Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

FAQ

Common questions. Straight answers.

Everything independent healthcare providers ask about HIPAA compliance, the Patient Protect platform, pricing, and how to get started.

72 questions13 categoriesUpdated for 2026

About Patient Protect

What it is, who it's for, and how to get started.

What is Patient Protect?

Patient Protect is a security-first HIPAA compliance platform built for independent healthcare providers. It provides automated security risk assessments, real-time threat monitoring, policy management, staff training, and secure communication tools — without enterprise pricing or complexity.

Who is Patient Protect designed for?

Independent healthcare providers including dental practices, medical offices, behavioral health and therapy practices, chiropractic offices, physical therapy centers, optometry practices, and dermatology clinics. It is not designed for large hospital systems or enterprise organizations with dedicated IT departments.

Is Patient Protect suitable for solo practices?

Yes. The platform is specifically designed for independent healthcare practices — dental offices, medical practices, behavioral health clinics, and specialty providers — that carry enterprise-grade HIPAA obligations without enterprise-grade resources.

How long does it take to get started with Patient Protect?

Start with the free risk assessment (5 minutes, no login). If you move to the platform, onboarding takes less than a day — no consultants, no implementation projects, no contracts. You can cancel anytime.

How quickly can my practice get set up?

Most practices complete initial setup in under two hours. The SRA wizard guides you through every required assessment step, policies auto-generate from your answers, and BAA templates are ready to send on day one. No consultants, no implementation projects.

Do small practices need to be HIPAA compliant?

Yes — every healthcare provider that transmits health information electronically is a covered entity under HIPAA, regardless of practice size. A solo dentist has the same legal obligations as a 500-bed hospital. The regulation does not scale down its requirements for smaller organizations; it only allows flexibility in how you implement safeguards.

Does Patient Protect replace my IT company?

No. Patient Protect handles the compliance layer — risk assessments, policy management, training documentation, BAA tracking, and audit evidence. Your IT provider handles infrastructure (firewalls, networking, hardware). The platform complements managed IT services; it does not duplicate them.

Pricing & Plans

What it costs and how it compares.

How much does Patient Protect cost?

Patient Protect offers two plans, priced per office: Basic at $39/month per office (up to 25 office personnel) for essential SaaS compliance, and Pro at $99/month per office (up to 50 office personnel) for complete operational visibility including advanced monitoring, training, and secure messaging. Larger single-office practices scale predictably with per-5-personnel add-ons published on the pricing page. Multi-office practice networks use custom pricing that reflects office count, vendor surface, and HIPAA-specific coordination requirements. Both plans include a 14-day free trial (credit card required for identity verification — no charge until trial ends). A free risk assessment is also available with no account required.

How much does HIPAA compliance software cost?

Pricing varies widely across vendors — some charge flat rates, some per employee, some require annual contracts. Patient Protect publishes pricing directly: $39/month per office for Basic (up to 25 office personnel) and $99/month per office for Pro (up to 50 office personnel). No contracts, no setup fees. Larger single-office practices scale predictably; see the pricing page for the exact per-5-personnel add-on rates. Multi-office networks use custom pricing that reflects the coordination each network actually needs.

What is the difference between HIPAA compliance software and doing it manually?

Manual compliance relies on spreadsheets, Word documents, and annual consultant visits. It cannot detect configuration drift in real time, cannot detect breaches in real time, and produces evidence that rarely satisfies OCR auditors. HIPAA compliance software like Patient Protect automates risk assessments, tracks training completion, monitors BAA status, and documents everything continuously — the difference between saying you're compliant and proving it.

How much does HIPAA compliance cost?

Total HIPAA compliance costs depend on your approach. Hiring a consultant runs $5,000–$25,000 per year for annual assessments alone. Software platforms vary widely in pricing and model — some charge per employee, some require annual commitments. Patient Protect delivers continuous compliance — not just an annual snapshot — starting at $39/month per office for practices up to 25 personnel, with no contracts. Multi-office networks are quoted individually.

Is Patient Protect priced per office or per organization?

