Five Nines Blog

Five Nines Experts Sharing Actionable IT Advice

 
When a Third-Party Clinical App Breach Becomes Your Hospital's HHS Problem: The Financial View

When a Third-Party Clinical App Breach Becomes Your Hospital's HHS Problem: The Financial View

Why a Vendor Breach Is the Hospital's Financial Problem A third-party breach involving the hospital's ePHI is the hospital's problem regardless of vendor responsibility. CFOs...

Read More
What Good Looks Like: A Hospital Board's Annual Cyber Risk Briefing

What Good Looks Like: A Hospital Board's Annual Cyber Risk Briefing

Why the CEO Should Design the Board Cyber Briefing, Not Accept What IT Prepares A hospital CEO walking into the next annual board cyber briefing is rarely framed as a governance...

Read More
What Good Looks Like: A Healthcare-Aware Tech-Operations Partnership (The CFO Contract View)

What Good Looks Like: A Healthcare-Aware Tech-Operations Partnership (The CFO Contract View)

Why the Tech-Operations Partnership Contract Is a Governance Instrument A healthcare CFO walking into a Tech-Operations partnership conversation is rarely framed as a contract...

Read More
What Good Looks Like: A HIPAA Risk Analysis That Survives an HHS Audit

What Good Looks Like: A HIPAA Risk Analysis That Survives an HHS Audit

Why the CEO Needs to Engage With the Risk Analysis, Not Just File It A healthcare CEO walking into the executive review is rarely asked to read the organization's HIPAA Risk...

Read More
What Good Looks Like: A Clinical Incident Response Runbook

What Good Looks Like: A Clinical Incident Response Runbook

The Six Elements a Clinical Incident Response Runbook Must Include Contact list with clinical leadership. Decision tree (clinical impact severity). Escalation including clinical...

Read More
Telehealth Security: The BAA Chain Most Clinics Miss, and the CFO Vendor-Risk Gap

Telehealth Security: The BAA Chain Most Clinics Miss, and the CFO Vendor-Risk Gap

Why the Telehealth BAA Chain Is a CFO Responsibility A clinic CFO walking into telehealth budget discussions typically sees the primary platform line. How the Telehealth Vendor...

Read More
How Shadow IT in Clinical Departments Creates the Worst Breaches: The Operations-Leader View

How Shadow IT in Clinical Departments Creates the Worst Breaches: The Operations-Leader View

Why Shadow IT Is an Operational Signal, Not an IT Failure A hospital or clinic COO walking into a shadow IT conversation is rarely framed as a strategic operations question. It...

Read More
Common HIPAA Risk Analysis Mistakes That Fail HHS Audits: The CEO Accountability View

Common HIPAA Risk Analysis Mistakes That Fail HHS Audits: The CEO Accountability View

The Five Risk Analysis Mistakes That Show Up in HHS Findings Incomplete scope (missing systems or vendors). Generic threat language (template rather than specific). Missing...

Read More
Why Your Clinical Platform Vendor's Security Posture Is Not Your HIPAA Compliance: What an Exec Must Own

Why Your Clinical Platform Vendor's Security Posture Is Not Your HIPAA Compliance: What an Exec Must Own

Where the Vendor's HIPAA Obligations End and Yours Begin A healthcare CEO whose organization runs on clinical platform vendors has signed Business Associate Agreements, almost...

Read More
The 10 HHS Audit Findings Most-Cited at Healthcare Organizations in 2026

The 10 HHS Audit Findings Most-Cited at Healthcare Organizations in 2026

What This Year's HIPAA Enforcement Record Has in Common The pattern is not subtle. HHS is not citing novel technical failures. The agency is citing the same governance and...

Read More
email icon

Stay Informed

Subscribe to our newsletter to get fresh insights delivered to your inbox.