Hooded figure working at multiple computer monitors displaying code

2 min read

What is a machine-in-the-middle attack?

Machine-in-the-middle attacks, often called "man-in-the-middle" (MitM) attacks, occur when an attacker intercepts communication between two parties without their knowledge. This allows the attacker to eavesdrop on the communication, alter messages,...

Read More
Person writing in a notebook with pen

2 min read

Mental health practitioners in community systems of care for children

Community care systems, or networks of service providers that support a child’s needs holistically, come about in various ways. These teams require...

Read More
Document labeled

2 min read

Are small health plans required to comply with the Privacy Rule? 

No, not all small health plans must comply with the HIPAA Privacy Rule. Specifically, an employee welfare benefit plan with fewer than 50...

Read More
Doctor holding blue shield with white medical cross surrounded by healthcare icons

2 min read

What are non-routine disclosures of PHI under HIPAA?

Non-routine disclosures refer to the instances where protected health information (PHI)is shared for unique or unexpected situations. These...

Read More
Digital globe with binary code, lock icons, and network symbols representing cybersecurity

4 min read

What are homograph domain attacks? 

Homograph domain attacks, closely linked to typosquatting techniques, take advantage of the fact that many Unicode characters from different...

Read More
Close-up of Social Security cards

2 min read

Is SSA a covered entity?

No, the Social Security Administration (SSA) is not a covered entity under HIPAA. According to the Department of Health and Human Services (HHS), the...

Read More
digital business icons over a laptop screen for post Instances where the minimum necessary standard does not apply

1 min read

Instances where the minimum necessary standard does not apply

There are cases where full access to patient health is necessary, such as for diagnosis or public health purposes.The minimum necessary standard...

Read More
Magnifying glass highlighting a red figure among white figures on a blue background

2 min read

OIG uncovers potential misuse of health risk assessments

The Office of Inspector General (OIG) found that some Medicare Advantage (MA) companies may be using health risk assessments (HRAs) and chart reviews...

Read More
Person typing on a keyboard at a desk

3 min read

Should direct care practices (DCPs) be HIPAA compliant? 

While not all DCPs are regulated by HIPAA, using HIPAA compliant email can help DCPs build patient trust through transparency and accountability. It...

Read More
Hands holding interlocking gears in different colors

2 min read

The benefits of integrated behavioral health

Mental and physical health often work in tandem and patients may experience physical symptoms as a result of mental health disorders. Primary care...

Read More
Digital padlock made of glowing blue pixels on a dark network background

2 min read

What is network segmentation?

Network segmentation is a security practice that involves dividing a computer network into smaller, manageable sub-networks (segments). This approach...

Read More
update symbol over keyboard for post Understanding thread hijacking for ‘account update’ phishing

2 min read

Understanding thread hijacking for ‘account update’ phishing

Hijacking communications between patients and providers often allows cybercriminals to extract information and solicit payments and other actions...

Read More
Digital lock icon with user silhouette and circuit board pattern

1 min read

Landmark Admin data breach exposes personal information of 800,000

In May 2024, hackers breached Landmark Admin’s network, encrypting systems and stealing sensitive information from over 800,000 people.

Read More