Per office. Each office instance covers the personnel and workflows for a single location — because each office has its own workforce roster, its own vendor set, its own BAAs, its own physical safeguards, and its own PHI-flow surface, even when several offices roll up to the same covered entity. A multi-office practice with three offices runs three Patient Protect instances at their tier's per-office rate; the platform coordinates across them and consolidated reporting is available. Practice networks with more than a handful of offices — DSOs, MSOs, therapy groups, specialty consolidators — should request a network quote so the price reflects office count, cross-office workflows, centralized oversight, and any shared-vendor coordination the network requires.

Are there hidden fees or per-provider charges?

No hidden fees. Pricing is published and per-office: $39/month per office for Basic (up to 25 office personnel) and $99/month per office for Pro (up to 50 office personnel). No setup fees, no implementation costs, no annual contract requirements. Larger single-office practices scale predictably at published per-5-personnel add-on rates ($10/mo on Basic, $5/mo on Pro) — the numbers are visible before you sign up, not sprung during onboarding. Multi-office networks receive a written custom quote before any commitment.

Platform & Features

What's included and how the technology works.

What features does Patient Protect include?

Twenty integrated platform features across five layers — System, Defense, Operations, Network, and Intelligence. Basic includes 14 features at $39/month. Pro unlocks all 20 with unlimited AI and expanded training at $99/month.

Does Patient Protect help with the HIPAA Security Risk Assessment?

Yes. Patient Protect includes an automated Security Risk Assessment (SRA) tool mapped to the NIST Cybersecurity Framework. It identifies vulnerabilities, scores risk, and generates documentation required by the HIPAA Security Rule.

What free HIPAA tools does Patient Protect offer?

More than 20 free tools and resources with no login required — including Ask PIPAA (AI HIPAA compliance assistant), the Unified Risk Assessment, the HIPAA Readiness Scan, the ePHI Data Flow Mapper, the HIPAA Breach Dashboard, and the HIPAA Risk Calculator. See the complete catalog at /free-tools.

Is Patient Protect's AI assistant HIPAA compliant?

Yes. PIPAA runs on Patient Protect-controlled inference infrastructure and applies dual-layer PHI redaction before any model call. Because prompts do not flow through OpenAI, Anthropic, Google, or other third-party consumer LLM APIs, PHI does not enter those providers' training pipelines. Fully air-gapped local deployment is on the development roadmap; contact us for waitlist access.

How does Patient Protect handle BAA management?

Full lifecycle: create, send for e-signature, track status, renewal alerts. BAA status gates Secure Messaging automatically.

What security standards does Patient Protect follow?

Built against OWASP Top 10 and NIST CSF. AES-256-GCM encryption, TLS 1.3, browser fingerprinting, AppSensor on every endpoint.

What is a HIPAA risk assessment?

A HIPAA Security Risk Assessment (SRA) is a mandatory evaluation of potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) in your practice. It identifies where data is stored, how it moves, who has access, and what threats exist. The Security Rule requires an accurate and thorough risk analysis and an ongoing process of review and update — it does not prescribe one universal annual frequency. Many organizations review at least annually and whenever material technological, operational, staffing, ownership, or threat changes occur. Risk analysis is the single most-cited deficiency in OCR enforcement actions.

Does Patient Protect integrate with my EHR?

Patient Protect operates alongside your EHR as a compliance and security layer — it does not require direct EHR integration to function. The platform tracks access controls, training, BAAs, and risk assessments independently. Your EHR handles clinical workflows; Patient Protect handles the compliance evidence those workflows generate.

HIPAA Compliance

Requirements, penalties, and what you need to know.

How do I know if my practice is actually HIPAA compliant?

Most practices assume they are compliant because they have policies on paper. Actual compliance requires continuous risk assessments, documented training, access controls, audit trails, and breach detection capability. The free risk assessment at Patient Protect shows you exactly where your gaps are in five minutes.

Is HIPAA compliance a one-time project or an ongoing requirement?

Ongoing. HIPAA requires continuous risk assessment, regular training, policy reviews, and active monitoring. A one-time assessment does not satisfy the regulation. That is why Patient Protect provides daily tasks, live scoring, and continuous diagnostics — not annual binders.

What happens if my practice is breached and I am not compliant?

