Questions? Talk to a Real Person via our Live Chat
Is Gmail HIPAA Compliant?
By Brenda Medel, , HIPAA Blog, HIPAA Email, Resources

Is Gmail HIPAA Compliant?

Short answer:No — Gmail is NOT HIPAA compliant by default.However, Gmail can be configured to support HIPAA compliance if (and only if) very specific technical, administrative, and contractual requirements are met. This distinction is where many healthcare organizations get into trouble. Simply using Gmail — even with Google’s strong security — does not make your... Continue reading
Common HIPAA Compliance Mistakes Healthcare Practices Still Make
By Brenda Medel, , HIPAA Blog, Resources, Security

Common HIPAA Compliance Mistakes Healthcare Practices Still Make

Common HIPAA compliance mistakes are still the leading cause of OCR investigations, breach notifications, and costly penalties across the healthcare industry. What surprises most organizations is that these violations rarely come from sophisticated cyberattacks — they come from everyday operational mistakes involving email, websites, staff workflows, and vendors. →   Not sure where your biggest HIPAA... Continue reading
Is Dropbox HIPAA Compliant? What Healthcare Organizations Need to Know
By Brenda Medel, , HIPAA Blog, HIPAA Cloud, Resources

Is Dropbox HIPAA Compliant? What Healthcare Organizations Need to Know

No — Dropbox is not HIPAA compliant by default. Dropbox can only be used for HIPAA-regulated data if the organization is on an eligible plan, has a signed Business Associate Agreement (BAA), and correctly configures security controls. Even then, HIPAA compliance responsibility remains with the healthcare organization, not Dropbox. This answer aligns with HHS guidance,... Continue reading
Healthcare Apps on Linux: Best Practices for Secure Deployment with Managed HIPAA Hosting
By Brenda Medel, , HIPAA Blog, HIPAA Linux, Resources

Healthcare Apps on Linux: Best Practices for Secure Deployment with Managed HIPAA Hosting

From Dev to Production: Secure Linux Deployment for Healthcare Apps Developers love Linux because it’s fast, scriptable, and reliable. But when you’re deploying a healthcare application—one that touches Protected Health Information (PHI)—Linux must be more than stable. It must be secure, hardened, monitored, and fully HIPAA-compliant. And that’s where most engineering teams run into trouble.... Continue reading
HIPAA Compliance for Dental Offices: The Complete Guide
By Brenda Medel, , HIPAA Blog, HIPAA Compliance, Resources

HIPAA Compliance for Dental Offices: The Complete Guide

HIPAA compliance for dental offices is essential for protecting patient information, avoiding costly violations, and maintaining patient trust. Dental practices manage sensitive information daily—insurance details, medical histories, X-rays, treatment plans, referrals—and because this qualifies as protected health information (PHI), every dental office must comply with HIPAA’s Privacy, Security, and Breach Notification Rules. This guide explains... Continue reading
The 5 Most Common HIPAA Mistakes Small Practices Make (and How to Fix Them Fast)
By Brenda Medel, , HIPAA Blog, Resources, Security

The 5 Most Common HIPAA Mistakes Small Practices Make (and How to Fix Them Fast)

If you run a small healthcare practice, you’re juggling everything—patient care, scheduling, billing, recordkeeping, and often IT. That’s exactly why HIPAA mistakes for small practice owners are so common. And unfortunately, even a single misstep can lead to fines that start at $10,000 per violation, according to the U.S. Department of Health & Human Services... Continue reading