Skip to main content

Your Email Domain Is Public Information, and Attackers Check It Before You Do

The business office manager at a Critical Access Hospital gets an email from the billing coordinator at the CAH forty

15 Million Records, a $10,000 Fine, and a Company That No Longer Exists: What the MMG Fusion Settlement Means for Your Vendor Relationships

On March 5, 2026, the U.S.

Risk Management Joins Risk Analysis Scrutiny

OCR's Risk Analysis Initiative has now produced 12 enforcement actions, and the program is expanding.

ABC HIPAA Framework Delivers Practical Disaster Recovery That Satisfies 45 CFR 164.308(a)(7) Without the Shelf-Ware

Health care IT teams already know the requirement.

"I Don't Touch PHI" - The Rural Health Care Administrator's Blind Spot

The CEO sits across from the IT team and says it with confidence: "I don't have patient information on my device.

When Interoperability Gets Exploited: What the UPMC-Health Gorilla Incident Means for Your EHR Exchange Logs

On March 13, UPMC began notifying patients that their electronic health records may have been improperly accessed thr

Subscribe to Risk Analysis