Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
Writing

Things we know because we ran into them.

No thought leadership, no trend pieces, no “five ways to.” Specific things about specific systems and specific regulations, written for a practice administrator or a compliance officer rather than for a search engine.

Compliance 08 Jul 2026

What OCR actually asks for in a data request

Eleven document categories, taken from a real request. Go down the list and mark which ones you could produce this week.

7 min
Compliance 24 Jun 2026

What a real risk analysis contains, and what the SRA Tool produces

A completed HHS Security Risk Assessment Tool questionnaire is not a risk analysis. OCR settlements have said so repeatedly. Here is the difference.

8 min
Dental 10 Jun 2026

Eaglesoft, dba, and sql

A practice management system that shipped with hardcoded database credentials, and what to actually do about it in a live operatory.

6 min
How we think 27 May 2026

Why we do not run our own 24/7 SOC

The arithmetic of covering one seat around the clock, and what we do with the money instead.

6 min
Behavioral health 13 May 2026

42 CFR Part 2 stopped being a paper rule in February

Civil enforcement began February 16, 2026. Almost no generalist IT provider has heard of it, and it sits on top of HIPAA rather than instead of it.

7 min
Acquisitions 29 Apr 2026

IT diligence for practice acquisitions: what to look for

What a buyer should check, what a seller should clean up first, and what post-close integration actually costs.

8 min
Compliance 15 Apr 2026

The evidence file

What it is, what is in it, and why the security program and the compliance evidence are the same work.

6 min
Imaging 25 Mar 2026

Your imaging server is probably on the internet

A late-2025 scan found 3,627 internet-accessible DICOM servers. CVE-2025-0896 is why the free ones are over-represented.

5 min
Next step

See where you actually stand.

Fifteen questions, each mapped to a Security Rule citation. You get a scored result naming the specific §164 requirement behind every gap. No call required to see it.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.