Feature Articles

Free Webinar: A Practical Guide to a HIPAA Security Risk Assessment

Security Risk Assessment for HIPAA ComplianceA missing or inadequate HIPAA Security Risk Assessment can leave a major gap in your HIPAA compliance program. It is also one of the issues most frequently identified in OCR enforcement actions.

Yet many practices remain uncertain about what an SRA should cover, how often it should be updated, and what distinguishes a genuine risk analysis from a simple checklist.

Join Bradley King, Senior Compliance Consultant, for a practical 30-minute webinar that will explain the role of the SRA and help you identify your next steps. Whether you are completing an SRA for the first time or reviewing your existing documentation, you will leave with a clearer understanding of what your practice needs to do.

You will discover:

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

  • What is-and is not-a HIPAA Security Risk Analysis
  • Where the SRA fits within your wider HIPAA compliance program
  • When your SRA should be reviewed and updated
  • Why SRA deficiencies are a recurring focus of OCR enforcement
  • The practical steps your organization can take to strengthen its approach

If you can’t attend the live event then register anyway, and we will send you the recording.


Date of Live Webinar: October 28, 2026

Time: 12-12:30 PM ET, 11-11:30 AM CT, 10-10:30 AM MT, 09-09:30 AM  PT

Duration: 00:30 Hour

Can’t join live? Register and we’ll send you the recording. 


 

This webinar is presented by Abyde in partnership with The HIPAA Journal.

Speaker: Bradley King, Senior Compliance Consultant

Bradley King has many years of experience in HIPAA and OSHA compliance consulting. He has spoken at national conferences and delivered continuing education webinars on HIPAA and OSHA compliance best practices, and has worked directly with thousands of practices, from solo, owner-operator practices to multi-location, multistate healthcare organizations, on building and maintaining compliance programs.

Abyde is a leader in the compliance software industry, streamlining HIPAA & OSHA requirements for thousands of practices across the United States.

 


Date of Live Webinar: October 28, 2026

Time: 12-12:30 PM ET, 11-11:30 AM CT, 10-10:30 AM MT, 09-09:30 AM  PT

Duration: 00:30 Hour

Can’t join live? Register and we’ll send you the recording. 

The post Free Webinar: A Practical Guide to a HIPAA Security Risk Assessment appeared first on The HIPAA Journal.

Free Webinar Today: Is AI Putting Your Practice at Risk?

HIPAA Rusk analysis security risk assessment toolAI tools are already in your practice. The question is whether you know about them and whether they are HIPAA-compliant. 

Most practices are using AI in some form already, whether it’s an EHR feature, a note-taking assistant, or a chatbot tool; however, they may not be aware of all locations where AI is used.

Join Ryan Boudreau, Senior VP of Operations at the healthcare compliance company Abyde, as he walks you through where AI may already be hiding in your practice, the HIPAA and privacy risks it creates, and a simple framework for using AI while remaining HIPAA-compliant. 


Live Webinar: Wednesday, Sept 30 

12:00-1:00 PM ET | 11:00 AM-12:00 PM CT | 10:00-11:00 AM MT | 9:00-10:00 AM PT

 A recording will be made available to anyone who registers but is unable to attend the live event.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy


Attendees will discover:

  • Where AI is most likely already in use in your practice, including the places you didn’t realize
  • A simple, four-question framework for evaluating any AI tool before you use it
  • The fine print that matters in vendor agreements to help avoid risk
  • Real-world cautionary tales on improper AI use in healthcare

Speaker: 

Ryan BoudreauRyan Boudreau – Senior Vice President of Operations 

Ryan Boudreau is the Senior Vice President of Operations at Abyde, where he leads a team of HIPAA and OSHA compliance experts. A cybersecurity and risk management veteran with nearly 15 years of experience, his team that has successfully navigated hundreds of OCR investigations on behalf of their clients.

Abyde is a leader in the compliance software industry, streamlining HIPAA & OSHA requirements for thousands of practices across the United States.


Live Webinar

Wednesday, Sept 30  | 12:00–1:00 PM ET | 11:00 AM–12:00 PM CT | 10:00–11:00 AM MT | 9:00–10:00 AM PT

 A recording will be made available to anyone who registers but is unable to attend the live event.

The post Free Webinar Today: Is AI Putting Your Practice at Risk? appeared first on The HIPAA Journal.

