HIPAA is complicated, but easily learned. The Datica HIPAA and Interoperability Academy walks you through the intricacies of HIPAA, HL7, and FHIR—from the highest concepts to the deepest details.
Authoritative Guides Written By Industry Experts
This eBook is a downloadable version of our detailed, interactive Digital Health Success Framework. It’s your guide to successfully launching a digital health product.
This guide to GDPR for the healthcare industry will prepare you to do business in the EU and understand how to handle PHI of EU citizens. With Datica, you’ll be ready when GDPR takes effect on May 25, 2018.
This lightweight self-assessment worksheet illuminates the cloud requirements of HIPAA that you need to plan for in your own digital health product.
HIPAA compliance at the application level is different than the infrastructure level. This comprehensive guide explains HIPAA considerations for digital health applications.
This guide is designed to be an educational piece for those just getting started with healthcare integration. It outlines the typical considerations, the technology required, and the players involved.
In this guide are tested formulas and directional advice from the compliance and cloud experts at Datica on how to measure and manage the total cost of ownership to achieve compliance in the cloud.
In this guide, we explain our methodology for calculating healthcare integration total cost of ownership. We make the case that modern, cloud-based technology has fundamentally changed the TCO formula.
This guide will walk you through important definitions and concepts, building on previous learnings. You will emerge armed with a basic understanding to HIPAA’s purpose and rules, your obligations, and ways to address compliance.
Datica walks you through the basics of HITRUST, how much it costs, why it’s important, and why it should be on your radar in the future.
Learning from the rest of the digital economy, how can application program interfaces (APIs) have the same impact in health IT.
Chief Medical Officer
The combination of service-oriented software architecture and robust, open APIs has made possible the transformation of huge swaths in the digital economy.
Chief Medical Officer
The recent announcement by AthenaHealth that their APIs had been called one billion times serves as both a milestone for the use of APIs in healthcare and a reminder that API quality is as important as quantity.
Chief Medical Officer
This guide is intended to give developers an easy to understand, step by step runbook for configuring their AWS RDS instance to be HITRUST CSF ready. In the following sections we’ll walk through the requirements, controls, and configurations for RDS.
Chief Product Officer and Chief Security Officer
This step-by-step guide gives developers easy-to-understand instructions to configure Amazon ElastiCache for Redis instances to be HITRUST CSF ready. In the following sections we walk through the requirements, controls, and configurations for ElastiCache for Redis.
Chief Product Officer and Chief Security Officer
With all the attention on compliance and the need for compliance artifacts, or evidence, to be successful, it’s helpful to understand more about artifacts.
Co-founder & Chief Technology Officer
This guide is intended to give developers a simple way to configure their Cosmos DB service to be HITRUST CSF ready. In this guide we’ll walk through the requirements, controls, and configurations for Azure Cosmos DB.
Chief Product Officer and Chief Security Officer
With ePHI access, business associates are required to sign a HIPAA business associate agreement (BAA). Learn more about business associate agreements here.
Co-founder & Chief Technology Officer
This GDPR data breach notification checklist outlines the steps that should be orchestrated by your data protection officer to ensure GDPR compliance.
Co-founder & Chief Technology Officer
One of the most challenging aspects of any security and compliance program, including GDPR, is breach notification.
Co-founder & Chief Technology Officer
GDPR compliance is an imperative starting May, 2018 for companies who work with data on EU citizens. Understand the fines and penalties in Article 83.
Co-founder & Chief Technology Officer
Cloud Service Providers doing business in the EU are Processors under GDPR—it’s kind of like being a HIPAA Covered Entity in the U.S. Read more on GDPR Service Providers.
Datica Alumni — Former Chief Marketing Officer
This guide helps developers configure their Google Cloud SQL instance to be HITRUST CSF ready. It covers requirements, controls, and configurations for GCP Cloud SQL.
Chief Product Officer and Chief Security Officer
GxP does not have the concept or BAAs or contracts that outline risk like HIPAA does. There is no concept of inheritance or chaining liability. Learn more here.
Datica Alumni — Former Chief Marketing Officer
The HIPAA acronym stands for the Health Insurance Portability and Accountability Act. This HIPAA primer covers HIPAA 101 basics, meaning, entitities, etc.
Co-founder & Chief Technology Officer
If you’re going through a HIPAA security audit by a hospital or payer compliance office, auditing and logging will show that your application is secure.
Chief Product Officer and Chief Security Officer
While HIPAA Compliance at the infrastructure level is heavy on technology, HIPAA Compliance at the application level is more of a blend of technology and policy.
Datica Alumni — Former Chief Marketing Officer
Business associates and subcontractors need a HIPAA disaster recovery contingency plan in place to maintain the integrity of ePHI in case of a disaster.
Co-founder & Chief Technology Officer
HIPAA requires that business associates and covered entities retain multiple types of data for at least six years. Learn what data you need to retain.
Co-founder & Chief Technology Officer
A risk assessment – a HIPAA requirement – is the first thing to do since it frames many decisions you’ll make regarding your security posture.
Co-founder & Chief Technology Officer
Understanding the HIPAA breach policy and having a breach notification checklist can prepare you in case of unauthorized disclosure of ePHI.
Co-founder & Chief Technology Officer
HIPAA encryption strategy is another factor of HIPAA compliance, whether HIPAA SSL, data at rest, Filevault2, firewall encryption, or more.
