Blog
HIPAA email, fax, and forms for clinic teams
Practical articles on the communication work physician offices already do: healthcare email, cloud fax, and personalized intake, with a BAA and an audit trail.
HIPAA training for front-desk messaging, not just the annual video
Front-desk staff send more PHI than almost anyone else. Generic modules miss the inbox, the fax, and the form link they use all day.
TLS, archiving, and the email logs OCR actually asks about
Investigators rarely ask if you "take security seriously." They ask who accessed a message and whether you can prove encryption was on.
Specialty intake forms without creating a new compliance gap
Custom fields for cardiology or nephrology are good care. Copying those packets into a consumer form builder is not.
Analog fax vs encrypted cloud fax: a side-by-side for offices
Both move images of documents. Only one gives you encryption, named users, and a confirmation you can find next year.
Right of access: deliver records through secure email and forms
OCR still penalizes delayed access. The fix is a tracked request path, not a scavenger hunt through paper and personal inboxes.
HIPAA Security Rule updates and what they mean for clinic email
Proposed Security Rule changes raise the bar on technical safeguards. Practices that still run PHI through consumer mail will feel it first.
Vendor breaches and why your fax and form tools are business associates
Healthcare has a high rate of third-party incidents. If a vendor holds your PHI, their breach becomes your notification problem.
Patient portal phishing: train staff before the fake MyChart mail arrives
Health systems keep warning patients about portal look-alike emails. Clinic staff get the same lures, often on the busiest inbox.
AI tools and HIPAA: do not paste patient details into a chatbot
Drafting letters with AI is fine. Dropping a name, DOB, and assessment into a consumer model is a disclosure you may not be able to unwind.
