<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Healthcare on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/healthcare/</link><description>Recent content in Healthcare on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/healthcare/index.xml" rel="self" type="application/rss+xml"/><item><title>HIPAA</title><link>https://lesitedefrancois.be/en/compliance/hipaa/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/hipaa/</guid><description>&lt;p&gt;The &lt;strong&gt;Health Insurance Portability and Accountability Act (HIPAA)&lt;/strong&gt; is a United States federal law enacted in 1996 and enforced by the &lt;strong&gt;Department of Health and Human Services (HHS)&lt;/strong&gt; Office for Civil Rights (OCR). HIPAA is not a voluntary standard or certification — it is &lt;strong&gt;mandatory US law&lt;/strong&gt; with civil and criminal penalties for non-compliance (fines up to $1.5M per violation category per year, and criminal penalties including imprisonment). HIPAA applies to &lt;strong&gt;covered entities&lt;/strong&gt; (health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically) and their &lt;strong&gt;business associates&lt;/strong&gt; (any entity that creates, receives, maintains, or transmits Protected Health Information — PHI — on behalf of a covered entity). The law&amp;rsquo;s security requirements are defined primarily in two rules: the &lt;strong&gt;Privacy Rule&lt;/strong&gt; (what PHI can be used and disclosed) and the &lt;strong&gt;Security Rule&lt;/strong&gt; (administrative, physical, and technical safeguards required to protect electronic PHI — ePHI). Key technical requirements include access controls, audit controls, integrity controls, transmission security (encryption), and contingency planning. Unlike prescriptive standards (like CIS or DISA STIG), HIPAA&amp;rsquo;s Security Rule is &lt;strong&gt;flexible and scalable&lt;/strong&gt; — it defines required outcomes but allows organizations to determine the specific technologies used. The &lt;strong&gt;Breach Notification Rule&lt;/strong&gt; requires reporting unauthorized disclosures to HHS and affected individuals within 60 days. HIPAA has no &amp;ldquo;certification&amp;rdquo; — compliance is demonstrated through documented risk assessments, policies, and technical controls.&lt;/p&gt;</description></item></channel></rss>