Questions? Talk to a Real Person via our Live Chat
Windows Azure HIPAA Compliance: What Healthcare Organizations Must Configure
By Gil Vidals, , HIPAA Blog, HIPAA Windows, Resources

Windows Azure HIPAA Compliance: What Healthcare Organizations Must Configure

Windows Azure HIPAA compliance is not automatic — and assuming it is one of the most common ways healthcare organizations accidentally violate HIPAA. Microsoft Azure can support HIPAA-regulated workloads, including Windows virtual machines and databases, but HIPAA compliance depends entirely on how Azure is configured, governed, and monitored. Simply running Windows servers on Azure does... Continue reading
Is Gmail HIPAA Compliant?
By Brenda Medel, , HIPAA Blog, HIPAA Email, Resources

Is Gmail HIPAA Compliant?

Short answer:No — Gmail is NOT HIPAA compliant by default.However, Gmail can be configured to support HIPAA compliance if (and only if) very specific technical, administrative, and contractual requirements are met. This distinction is where many healthcare organizations get into trouble. Simply using Gmail — even with Google’s strong security — does not make your... Continue reading
Common HIPAA Compliance Mistakes Healthcare Practices Still Make
By Brenda Medel, , HIPAA Blog, Resources, Security

Common HIPAA Compliance Mistakes Healthcare Practices Still Make

Common HIPAA compliance mistakes are still the leading cause of OCR investigations, breach notifications, and costly penalties across the healthcare industry. What surprises most organizations is that these violations rarely come from sophisticated cyberattacks — they come from everyday operational mistakes involving email, websites, staff workflows, and vendors. →   Not sure where your biggest HIPAA... Continue reading
Patient Intake Form: How to Create a HIPAA-Compliant Version
By Alicia Vidals, , HIPAA Blog, HIPAA WordPress, Resources

Patient Intake Form: How to Create a HIPAA-Compliant Version

A patient intake form is one of the first systems that collects protected health information (PHI).Yes — patient intake forms are regulated under HIPAA the moment they collect identifiable health data. Many healthcare organizations still rely on emailed PDFs or general-purpose form builders. These tools feel efficient, but they often lack the safeguards required by... Continue reading
Is Dropbox HIPAA Compliant? What Healthcare Organizations Need to Know
By Brenda Medel, , HIPAA Blog, HIPAA Cloud, Resources

Is Dropbox HIPAA Compliant? What Healthcare Organizations Need to Know

No — Dropbox is not HIPAA compliant by default. Dropbox can only be used for HIPAA-regulated data if the organization is on an eligible plan, has a signed Business Associate Agreement (BAA), and correctly configures security controls. Even then, HIPAA compliance responsibility remains with the healthcare organization, not Dropbox. This answer aligns with HHS guidance,... Continue reading
HIPAA Basics V: The Comprehensive Guide to the HIPAA Breach Notification Rule
By Josh Vidals, , HIPAA Blog, HIPAA Compliance, Resources

HIPAA Basics V: The Comprehensive Guide to the HIPAA Breach Notification Rule

Cyberattacks continue to dominate healthcare data incidents, and OCR investigations are becoming more frequent — especially into late-reported breaches. For covered entities, the HIPAA Breach Notification Rule isn’t just a compliance requirement. It’s become a core operational risk that directly affects reputation, patient trust, and financial stability. Many organizations still scramble when a breach occurs.... Continue reading