Skip to main content
CoreFolioHIPAA

CoreFolio Learn

How-to

Practical walkthroughs for the work HIPAA actually requires — risk analysis, gap analysis, vendor reviews.

35 articles in this topic

What is a fractional HIPAA compliance officer?

HIPAA requires every covered entity to name a Privacy and Security Official. Who typically fills the role in small practices, and when an outsider can serve.

10-minute read

Does HIPAA apply to small practices?

Many small practices assume they are too small for HIPAA, but the law has no size exemption. The two-part test for whether you are a covered entity.

6-minute read

HIPAA risk analysis template for small practices

What a defensible HIPAA risk analysis template must include, how to structure it for Office for Civil Rights (OCR) review, and why many free templates fail the accuracy requirement.

8-minute read

What goes in a HIPAA risk management plan

The risk analysis gets attention, but Office for Civil Rights (OCR) also requires a risk management plan. What it must contain, how it ties to the risk analysis, and what to include.

6-minute read