HIPAA | The Library

Technical deep-dives into HIPAA, HITECH, and HITRUST requirements. This resource provides specific configuration guides for PHI protection, Business Associate Agreement (BAA) negotiation strategies, and technical safeguards for health-tech innovators.

All AI GovernanceCloud SecurityCybersecurityGRC EngineeringHIPAASOC 2
BAA for Claude AI: Featured image for josefkamara.com Healthcare Compliance article
HIPAA

BAA for Claude AI: Is Anthropic HIPAA Compliant?

Healthcare AI adoption accelerated faster than the compliance infrastructure supporting it. By Q1 2026, 73% of health systems reported clinical staff using large language models for documentation, referral letters, or prior authorization appeals [KLAS Research...

Read the Guide
Can a Covered Entity Audit a Business Associate: Featured image for josefkamara.com Healthcare Compliance article
HIPAA

Can a Covered Entity Audit a Business Associate?

The "Right to Audit" clause in your Business Associate Agreement is a liability, not a protection. Compliance teams draft aggressive audit provisions granting the covered entity permission to inspect vendor firewalls, review security configurations, and...

Read the Guide
HIPAA Addressable vs Required 2026: Featured image for josefkamara.com Healthcare Compliance article
HIPAA

HIPAA Addressable vs Required 2026: Mandatory Update

The compliance officer documented the exception in 2021. Line item: Encryption at rest. Classification: "Addressable, Not Implemented." Justification: legacy EHR servers do not support AES-256, and hardware replacement exceeds the current budget cycle. The risk...

Read the Guide
HIPAA Encryption Requirements 2026: Featured image for josefkamara.com Healthcare Compliance article
HIPAA

HIPAA Encryption Requirements 2026: At Rest vs Transit

Three thousand nine hundred patients. One unencrypted laptop. One parked car. The theft triggered a breach notification to every patient, a media disclosure to local news outlets, and an OCR investigation that ended in a...

Read the Guide
HIPAA Risk Analysis Documentation: Featured image for josefkamara.com Healthcare Compliance article
HIPAA

HIPAA Risk Analysis Documentation: Stop Using the Excel Template

Organization A downloads the HHS Security Risk Assessment Tool, changes the organization name, and answers 40 yes/no questions in two hours. The spreadsheet goes into a shared drive with "FINAL" in the filename. When an...

Read the Guide
HIPAA Asset Inventory Requirement: Featured image for josefkamara.com Healthcare Compliance article
HIPAA

HIPAA Asset Inventory Requirement

How many systems in your organization touch Protected Health Information? Not the ones your IT department provisioned. All of them. The 23 AWS S3 buckets your cloud billing statement reveals. The Salesforce instance storing patient...

Read the Guide
HIPAA Risk Assessment: Featured image for josefkamara.com Healthcare Compliance article
HIPAA

HIPAA Risk Assessment: Five-Step Process for OCR

Every HIPAA risk assessment I review commits the same fundamental error. The document is titled "Risk Assessment." The content is a checklist. MFA: yes. Encryption: yes. Backup: yes. A series of binary answers telling OCR...

Read the Guide
BAA for Google Drive: Featured image for josefkamara.com Healthcare Compliance article
HIPAA

BAA for Google Drive

The most common HIPAA violation I encounter during healthcare practice assessments is the one nobody suspects. Not missing encryption. Not absent MFA. A therapist, office manager, or billing coordinator sending patient intake forms through a...

Read the Guide
HIPAA Compliant Firewall Requirements: Featured image for josefkamara.com Healthcare Compliance article
HIPAA

HIPAA Compliant Firewall Requirements: 2026 Guide (50 chars)

In 2011, the first OCR enforcement action targeting network security infrastructure fined a community health center $750,000 for lacking "technical policies and procedures for electronic information systems that maintain ePHI" [OCR Phoenix Cardiac Surgery Settlement...

Read the Guide
Is ChatGPT HIPAA Compliant: Featured image for josefkamara.com Healthcare Compliance article
HIPAA

Is ChatGPT HIPAA Compliant? Plan-by-Plan Matrix

Which ChatGPT plan does your organization use? Not the plan the IT department approved. The plan your clinical staff actually uses. The one a medical assistant discovered through a colleague. The one a billing specialist...

Read the Guide