JGJoe Gellatlyinmedcurity.hashnode.dev·1d ago · 4 min readHIPAA Compliance for Business Associates: What Vendors Handling PHI Need in 2026If a healthcare provider or health plan pays your company to handle protected health information, you are a business associate under HIPAA. That status comes from 45 CFR 160.103 and from what your sys00
JGJoe Gellatlyinmedcurity.hashnode.dev·Aug 4 · 6 min readSOC 2 Is Not HIPAA: Choosing Between Horizontal GRC and Healthcare-Native SRASOC 2 Is Not HIPAA: Choosing Between Horizontal GRC and Healthcare-Native SRA There is a conversation happening in health-tech companies and healthcare organizations everywhere right now, and it usual00
JGJoe Gellatlyinmedcurity.hashnode.dev·Jul 29 · 4 min readA Hospital HIPAA Risk Analysis Is Not an Evidence Scan: Why 45 CFR 164.310 Requires Someone OnsiteA HIPAA Security Risk Analysis and automated compliance-evidence monitoring are different deliverables, and a hospital should know which one it is buying. The risk analysis is required of every covere00
JGJoe Gellatlyinmedcurity.hashnode.dev·Jul 20 · 5 min readPhysical Safeguards Are in Scope for Your SRA. A Questionnaire Cannot Assess Them.45 CFR §164.310 is part of the HIPAA Security Rule, and its requirements are in scope for a Security Risk Analysis. Most SRA tooling assesses it by asking you. That works exactly as well as self-asses00
JGJoe Gellatlyinmedcurity.hashnode.dev·Jul 17 · 8 min readMulti-Site HIPAA Security Risk Analysis: One Engagement, Every LocationShort answer: one Security Risk Analysis can cover every location you operate, and for most multi-site organizations that is the right structure. HIPAA scopes the requirement to the organization and t00