Chief Product Officer and Chief Security Officer
What exactly is multi tenant cloud and does Datica Compliant Cloud offer a multi tenant environment?
Chief Product Officer and Chief Security Officer
The major part of security in healthcare is HIPAA, and the HIPAA rules changed in late 2013 with the new HIPAA Omnibus that adds subcontractors entities.
Co-founder & Chief Technology Officer
HL7 is a healthcare industry standard for messaging between applications, for example from EHR to PMS. Learn HL7 basics, including HL7 v2 and v3.
Datica Alumni — Former Co-Founder
This deep dive explains HL7 message types, message structure, message segments, codes, fields and the complete anatomy of an HL7 message.
Datica Alumni — Former Co-Founder
HL7 ADT message types are the most common HL7 messages. We explain ADT message structure, segments, and event types, including HL7 ADT message examples.
Datica Alumni — Former Co-Founder
The HL7 acknowledgement message, HL7 ACK, is critical for smooth, ongoing HL7 communication. Learn the nuances of HL7 ACK messages, segments, and codes.
Datica Alumni — Former Co-Founder
The Order Entry (ORM) message is a common HL7 message type. ORM messages contain information about an order, most commonly radiology or lab orders.
Datica Alumni — Former Co-Founder
The HL7 SIU and HL7 SRM message types are HL7 appointment scheduling messages with date and time, resources, services, location, and more appoint info.
Datica Alumni — Former Co-Founder
The Medical Document Management (MDM) message is a commonly used HL7 message type that provides information about new or updated notes or documents.
Healthcare Integration Engineer Team Lead
In this guide, we will walk you through the reasoning, structure, and ways to leverage a maturity model, such as the HITRUST maturity model, to optimize your compliance posture.
Co-founder & Chief Technology Officer
Lets walk through the names, players and timelines for delivering your first HL7 Epic integration or any other EHR integration like Cerner or Allscripts.
Datica Alumni — Former Chief Data Officer
RESTful APIs are the backbone of many webservices today. Having the tools to integrate an not-natively-RESTful interface engine with this common standard opens a lot of possibilities. In the healthcare space, queuing the HL7 properly is critical. In this article, we explore ways to do this properly.
Datica Alumni — Former Co-Founder
The FHIR acronym stands for Fast Healthcare Interoperability Resources. FHIR is a new open sourced interoperability standard of the HL7 organization.
Datica Alumni — Former Chief Data Officer
There’s confusion around the MACRA, MIPs, and APMs goals. It begs the question, Is Meaningful Use dead? Learn the MIPS APM and MACRA acronyms and more.
Datica Alumni — Former Chief Marketing Officer
High performance scores and ratings can be a strategic advantage over competitors. Understand MIPS, including qualifiers, scoring, and threshholds.
Datica Alumni — Former Chief Marketing Officer
In starting a compliance program, there is work to be done before you get to level one of the maturity model. We call this level zero.
Co-founder & Chief Technology Officer
HIPAA attestation is everywhere but are they really compliant? Companies can self-attest to HIPAA compliance because there are no HIPAA certifications.
Co-founder & Chief Technology Officer
The FHIR standard is based on API routes but what should the API route look like? Learn general design principles and guidelines to build RESTful APIs.
Datica Alumni — Former Chief Data Officer
At Datica, we are often asked about SOC 2 Type II and how it relates to HIPAA and HITRUST. This article is to help explain how a SOC 2 Type II audit compares to HIPAA compliance and other regulatory audits in the United States.
Director of Marketing
Getting started with compliance on the cloud is easiest if you have a stepwise approach like the 5-level maturity model outlined in this post.
Co-founder & Chief Technology Officer
To understand FHIR, you must understand the FHIR Resource Object. This entry will help explain its origins and intent with links to help.
Datica Alumni — Former Chief Data Officer
The HIPAA Privacy Rule is important to understand because it explains the types of data, covered entities, and uses of data HIPAA is concerned about.
Co-founder & Chief Technology Officer
Learn about HIPAA enforcement, including who is responsible for enforcing HIPAA violations and compliance, and the fines for violating HIPAA.
Co-founder & Chief Technology Officer
GxP stands for “Good Practice” and is a set of operational controls for Life Sciences organizations working within the confines of the FDA. Learn more about GxP compliance.
Datica Alumni — Former Chief Marketing Officer
HITRUST certification by the HITRUST Alliance enables vendors and covered entities to prove HIPAA compliance based on a standardized framework.
Co-founder & Chief Technology Officer
The acronym PHI stands for Protected Health Information. An individual’s PHI is data on health status, provision of health care, or payment for health.
Co-founder & Chief Technology Officer
What is the definition of a security incident and data breach under HIPAA and GDPR and how do they compare? This article breaks down the key terminology.
Co-founder & Chief Technology Officer
This post discusses HIPAA and different types of hosted infrastructure options, answering the question of why HIPAA is not PCI.
Co-founder & Chief Technology Officer
Chief Medical Officer
To make it easier for you to plan your conference attendance schedule for 2020, we’ve compiled our picks for the 50 must-attend health IT conferences. These events are designed to connect healthcare professionals working in a variety of unique disciplines, touching on hot-button topics for...
Attend a live demonstration of CCMS to see how you can monitor and manage compliance
Register todayThe Digital Health Success Framework is a simple guide for the makers of digital healthcare products.
Explore the framework