Plain-language answers, kept current.
Compliance and security writing is usually either marketing or unreadable. We are aiming for the third thing: accurate, dated, and useful to somebody running a practice.
What is being written first
This section runs on a content collection so it can grow. These are the pieces queued for publication, each reviewed against primary sources before it goes live.
The 2026 HIPAA Security Rule changes, explained
What is proposed, what it means for an independent practice, and what to start on now. Reviewed against HHS guidance and re-dated whenever the rule moves.
A practice’s security risk analysis checklist
What a real risk analysis contains, what auditors look for, and how to tell whether the one you have is adequate.
What to do in the first hour of a ransomware incident
A one-page runbook for a practice manager, written for the moment when nobody is thinking clearly.
Business associate agreements: what to actually check
Which vendors need one, what a good one says, and the annual verification requirement now being proposed.
Opening a practice: the IT timeline
A ninety-day sequence with the lead times that most often cause delayed openings.
Choosing an IT provider: questions worth asking
Including the ones we would find uncomfortable. A buying guide rather than a sales page.
We would rather show an honest empty shelf than fill this page with generic filler. Each piece will carry a review date and link its sources. If there is something you would find useful, tell us and we will write that first.
Want to be told when these publish?
Ask us and we will add you to a short list. No newsletter, no drip campaign — a note when something worth reading goes up.

