
The Copier Down the Hall Might Be Storing More PHI Than You Think
Most practices think of the office copier as furniture — something the front desk uses to scan insurance…

The Person Logging Into Your Patient Portal Might Not Be Your Patient
Most HIPAA security work focuses on the systems staff use — the EHR, email, the front-desk workstations. The…

Your Biggest HIPAA Risk in 2026 Might Not Be Your Practice — It Might Be Your Vendor
You can lock down every workstation in your office, encrypt every laptop, and pass your own HIPAA risk…

The X-Ray Sensor on Your Network Might Still Be Running Windows XP
Your practice’s IT security probably focuses on computers: the front desk PC, the laptops, maybe a server. But…

The QR Code in Your Waiting Room Might Not Be Yours Anymore
Your check-in kiosk has one. So does the payment terminal, the parking validation machine, and probably a flyer…

That Urgent Call Might Be an AI Clone of Your Doctor’s Voice
A voicemail greeting is enough. Three to ten seconds of someone’s voice — a podcast clip, a conference…

That “Helpful” Browser Extension Might Be Bypassing Your Practice’s MFA
Multi-factor authentication is supposed to be the safety net that stops a stolen password from becoming a full…

Zero Trust Architecture: What It Actually Means for Your Practice’s HIPAA Compliance in 2026
“Zero trust” gets thrown around a lot in cybersecurity marketing, usually without much explanation of what it actually…

FedRAMP 20x Explained: What the 2026 Consolidated Rules Mean for Cloud Providers
If your company sells cloud software to the federal government, the rules just changed in a big way.…

AI Medical Scribes: Are They Actually HIPAA Compliant in 2026?
A federal class action against Sutter Health puts ambient AI scribes under the microscope. Here are 5 HIPAA…








