Skip to main content
CoreFolioHIPAA

CoreFolio Learn

What small practices actually need to know.

Plain-English explainers of HIPAA enforcement, the proposed 2026 Security Rule, the California rules that layer on top, and honest reviews of the tools small practices reach for first. Every claim cites the underlying CFR section, Federal Register entry, or OCR press release.

Browse by topic

Latest

The OCR Risk Analysis Initiative, explained

OCR is now investigating small practices that have never had a breach — because they never did a risk analysis. Here is what changed in late 2024, what the rule actually requires, and what a defensible answer looks like.

12-minute read

What OCR actually wants in a risk analysis

HHS's Office for Civil Rights has now settled with dozens of practices for risk analysis failures. The pattern in their investigation letters and resolution agreements tells you exactly what they are looking for.

5-minute read

What goes in a HIPAA risk management plan

The risk analysis gets all the attention, but OCR requires the risk management plan too. Here is what it needs to contain, how it relates to the risk analysis, and what a defensible plan looks like.

5-minute read

The HHS SRA Tool, honestly reviewed

The free HHS Security Risk Assessment Tool is the most common starting point for small practices doing their first HIPAA risk analysis. Here is an honest look at what it does well and where it falls short.

5-minute read