Tagged: hipaa
HIPAA Retention Requirements: Medical Records, Policies, and Audit Logs
Separate HIPAA's six-year documentation requirements from medical-record schedules and audit-log decisions before configuring retention, holds, and deletion.
HIPAA Employee Offboarding Checklist: Email, Files, Chat, and Shared Access
Use an owner, action, and evidence checklist to end healthcare staff access across email, files, chat, integrations, and devices while preserving needed records.
Where Is Your ePHI? An Inventory Checklist Beyond the EHR
Map ePHI beyond your EHR with a practical inventory covering inboxes, spreadsheets, shared files, chat, exports, devices, vendors, and backups.
Is Slack HIPAA Compliant? Plans, BAAs, and Patient Messaging Limits
Understand Slack's HIPAA requirements and patient messaging limits, then evaluate your plan, BAA, connected apps, monitoring, and record-handling workflow.
Is Google Drive HIPAA Compliant? Check Sharing Before Uploading PHI
Review Google Drive for PHI: Workspace BAA scope, inherited folder permissions, external recipients, downloaded copies, and access after staff changes.
Is Google Workspace HIPAA Compliant? What a BAA Does and Does Not Cover
Evaluate Google Workspace for HIPAA workflows: BAA acceptance, covered services, third-party apps, sharing decisions, and evidence to keep before using PHI.
HIPAA Compliant File Sharing: From Upload to Offboarding
Review how healthcare files are uploaded, shared, downloaded, retained, and removed, with practical tests for access, recovery, and vendor scope.
HIPAA Compliant Email: A Practical Guide for Small Healthcare Teams
Evaluate email for ePHI with practical checks for business associate agreements, encryption, recipient access, shared mailboxes, and staff workflows.
HIPAA Business Associate Agreements: Questions for Cloud Vendors
Understand when a cloud vendor needs a BAA and what to review about service scope, subcontractors, incident reporting, data access, and termination.