The average healthcare data breach costs $6.64 million (IBM, 2026). OCR civil monetary penalties for HIPAA violations range from $145 to $73,011 per violation at Tier 1 (unknowing) up to $73,011 to $2,190,294 per violation at Tier 4 (willful neglect, uncorrected), with a $2,190,294 annual cap for identical violations of the same provision (2025 inflation-adjusted per 45 CFR §102.3). Beyond fines, breaches cause patient lawsuits, reputational damage, and operational disruption. For an independent practice, the financial and operational impact of a breach can be existential.

Do I need a Business Associate Agreement with every vendor?

Yes — every vendor that creates, receives, maintains, or transmits ePHI on your behalf must have a signed BAA. Missing BAAs are one of the most commonly cited HIPAA violations, even when no breach has occurred.

Do I need to hire a consultant to become compliant?

Not necessarily. Patient Protect automates much of the work consultants do manually — risk assessments, policy management, training, BAA tracking — and adds the security layer most consultants don't cover. Many practices use Patient Protect alongside their existing compliance partner; others use it as their standalone solution. Both approaches work.

What is the HIPAA breach notification requirement?

Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals within 60 calendar days of discovering a breach of unsecured protected health information. Breaches affecting 500 or more individuals must also be reported to HHS OCR and prominent media outlets.

What happens if you violate HIPAA?

OCR civil monetary penalties for HIPAA violations range from $145 to $73,011 per violation at Tier 1 (unknowing) up to $73,011 to $2,190,294 per violation at Tier 4 (willful neglect, uncorrected), with a $2,190,294 annual cap for identical violations of the same provision (2025 inflation-adjusted per 45 CFR §102.3). Willful neglect that goes uncorrected can trigger criminal penalties including fines up to $250,000 and imprisonment. Beyond enforcement, violations cause patient lawsuits, mandatory corrective action plans, reputational harm, and operational disruption that can last years.

Can you be fined for accidental HIPAA violations?

Yes. HIPAA's penalty tiers include violations where the covered entity did not know and could not have reasonably known about the breach. These carry penalties of $145 to $73,011 per violation at Tier 1 under the 2025 inflation-adjusted schedule (per 45 CFR §102.3). Ignorance is not a defense — OCR expects organizations to have systems in place that prevent and detect violations regardless of intent.

What is the difference between HIPAA Privacy and Security Rules?

The Privacy Rule governs how protected health information (PHI) in any form — paper, oral, or electronic — can be used and disclosed. The Security Rule applies specifically to electronic PHI (ePHI) and mandates administrative, physical, and technical safeguards to protect it. Both are mandatory; the Security Rule is where most enforcement actions and technical audit findings originate.

Messaging & Communication

Texting, messaging apps, and HIPAA-compliant alternatives.

Can I text patients from my personal phone?

No. SMS, iMessage, and WhatsApp are not HIPAA compliant — each text containing ePHI is a separate potential violation. Patient Protect includes encrypted secure messaging that replaces personal phone communication with compliant, auditable workflows.

Is texting patients a HIPAA violation?

Yes, if the text contains protected health information (PHI) and is sent via standard SMS, iMessage, WhatsApp, or other non-compliant channels. HIPAA requires encryption, access controls, and audit logging for all electronic communication containing ePHI.

Can I use WhatsApp to communicate with patients?

No. WhatsApp does not offer a Business Associate Agreement (BAA), does not provide audit logging, and does not meet HIPAA access control requirements. Even though it offers end-to-end encryption, it is not HIPAA compliant.

What makes messaging HIPAA compliant?

HIPAA compliant messaging requires: end-to-end encryption, unique user authentication, role-based access controls, audit logging, message retention controls, automatic session timeout, and a signed BAA with the messaging platform.

What is a Business Associate Agreement?

A Business Associate Agreement (BAA) is a legally binding contract required under HIPAA between a covered entity and any third party that creates, receives, maintains, or transmits protected health information on its behalf. It defines permitted uses and disclosures of PHI, requires the business associate to implement safeguards, and establishes breach notification obligations. Operating without signed BAAs for qualifying vendors is itself a HIPAA violation.

Can I use regular email to send patient information?

Standard unencrypted email is not HIPAA compliant for transmitting PHI. If you must use email, it requires end-to-end encryption, a BAA with the email provider, access controls, and audit logging. In practice, most small-practice email setups fail multiple requirements. Patient Protect's secure messaging eliminates this risk entirely.

