HIPAA

Is that AI Tool your Staff Loves Actually HIPAA-Covered?

By Mat Steinlin – According to the AMA’s 2026 Physician Survey on Augmented Intelligence, over 80% now use AI in a professional context (roughly double the share reported in 2023). The same survey found physicians are significantly more concerned about patient privacy when using non-institutional AI tools (71%) than institutional ones (42%).


Waiting and Waiting for Security Updates

By Matt Fisher – The biggest recent news for HIPAA is the quiet reveal that updates to the Security Rule are now delayed until sometime in the middle of 2027. The update was made on an Office of Management and Budget webpage, which now shows expected final action as an undefined date in July 2027.


Establishing Data Governance Guardrails for AI Training in Healthcare

By Zac Amos – Automation has supported unprecedented operational efficiency in the healthcare industry. Yet, it has also brought a unique set of challenges. With the Health Insurance Portability and Accountability Act constantly evolving to address new technologies and the privacy concerns they raise, achieving absolute compliance can often feel like a moving target without the right guardrails.


Compliance by Design

By Kishore Pendyala – Compliance by design has emerged as a defining advantage for AI‑driven healthcare IT startups, reshaping how they earn trust and compete in a rapidly shifting regulatory landscape. As CMS and ONC continue to refine expectations around data privacy, interoperability, algorithmic transparency, and patient rights, startups that embed…


Painful, But Notice Mandatory

By Matt Fisher – Revealing a data breach can be a hard action for an organization to take. The ongoing stream of notifications still generates attention, which is typically not positive when a security breakdown is revealed. At the same time, the notification is (or should be) unavoidable since the HIPAA breach notification rule is clear about what action is necessary.



Shadow IT: Healthcare’s $10 Billion Compliance Blind Spot

By Frank Zamani – A physician needed to share large imaging files with a specialist. The hospital’s file transfer system was too slow, so she used Dropbox instead. Three months later, a compliance audit revealed PHI for 2,400 patients had been stored on an unauthorized platform, no encryption, no access controls, no business associate agreement. The potential HIPAA penalties: up to $1.7 million.