Free Webinar Recording: Inside 250 HIPAA Investigations – What You Need to Know

Free Webinar Inside a HIPAA InvestigationLearn exactly what happens during a HIPAA investigation. Understand where organizations fail so you can avoid government fines and drawn-out investigations.

Based on real experience from over 250 actual OCR investigations.

When it comes to HIPAA investigations, many organizations lean on the hope that they will never be implicated. But, with the rise of ransomware breaches and patient complaints, your organization is much more likely to end up in the crosshairs of the Office for Civil Rights (OCR) than you might expect. 

While you can’t always prevent breaches from occurring, you can control your preparedness for everything that follows when it comes to your HIPAA compliance posture. 

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Join Jake Dewberry, Chief Legal Officer, and Ryan Boudreau, Senior Vice President of Operations from Abyde, as they walk through the details of what an investigation actually looks like and where organizations fail based on their experience in over 250 OCR investigations. They will be sharing real (redacted) examples from past investigations, detailing what the OCR asks for, how to respond safely, and how others failed so you can avoid government fines and drawn-out investigations. 


On Demand Webinar Recording

August 19th Event Ended – Available on Demand 

 

 A recording will be made available to anyone who registers but is unable to attend the live event.


Attendees discover:

  • What triggers an investigation
  • What to do immediately after receiving an investigation letter
  • A breakdown of what the OCR is really asking for, including the most commonly missed requirement
  • Best practices for building your response
  • The possible results of an investigation
  • Real examples of investigation letters

Speakers: 

Jake Dewberry Jake Dewberry – Chief Legal Officer

Jake Dewberry serves as the Chief Legal Officer at Abyde. With over 14 years of experience in the healthcare industry, Jake has worked closely with hospitals and small to mid-sized practices across the country, helping them navigate the evolving world of healthcare technology and regulatory requirements. Jake is also a licensed attorney based in Florida. At Abyde, he wears multiple legal hats — from advising clients during breach responses and audits, to managing the company’s day-to-day legal operations, and staying on top of federal and state regulatory changes impacting HIPAA and OSHA compliance.

 

Ryan BoudreauRyan Boudreau – Senior Vice President of Operations 

Ryan Boudreau is the Senior Vice President of Operations at Abyde, where he leads a team of HIPAA and OSHA compliance experts. A cybersecurity and risk management veteran with nearly 15 years of experience, his team has successfully navigated hundreds of OCR investigations on behalf of their clients.

Abyde is a leader in the compliance software industry, streamlining HIPAA & OSHA requirements for thousands of practices across the United States.


On Demand Webinar Recording

August 19th Event Ended – Available on Demand

 A recording will be made available to anyone who registers but is unable to attend the live event.

The post Free Webinar Recording: Inside 250 HIPAA Investigations – What You Need to Know appeared first on The HIPAA Journal.

Free Webinar Tomorrow: Inside 250 HIPAA Investigations – What You Need to Know

Free Webinar Inside a HIPAA InvestigationLearn exactly what happens during a HIPAA investigation. Understand where organizations fail so you can avoid government fines and drawn-out investigations.

Based on real experience from over 250 actual OCR investigations.

When it comes to HIPAA investigations, many organizations lean on the hope that they will never be implicated. But, with the rise of ransomware breaches and patient complaints, your organization is much more likely to end up in the crosshairs of the Office for Civil Rights (OCR) than you might expect. 

While you can’t always prevent breaches from occurring, you can control your preparedness for everything that follows when it comes to your HIPAA compliance posture. 

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Join Jake Dewberry, Chief Legal Officer, and Ryan Boudreau, Senior Vice President of Operations from Abyde, as they walk through the details of what an investigation actually looks like and where organizations fail based on their experience in over 250 OCR investigations. They will be sharing real (redacted) examples from past investigations, detailing what the OCR asks for, how to respond safely, and how others failed so you can avoid government fines and drawn-out investigations. 


Live Webinar: Wednesday, August 19

12-1 pm ET | 11-12 am CT | 10-11 am MT | 9-10 am PT

 

 A recording will be made available to anyone who registers but is unable to attend the live event.