Breach Data & Research

Statistics and findings from Patient Protect's research.

What is the average cost of a healthcare data breach?

The average cost of a U.S. healthcare data breach was $6.64 million per IBM's 2026 Cost of a Data Breach Report — more than double the financial services sector and roughly 2.4 times the cross-industry average. Healthcare has held the #1 position in breach costs for 13 consecutive years.

How much is stolen medical data worth on the dark web?

A full-package PHI record — including SSN, date of birth, diagnosis codes, and insurance information — commands a median dark-market value of $280–$310 per record. That is 8 to 10 times the value of stolen credit card data, driven by PHI's immutability and multi-domain fraud utility (Intel 471, Recorded Future, Flashpoint, 2024).

How long does it take healthcare organizations to detect a data breach?

Healthcare organizations take an average of 93 days to detect a breach, compared to 4 business days for mandatory disclosure in SEC-regulated finance. This 93-day window creates a sustained exploitation period where stolen data retains maximum dark-market liquidity and fraud utility (Ponemon Institute, 2024).

What percentage of Americans had their health data exposed in 2024?

Over 276 million Americans — approximately 81% of the U.S. population — had their protected health information exposed in data breaches in 2024. This represents a 64% increase from 2023's previous record (HHS Office for Civil Rights Breach Portal, 2025).

How does AI affect healthcare cybersecurity risk?

Our research quantifies an AI Amplification Factor (AAF) of 1.18–1.30 following the November 2022 ChatGPT release. AI has increased voice-cloning attacks on healthcare insurers by 475% year-over-year, boosted synthetic identity fraud by 27%, and improved phishing yield by 36% per compromised record — all while reducing the skill barrier for attackers to near-zero (Pindrop Security, 2025).

How often do independent practices get audited by OCR?

OCR conducts both complaint-driven investigations and random audits. While large-scale audit programs are infrequent, any patient complaint triggers an investigation regardless of practice size. In 2024, OCR resolved over 32,000 cases. The more common risk for independent practices is a complaint-initiated review — which can happen at any time and demands immediate evidence production.

What are the most common causes of healthcare data breaches?

The top three causes are hacking/IT incidents (79% of breaches), unauthorized access or disclosure by internal actors (18%), and theft or loss of unencrypted devices (3%). Phishing remains the primary initial attack vector, followed by exploitation of unpatched systems and credential compromise from password reuse (HHS OCR Breach Portal, 2024).

Resources & Downloads

About the free compliance resources we publish.

Are these resources really free?

Yes. Every resource is free to download. We ask for your name and email so we can send relevant updates — but there is no paywall, no trial, and no credit card.

Who created these guides?

All resources are authored by the Patient Protect team — a certified HIPAA consultant with 10+ years of clinical experience, a healthcare infrastructure architect, and a SaaS founder with 20 years in enterprise technology.

Do I need an account to download?

No. You provide your name and email once, and every resource on this page unlocks immediately — no account, no login, no password.

How often do you need HIPAA training?

HIPAA requires training for all workforce members upon hiring and periodically thereafter — most compliance authorities recommend at least annual refresher training. Additionally, training must occur whenever policies or procedures change materially. Patient Protect tracks completion dates and automatically surfaces training tasks when staff are due for renewal.

Are Patient Protect's training certificates accepted by auditors?

Yes. Patient Protect training modules generate timestamped completion certificates tied to individual user accounts. These records satisfy OCR's documentation requirements for workforce training under §164.530(b) and §164.308(a)(5). Evidence is stored for the mandatory 6-year retention period and exportable on demand.

Training & Workforce

Meeting HIPAA's workforce-training and sanctions requirements.

Does HIPAA require training for every workforce member?

Yes. Under 45 CFR §164.530(b), covered entities must train all members of the workforce on the policies and procedures that govern PHI. That includes clinical staff, front-desk staff, IT contractors with access to systems, volunteers, and interns. §164.308(a)(5) adds the Security Awareness and Training standard for anyone touching ePHI. There is no exemption for part-time staff or short-term contractors.

What must HIPAA training cover to satisfy OCR?

