Cyber insurance

What your cyber insurance actually covers (and what it doesn’t)

Most small practices assume their cyber policy protects them. Then a claim gets denied for a missing control they didn’t know they needed. Here’s what insurers actually look for before they pay out.

6 min read
Read the guide
HIPAA & compliance

The 5 HIPAA controls every solo practice needs in place today

You don’t need a full compliance program to stay out of trouble. You need five things in place and documented. This is what they are.

5 min read
Read the guide
AI tools

Is your AI transcription tool HIPAA-compliant? Here’s how to check

AI note-taking tools are everywhere in healthcare now. Some have Business Associate Agreements. Most don’t. Here’s the one-step check every practice should run.

4 min read
Read the guide
Security basics

Why small practices are the number-one ransomware target

It’s not random. Attackers go after small practices because the data is valuable, the defenses are thin, and the pressure to pay is real. Here’s how the targeting actually works.

5 min read
Read the guide
HIPAA & compliance

What actually happens when you fail a compliance audit

The fines get the headlines. The real cost is the remediation clock, the reputational hit, and the mandatory follow-up scrutiny. Here’s the full picture.

6 min read
Read the guide
Security basics

How to write a data breach response plan in an afternoon

You don’t need a 40-page policy. You need a one-page plan your whole team can follow at 9pm on a Friday. Here’s what to put in it.

7 min read
Read the guide
Security basics

Two-factor authentication: why it matters and how to turn it on

MFA stops the majority of account takeover attacks. It’s free on almost every major platform and takes ten minutes to set up. Here’s how.

5 min read
Read the guide
HIPAA & compliance

The business associate agreement checklist for small practices

A BAA is required for every vendor that touches your patient data. Most small practices are missing several. Here’s who needs one and what it should say.

5 min read
Read the guide
Cyber insurance

How to review your cyber insurance application before you sign it

The application you sign becomes the baseline for any future claim. Here’s how to read it carefully and avoid the mistakes that lead to denied claims.

5 min read
Read the guide
Security basics

Phishing attacks: how to spot them and train your staff

Most breaches start with a phishing email. Here’s how to recognize them and build a simple staff training approach that actually reduces click rates.

6 min read
Read the guide
HIPAA & compliance

Cloud storage and HIPAA: what Google Drive and Dropbox don’t tell you

Most popular cloud tools are not HIPAA-compliant by default. Here’s what "HIPAA-eligible" actually means and what your practice needs to do.

5 min read
Read the guide
Security basics

Passwords are not enough: a practical guide to access control for small practices

Access control is about more than passwords. Here’s how to think about who can access what, and how to keep that access right as your team changes.

6 min read
Read the guide

Not sure where your practice stands?

The free Cyber Health Score takes 5 minutes and gives you an instant read on your biggest risks. No technical knowledge required.

Get your free Cyber Health Score