Attendees will discover:

  • What triggers an investigation
  • What to do immediately after receiving an investigation letter
  • A breakdown of what the OCR is really asking for, including the most commonly missed requirement
  • Best practices for building your response
  • The possible results of an investigation
  • Real examples of investigation letters

Speakers: 

Jake Dewberry Jake Dewberry – Chief Legal Officer

Jake Dewberry serves as the Chief Legal Officer at Abyde. With over 14 years of experience in the healthcare industry, Jake has worked closely with hospitals and small to mid-sized practices across the country, helping them navigate the evolving world of healthcare technology and regulatory requirements. Jake is also a licensed attorney based in Florida. At Abyde, he wears multiple legal hats — from advising clients during breach responses and audits, to managing the company’s day-to-day legal operations, and staying on top of federal and state regulatory changes impacting HIPAA and OSHA compliance.

 

Ryan BoudreauRyan Boudreau – Senior Vice President of Operations 

Ryan Boudreau is the Senior Vice President of Operations at Abyde, where he leads a team of HIPAA and OSHA compliance experts. A cybersecurity and risk management veteran with nearly 15 years of experience, his team has successfully navigated hundreds of OCR investigations on behalf of their clients.

Abyde is a leader in the compliance software industry, streamlining HIPAA & OSHA requirements for thousands of practices across the United States.


Live Webinar: Wednesday, August 19

12-1 pm ET | 11-12 am CT | 10-11 am MT | 9-10 am PT

 A recording will be made available to anyone who registers but is unable to attend the live event.

The post Free Webinar Tomorrow: Inside 250 HIPAA Investigations – What You Need to Know appeared first on The HIPAA Journal.

What is a HIPAA Audit Checklist?

A HIPAA audit checklist is a document covered entities and business associates should use to audit compliance with the standards of the HIPAA Administrative Simplification Regulations applicable to their operations.

HIPAA Audit ChecklistAn internal HIPAA audit checklist differs from an external HIPAA audit checklist inasmuch as an external HIPAA audit checklist is designed to meet specific criteria of the OCR audit protocol, CMS’ compliance review program, or a third-party’s certification requirements.

By comparison, an internal HIPAA audit checklist is a comprehensive document that covers all areas of an organization’s compliance obligations. However, as different organizations have different compliance obligations, there is no “one-size-fits-all” internal HIPAA audit checklist.

Covered entities and business associates should review the following content, determine which standards of the HIPAA Administrative Simplification Regulations apply to their operations, and develop a HIPAA internal audit checklist that meets their requirements. The checklist should then be used as a HIPAA compliance audit checklist to identify gaps in compliance and implement measures to fill gaps.

hipaa audit checklist - thehipaajournal.com

Administrative Requirements Audit Checklist

The Administrative Requirements of HIPAA (Part 162) cover areas such as Unique Health Identifiers, Transaction Rules, and Code Set Standards. Covered entities that conduct claims processing or administration in-house, and business associates that provide billing and claims management services for covered entities, are required to comply with the standards of this Part.

Generally, there are only three areas of compliance organizations may need to include on an internal HIPAA audit checklist – the operating rules, the transaction rules, and documentation.

  • Verify compliance with the operating rules for eligibility, claims status, and electronic funds transfer/remittance advice.
  • Test transactions for compliance using the Administrative Simplification Enforcement and Testing Tool (ASETT).
  • Document policies, procedures, and test results for when the documentation is required for a compliance review.

While violations of the Administrative Requirements have never yet resulted in a civil monetary penalty, CMS has the authority to fine covered entities and business associates for noncompliance with Part 162 if an organization fails a CMS HIPAA audit and subsequently fails to comply with a corrective action plan. In the year to May 2023, 51% of organizations failed compliance reviews and were issued with a corrective action plan. (Reports for 2024 and 2025 have not been published).

HIPAA Privacy Rule Audit Checklist

The HIPAA Privacy Rule only has two basic HIPAA audit requirements – to protect individually identifiable health information from impermissible uses and disclosures, and to give individuals rights over their protected health information. To comply with these two requirements, organizations subject to the HIPAA Privacy Rule must comply with up to fourteen sets of standards depending on the nature of their operations.

Why “up to” fourteen? This is because, while all covered entities are required to comply with the HIPAA Privacy Rule, some standards do not apply to all types of organizations – for example, some standards apply to only health plans. Some business associates may be required to comply with specific HIPAA Privacy Rule standards depending on the service being provided for or on behalf of a covered entity and/or on the terms of their Business Associate Agreement with the covered entity.

