The HIPAA Right to Amend: The Steps Many Organizations Forget

One of the most misunderstood patient rights under HIPAA is the Right to Amend. Ask most healthcare compliance professionals about the amendment process and they’ll likely explain how patients can request a correction to their medical record. That’s certainly the first step, but not the last. Many organizations have policies describing how to receive and […]

Google’s New Review Rules: What Medical Practices Need to Know

For small and mid-sized medical practices, Google reviews are often one of the first places patients look when evaluating a provider. Before a patient calls or books an appointment, they are likely comparing providers online, scanning star ratings, reading comments, and deciding who feels trustworthy. Fair or not, that first impression often happens long before […]

You Completed Your Security Risk Analysis—Now What?

security risk analysis (SRA)

Finishing a Security Risk Analysis (SRA) feels like a major milestone, and it is! It takes time, coordination, and effort to do it right.  The part that often gets overlooked from The Office for Civil Rights (OCR’s) perspective, is that completing the SRA isn’t the finish line. It’s the starting point. What we’re seeing in […]

The Hidden Risk of “Shadow AI” in Smaller Clinics

AI tools are becoming common in medical and dental offices to summarize notes, draft emails, or help with office policies. While these tools offer incredible convenience, using them without oversight creates a major privacy risk known as Shadow AI. For smaller practices, Shadow AI is a significant HIPAA problem that can sneak up on you […]

A Reality Check on Recent HIPAA Updates

HIPAA recent updates

If you work anywhere near healthcare compliance right now, it probably feels like HIPAA is changing every five minutes. Vendors are blasting emails. Consultants are posting urgent LinkedIn takes. Webinars are promising to explain “major HIPAA updates” before it’s “too late.” Let’s slow this way down and separate fact from hype. The NPP Changes Are […]

Important Update: Substance Use Disorder Records – Get Ready by February 16, 2026

substance use disorder records

Federal privacy rules for substance use disorder (SUD) treatment records are changing. On February 8, 2024, the U.S. Department of Health and Human Services updated 42 CFR Part 2, the law that governs how these records are handled. While the rule is already in effect, all covered organizations must be fully compliant by February 16, […]

HIPAA Reminder: Cadia Healthcare Settles OCR Investigation Over Unauthorized PHI Disclosures

The U.S. Department of Health and Human Services (HHS), through its Office for Civil Rights (OCR), recently announced a settlement with five healthcare providers collectively known as Cadia Healthcare Facilities. This settlement resolves potential violations of the HIPAA Privacy and Breach Notification Rules. Cadia Healthcare provides rehabilitation, skilled nursing, and long-term care services in Delaware. […]

The Patient’s Right to Restrict: What You Need to Know

When it comes to HIPAA, one of the lesser-known patient rights is the right to request restrictions on the use and disclosure of their protected health information (PHI). For staff and providers who are just starting to learn about compliance, this right can feel confusing. Do you always have to agree? What happens if you […]

Using AI in Healthcare: Key Compliance Considerations for Tools and Devices

Using Artificial Intelligence in Healthcare

Artificial intelligence (AI) is revolutionizing healthcare. From smart diagnostic tools and virtual assistants to AI-enabled devices like smart glasses or wearable monitors, this technology helps providers streamline workflows, improve accuracy, and enhance patient engagement. But as these tools become more common in clinical and administrative settings, it’s critical to ensure they’re used safely, ethically, and […]

TMC Expert On HIPAA 2.0

HIPAA 2.0

Nancy Ware, HIPAA Compliance Specialist at Total Medical Compliance, recently joined the ComTech Network Solutions podcast to cut through the noise surrounding “HIPAA 2.0.” With so much speculation about upcoming changes to the HIPAA Security Rule, Nancy provides clear, practical insight into what’s actually proposed—and what it means for healthcare providers. While no final rule […]