by Kim Singletary | Jun 3, 2026 | Blog
In HITRUST, illustrative procedures are not optional examples; they define exactly how assessors test your controls. Miss one evaluative element and your score can drop an entire tier. How Assessors Think and Why it Matters HITRUST scoring has two distinct layers that...
by Kim Singletary | May 20, 2026 | Blog
Why your high-rise lease may deserve a seat at your HITRUST r2 scoping table This post reflects the practitioner’s perspective on a scoping factor that reasonable people read differently. For authoritative guidance, consult HITRUST’s published scoping...
by Kim Singletary | May 19, 2026 | Guide
The Guide to 405(d) Health Industry Cybersecurity Practices How to Advance Your Cybersecurity Program Following Federally Recognized Standards The Beginning In January 2021, HR 7898 became law as an amendment to the Health Information Technology for Economic and...
by Kim Singletary | May 18, 2026 | Guide
From HIPAA Risk Analysis to Risk Management: A Step-by-Step Approach What You Need to Know Healthcare cybersecurity expectations have never been higher. Threats are sharper, regulators are more vocal, and the cost of an undefended risk analysis, or of failing to...
by Kim Singletary | May 15, 2026 | Guide
Cloud Risk Insights from a HIPAA Perspective Healthcare Organizations Are Increasingly Exposed to Cloud Risk If you’re a covered entity or business associate, you already understand the importance of protecting electronic protected health information (ePHI). But as...