HIPAA compliance
Safeguards, agreements, access records and what happens when something is disclosed.

Protected health information carries administrative, physical and technical safeguard requirements, plus a risk analysis that has to be current rather than performed once.
Access to records is logged. Reviewing those logs is itself a required activity, not an optional one.
Where everything sits






How to work this page
It underpins every other safeguard decision and it is the first document requested in an investigation. Out of date is close to not having one.
A business associate agreement is required before the data reaches them. Any subcontractor of theirs needs one too.
Logging without reviewing satisfies nothing. Reviews are recorded as performed.
Notification deadlines run from discovery. The assessment of whether an incident is a reportable breach is itself documented.
On a phone

Every figure from the desktop appears here, stacked rather than reduced. Tables scroll inside themselves so the page never moves sideways, and figures keep their separators and their alignment at every width.
Questions people actually ask
Impermissible use or disclosure is presumed a breach unless a risk assessment across the specified factors shows low probability of compromise. The assessment must be documented either way.
Six years for required documentation, from creation or from last effective date, whichever is later. State law may require longer.