HIPAA role guide
Practice Manager HIPAA Guide
Make HIPAA operational for staff without disrupting patient care, focusing on training, physical safeguards, and clear workflows.
Reviewed August 2026
Learn → Assess → Remediate
Sources and limitations
Source types include regulation, official guidance, NIST and CISA materials, and clearly labeled HIPAAmart implementation notes. This educational starting point is not legal advice, a risk determination, an audit opinion, or a certification of compliance.
Available guidance
- HIPAA Privacy Rule
Understand how the Privacy Rule protects individually identifiable health information and gives people meaningful rights over their records.
- HIPAA Security Rule
A practical guide to the administrative, physical, and technical safeguards used to protect electronic protected health information.
- Protected Health Information
A plain-English starting point for recognizing PHI, understanding identifiers, and separating HIPAA analysis from broader privacy questions.
- HIPAA Risk Assessment
Build a defensible risk analysis by connecting assets, threats, vulnerabilities, likelihood, impact, and remediation evidence.
- HIPAA Overview
A map of the HIPAA rules, the organizations they reach, and the operational work that turns obligations into evidence.
- Covered Entities
How to analyze whether an organization is a health plan, health care clearinghouse, or covered health care provider under HIPAA.
- Electronic Protected Health Information
A working guide to ePHI, the electronic form of protected health information that the Security Rule safeguards.
- Minimum Necessary Standard
How to limit many uses, disclosures, and requests for PHI to what is reasonably needed for the intended purpose.
- HIPAA Enforcement Rule
What enforcement authority can examine, investigate, and resolve alleged HIPAA violations—and how organizations can prepare.
- HIPAA Disaster Recovery
Make contingency planning and recovery evidence useful for the availability of ePHI and the continuity of critical work.