All organizations subject to HIPAA compliance should review the following list, determine which applies to their operations, and add the relevant items to a HIPAA compliance audit checklist.

1. Designate a HIPAA Privacy Officer

Although most organizations will be familiar with this requirement, it is essential a member of the workforce is designated the role of Privacy Officer to be the point of contact for patients/plan members, workforce members, and regulatory agencies. The HIPAA Privacy Officer also has the responsibility to develop and implement HIPAA-compliant policies and procedures.

2. Understand What Constitutes PHI

There is a lot of misunderstanding about PHI, due to which some organizations can be unnecessarily overprotective with data, while others can be a little too carefree. Not only is it important to understand what constitutes PHI; but, for the sake of security and efficiency, to develop procedures for securing PHI in the minimum number of designated record sets practical.

3. Permissible Uses and Disclosures

Make sure all members of your organization´s workforce understand the difference between required, permissible, and attestable uses and disclosures of PHI, uses and disclosures of PHI for which an individual should be given an opportunity to consent or object, and uses and disclosures of PHI for which an individual´s written HIPAA authorization is required.

4. Procedures for Obtaining Authorizations

Every covered entity should have procedures for obtaining and managing authorizations so that if an individual exercises the right to revoke an authorization, the revocation can be actioned without delay. Procedures should also exist for (for example) withdrawing any information about the patient that has been used in fundraising or marketing material.

5. Notices of Privacy Practices

Every patient or plan member must be given a Notice of Privacy Practices when first attending a healthcare facility or enrolling in a health plan. The Notice must contain details of how PHI may be used or disclosed without an authorization, when it may only be used with the individual´s authorization, the rights of the individual to request privacy protection or copies of PHI.

6. Procedures for Responding to Requests for Privacy Protection

Individuals have the right to request restrictions on certain uses and disclosures – which can be situation-specific – and request to restrict how they are contacted by a covered entity or business associate. Organizations must have procedures in place to respond to requests for privacy protection, manage requests, and document oral terminations of requests.

7. Procedures for Responding to Requests for Access, Correction, and Transfer

The failure to provide access to health information, correct it when necessary, and transfer it to other providers when requested is one of the leading causes of complaints to HHS’ Office for Civil Rights. In an attempt to reduce the number of complaints, the agency is increasing its enforcement action against organizations that fail to respond to requests in a timely manner.

8. Procedures for Maintaining an Accounting of Disclosures

Individuals have the right to request an accounting of disclosures of their PHI for the six years prior to the request being made. However, not all disclosures have to be accounted for. It is important that covered entities understand which disclosures have to be accounted for and adopt procedures for maintaining an accounting of disclosures for each individual.

9. Workforce Training

Under the Privacy Rule, the training requirements are limited in scope to members of the workforce to whom HIPAA policies and procedures apply. However, basic HIPAA training should be provided to all members of the workforce in order to mitigate the risk of impermissible disclosures due to a lack of knowledge and reduce the risk of human error.

10. Documentation

Documentation is a requirement of nearly every standard in the HIPAA Privacy Rule, and organizations required to comply with the standards must put procedures in place for documenting policies and procedures, Notices of Privacy Practices, individual authorizations, workforce training, etc., and retaining policies and procedures for at least six years since they were last in force.

Organizations subject to the HIPAA Privacy Rule should also review the General Provisions of Part 164 – a section of the Administrative Simplification Regulations not covered by a “Rule”. These provisions primarily apply to Hybrid Entities, Affiliated Entities, and Organized Health Care Arrangements, and cover restricting access to PHI to only those who are authorized to access it within their roles and safeguarding PHI from non-covered areas of the organization.

HIPAA Security Rule Audit Checklist

Compared to the potential complexity of a HIPAA Privacy Rule audit checklist, a HIPAA Security Rule audit checklist is relatively straightforward. Not only does the HIPAA Security Rule contain far fewer standards than the HIPAA Privacy Rule, but the standards within the HIPAA Security Rule are less open to interpretation. The Security Standards General Rules also allow covered entities and business associates a “flexibility of approach” about how the standards are implemented.

