies by use rather than signature. Its scope clause names Appointments and Invoices, and expressly excludes Square Buyer Services.

HIPAA business associate agreement checklist for independent healthcare practices
Compliance Operations·March 10, 2026

HIPAA BAA Checklist: 10 Required Elements (2026)

Business associate agreements are one of the most commonly violated HIPAA requirements. This checklist covers what a BAA must include, which vendors need one, and how to manage the entire lifecycle.

Mailchimp HIPAA compliance analysis for healthcare email marketing
Compliance Operations·March 6, 2026

Is Mailchimp HIPAA Compliant? No BAA Offered

Mailchimp cannot be used for healthcare email marketing involving PHI. No published BAA offering was found on any Mailchimp plan — Free, Essentials, Standard or Premium.

Patient rights framework showing access, amendment, and accounting obligations under HIPAA Privacy Rule
Compliance Operations·September 30, 2025

Strengthen Patient Rights (Step 7 of 17)

HIPAA gives patients specific, enforceable rights over their health information. Most independent practices comply with some of them and overlook the rest.

Physical security diagram showing access controls for protecting electronic health information in facilities
Compliance Operations·May 4, 2025

Lock Down Physical Access to ePHI (Step 4 of 17)

Most practices think physical security means locking the server room. It actually means controlling every point where someone could see, touch, or walk away with patient data.

Healthcare provider reviewing HIPAA compliance documentation with a patient in a clinical setting
Compliance Operations·February 1, 2019

Accelerating Patient Trust Through HIPAA Compliance

Patients are paying attention to how their data is handled. Practices that treat compliance as a trust-building tool — not just a legal requirement — outperform on retention, reputation, and referrals.