Skip to content
  • About Us
    • Who We Serve
  • Solutions
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
    • Abyde Incident Response Program
    • Abyde Reseller Program
  • Resources
  • News
  • Events
  • Partners
  • Contact Us
  • Login
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
SIGN UP
BOOK A DEMO

December 2025

End of Year HIPAA Checklist
Abyde News, Best Practices, HIPAA

End of Year HIPAA Checklist: 5 Things to Wrap Up Before 2026

December 30, 2025 Penelope Schweitzer No comments yet

December 30, 2025   You may be done wrapping gifts, but year-end is the perfect time to wrap up compliance loose ends and start the new year with everything tied up in a neat bow.  As your office returns to normal after a post-holiday haze, use the (hopefully) quiet time to get your compliance program in order. Here’s your practice’s end-of-year HIPAA checklist to help you confirm the essentials are handled and documented before 2026 begins.   Confirm HIPAA Training is Complete (and Documented) HIPAA training is required yearly and for all new staff members upon joining the team. As the year comes to a close, it’s strongly recommended to review all training documentation. This should include confirming that any new hires have received HIPAA onboarding training, verifying that all current staff completed training during the calendar year, and ensuring that your practice has the necessary documentation, such as training certificates, to prove it.  Maintaining records of your training is crucial. Not only does it keep your documentation organized, but the Office for Civil Rights (OCR) will require this proof if your practice is ever investigated.   Make sure your Right of Access Process is Crystal Clear to all Staff While patient record requests might seem simple, they’re one of the most common HIPAA violations. In fact, the latest HIPAA fine, exceeding $100,000, was issued due to one patient’s complaint after their records weren’t properly released.  Ensure your staff is aware of the process for releasing patient records and the strict timelines your practice must follow. On a federal level, records must be released within 30 days; however, depending on the state, they may be released even sooner.    Review your Business Associate Agreements (BAAs) This is one of the most common gaps across practices: vendors have access to PHI, but the paperwork isn’t complete or updated. The vendors, or Business Associates (BAs), with which your practice works must also follow HIPAA requirements. To protect your practice, ensure your practice has a Business Associate Agreement (BAA) in place with any vendors you work with. A BAA establishes legal liability if your BA experiences a breach. It also outlines the steps your vendor must take to maintain the security of Protected Health Information (PHI) and how to respond to a data breach.    Confirm your Security Risk Analysis (SRA) is Current The Security Risk Analysis (SRA) is at the foundation of a compliant practice. The SRA is a comprehensive review of all physical, technical, and administrative safeguards your practice has in place. For example, the SRA would review how your practice checks patients, as well as the operating system used on the computers in your practice.  Take this downtime to review your SRA. The OCR expects this to be an active, living document, not something that sits in a folder gathering dust. Ensure you have identified any new risks, such as new software implementations or changes in office layout, and have updated your SRA accordingly.    Update Your Policies and Procedures Operating on “outdated instructions” is a major liability. HIPAA requires that your written policies and procedures accurately reflect your practice’s current daily operations. If you’ve implemented new technology in your practice or changed any internal workflows, now is the time to ensure that the policies and procedures show that.  While policies and procedures might feel like just paperwork, alongside thorough training, they are the primary tools for ensuring your staff knows exactly how to handle and protect patient data.   Streamline Compliance in 2026 If this End of Year HIPAA checklist feels overwhelming to manage while running a busy practice, you’re not alone. The good news? You don’t have to do it manually. Smart compliance software is designed to eliminate the guesswork from the process. From dynamically generating your policies and procedures to automating employee training and guiding you through your SRA, turning hours of “paperwork” into a few simple clicks. Meet with a compliance expert today to see how you can streamline compliance in 2026.

Abyde News, Fines, HIPAA

One Patient Request, Years of Fallout: The Concentra Right of Access Case

December 22, 2025 Penelope Schweitzer No comments yet

December 22, 2025 Well, the Office for Civil Rights (OCR) is back, folks!  After a historic government shutdown, the OCR has announced its first fine.  The recipient of the latest fine is Concentra, Inc., a Texas-based enterprise healthcare provider. While this health organization might have numerous locations, the root of this federal fine and years of legal battles stems from one patient complaint to the OCR.  With the 21st fine of the year, we’re taking it back to the basics: Patient Right of Access.  What Happened?  In February 2018, a patient requested a copy of their medical and billing records from Concentra’s Peoria, Arizona, location. While a Concentra employee forwarded the request to the billing office, the patient did not receive their medical records in a timely manner. The patient sent several requests throughout the year.  In October 2018, Concentra’s Business Associate issued an invoice to the patient for $82.57 for the requested medical records. This amount was disputed.  After months of back-and-forth with Concentra, in December 2018, the patient filed a complaint with the OCR regarding how the healthcare provider handled their record request. Finally, in March 2019, over a year after the initial request, Concentra’s Business Associate provided the health records to the patient for an adjusted rate of $6.50.  Providing the records was just the beginning for Concentra. In the summer of 2020, the OCR notified the healthcare provider that this case indicated noncompliance with the Privacy Rule and provided Concentra with the opportunity to submit mitigating evidence.  Then, in 2021, the OCR proposed to levy a $250,000 penalty. After several more years of legal battles, the OCR settled this case in 2025 with a $112,500 settlement.  Patient Right of Access 101 This lengthy chain of events highlights the importance of promptly and thoroughly addressing patient requests.  Detailed in the Privacy Rule, patients have the right to access their health records within 30 days from the initial request, known as the Right of Access. This timely access empowers patients to make informed decisions about their healthcare. This 30-day timeline applies on the federal level. Depending on the state, your practice may be required to comply with more stringent timelines, as seen in California.  The 30-day timeline is firm, and a practice can only be granted an extension once, for an additional 30 days. In addition to adhering to a 30-day timeline, the fees for copies of records must be reasonable and feasible.  The acceptable fee for providing copies of documents is limited to the cost of labor for copying, supplies, postage, and any provided summary. Alternatively, your practice can charge a flat fee of not more than $6.50 instead of calculating these specific costs.   Keeping Your Practice Compliant (And Your Patients Happy) While following the Right of Access might seem straightforward, it’s one of the most common HIPAA violations practices make. There have been 50+ HIPAA Right of Access enforcement actions levied by the OCR.  With the right compliance program, you can ensure that your staff is aware of all requirements when handling patient requests. Clear policies and engaging training help you respond correctly, on time, and with confidence. Ready to ensure your practice is HIPAA compliant? Schedule a consultation with one of our compliance experts today.