To help organizations compile a HIPAA audit checklist for the HIPAA Security Rule, the Office of the National Coordinator for Health Information Technology (ONC) and HHS’ Office for Civil Rights have jointly produced a HIPAA Security Risk Assessment (SRA) Tool. Organizations can use the tool online or download as an Excel document to fulfill the risk assessment requirements of the Security Rule. However, this tool may not be suitable for all organizations; and before using it, it is advisable to consider the following questions:

1. Has your organization designated a HIPAA Security Officer?

This can be the same person as the HIPAA Privacy Officer but they need to be qualified for the position inasmuch as they have to design, implement, and enforce security policies and procedures. Ideally, it is best to designate this role to a senior member of the IT team.

2. Have you identified from where ePHI originates?

In order to protect ePHI from unauthorized access, disclosure, alteration, or deletion, you have to know from where ePHI originates, where it is maintained, and to where it is transmitted. Effectively, you need to create an audit trail for all ePHI in your organization´s possession.

3. Do you know how users access ePHI?

Before using the ONC/OCR Security Risk Assessment Tool, you need to conduct an inventory of devices used to access ePHI and the media on which it is stored. This not only includes onsite devices and servers, but also devices used to access ePHI remotely.

4. What security software is already in place?

As a covered entity or business associate, you are required to implement measures to mitigate threats from malware, ransomware, and phishing. Many organizations already have security measures – such as email and web filters – in place to mitigate threats.

5. What role-based access controls are already in place?

Similar to the previous item, many organizations already utilize role-based access controls to control what information users can access. It is far easier to adjust existing controls to comply with the Security Rule standards than start from scratch.

6. What other security mechanisms do you already use?

Due to the “flexibility of approach” clause and the fact that some implementation specifications are addressable, it may be possible to comply with many HIPAA Security Rule standards by enforcing the use of existing security mechanisms – i.e., PIN lock, automatic log-off, password managers, etc.

7. What processes already exist for reporting security incidents?

Most organizations should already have processes in place to flag suspect emails, malware, and other anomalies. These are usually sufficient for internal compliance with the HIPAA Security Rule – not forgetting that business associates are required to report all security incidents to covered entities.

8. Does the organization already have a security awareness training program?

The likelihood is that most organizations will have some form of security awareness training, and all that may be necessary for the training to meet the General Requirements of the HIPAA Security Rule (§164.406) is to tweak it to be more HIPAA-centric and ensure the training is documented.

9. Does the organization enforce a scaled sanctions policy?

Enforcing a scaled sanctions policy is an important step toward HIPAA compliance because it serves as a reminder to members of the workforce that minor or repeated violations of HIPAA can have consequences.

10. Does the organization have a contingency or emergency action plan?

Developing a contingency plan for foreseeable emergency events that may threaten the confidentiality, integrity, and availability of ePHI is a requirement of HIPAA. You may need to review the SRA Tool to ensure you have every type of emergency covered.

Although this HIPAA Security Rule HIPAA audit checklist is relatively basic with regards to the questions it asks, it is advisable to start a journey to HIPAA compliance by assuming zero knowledge – rather than assuming an existing degree of knowledge as the SRA Tool does. In addition, when implementing new measures, it is a best practice to test members of the workforce on what information they have absorbed rather than assume they have understood the new measures in one explanation.

HIPAA Audit Log Requirements

Whether you use a HIPAA Security Rule Audit Checklist or the SRA Tool, it is important not to overlook the HIPAA audit log requirements. The HIPAA Security Rule requires covered entities and business associates to implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic Protected Health Information.

Audit logs enable covered entities and business associates to identify risks associated with events such as unauthorized access, impermissible disclosures, application flaws, and suspicious activities. They can also be used to provide forensic evidence following a security incident or data breach so measures can be put in place to prevent a reoccurrence.

The HIPAA Security Rule does not specify what data needs to be collected by audit logs or how frequently logs should be reviewed. HHS also acknowledges that different software solutions and applications record and examine system activity in different ways. For this reason, it can be beneficial for covered entities and business associates to implement HIPAA compliance software that can monitor all system activity and flag issues for further investigation.

Breach Notification Rule Audit Checklist

As business associates are required to notify covered entities of all security incidents (not just those that result in a breach of unsecured ePHI), business associates will need to use a different Breach Notification Rule audit checklist than a covered entity – who can use a HIPAA breach notification tool to determine whether a security incident is reportable or not. However, both Breach Notification Rule audit checklists will share some common items – for example:

  • How did the breach/security incident occur?
  • How has the impact of the breach/security incident been mitigated?
  • What should be done to prevent the breach/security incident from happening again?

