Questions? Talk to a Real Person via our Live Chat
HIPAA Compliant Email Providers: The Complete 2026 Guide
By Josh Vidals, , HIPAA Blog, HIPAA Email, Resources

HIPAA Compliant Email Providers: The Complete 2026 Guide

Gmail (through Google Workspace Business Plus or higher), Outlook (through Microsoft 365 Business with the right licenses), and several other enterprise email platforms can be made HIPAA compliant — but only with a signed Business Associate Agreement (BAA) and proper configuration. Free Gmail, free Outlook.com, and consumer email accounts of any kind are not HIPAA... Continue reading
Is Zoom, Teams, Google Meet, Webex, Slack, FaceTime or WhatsApp HIPAA Compliant?
By Josh Vidals, , HIPAA Blog, HIPAA Hosting, Resources

Is Zoom, Teams, Google Meet, Webex, Slack, FaceTime or WhatsApp HIPAA Compliant?

The short answer: Zoom Healthcare, Microsoft Teams (Business/Enterprise), Cisco Webex (paid plans), Google Meet through Google Workspace (paid), and Slack (Business+ and Enterprise Grid) can all be made HIPAA compliant — but only with a signed Business Associate Agreement (BAA). FaceTime, WhatsApp, Signal, Skype (consumer), and all free versions of every major platform are not... Continue reading
UK Biobank Breach: Why Insider Threats Are the Next Major HIPAA Risk
By Josh Vidals, , Cyber Data, HIPAA Blog, Resources

UK Biobank Breach: Why Insider Threats Are the Next Major HIPAA Risk

Healthcare organizations spend millions defending themselves against ransomware, phishing campaigns, and external cyberattacks. But one of the most dangerous threats in modern healthcare security may already have authorized access to sensitive data. The recent UK Biobank breach is a powerful reminder that insider threats are becoming one of the biggest cybersecurity and compliance risks facing... Continue reading
HIPAA Security Rule 2026: What Healthcare Providers Must Do Now
By Josh Vidals, , HIPAA Blog, Resources, Security

HIPAA Security Rule 2026: What Healthcare Providers Must Do Now

Healthcare organizations can no longer treat HIPAA compliance as a one-time setup. The expectations around security, documentation, and accountability are rising—and regulators are making it clear that “good enough” is no longer acceptable. The upcoming HIPAA Security Rule 2026 changes reflect a broader shift: healthcare providers must now actively prove that their safeguards are in... Continue reading
HIPAA Compliant WordPress Hosting: A Real Healthcare Team Evaluation
By Josh Vidals, , HIPAA Blog, HIPAA Hosting, HIPAA WordPress, Resources

HIPAA Compliant WordPress Hosting: A Real Healthcare Team Evaluation

When a healthcare organization evaluates HIPAA compliant WordPress hosting, the decision rarely comes from a single stakeholder. Instead, it involves IT, marketing, compliance, and development teams—all with different priorities. In this case, a pediatric healthcare organization brought together five stakeholders across departments to evaluate their hosting environment and ensure it could securely handle protected health... Continue reading
How to Run a HIPAA Compliant LLM
By Josh Vidals, , Artificial Intelligence, HIPAA Blog, Resources

How to Run a HIPAA Compliant LLM

A HIPAA compliant LLM is not a model you buy off the shelf. It is a large language model deployed inside a compliant environment with the right contracts, safeguards, access controls, and oversight. HHS says cloud service providers that create, receive, maintain, or transmit ePHI on behalf of a covered entity or business associate are... Continue reading