JGJoe Gellatlyinmedcurity.hashnode.dev·5d ago · 4 min readA Hospital HIPAA Risk Analysis Is Not an Evidence Scan: Why 45 CFR 164.310 Requires Someone OnsiteA HIPAA Security Risk Analysis and automated compliance-evidence monitoring are different deliverables, and a hospital should know which one it is buying. The risk analysis is required of every covere00
JGJoe Gellatlyinmedcurity.hashnode.dev·Jul 20 · 5 min readPhysical Safeguards Are in Scope for Your SRA. A Questionnaire Cannot Assess Them.45 CFR §164.310 is part of the HIPAA Security Rule, and its requirements are in scope for a Security Risk Analysis. Most SRA tooling assesses it by asking you. That works exactly as well as self-asses00
JGJoe Gellatlyinmedcurity.hashnode.dev·Jul 17 · 8 min readMulti-Site HIPAA Security Risk Analysis: One Engagement, Every LocationShort answer: one Security Risk Analysis can cover every location you operate, and for most multi-site organizations that is the right structure. HIPAA scopes the requirement to the organization and t00
JGJoe Gellatlyinmedcurity.hashnode.dev·Jun 12 · 8 min readThe 2026 HIPAA Risk Assessment Pattern for Healthcare APIsOriginally published at medcurity.com. Mirrored here for engineering teams shipping healthcare-adjacent software. If you ship any service that reads, writes, or transports electronic protected health 00
JGJoe Gellatlyinmedcurity.hashnode.dev·Jun 1 · 6 min readBuilding a BAA Inventory System That Holds Up Under a 2026 HIPAA AuditIf you maintain HIPAA-covered systems, your Business Associate Agreement (BAA) inventory is one of the most under-engineered parts of your compliance posture. Most organizations carry it in a spreadsh00