Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

Intelligence · Compliance News

The news arrives where the work is. Not in a newsletter you meant to read.

A modest thing done properly: enforcement and breach news on the same screen as your compliance queue, refreshed daily, with an office setting for what the feed carries.

Included in Basic·Starting at $39/mo

HIPAA mapping

Where this fits in the HIPAA rules.

2 provisions this capability contributes to, each with the specific Compliance News behavior behind it. The obligation stays with your practice — the mapping shows which part of the work the platform carries.

§164.404

Notification to individuals

Specifies notification requirements following breaches. The news feed surfaces breach patterns useful for understanding notification practices in your sector.

§164.408

Notification to the Secretary

Specifies reporting obligations to HHS. The OCR breach disclosure data is the public output of these reports; the feed surfaces the relevant disclosures for your context.

What it does

Filtered intelligence. No noise.

Independent practices can't keep up with HIPAA enforcement and breach activity by reading every health-IT publication. The volume is too high; the relevance is too uneven. Most practices end up either over-subscribed (signal lost in noise) or under-subscribed (missing patterns that affect their sector). Neither produces actionable intelligence.

Compliance News is the alternative. The platform ingests HHS OCR breach data daily, layers in enforcement actions and regulatory updates, and filters to what's relevant for your practice — your sector, your size, your operational context. The result is a focused intelligence feed: what's happening in HIPAA enforcement that you should know about, and only that.

Some items are informational (“here's what happened”); some trigger Compliance Advice items (“review your training given this enforcement pattern”); some inform Risk Intelligence (“vendor X had a public incident, your BAA relationship may warrant review”).

How it works

7 mechanisms keep Compliance News working.

01

Daily OCR data ingestion.

The HHS Office for Civil Rights publishes breach disclosure data publicly. The platform ingests this data daily via the public APIs and feeds. New disclosures appear in the news feed within 24 hours of HHS publication.

02

Enforcement, as it publishes.

Settlements and corrective action plans as they are announced.

03

The office manages its own feed.

An Administration screen governs what the feed carries, so the news a practice sees is a setting rather than a fixed broadcast. What that screen exposes today is worth asking us about directly rather than reading here — this page is deliberately not going to describe filtering behavior it cannot show you.

04

News beside the queue, not in an inbox.

The feed lives in the platform, on the same screen set as the Compliance Advice you are already working through. That placement is the mechanism. Enforcement news delivered by newsletter competes with everything else in a practice manager's morning; enforcement news sitting next to the queue is read by the person who can act on it.

05

A news surface, and only that.

This is not the threat-intelligence system and the two should not be collapsed. The sector-wide picture — breach filings, enforcement actions, advisories, maps and trends — is a different capability with different mechanics, and it has a public home at the Breach Dashboard. What this does is put the reading material where the work is.

06

Public sources only.

Nothing in the feed comes from another practice's private data.

07

A news surface.

Not the threat-intelligence system, which is a different capability.

Who this is for

Built for the practices that need it most.

Practices that want signal without subscribing to publications.

Health-IT publications, compliance newsletters, vendor blog feeds — all carry HIPAA news, all carry mostly-irrelevant HIPAA news for any specific independent practice. The filtered feed is the alternative.

Practices in sector-specific threat contexts.

Behavioral health attacks differ from optometry attacks differ from primary care attacks. Sector-relevant news produces intelligence that generic feeds dilute.

Practices with vendor concentration.

When a major vendor experiences an incident, every connected practice is affected. The feed surfaces vendor-specific events that warrant review of your own vendor relationships.

Practices with reporting or board responsibilities.

The feed's trend analytics produce useful inputs for board reporting — sector breach trends, enforcement patterns, relevant comparison points.

What you get

6 outcomes you’ll feel in week one.

Where the work is.

On the same screens as your compliance queue.

Daily OCR data.

Public breach disclosures ingested within 24 hours of HHS publication.

Enforcement action tracking.

Settlement and CMP patterns observable as they emerge.

Managed by the office.

An Administration screen governs what the feed carries.

Community signal aggregation.

Network-effect intelligence from connected practices.

Trend analytics.

Sector and pattern visualization for board and program reporting.

FAQ

What people ask first.

6 questions cover most first-time evaluations. See all FAQs →

Can the office control what the feed carries?
There is an Administration screen for managing the news feed, so this is a setting rather than a fixed broadcast. What exactly it exposes today is a question worth putting to us directly — describing filtering behavior we cannot demonstrate is how a page ends up promising a control that does not exist.
How current is it?
The breach ingest runs daily, which is the cadence HHS publication supports — OCR does not publish continuously, so a feed claiming to be live would be claiming to know things before they exist. Enforcement announcements and regulatory items arrive as they are published. Daily is the honest word and we use it deliberately rather than reaching for a livelier one.
What about non-public information?
The feed uses only publicly-available data. Non-public information (your practice's own incident details, specific practices' confidential information) is never in the feed. Network signals from connected practices are aggregated anonymously.
How is this different from the Breach Dashboard?
Different jobs and different mechanics. The Breach Dashboard is the public sector-wide picture — filings, enforcement, maps, trends, severity — and it is open to anyone. This is a reading surface inside the platform, positioned next to the work. Collapsing the two into one claim about a threat-intelligence platform would misdescribe both.
Does the feed replace my legal counsel?
No. The feed is intelligence; legal counsel is interpretation. Significant enforcement actions warrant counsel discussion. The feed surfaces what's worth discussing.
Which plan includes it?
Basic. There is no Pro tier of the news feed, and an earlier version of this page claimed one.

What it does not do.

  • A news surface, not the threat-intelligence system — different mechanisms, and collapsing them would misdescribe both
  • Basic. There is no Pro tier of the feed, whatever an earlier page said.

HIPAA news that's relevant. Filtered daily. Without the noise.

Most practices configure their sector and size in minutes. The feed starts surfacing relevance the same night.