hipaa.app Blog

hipaa.app updates, status and compliance updates

Latest Posts

HIPAA

HIPAA Compliant Fax: What Your Practice Must Document

Fax is still the default channel for referrals, prior auth, and records requests. Here is what a HIPAA compliant fax setup actually requires — vendor BAA terms, workflow controls, and the documentation an OCR investigator will ask for.

Carl B. Johnson Carl B. Johnson
HIPAA

HIPAA Texting Patients: What Your Practice Must Document

Texting patients is permitted under HIPAA — but only with a documented warning, a recorded patient preference, a signed BAA with your messaging platform, and a risk analysis that mentions SMS. Here's the workflow and the paper trail.

Carl B. Johnson Carl B. Johnson
HIPAA

HIPAA Disposal of PHI: Methods, Vendors, and Records

Paper in the dumpster, hard drives in the copier, labeled specimen containers in the regular trash. A practical walkthrough of HIPAA disposal of PHI: acceptable methods, vendor contracts, role assignments, and the destruction records that prove you did it.

Carl B. Johnson Carl B. Johnson
De-Identification

Safe Harbor De-Identification: The 18-Item Checklist

A marketing vendor asks for "de-identified" data and your billing team exports a CSV with dates of service and full ZIP codes. That file is still PHI. Here's exactly what safe harbor de-identification requires, where practices fail it, and what to document.

Carl B. Johnson Carl B. Johnson