HIPAA Compliant Remote Work
Abyde News, Best Practices, HIPAA

Secure Care, Anywhere: A HIPAA Guide to Telehealth and Remote Work

December 8, 2025 Penelope Schweitzer No comments yet

December 8, 2025   Nearly six years ago, office staff discovered that work from home was a possible model in the healthcare field. Not only did the work move to the house, but digital, at-home healthcare became wildly popular.  If part of your team is still working remotely, whether full-time or part-time, remember: HIPAA isn’t only within the four walls of your organization.  Here’s the good news: staying HIPAA compliant from a home office isn’t meant to be complicated. With the right tools and game plan, you can keep Protected Health Information (PHI) secure from the comfort of your own home.    Lock It Down at Home Remote work doesn’t change the HIPAA baseline. The standard of “minimum necessary” still applies, safeguards still span people, process, and technology, and documentation still matters. Think of compliance like a thermostat you’ve set correctly: once it’s dialed in, it quietly keeps everything in range. First, your staff needs to understand the standard requirements for keeping data secure and be trained on safely accessing PHI remotely. Do your employees know that it’s a big HIPAA no-no to share sensitive patient data with family during casual conversations while working from home? The best way to communicate what to do is through relevant, documented policies, including a remote work policy. It’s essential that work laptops and any devices with access to PHI are encrypted, and that all logins utilize Multi-Factor Authentication (MFA). Encryption and MFA are both additional layers of protection, ensuring that only authorized users can access PHI. Does staff utilize personal devices for work from home? If so, require mobile device management policies, encryption information, and clear off-boarding procedures. Have a lost-device and incident response policy so your team knows exactly who to notify, how to lock or wipe a lost device, and how you’ll assess whether an event rises to the level of a breach. The work station should also include HIPAA-compliant communication through email and phone calls. If you meet with patients through telehealth services, use an encrypted platform and verify the patient’s identity before each session.  As your organization ensures that the proper safeguards are in place, Business Associate Agreements (BAAs) must also be signed for any third parties (encryption services, IT providers, HIPAA-compliant platforms) with access to your PHI. BAAs offset the liability if a breach occurs due to your BA’s negligence. The legal document details exactly what each party is responsible for and how to handle any situation.  While the legal aspects might feel overwhelming, they are necessary to keep patient data safe. With clear policies, trained people, and the right security controls, remote work and telehealth can be both convenient and compliant.   Remote Ready  Remote work and telehealth are no longer temporary fixes to the problem of a pandemic; they’re a simple fact of operating today. HIPAA didn’t change with the scenery, but the right tools can. Intelligent software solutions can provide clear policies, thorough training, compliant BAAs, and more. Telehealth and remote work are here to stay. Keep the safeguards in place, and you’ll be compliant wherever you work, even at home. Meet with a compliance expert to learn more about how your remote organization can achieve HIPAA compliance. 

Recent Posts

  • What OSF Healthcare’s Ransomware Fine Teaches Every Practice About SRAs
  • Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next
  • OCR Ransomware Settlements: 4 Massive HIPAA Fines from April 2026 & How to Avoid Them
  • 2026 OSHA HazCom Deadlines: How the GHS Update Impacts Your Practice
  • 15 Million Reasons to Review Your Business Associates: Lessons from the MMG Fusion Settlement

Recent Comments

No comments to show.

Archives

  • August 2026
  • June 2026
  • May 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • September 2019
  • October 2018
  • July 2018
  • May 2018
  • November 2017
  • April 2017

Categories

  • Abyde News
  • Audits
  • Best Practices
  • Business Associates
  • Cybersecurity
  • Fines
  • HIPAA
  • Legislation
  • OSHA
  • Partner News
  • Facebook
  • Instagram
  • LinkedIn
  • YouTube
Abyde Logo

1.800.594.0883 | info@abyde.com

Automated HIPAA and OSHA Compliance

Our Reviews

From Our Blog
  • Don’t Get Caught Off Guard: HIPAA Audits are Back!
  • Don’t Be a Statistic: Why OSHA Compliance Matters in Healthcare
  • What Money Doesn’t Cover: The True Price of HIPAA Non-Compliance
  • HIPAA: It’s Not Just a Training – Your Guide to Continuous Compliance
Solutions
  • HIPAA for Covered Entities
  • OSHA for Healthcare
  • HIPAA for Business Associates
  • SRA for Covered Entities
  • Abyde Incident Response Program
  • Abyde Reseller Program
Resources
  • News
  • Events
  • Partners
  • HIPAA Badges
  • OSHA Badges
  • Learning Center
  • Compliance FAQs
Company
  • About Us
  • Who We Serve
  • Pricing
  • Contact Us
  • Newsletter
  • Jobs
  • COPYRIGHT © 2026 ABYDE
  • |

  • TERMS & CONDITIONS
  • |

  • PRIVACY POLICY
  • |

  • SECURITY MEASURES
  • |

  • E-SIGNATURE TERMS