JGJoe Gellatlyinmedcurity.hashnode.dev·Aug 31 · 4 min readIf You're a Healthcare Vendor, a Signed BAA Is the Start of Your HIPAA Job, Not the EndIf your company handles protected health information for healthcare clients, you are a business associate, and your clients are starting to ask a harder question than "will you sign a BAA?" They want 00
JGJoe Gellatlyinmedcurity.hashnode.dev·Aug 27 · 4 min readThe Business Associate Inventory Nobody KeepsAsk a healthcare organization for its list of business associates and you will usually get one of two answers. A folder of signed PDFs, or a spreadsheet somebody built two years ago and stopped updati00
JGJoe Gellatlyinmedcurity.hashnode.dev·Aug 21 · 4 min readHIPAA Compliance for Business Associates: What Vendors Handling PHI Need in 2026If a healthcare provider or health plan pays your company to handle protected health information, you are a business associate under HIPAA. That status comes from 45 CFR 160.103 and from what your sys00
JGJoe Gellatlyinmedcurity.hashnode.dev·Aug 4 · 6 min readSOC 2 Is Not HIPAA: Choosing Between Horizontal GRC and Healthcare-Native SRASOC 2 Is Not HIPAA: Choosing Between Horizontal GRC and Healthcare-Native SRA There is a conversation happening in health-tech companies and healthcare organizations everywhere right now, and it usual00
JGJoe Gellatlyinmedcurity.hashnode.dev·Jul 29 · 4 min readA Hospital HIPAA Risk Analysis Is Not an Evidence Scan: Why 45 CFR 164.310 Requires Someone OnsiteA HIPAA Security Risk Analysis and automated compliance-evidence monitoring are different deliverables, and a hospital should know which one it is buying. The risk analysis is required of every covere00