Knowledge Hub
The clear answer, before the rabbit hole.
Browse sourced HIPAA rules, explainers, practical tools, and clear answers.
Reviewed August 2026
Available guidance
- HIPAA Privacy Rule
Understand how the Privacy Rule protects individually identifiable health information and gives people meaningful rights over their records.
- HIPAA Security Rule
A practical guide to the administrative, physical, and technical safeguards used to protect electronic protected health information.
- Breach Notification Rule
Know when an impermissible use or disclosure may be a breach, who must be notified, and what documentation supports the decision.
- Business Associates
Learn when a vendor is a business associate, what a BAA should cover, and how subcontractors extend your compliance responsibilities.
- Protected Health Information
A plain-English starting point for recognizing PHI, understanding identifiers, and separating HIPAA analysis from broader privacy questions.
- HIPAA Risk Assessment
Build a defensible risk analysis by connecting assets, threats, vulnerabilities, likelihood, impact, and remediation evidence.
- AI and HIPAA
A practical framework for evaluating generative AI, PHI leakage, retention, vendors, prompts, and governance.
- Cloud and HIPAA
Understand shared responsibility, BAAs, identity, logging, encryption, and why an eligible cloud service is not the whole compliance program.
- HIPAA Overview
A map of the HIPAA rules, the organizations they reach, and the operational work that turns obligations into evidence.
- Covered Entities
How to analyze whether an organization is a health plan, health care clearinghouse, or covered health care provider under HIPAA.
- Electronic Protected Health Information
A working guide to ePHI, the electronic form of protected health information that the Security Rule safeguards.
- Minimum Necessary Standard
How to limit many uses, disclosures, and requests for PHI to what is reasonably needed for the intended purpose.
- HIPAA Enforcement Rule
What enforcement authority can examine, investigate, and resolve alleged HIPAA violations—and how organizations can prepare.
- Administrative Safeguards
The governance, risk, workforce, incident, and contingency practices that organize Security Rule protection.
- Physical Safeguards
Facility, workstation, device, and media controls that help protect ePHI from physical threats.
- Technical Safeguards
Access, audit, integrity, authentication, and transmission controls for systems handling ePHI.
- HIPAA Access Controls
Designing unique identification, emergency access, automatic logoff, and least-privilege practices around ePHI.
- Encryption and HIPAA
How to evaluate encryption for ePHI without reducing a broader risk decision to a yes-or-no checkbox.
- HIPAA Audit Controls
Create useful, reviewable records of activity in systems that contain or use ePHI.
- HIPAA Incident Response
Build an incident process that connects security containment, privacy analysis, breach decisions, communications, and evidence.
- HIPAA Disaster Recovery
Make contingency planning and recovery evidence useful for the availability of ePHI and the continuity of critical work.
- Ransomware and HIPAA
A grounded response framework for ransomware risk, availability, evidence, and breach analysis.
- Business Associate Agreements
A practical center for deciding when a BAA is needed and connecting contract terms to the vendor's actual service.
- HIPAA Vendor Management
Connect business associate inventory, security review, contract scope, monitoring, and offboarding into one repeatable practice.
- What Evidence Should a Small Healthcare Organization Gather Before a HIPAA Risk Analysis?
An evidence map for organizing systems, data flows, people, vendors, safeguards, incidents, and resilience before a documented risk analysis. This is HIPAAmart editorial guidance, not a legal determination.