OCR looks for training that (1) is documented per individual, (2) covers the practice's actual policies (not a generic slide deck), (3) addresses both the Privacy Rule and the Security Rule, (4) includes real-world scenarios such as phishing recognition and permitted disclosures, and (5) is refreshed periodically. Patient Protect's HIPAA Foundations training covers all five categories and stores per-workforce completion records.

How long do we need to keep training records?

Six years from the date of creation or the date the record was last in effect, whichever is later (§164.530(j)). This applies to individual completion records, the training materials themselves, and any related policies. Missing training records is one of the most common findings in OCR investigations.

What is a HIPAA sanctions policy and do we need one?

Yes — §164.308(a)(1)(ii)(C) requires covered entities to apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures. In practice this means a written sanctions policy, documented enforcement actions, and evidence that the policy is applied consistently. A sanctions policy without a documented enforcement trail is the weakest form and OCR treats it as such.

Can I use the same training program my EHR vendor provides?

You can, but you are responsible for confirming it covers your policies, includes documentation per individual, satisfies the Security Awareness elements of §164.308(a)(5), and is refreshed at a defensible cadence. Many EHR-bundled training modules cover only Privacy Rule fundamentals and miss security-awareness content required for administrative safeguards.

Do independent contractors need HIPAA training?

If they access PHI, yes. Whether they are covered under your workforce training obligation or via a Business Associate Agreement depends on the arrangement — but the training requirement itself does not disappear. When in doubt, treat contractors with PHI access the same way you treat employees for training purposes.

What is the Patient Protect Training Initiative?

A free training program for independent healthcare practices that qualify under the initiative's eligibility criteria. Selected practices receive the full HIPAA Foundations curriculum at no cost, with completion certificates and audit-ready documentation. Apply at /independent-practice-hipaa-training-initiative.

Vendors & Business Associates

Managing BAAs, vendor risk, and third-party access to PHI.

What qualifies a vendor as a Business Associate?

Under §160.103, a Business Associate is any person or entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity for a function or activity regulated by HIPAA. Common examples: EHR vendors, billing services, cloud storage providers, IT support, medical transcription, secure messaging platforms, and analytics tools. If a vendor can access PHI — even incidentally — they are typically a Business Associate.

What must a BAA include to satisfy HIPAA?

§164.504(e) specifies the required BAA elements: permitted uses and disclosures, safeguard requirements, breach-notification timelines, obligation to enter downstream BAAs with subcontractors, return or destruction of PHI at termination, and provisions for termination if the BA breaches the agreement. A signed document that lacks these elements is not a compliant BAA.

How do I know if a vendor's BAA is up to date?

Check three things: (1) the BAA was signed by an authorized signatory at both organizations, (2) it references the Omnibus Rule (2013) rather than pre-2013 language, and (3) the vendor is currently listed on your Business Associate Inventory. Patient Protect's BAA Management surfaces expired, unsigned, and stale agreements automatically.

Are cloud providers like AWS, Google Cloud, and Azure Business Associates?

They can be, if you have executed their HIPAA-eligible BAA and are only using their HIPAA-eligible services. Both AWS and Google Cloud maintain published lists of HIPAA-eligible services; using a non-eligible service to process PHI creates exposure even with a signed BAA. Configuration matters as much as the paperwork.

What happens if a Business Associate has a breach?

Under §164.410, the Business Associate must notify the covered entity of the breach without unreasonable delay and no later than 60 days after discovery. The covered entity then owns the downstream notification obligation to affected individuals, HHS, and — in breaches affecting 500 or more individuals in the same state — the media. A BA breach does not shift the covered entity's own notification clock; it starts it.

Breach Response & Incident Handling

What to do the moment a breach is suspected — and what OCR expects to see afterward.

What counts as a breach under HIPAA?

§164.402 defines a breach as an impermissible use or disclosure of PHI that compromises the security or privacy of the information. There is a presumption of breach unless the covered entity can demonstrate — via a four-factor risk assessment (nature of PHI, unauthorized recipient, whether PHI was actually acquired or viewed, and mitigation) — a low probability that the PHI was compromised.

How fast do I need to notify affected patients after a breach?

For breaches affecting 500 or more individuals: without unreasonable delay and no later than 60 days after discovery. For breaches affecting fewer than 500: still without unreasonable delay, but the aggregate notification to HHS may be made annually. Discovery is the date the breach is known — or should have been known through reasonable diligence.