It is also the case that procedures should be in place and responsibilities assigned for notifying covered entities of a security incident or for covered entities notifying HHS’ Office for Civil Rights and impacted individuals of a breach of unsecured ePHI. As with all other areas of HIPAA compliance, the procedures, all breaches/security incidents, and their outcomes must be documented and the documentation retained for a minimum of six years.

Advice for Developing and Completing HIPAA Audit Checklists

Integrating every element of HIPAA compliance into a single HIPAA audit checklist can be challenging and – due to the checklist’s comprehensiveness – potentially leave gaps that lead to compliance failures. There are two ways to overcome this challenge. Either divide the HIPAA audit checklist into smaller, more manageable units, or engage the services of a compliance professional to help you with both the development and the completion of the checklist.

One of the advantages of choosing the latter option is that compliance professionals have the experience to assess an existing checklist, determine how much help you need, and provide as much help as necessary to produce an accurate and comprehensive checklist. This approach has the benefit of preventing the scenario in which you are looking for threats that do not exist in standards that do not apply to your organization – saving your time and your organization’s money.

FAQs

What are the HIPAA Administrative Simplification Regulations?

The HIPAA Administrative Simplification Regulations are the “Administrative Data Standards and Other Requirements” that were developed as a result of the passage of HIPAA (Title 45, Subtitle A, Subchapter C of the Code of Federal Regulations).

The Regulations not only include the standards for the Administrative Requirements and the HIPAA Privacy, Security, and Breach Notification Rules, but also the General Administrative Provisions, the General Security and Privacy Provisions, and the Enforcement Rule.

Could CMS issue a civil monetary penalty for noncompliance?

The Centers for Medicare and Medicaid Services (CMS) has the same authority to impose sanctions on noncompliant organizations as HHS’ Office for Civil Rights. In theory, CMS could impose a fine of up to $2,134,831 on a covered entity or business associate who repeatedly failed to comply with the Administrative Requirements due to willful neglect.

Why are business associates required to comply with the Privacy Rule?

The applicability standard of the HIPAA Privacy Rule (§164.104) was amended via the Final Omnibus Rule in 2013 to read “Where provided, the standards, requirements, and implementation specifications adopted under this part [the HIPAA Privacy Rule] apply to a business associate.”

This means that a business associate may need to develop policies and procedures relating to permissible uses and disclosures and for managing access requests if an individual’s ePHI is maintained in a separate designated record set from that of the covered entity.

Does a business associate have to designate a Privacy Officer?

This depends on the nature of the business associate’s operations and the potential for interactions with the public and regulatory authorities. If there is likely to only be minimal interaction, the role of Privacy Officer could be designated to a Security Officer.

What is considered PHI under HIPAA?

This is possibly the most frequently asked question relating to HIPAA compliance because what is considered PHI under HIPAA is complicated – so complicated that we have dedicated a full-page article to answering this question.

Why is the ONC/OCR Security Risk Assessment Tool not suitable for all organizations?

According to the OCR’s website, “the tool’s features make it useful in assisting small and medium-sized health care practices and business associates”. This implies that it is not suitable for health plans, healthcare clearinghouses, and larger organizations.

In addition, the tool assumes a certain level of knowledge and that a number of measures have already been implemented to comply with HIPAA Security Rule standards. If your organization is taking its first steps towards HIPAA compliance, you may find the tool too advanced for your needs.

How might an organization already have role-based access controls in place?

Many organizations use identity and access management services such as Microsoft AD, Okta Lifecycle Management, or Open LDAP (etc.) to control who in the organization has access to systems and databases. These services can often be used to comply with the HIPAA Security Rule access requirements.

What is the difference between a HIPAA compliance audit checklist and a healthcare compliance audit checklist?

The difference between a HIPAA compliance audit checklist and a healthcare compliance audit checklist is that a HIPAA compliance checklist helps organizations audit their compliance with HIPAA, while a healthcare compliance checklist helps organizations audit their compliance with all applicable federal, state, and local regulations related to their healthcare activities (i.e., CMS’ Medicare regulations, OSHA workplace regulations, and state licensing requirements).

What are 3 important components of a HIPAA security audit?

