Insights
Plain answers for boards and executive directors
Guidance on HIPAA applicability, privacy claims, cybersecurity, and compliance — written for pregnancy help organizations and healthcare nonprofits that answer to boards, insurers, and the communities they serve.
Articles
-
Security risk assessment
The security risk assessment checklist for volunteer-run clinics
What a security risk assessment is, why the volunteer-scale model raises specific risks, and the item-by-item checklist to run before or alongside a formal assessment.
-
Accreditation readiness
The accreditation-readiness checklist for pregnancy medical clinics
What accreditation surveyors examine in information handling and governance, and the checklist to prepare before a survey. AAAHC is the common accreditor for women’s health centers.
-
Board governance
Who owns technology risk in a healthcare nonprofit
Your IT provider manages systems. Your governing body remains accountable for the arrangement. What the standards already say, and the four questions that close the gap.
-
Risk management
What counts as an incident in a healthcare organization
A compromised mailbox is not only an IT problem. Under the standards you are already held to it is an incident — and where it is recorded decides whether you can prove it.
-
Board governance
Cybersecurity questions every nonprofit healthcare board should ask
The questions a nonprofit healthcare board should ask about privacy, cybersecurity, and governance — framed as oversight, not IT, with what a good answer sounds like.
-
Vendor risk
The vendor-risk checklist for scheduling and client-management systems
Most client data lives inside third-party systems. The checklist to inventory and evaluate them, and when a written agreement or Business Associate Agreement is needed.
-
HIPAA applicability
Does HIPAA apply to your pregnancy help organization?
Most centers that do not bill insurance electronically are not HIPAA covered entities. That is not the end of the risk conversation. Here is the honest answer, what still governs you, and how to align your public language with your real status.
-
Client privacy & stewardship
Guarding her trust: how pregnancy help organizations protect the women they serve
Privacy as stewardship rather than paperwork: what client information a center actually holds, how a volunteer-powered team protects it without a security department, and where to start.
-
Honest privacy claims
Before your website says “HIPAA compliant”: what regulators actually look at
No United States government agency certifies HIPAA compliance. What state regulators compare when a website makes the claim — and the privacy language your organization can prove instead.
Prefer the full briefing for your board?
Guarding Her Trust: The 2026 Executive Briefing covers the HIPAA question, what regulators are pursuing, what insurers and accreditors expect, and a twelve-question self-assessment you can complete in one meeting.
Get the free 2026 briefing