Paul R. Hales

Attorney, Attorney at Law LLC,

Paul R. Hales, J.D. is widely recognized for his expert knowledge and ability to explain the HIPAA Rules clearly in plain language. Paul is an attorney licensed to practice before the Supreme Court of the United States and a graduate of Columbia University Law School with an international practice in HIPAA privacy and security. He is the author of all content in The HIPAA E-Tool®, an Internet-based, complete HIPAA compliance solution with separate editions for Covered Entities, Business Associates, Health Plans and Third Party Administrators.



NIST/OCR–HIPAA Risk Analysis & Risk Management Explained Step-by-Step

Risk Analysis and Risk Management (RA-RM) are OCR’s top enforcement priority and the basis of every HIPAA Compliance program. RA-RM steps are easy to follow - if you know the steps. But the HIPAA Rules do not lay out specific RA-RM steps. According to OCR the HIPAA RA-RM steps are easy to find. They simply are certain procedures explained by the National Institute of Standards and Technology (NIST) in manuals that are free to download.

New HIPAA Encryption Rules for Email & Text Message and Mandatory Exception for Patients

Regular (unencrypted) Email and Text Messaging containing Protected Health Information (PHI) are effective engagement and communication tools that patients like and have the right to use.

New HIPAA Rules for Text Messaging & Email

Regular (unencrypted) Email and Text Messaging containing Protected Health Information (PHI) are effective engagement and communication tools that patients like and have the right to use.

HHS Mandatory Email & Text Message Encryption Rules with Only One Exception for Informed Patients

HHS and CMS have confirmed the requirement that all Emails and Text Messages containing Protected Health Information (PHI) must be encrypted.