Questions? Talk to a Real Person via our Live Chat
Is WordPress HIPAA Compliant? 2026 Requirements, Risks, and Best Practices
By Brenda Medel, , HIPAA Blog, HIPAA WordPress, Resources

Is WordPress HIPAA Compliant? 2026 Requirements, Risks, and Best Practices

WordPress powers millions of websites — including healthcare websites that collect, process, or transmit protected health information (PHI). As HIPAA enforcement expectations increase heading into 2026, many organizations are asking a critical question: Is WordPress HIPAA compliant? If you’re evaluating whether your current WordPress setup meets HIPAA expectations heading into 2026, a HIPAA risk assessment... Continue reading
HIPAA Cloud Misconfigurations: How PHI Gets Exposed in the Cloud
By Brenda Medel, , Cyber Data, HIPAA Blog, Resources

HIPAA Cloud Misconfigurations: How PHI Gets Exposed in the Cloud

HIPAA cloud misconfigurations are one of the most common—and most preventable—causes of healthcare data breaches. As healthcare organizations and SaaS platforms move protected health information (PHI) into AWS, Azure, and Google Cloud, breaches are increasingly caused not by sophisticated cyberattacks, but by incorrect cloud configurations, missing agreements, and misunderstood responsibility models.If you’re already running PHI... Continue reading
Are Google Forms HIPAA Compliant?
By Brenda Medel, , HIPAA Blog, HIPAA Forms, Resources

Are Google Forms HIPAA Compliant?

No — Google Forms are not HIPAA compliant for collecting protected health information (PHI). If you’re asking whether Google Forms are HIPAA compliant, you’re asking the right question. Using the wrong form tool to collect PHI is one of the most common causes of HIPAA violations, especially when forms are used without proper access controls,... Continue reading
Is Gmail HIPAA Compliant?
By Brenda Medel, , HIPAA Blog, HIPAA Email, Resources

Is Gmail HIPAA Compliant?

Short answer:No — Gmail is NOT HIPAA compliant by default.However, Gmail can be configured to support HIPAA compliance if (and only if) very specific technical, administrative, and contractual requirements are met. This distinction is where many healthcare organizations get into trouble. Simply using Gmail — even with Google’s strong security — does not make your... Continue reading
Common HIPAA Compliance Mistakes Healthcare Practices Still Make
By Brenda Medel, , HIPAA Blog, Resources, Security

Common HIPAA Compliance Mistakes Healthcare Practices Still Make

Common HIPAA compliance mistakes are still the leading cause of OCR investigations, breach notifications, and costly penalties across the healthcare industry. What surprises most organizations is that these violations rarely come from sophisticated cyberattacks — they come from everyday operational mistakes involving email, websites, staff workflows, and vendors. →   Not sure where your biggest HIPAA... Continue reading
Is Dropbox HIPAA Compliant? What Healthcare Organizations Need to Know
By Brenda Medel, , HIPAA Blog, HIPAA Cloud, Resources

Is Dropbox HIPAA Compliant? What Healthcare Organizations Need to Know

No — Dropbox is not HIPAA compliant by default. Dropbox can only be used for HIPAA-regulated data if the organization is on an eligible plan, has a signed Business Associate Agreement (BAA), and correctly configures security controls. Even then, HIPAA compliance responsibility remains with the healthcare organization, not Dropbox. This answer aligns with HHS guidance,... Continue reading