Skip to main content
CoreFolioHIPAA

CoreFolio Learn

How-to

Practical walkthroughs for the work HIPAA actually requires — risk analysis, gap analysis, vendor reviews.

What is a fractional HIPAA compliance officer?

HIPAA requires every covered entity to designate a Privacy Official and Security Official. Here is what that means, who typically fills the role in small practices, and when an outside consultant can serve in it.

10-minute read

HIPAA compliance responsibilities for office managers

In most small practices, the office manager is the de facto Privacy and Security Official. Here is what that means — the specific CFR obligations, the annual cycle, and what documentation needs to exist.

10-minute read

Does HIPAA apply to small practices?

Many small healthcare practices assume they are too small for HIPAA. The law has no size exemption. Here is the two-part test that determines whether you are a covered entity — and what applies if you are.

5-minute read

What must a HIPAA business associate agreement include?

A HIPAA BAA is not just a signature on a template — 45 CFR § 164.504(e) specifies the exact provisions it must contain. Here is every required element, the common drafting gaps OCR finds, and what to verify before you sign one.

7-minute read

HIPAA compliance for physical therapy practices

Physical therapy practices are covered entities subject to the full HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. Here is what the requirements mean in a PT setting — including EHR selection, telehealth, and the 2026 NPP update deadline.

6-minute read

Who needs a HIPAA business associate agreement?

Not every vendor needs a BAA. Not every relationship that feels like it should requires one. Here is the legal test, the categories that consistently require BAAs, the common exceptions, and what happens if you skip one.

6-minute read

HIPAA risk analysis for behavioral health practices

Behavioral health-specific risk analysis considerations: therapy notes, telehealth, session recordings, 42 CFR Part 2, and the unique privacy threats mental health practices face.

9-minute read

What goes in a HIPAA risk management plan

The risk analysis gets all the attention, but OCR requires the risk management plan too. Here is what it needs to contain, how it relates to the risk analysis, and what a defensible plan looks like.

5-minute read

What is a business associate agreement, and who needs one?

A business associate agreement (BAA) is required whenever a vendor handles your patient data. Here is who qualifies as a business associate, what the agreement must contain, and what happens when you skip it.

5-minute read