All components of a HIPAA security audit are important. However, the 3 elements of a HIPAA security audit most organizations should focus on include:

  • An inventory and audit trail of ePHI. If you do not know where ePHI originates, where it is stored, how it is used, and how it is disclosed, it will be impossible to implement measures to safeguard the confidentiality, integrity, and availability of health information.
  • The implementation and configuration of software. It is often not sufficient to implement software described as “HIPAA compliant” to comply with the HIPAA Security Rule. The software also has to be configured to mitigate threats to health information.
  • Workforce training and compliance monitoring. All members of the workforce must receive security awareness training even when they do not have access to ePHI. It is also important to monitor compliance with the security awareness training.

The post What is a HIPAA Audit Checklist? appeared first on The HIPAA Journal.

Free Webinar TODAY: AI + HIPAA: Innovating in Healthcare Without Leaving Compliance Behind

Artificial intelligence has tremendous potential in healthcare, and healthcare organizations have embraced AI tools in all areas of their operation; however, there are compliance risks associated with AI when tools engage with health information protected under the Health Insurance Portability and Accountability Act (HIPAA). Incorporating AI tools while complying with all HIPAA Privacy and Security Rule implementation specifications can be challenging, especially when there is limited guidance on how HIPAA applies to AI.

Fortunately, help is at hand. On July 8, 2026, the HIPAA-compliant communication platform provider Paubox is hosting a webinar where healthcare organizations can learn from a diverse panel of experts about AI-related HIPAA compliance challenges and receive invaluable advice on how to keep innovating without leaving HIPAA compliance behind.

During the webinar, attendees will learn about how real-world healthcare teams are developing and implementing AI tools and the challenges they have faced, the specific questions you need to be asking any AI vendor before you sign and handle business associate agreements (BAAs), what responsible use of AI with PHI looks like, and what the future holds, and what you need to do right now.  At the end of the webinar, there will be time allocated for a Q&A with the panel to get answers to your questions.

Speakers:

Heather Phillips, FoXX Health

Heather Phillips – Advisory Committee Member, FoXX Health
Tim Gutwald - Partner, Elevare Law Tim Gutwald – Partner, Elevare Law
Brittany Sigler - DrPH, Founder & Product Leader, Bright Signal Consulting Brittany Sigler – DrPH, Founder & Product Leader, Bright Signal Consulting
Mike Maseda - Head of Sales & Ops, GenHealth.ai Mike Maseda – Head of Sales & Ops, GenHealth.ai

Webinar Details

AI + HIPAA: Innovating in Healthcare Without Leaving Compliance Behind

July 8, 2026

1.00 p.m. ET | 12.00 p.m. CT | 11.00 a.m. MT | 10:00 a.m. PT

Click Here to Register for the Webinar

Can’t attend on the day? Register to receive a link to the recording!

This webinar is eligible for 1 self-reported CPE

The post Free Webinar TODAY: AI + HIPAA: Innovating in Healthcare Without Leaving Compliance Behind appeared first on The HIPAA Journal.

Free Webinar: How to Stop Phishing Attacks Before They Reach Your Team

webinar - how to stop healthcare phishing attacksPhishing has long been a leading cause of healthcare data breaches. Hackers target employees as they are a weak link in the security chain, and many healthcare ransomware attacks start with credentials stolen in phishing attacks.

Phishing attacks are often blamed on the employees who respond to phishing attempts. A survey of healthcare IT leaders found 85% of respondents believe employee negligence is a top email security risk, yet despite that, only 16% of respondents said they train their workforce on how to recognize phishing attempts quarterly or more frequently. The majority of healthcare organizations only provide training to their workforce once a year, and hope that the training sticks and employees will remain vigilant throughout the year, which is seldom the case.

Unfortunately, the risk from phishing is getting worse as AI-generated phishing campaigns are difficult for employees to identify. AI-generated phishing emails are grammatically correct, free of spelling mistakes, and use advanced impersonation techniques. An analysis of phishing emails by KnowBe4 between late 2024 and early 2025 found that 83% of phishing emails were AI-generated.  Not only is AI-generated phishing outpacing training programs, the phishing emails also bypass traditional email spam filters. Further, Paubox research shows that when employees do identify phishing attempts, only 5% of attacks are reported to the security team! If you rely on employee training and a traditional email filter, your organization is at risk.

In this free webinar on April 28, 2026, discover why phishing defenses are failing and how you can improve your security posture and block attacks before they reach your team. The webinar is aimed at IT directors, CISOs, security leaders responsible for email infrastructure, compliance officers managing HIPAA email requirements, healthcare administrators who oversee PHI-handling workflows, and security teams weighing whether current controls match current threats.

