Articles tagged: Healthcare
23 articles on Healthcare from the Top Floor insights library.
2026-08-25
How Long Does HITRUST Take?
HITRUST publishes a duration for two of its three assessments and none for the third, and the Assessment Handbook fixes several clocks that no amount of readiness can shorten: a 90-day fieldwork cap, a 90-day control incubation period and a reserved QA block. Here is the calendar for each tier, sourced to HITRUST.
2026-08-25
What Does HITRUST Certification Cost?
HITRUST certification is three separate bills: the MyCSF subscription and report credit paid to HITRUST, the authorised assessor's fee, and your own readiness and remediation effort. HITRUST publishes the structure of the first and, on every page we could fetch, no price. What each bill covers, and our own planning figures.
2026-08-25
What Is ePHI, Exactly? The Scoping Test Behind the Definition
The regulation defines ePHI in one sentence that points at two other definitions, and the scoping decision hides in the pointer. Three nested tests decide whether a record is protected health information; one more decides whether the Security Rule reaches it.
2026-08-25
How Long Does FDA Premarket Cybersecurity Review Take?
FDA publishes its clocks: 90 FDA Days for a 510(k), 150 review days for a De Novo, 180 days from filing for a PMA, and 70 days for Pre-Submission feedback. The cybersecurity question is whether your submission stays on those clocks or falls off them, and the two places it falls off are screening and the Additional Information hold.
2026-08-23
You Got an FDA Cybersecurity Deficiency Letter. Now What?
180 calendar days, no extensions, and the submission is deleted if you miss it. What the three FDA hold types actually are, how to read a deficiency, and why the fast partial response is the one that costs a cycle.
2026-08-23
What Goes in the Cybersecurity Section of a 510(k)?
FDA screens a 510(k) eSTAR within about 15 days and holds it if the cybersecurity section is missing attachments, before the review clock starts. The February 3, 2026 guidance says what belongs there: six document types, fourteen rows.
2026-08-23
What FDA Expects After Clearance: Postmarket Device Cybersecurity
Most cybersecurity patches are device enhancements that need no report to FDA at all. The exception is the small subset addressing uncontrolled risk, where the enforcement discretion has four conditions and two of them are clocks.
2026-08-23
Is It a Reportable HIPAA Breach? The Four-Factor Test
Every impermissible use or disclosure of unsecured PHI is presumed to be a breach. You are not deciding whether to notify; you are deciding whether you can document your way out of a presumption, and the burden of proof is on you.
2026-08-23
42 CFR Part 2 vs HIPAA: What the Alignment Rule Changed
Substance use disorder records carry a second federal confidentiality rule on top of HIPAA, and the compliance date for its overhaul passed on February 16, 2026. What actually changed, what deliberately did not, and how to tell whether it applies to you.
2026-08-23
De-Identifying PHI: Safe Harbor vs Expert Determination
HIPAA recognizes exactly two ways to de-identify protected health information. Stripping the names is neither of them. What each method costs you, why the cheap one is usually the wrong one for analytics, and what de-identification does not buy.
2026-08-23
Does HIPAA Apply to My Health App?
For most direct-to-consumer health apps the answer is no, and founders treat that as good news. It usually is not: falling outside HIPAA drops you into the FTC's Health Breach Notification Rule, which has no risk-assessment off-ramp.
2026-08-23
What Audit Logging Does HIPAA Actually Require?
The audit controls standard is one sentence long and names no log type, no retention period, and no review cadence. The six years everyone quotes is a documentation rule, not a log rule, and the requirement people miss is the one about reading the logs.
2026-08-22
How Much Does a HIPAA Risk Analysis Cost?
Published ranges run from $0 to about $25,000, and the free federal tool is real. What actually drives the number, what the money buys that the free tool does not, and the enforcement record that sets the price of getting it wrong.
2026-08-22
HITRUST e1 vs i1 vs r2: Which One Do You Actually Need?
HITRUST publishes the control counts: 43 for e1, 182 for i1, and a tailored set for r2, which is the only one valid for two years. The tier you need is the one your customer's contract names, and the cost sources disagree more than they admit.
2026-08-22
Do You Need HITRUST, or Is SOC 2 Enough for Healthcare?
If a contract names HITRUST, SOC 2 will not substitute, because one is a scored certification and the other is an auditor's opinion. If no contract names it, the numbers say start with SOC 2 and documented HIPAA compliance.
2026-08-22
FDA Cybersecurity for Medical Devices: What Section 524B Requires
Since March 2023, a cyber device submission without the Section 524B package is incomplete, and since October 2023 FDA has expected sponsors to be ready. The operative guidance changed again in February 2026, which most content on this topic has not caught up with.
2026-08-21
HITRUST Inheritance: What You Can Actually Reuse
HITRUST says organisations can inherit as much as 70 to 85 percent of requirements from participating cloud providers. AWS attaches a conditional to that number which is where most of it goes. What inheritance moves, what it does not, and what HITRUST's public pages decline to explain.
2026-08-16
When Does the New HIPAA Security Rule Take Effect?
It has not taken effect, and as of August 2026 the Federal Register holds exactly one document for this rulemaking: the January 2025 proposal. Here is how to check that yourself, and what the current rule already requires while everyone waits.
2026-08-16
Is There Such a Thing as HIPAA Certification?
No. There is no government-issued HIPAA certification, and a seal from a vendor proves nothing to an investigator. Here is what your customers will actually accept as proof, and what it costs you to produce it.
2026-08-16
Do You Need a BAA? A Decision Guide for SaaS Vendors
If protected health information can sit on your systems, plan on signing one, even encrypted, even if you never look at it. HHS said so in the Omnibus preamble in 2013 and the conduit exception is narrower than almost everyone assumes.
2026-08-16
Does HIPAA Require Penetration Testing?
The Security Rule never uses the words. It requires a risk analysis and a periodic evaluation, and a penetration test is the usual way to evidence the technical half of that evaluation. Your customers are the ones with the actual deadline.
2026-08-16
Is Zoom HIPAA Compliant? Telehealth Rules Since the Waiver Ended
Only on plans where the vendor signs a BAA. The COVID-era enforcement discretion expired on May 11, 2023 and the 90-day transition period closed at 11:59 pm on August 9, 2023, both stated in the HHS notice at 88 FR 22380.
2026-02-05
HIPAA Compliance Checklist for HealthTech Companies
HIPAA violations can cost HealthTech companies millions in fines and destroy customer trust overnight. This practical checklist covers every safeguard category, BAA requirements, and breach notification rule you need to get right from day one.