Articles tagged: HIPAA
17 articles on HIPAA from the Top Floor insights library.
2026-08-25
What Is a Compensating Control, and When Will an Assessor Accept One?
A compensating control substitutes for a requirement you cannot meet as stated. The word doing the work is constraint, and the acceptance test differs by regime: PCI DSS wants a worksheet, HIPAA wants a documented reason, DoD wants a written variance, and SOC 2 has no worksheet at all.
2026-08-25
What Is ePHI, Exactly? The Scoping Test Behind the Definition
The regulation defines ePHI in one sentence that points at two other definitions, and the scoping decision hides in the pointer. Three nested tests decide whether a record is protected health information; one more decides whether the Security Rule reaches it.
2026-08-23
Is It a Reportable HIPAA Breach? The Four-Factor Test
Every impermissible use or disclosure of unsecured PHI is presumed to be a breach. You are not deciding whether to notify; you are deciding whether you can document your way out of a presumption, and the burden of proof is on you.
2026-08-23
42 CFR Part 2 vs HIPAA: What the Alignment Rule Changed
Substance use disorder records carry a second federal confidentiality rule on top of HIPAA, and the compliance date for its overhaul passed on February 16, 2026. What actually changed, what deliberately did not, and how to tell whether it applies to you.
2026-08-23
De-Identifying PHI: Safe Harbor vs Expert Determination
HIPAA recognizes exactly two ways to de-identify protected health information. Stripping the names is neither of them. What each method costs you, why the cheap one is usually the wrong one for analytics, and what de-identification does not buy.
2026-08-23
Does HIPAA Apply to My Health App?
For most direct-to-consumer health apps the answer is no, and founders treat that as good news. It usually is not: falling outside HIPAA drops you into the FTC's Health Breach Notification Rule, which has no risk-assessment off-ramp.
2026-08-23
What Audit Logging Does HIPAA Actually Require?
The audit controls standard is one sentence long and names no log type, no retention period, and no review cadence. The six years everyone quotes is a documentation rule, not a log rule, and the requirement people miss is the one about reading the logs.
2026-08-22
How Much Does a HIPAA Risk Analysis Cost?
Published ranges run from $0 to about $25,000, and the free federal tool is real. What actually drives the number, what the money buys that the free tool does not, and the enforcement record that sets the price of getting it wrong.
2026-08-16
When Does the New HIPAA Security Rule Take Effect?
It has not taken effect, and as of August 2026 the Federal Register holds exactly one document for this rulemaking: the January 2025 proposal. Here is how to check that yourself, and what the current rule already requires while everyone waits.
2026-08-16
Is There Such a Thing as HIPAA Certification?
No. There is no government-issued HIPAA certification, and a seal from a vendor proves nothing to an investigator. Here is what your customers will actually accept as proof, and what it costs you to produce it.
2026-08-16
Do You Need a BAA? A Decision Guide for SaaS Vendors
If protected health information can sit on your systems, plan on signing one, even encrypted, even if you never look at it. HHS said so in the Omnibus preamble in 2013 and the conduit exception is narrower than almost everyone assumes.
2026-08-16
Does HIPAA Require Penetration Testing?
The Security Rule never uses the words. It requires a risk analysis and a periodic evaluation, and a penetration test is the usual way to evidence the technical half of that evaluation. Your customers are the ones with the actual deadline.
2026-08-16
Is Zoom HIPAA Compliant? Telehealth Rules Since the Waiver Ended
Only on plans where the vendor signs a BAA. The COVID-era enforcement discretion expired on May 11, 2023 and the 90-day transition period closed at 11:59 pm on August 9, 2023, both stated in the HHS notice at 88 FR 22380.
2026-08-02
Breach Notification Deadlines: Every Clock You Are On
A breach puts you on multiple notification clocks at once, and they start on different trigger events: discovery, awareness, materiality determination. Here is the full crosswalk (SEC, HIPAA, GDPR, all 50 states, CIRCIA) and how to build your response to the shortest binding clock.
2026-03-24
Virtual CISO: When Your Organization Needs Fractional Security Leadership
A full-time CISO at a small or midmarket company averages $415K in total compensation, but most mid-market organizations need strategic security leadership without the executive price tag. Here is how a virtual CISO works, what they deliver, and when the model makes sense.
2026-03-19
Penetration Testing: Beyond Checkbox Compliance
Automated scanners catch the low-hanging fruit, but real attackers chain business logic flaws, misconfigurations, and social engineering into full compromise. Here is how to scope, execute, and integrate penetration testing into your compliance program across SOC 2, PCI DSS, HIPAA, and CMMC.
2026-02-05
HIPAA Compliance Checklist for HealthTech Companies
HIPAA violations can cost HealthTech companies millions in fines and destroy customer trust overnight. This practical checklist covers every safeguard category, BAA requirements, and breach notification rule you need to get right from day one.