Webinar attendees will learn about:

  • The evolution of AI-generated phishing and BEC attacks and why they bypass defenses
  • Why healthcare organizations are targeted
  • The findings of a Paubox analysis of 170 email-related data breaches in 2025 and common authentication gaps
  • How the “training plus spam filter” model leaves measurable security gaps
  • How inbound email security at the technical layer catches what training and traditional filters miss
  • How to assess where your organization’s email security actually stands today

WEBINAR DETAILS

How to Stop Phishing Attacks Before They Reach Your Team

Tuesday, April 28, 2026

10 a.m. PT | 11 a.m. MT | 12 p.m. CT | 1 p.m. ET | 6 p.m. BST

Register for the Webinar


Speaker: Dawn Halpin, Demand Generation Manager, Paubox

Dawn Halpin, Paubox

Dawn Halpin, a Marquette University and University of Wisconsin-Milwaukee graduate, is the Demand Generation Manager at the email security firm Paubox. Paubox is a leader in HIPAA-compliant email security for the healthcare industry and is trusted by more than 8,000 organizations, including Cost Plus Drugs, Rippling, and Covenant Health.

The post Free Webinar: How to Stop Phishing Attacks Before They Reach Your Team appeared first on The HIPAA Journal.

Free HIPAA Compliance Risk Check for Covered Entities

HIPAA compliance is mandatory for organizations that qualify as HIPAA covered entities. But how compliant is your organization really?

Free Online HIPAA Compliance AssessmentWith our 2-minute free HIPAA Compliance Risk Check, you can quickly evaluate the compliance status of your organization and receive a report with actionable insights to immediately improve compliance with HIPAA.

Please note that in order for the report to accurately reflect your organization’s compliance status, you need to be aware of your organization’s current compliance activities when you take our free HIPAA risk check.

Please also note that this check is designed to be used by organizations that are HIPAA covered entities. It is not suitable for solo practitioners or HIPAA Business Associates.

Why Take The HIPAA Compliance Risk Check?

Being aware of your compliance obligations and those of your business partners can be vital because, in the event of a HIPAA violation, ignorance of the HIPAA requirements is not an acceptable defense against enforcement action. This free assessment is:

  • Quick and Convenient: In just two or three minutes, answer a series of targeted questions designed to gauge your organization’s compliance with the latest HIPAA regulations.
  • Instant Results: Receive a compliance score immediately after completing the assessment, giving you a quick snapshot of where your organization stands.
  • 100% Private: Your name and your organization name do not appear on the report and it is only sent to the email address you designate and not copied or stored on any server.

What Does Your Risk Report Include?

  • Your HIPAA Compliance Risk Score: Understand how well your organization adheres to HIPAA standards.
  • Analysis of Compliance Risk Score: Identify specific areas where your organization may be falling short.
  • Tailored Recommendations: Get expert advice on what steps to take to improve your compliance score.

How It Works

  1. Start the Risk Check: Click on this link to get started.
  2. Assessment Steps: You will be taken through a series of multiple choice questions to answer covering a range of HIPAA compliance requirements.
  3. Choose One Answer: Select the answer which best reflects the current situation within the organization.
  4. Receive Your Score: After completing the assessment, you’ll immediately see your HIPAA compliance risk score on screen.
  5. Take Action: Use the insights provided in your report to take actionable steps towards improving your client score.

Your name and your organization name do not appear on the report and you decide what you wish to do with the information. Your email address and your answers to the risk check are not copied or stored on any server, so you can be sure they will remain 100% confidential.

The post Free HIPAA Compliance Risk Check for Covered Entities appeared first on The HIPAA Journal.

Business Associate HIPAA Checklist

As aBusiness Associate, it is important to be aware of which HIPAA compliance standards apply to your organization.

Do you have the correct procedures in place to avoid costly data breaches, HIPAA violations, and regulatory fines?

Find out now with our comprehensive HIPAA Checklist for Business Associates that has been compiled by leading compliance experts.

Use the form to download this checklist.

Non Compliance Is Not An Option

HIPAA compliance standards are enforced by HHS Office of Civil Rights, the Centres for Medicare and Medicaid, and the Federal Trade Commission.

The post Business Associate HIPAA Checklist appeared first on The HIPAA Journal.