When do I have to notify the media of a breach?

If the breach affects 500 or more individuals in a single state or jurisdiction, notice must be provided to prominent media outlets in that state or jurisdiction (§164.406). This is in addition to HHS and individual notifications. Some state breach notification laws impose additional media requirements.

What documentation does OCR expect after a breach?

The four-factor risk assessment, notification records (individuals, HHS, media if applicable), the incident-response actions taken, evidence of mitigation, workforce sanctions if applicable, and any updates to policies or training triggered by the incident. Documentation gaps are what turn a breach into an enforcement action.

2026 HIPAA Security Rule Update

How the proposed 2026 Security Rule changes affect independent practices.

What is the 2026 HIPAA Security Rule update?

HHS published a Notice of Proposed Rulemaking in late 2024 to significantly modernize the HIPAA Security Rule for the first time since 2003. Proposed changes include mandatory encryption of ePHI at rest and in transit, mandatory MFA, formal asset inventories, network segmentation, incident-response testing, and shorter contingency-plan recovery targets. Once finalized, covered entities and business associates will have a transition period to comply.

Will the 2026 Security Rule affect small practices?

Yes. The proposed rule removes the current 'addressable vs. required' distinction that has historically given smaller practices flexibility on controls like encryption. Under the proposed framework, controls that were previously 'addressable' become required for all covered entities regardless of size.

What can my practice do now to prepare for the 2026 Security Rule?

Three priorities: (1) inventory every system and vendor that touches ePHI, (2) enable encryption and MFA on any system that supports it, and (3) formalize your incident-response plan with at least an annual tabletop test. Patient Protect's platform maps to the proposed rule's control categories so a practice's compliance state translates directly when the rule finalizes.

State Laws & Multi-State Practices

How state privacy laws layer on top of HIPAA.

Do state privacy laws override HIPAA?

No — but they can add requirements HIPAA does not impose. HIPAA is a floor, not a ceiling. State laws that are more protective of patient privacy (California's CCPA/CPRA, Texas Medical Records Privacy Act, Washington's My Health My Data Act, and others) apply in addition to HIPAA, not instead of it. Multi-state practices need to track requirements in every state where they operate.

Do I need to notify state Attorneys General after a breach?

Many states require it. Massachusetts, New York, California, Texas, and Washington are among the states with state-AG notification requirements that often run on shorter timelines than HIPAA's 60 days. Check the state law for every state where any affected individual resides — not just the state of your practice.

How does Washington's My Health My Data Act interact with HIPAA?

The Washington MHMDA covers consumer health data broadly and can apply to entities not otherwise covered by HIPAA — health apps, wellness platforms, wearable-device makers. Where an entity is subject to both HIPAA and MHMDA, HIPAA-compliant handling generally satisfies MHMDA's baseline. But MHMDA adds consent, disclosure, and consumer-rights requirements that HIPAA does not impose.

AI & Clinical Technology

How HIPAA applies to AI scribes, ambient documentation, and clinical AI.

Are AI clinical scribes HIPAA compliant?

It depends on the specific vendor, their BAA, and their configuration. A HIPAA-compliant AI scribe must (a) have an executed BAA with your practice, (b) process PHI only in HIPAA-eligible infrastructure, (c) retain audio and generated notes per your retention policy, and (d) provide access logs. Consumer-grade AI assistants (ChatGPT, general Claude, Gemini) without a BAA are not HIPAA-compliant for PHI processing.

Can I use ChatGPT or general-purpose AI to draft patient communications?

Not with real patient identifiers, and not through a consumer account without a BAA. Even in the paid API tier, OpenAI's BAA requires specific configuration to be considered compliant handling of PHI. For patient-communication drafting, use tools with an executed BAA — or de-identify data before input. Patient Protect's PIPAA is built to answer HIPAA questions without ingesting your PHI.

Patient Protect is intuitive, proactive, and affordable — exactly what small clinics like ours need to keep patient data safe and stay on the right side of HIPAA.
Dr. Thomas E Murray, D.D.S.Patient Protect Member Since 2017

Next step

Get your Patient Protect Score Snapshot in 2 minutes.

Free risk assessment — no login, no credit card. Whether you already work with a compliance vendor or are starting fresh.