HIPAA, explained in plain English
Guides for people who run a practice, not a compliance department. What the rules actually require, what insurers actually ask, and what’s just noise — written to be honest even when honest is less dramatic.
Comparisons
HIPAAPath vs Medcurity: an honest comparison
Medcurity pairs its SRA platform with human expert review, published at $499/yr for small practices. HIPAAPath is self-serve and free to complete. Which fits — honestly.
Comparisons
HIPAAPath vs Abyde: an honest comparison
Abyde bundles HIPAA and OSHA software with expert access, priced by quote. HIPAAPath is self-serve with visible pricing. An honest comparison for small practices.
Comparisons
HIPAAPath vs Patient Protect: an honest comparison
Patient Protect publishes its pricing and offers real free tools — credit where due. Where the browser-local HIPAAPath model differs, honestly.
Medicare & MIPS
MIPS and the security risk analysis: the December 31 rule
Reporting MIPS Promoting Interoperability? The security risk analysis must happen within the calendar year. Who the December 31 wall binds — and who it doesn’t.
Tools
Should you use the free HHS SRA Tool? An honest look
The government’s free SRA Tool is real and legitimate. What it does well, where it’s heavy going, and how to decide whether it fits your practice.
Insurance
The HIPAA question on cyber-insurance applications
Some cyber-insurance applications ask you to confirm, above your signature, that you comply with HIPAA. Which forms ask, what a yes implies, and where a defensible answer starts.
Email & BAAs
Does your email need a BAA? The gap careful practices miss
Your email provider can see what clients send about their care. A BAA is the contract that makes that okay — and free Gmail doesn’t offer one. How to find and close the gap.
Rule status
Is the 2026 HIPAA Security Rule update final?
The 2026 HIPAA Security Rule update is still a proposed rule — not final, no new deadline. What it would change, and what OCR already enforces today.