HIPAA role guide
Executive HIPAA Guide
Oversee third-party risk, resource allocation, and organizational accountability without getting lost in technical details.
Reviewed August 2026
Learn → Assess → Remediate
Sources and limitations
Source types include regulation, official guidance, NIST and CISA materials, and clearly labeled HIPAAmart implementation notes. This educational starting point is not legal advice, a risk determination, an audit opinion, or a certification of compliance.
Available guidance
- Breach Notification Rule
Know when an impermissible use or disclosure may be a breach, who must be notified, and what documentation supports the decision.
- Business Associates
Learn when a vendor is a business associate, what a BAA should cover, and how subcontractors extend your compliance responsibilities.
- HIPAA Risk Assessment
Build a defensible risk analysis by connecting assets, threats, vulnerabilities, likelihood, impact, and remediation evidence.
- HIPAA Incident Response
Build an incident process that connects security containment, privacy analysis, breach decisions, communications, and evidence.
- HIPAA Disaster Recovery
Make contingency planning and recovery evidence useful for the availability of ePHI and the continuity of critical work.
- Business Associate Agreements
A practical center for deciding when a BAA is needed and connecting contract terms to the vendor's actual service.
- HIPAA Vendor Management
Connect business associate inventory, security review, contract scope, monitoring, and offboarding into one repeatable practice.