Teaches students the regulatory and compliance foundations required to work in any healthcare IT role. Covers HIPAA Privacy and Security Rules in operational detail — PHI identification, the 18 identifiers, minimum necessary standard, breach response protocols, and personal liability. Includes the 2026 HIPAA Security Rule changes: mandatory MFA, encryption at rest and in transit, network segmentation, and the 180–240 day compliance window. Extends to BAAs, Joint Commission and CMS readiness, NIST 800-66 risk assessments, and SOC 2 evidence collection for health-tech companies.
Levels: Remember · Understand · Apply · Analyze · Evaluate · Create — highest demands most original thinking.
PHI handling, minimum necessary standard, TPO determination, workforce training requirements, personal liability awareness.
Detection, scope assessment, escalation protocols, notification timelines, remediation documentation.
Break the Glass configuration, audit log analysis, anomaly detection, VIP patient protections, proactive monitoring.
Contract review, subprocessor evaluation, cloud provider HIPAA configuration (AWS/GCP BAAs), E&O insurance requirements.
Joint Commission survey preparation, CMS Conditions of Participation, Meaningful Use/Promoting Interoperability reporting, SOC 2 Type II evidence collection.
Healthcare Compliance Audit Package — Student conducts a simulated compliance audit for a health-tech organization: a NIST 800-66 risk assessment identifying 10+ threats with safeguard recommendations, a BAA review checklist applied to a sample vendor agreement with flagged gaps, a breach response playbook with decision tree and notification templates, and an access audit analysis of a simulated Epic audit log identifying unauthorized access patterns.
AI assistant for de-identified compliance research, policy analysis, and regulatory interpretation.
Audit log analysis, risk assessment documentation, and compliance tracking spreadsheets.
Simulated Epic audit log environment for access monitoring and compliance verification.
Security risk assessment framework specifically designed for healthcare organizations.
SOC 2 evidence collection and compliance automation platforms for health-tech companies.
Take the free AI-guided assessment. We'll build your personalized path through the Foundations and your chosen major.
Start Your Assessment