Five Nines Blog

Five Nines Experts Sharing Actionable IT Advice

 

Strategic Planning

What Good Looks Like: A Vendor Risk Management Program for Healthcare Under HIPAA (The CFO Governance View)

What Good Looks Like: A Vendor Risk Management Program for Healthcare Under HIPAA (The CFO Governance View)

The Five Functions a Defensible Healthcare Vendor Risk Program Must Operate Tiering and inventory of all vendors handling ePHI. Due diligence proportional to vendor criticality....

Read More
What a Vendor BAA Actually Obligates the Vendor To, and What It Does Not: The CEO Accountability View

What a Vendor BAA Actually Obligates the Vendor To, and What It Does Not: The CEO Accountability View

Where the Vendor's BAA Obligations End and the CEO's Program Begins A healthcare CEO whose organization runs on cloud, software-as-a-service, or any third-party platform handling...

Read More
The HIPAA Security Rule Is Changing for the First Time in Over a Decade: What a Healthcare CEO Needs to Know and Do Now

The HIPAA Security Rule Is Changing for the First Time in Over a Decade: What a Healthcare CEO Needs to Know and Do Now

Why the HIPAA Security Rule Is Being Revised — And What Changed Since 2013 The HIPAA Security Rule's last meaningful update came through the Omnibus Rule in 2013. In 2013, the...

Read More
What Good Looks Like: A HIPAA Risk Analysis That Survives an HHS Audit

What Good Looks Like: A HIPAA Risk Analysis That Survives an HHS Audit

Why the CEO Needs to Engage With the Risk Analysis, Not Just File It A healthcare CEO walking into the executive review is rarely asked to read the organization's HIPAA Risk...

Read More
What Good Looks Like: A Clinical Incident Response Runbook

What Good Looks Like: A Clinical Incident Response Runbook

The Six Elements a Clinical Incident Response Runbook Must Include Contact list with clinical leadership. Decision tree (clinical impact severity). Escalation including clinical...

Read More
Telehealth Security: The BAA Chain Most Clinics Miss, and the CFO Vendor-Risk Gap

Telehealth Security: The BAA Chain Most Clinics Miss, and the CFO Vendor-Risk Gap

Why the Telehealth BAA Chain Is a CFO Responsibility A clinic CFO walking into telehealth budget discussions typically sees the primary platform line. How the Telehealth Vendor...

Read More
Common HIPAA Risk Analysis Mistakes That Fail HHS Audits: The CEO Accountability View

Common HIPAA Risk Analysis Mistakes That Fail HHS Audits: The CEO Accountability View

The Five Risk Analysis Mistakes That Show Up in HHS Findings Incomplete scope (missing systems or vendors). Generic threat language (template rather than specific). Missing...

Read More
The 10 HHS Audit Findings Most-Cited at Healthcare Organizations in 2026

The 10 HHS Audit Findings Most-Cited at Healthcare Organizations in 2026

What This Year's HIPAA Enforcement Record Has in Common The pattern is not subtle. HHS is not citing novel technical failures. The agency is citing the same governance and...

Read More
Structuring a Hospital's Security Operations Capability: Build vs Buy on a Five-Year Horizon

Structuring a Hospital's Security Operations Capability: Build vs Buy on a Five-Year Horizon

Why Security Operations Is a Capability Budget, Not a Tool Purchase A hospital CFO walking into the security operations decision is not buying a tool stack or a license. The CFO...

Read More
On-Premise vs Cloud-Hosted Clinical Infrastructure: The CFO Investment Lens

On-Premise vs Cloud-Hosted Clinical Infrastructure: The CFO Investment Lens

The Five Dimensions a Cloud vs. On-Prem Decision Actually Requires Capital structure: on-prem requires capital; cloud is operating expense. Operating cost trajectory: long-term...

Read More
email icon

Stay Informed

Subscribe to our newsletter to get fresh insights delivered to your inbox.