Resources

Plain-language answers to the questions we get asked most.

Articles on HIPAA Security Risk Analysis, MIPS requirements, business associate obligations, and the practical side of healthcare compliance. Written by our founder from fifteen years of doing the work.

MIPS Compliance

MIPS Security Risk Analysis requirements for 2026: what changed, and what auditors expect to see

For the 2026 performance year the measure asks two questions instead of one, and getting either wrong zeroes out the entire Promoting Interoperability category.

September 6, 20269 min read
HIPAA Fundamentals

What a HIPAA Security Risk Analysis actually is, and what OCR expects to see

The most cited failure in HIPAA enforcement, and most organizations cited believed they had one. The nine elements OCR looks for, and how to tell a real analysis from a document that resembles one.

September 6, 20268 min read
HIPAA Fundamentals

Risk analysis, risk assessment, gap assessment: the differences that matter

Vendors use these terms loosely and organizations buy the wrong thing as a result. What each one is, which one HIPAA requires, and what to ask before you sign.

September 6, 20267 min read
HIPAA Fundamentals

How often is a HIPAA Security Risk Analysis required?

The rule does not give a number. Why annual became the working standard, what MIPS requires, and the events that should trigger a fresh look regardless of the calendar.

September 6, 20266 min read
Business Associates

HIPAA requirements for business associates: what you are directly on the hook for

Since 2013, vendors handling patient data are directly liable under the Security Rule. Who qualifies, what is required, and the gaps that most often catch companies off guard.

September 6, 20268 min read
Have a question you would like to see answered here? Send it to us. The questions clients actually ask are where these articles come from.