HIPAA Compliance
Go deep on HIPAA: what the law actually requires, what counts as protected health information (PHI) and who's in scope, the administrative/physical/technical safeguards, the risk analysis OCR looks for, breach notification, and how to run it as a continuous program. The healthcare deep-dive spoke — take it after the Compliance Frameworks hub. Educational, not legal advice.
"We know our PHI, we've done a real risk analysis, our BAAs are in place, and we have a breach plan — HIPAA as a running program"
6 Interactive Sessions
Short, interactive sessions — watch it work, steer it, then build it yourself. Go deeper anytime with the full code walkthrough.
- 1
What HIPAA actually is — a law, not a certificate
HIPAA is a US federal law that protects health information, enforced by HHS's Office for Civil Rights — made of rules you comply with and document, not a certificate the government hands you.
- 2
PHI and who's in scope — scope follows the protected health information
HIPAA scope follows the PHI: only the systems, people, and vendors that touch protected health information are in scope.
- 3
The safeguards — how HIPAA says to protect ePHI
The HIPAA Security Rule organizes protecting ePHI into three safeguard categories — administrative, physical, and technical — and much of it is the same shared security core the hub already taught, just sorted into buckets.
- 4
Risk analysis & documentation
The risk analysis is the cornerstone of the HIPAA Security Rule — a thorough, current assessment of the risks to your ePHI — and it's the #1 thing OCR looks for.
- 5
Breach notification — what triggers it, who you tell, and when
Not every incident is a reportable breach — a risk assessment decides — and when it is, you notify individuals, HHS, and (for large breaches) the public, without unreasonable delay.
- 6
Staying compliant
HIPAA is an ongoing program, not a one-time project: you keep the safeguards operating, the risk analysis current, and the evidence flowing — so you can demonstrate compliance at any time.
Production patterns you'll master
Synthetic data included
- Covered entity vs business associate examples
- PHI / ePHI examples
- The three safeguard categories
- Breach decision aid
What you walk away with
Shareable portfolio
A public URL showing your module timeline, patterns mastered, and completion status.
All the code
Download everything as a ZIP — pipelines, guardrails, deployment configs. Yours forever.
Module walkthrough
Each module documented with deliverables and the production pattern you implemented.
Ready to build your hipaa compliance?
First course free. $20 per course after that.