Person using stylus to write or sign on a tablet

2 min read

Do electronic BAAs meet HIPAA Privacy Rule requirements?

Electronic business associate agreements (BAAs), signed with an electronic signature, are permissible under the HIPAA Privacy Rule if they meet all relevant legal and regulatory requirements.

Read More
Silver padlock on a digital cube surrounded by glowing blue and purple tech blocks

2 min read

What are cybersecurity performance goals (CPGs)?

Cybersecurity performance goals (CPGs) are a set of cybersecurity best practices and minimum-security standards developed by the Cybersecurity and...

Read More
Hooded figure working at multiple computer monitors displaying code

2 min read

What is a machine-in-the-middle attack?

Machine-in-the-middle attacks, often called "man-in-the-middle" (MitM) attacks, occur when an attacker intercepts communication between two parties...

Read More
Digital padlock made of glowing blue pixels on a dark network background

2 min read

What is network segmentation?

Network segmentation is a security practice that involves dividing a computer network into smaller, manageable sub-networks (segments). This approach...

Read More
Red neon padlock on digital circuit board background

2 min read

FAQs: Access controls

Access controls are the security protocols and measures that determine who can access specific resources, systems, or information within an...

Read More
Digital security shield with keyhole on blue network background

2 min read

Preparing for HIPAA security updates

At the recent joint HHS and National Institute of Standards and Technology security conference, HHS OCR senior advisor for health information...

Read More
Digital shield with keyhole on blue networked background

3 min read

OCR releases ransomware prevention guidance

The U.S. Department of Health and Human Services’ Office for Civil Rights has published a video to help healthcare organizations prevent ransomware...

Read More
Hand holding stethoscope next to 'Change Healthcare' text

2 min read

Over 100 million impacted by Change Healthcare ransomware attack

UnitedHealth has confirmed that the February ransomware attack on Change Healthcare exposed the personal and healthcare data of over 100 million...

Read More
BCHP logo for post Boston Children’s Health Physicians targeted in ransomware attack

2 min read

Boston Children’s Health Physicians targeted in ransomware attack

Boston Children’s Health Physicians (BCHP) fell victim to a ransomware attack involving an IT vendor. The attacker, the BianLian group, is now...

Read More
Red shipping container on a delivery truck on a highway at sunset

2 min read

Are delivery truck lines business associates?

Delivery truck lines help transport goods or documents. They are not considered business associates under HIPAA, as they typically do not handle or...

Read More
Person holding a cardboard package with shipping label

2 min read

Is the United Parcel Service considered a business associate under HIPAA?

In its role as a carrier of physical packages containing PHI, UPS is not considered a business associate under HIPAA because it qualifies for the...

Read More
White mail delivery truck

2 min read

What is HIPAA's Conduit Exception

The HIPAA Conduit Exception refers to a specific provision in the HIPAA Privacy Rule that allows certain entities to share protected health...

Read More
Four padlock icons on yellow background

2 min read

Privacy vs confidentiality in healthcare

Privacy is about a patient's control over their information while confidentiality is the healthcare provider's duty to safeguard that information...

Read More