Things we know because we ran into them.
No thought leadership, no trend pieces, no “five ways to.” Specific things about specific systems and specific regulations, written for a practice administrator or a compliance officer rather than for a search engine.
What OCR actually asks for in a data request
Eleven document categories, taken from a real request. Go down the list and mark which ones you could produce this week.
What a real risk analysis contains, and what the SRA Tool produces
A completed HHS Security Risk Assessment Tool questionnaire is not a risk analysis. OCR settlements have said so repeatedly. Here is the difference.
Eaglesoft, dba, and sql
A practice management system that shipped with hardcoded database credentials, and what to actually do about it in a live operatory.
Why we do not run our own 24/7 SOC
The arithmetic of covering one seat around the clock, and what we do with the money instead.
42 CFR Part 2 stopped being a paper rule in February
Civil enforcement began February 16, 2026. Almost no generalist IT provider has heard of it, and it sits on top of HIPAA rather than instead of it.
IT diligence for practice acquisitions: what to look for
What a buyer should check, what a seller should clean up first, and what post-close integration actually costs.
The evidence file
What it is, what is in it, and why the security program and the compliance evidence are the same work.
Your imaging server is probably on the internet
A late-2025 scan found 3,627 internet-accessible DICOM servers. CVE-2025-0896 is why the free ones are over-represented.