← All courses
$20

HIPAA Compliance

Go deep on HIPAA: what the law actually requires, what counts as protected health information (PHI) and who's in scope, the administrative/physical/technical safeguards, the risk analysis OCR looks for, breach notification, and how to run it as a continuous program. The healthcare deep-dive spoke — take it after the Compliance Frameworks hub. Educational, not legal advice.

"We know our PHI, we've done a real risk analysis, our BAAs are in place, and we have a breach plan — HIPAA as a running program"

6 Interactive Sessions

Short, interactive sessions — watch it work, steer it, then build it yourself. Go deeper anytime with the full code walkthrough.

  1. 1

    What HIPAA actually is — a law, not a certificate

    HIPAA is a US federal law that protects health information, enforced by HHS's Office for Civil Rights — made of rules you comply with and document, not a certificate the government hands you.

  2. 2

    PHI and who's in scope — scope follows the protected health information

    HIPAA scope follows the PHI: only the systems, people, and vendors that touch protected health information are in scope.

  3. 3

    The safeguards — how HIPAA says to protect ePHI

    The HIPAA Security Rule organizes protecting ePHI into three safeguard categories — administrative, physical, and technical — and much of it is the same shared security core the hub already taught, just sorted into buckets.

  4. 4

    Risk analysis & documentation

    The risk analysis is the cornerstone of the HIPAA Security Rule — a thorough, current assessment of the risks to your ePHI — and it's the #1 thing OCR looks for.

  5. 5

    Breach notification — what triggers it, who you tell, and when

    Not every incident is a reportable breach — a risk assessment decides — and when it is, you notify individuals, HHS, and (for large breaches) the public, without unreasonable delay.

  6. 6

    Staying compliant

    HIPAA is an ongoing program, not a one-time project: you keep the safeguards operating, the risk analysis current, and the evidence flowing — so you can demonstrate compliance at any time.

Production patterns you'll master

PHI ScopingBusiness Associate AgreementsSecurity Rule SafeguardsRisk AnalysisBreach NotificationContinuous Compliance

Synthetic data included

  • Covered entity vs business associate examples
  • PHI / ePHI examples
  • The three safeguard categories
  • Breach decision aid

What you walk away with

Shareable portfolio

A public URL showing your module timeline, patterns mastered, and completion status.

All the code

Download everything as a ZIP — pipelines, guardrails, deployment configs. Yours forever.

Module walkthrough

Each module documented with deliverables and the production pattern you implemented.

Ready to build your hipaa compliance?

First course free. $20 per course after that.