Articles on HIPAA Security Risk Analysis, MIPS requirements, business associate obligations, and the practical side of healthcare compliance. Written by our founder from fifteen years of doing the work.
For the 2026 performance year the measure asks two questions instead of one, and getting either wrong zeroes out the entire Promoting Interoperability category.
The most cited failure in HIPAA enforcement, and most organizations cited believed they had one. The nine elements OCR looks for, and how to tell a real analysis from a document that resembles one.
Vendors use these terms loosely and organizations buy the wrong thing as a result. What each one is, which one HIPAA requires, and what to ask before you sign.
The rule does not give a number. Why annual became the working standard, what MIPS requires, and the events that should trigger a fresh look regardless of the calendar.
Since 2013, vendors handling patient data are directly liable under the Security Rule. Who qualifies, what is required, and the gaps that most often catch companies off guard.